Privacy
OneAvail exists to give you one clear view of your time. That only works if you trust how we handle your calendars. Here's the short version.
Read-only by design
OneAvail requests read-only access to your calendars. We read events to build your unified view and calculate your availability. We do not create, edit, move, or delete events on your source calendars.
Your tokens stay server-side
Calendar access tokens and credentials are stored securely on the server and are never exposed to the browser or shared with other users.
You control what's connected
You can disconnect any provider at any time. You can mark any calendar as non-blocking so it never affects your availability, or deactivate it so it's excluded from your view entirely.
Public booking pages stay private
When you share a scheduling link, the public page shows only open time slots. It never exposes event titles, source calendars, attendees, or any private calendar detail.
Minimal logging
We avoid logging the contents of your calendar events. Operational logs are kept to what's needed to keep sync healthy and secure.
Your data ownership
Your connected accounts, calendars, and preferences belong to you. Every record is scoped to your user account and protected by row-level security so only you can access it.
This summary describes the product's intended data practices for the MVP and is not a substitute for a full legal privacy policy.
