Privacy

OneAvail exists to give you one clear view of your time. That only works if you trust how we handle your calendars. Here's the short version.

Read-only by design

OneAvail requests read-only access to your calendars. We read events to build your unified view and calculate your availability. We do not create, edit, move, or delete events on your source calendars.

Your tokens stay server-side

Calendar access tokens and credentials are stored securely on the server and are never exposed to the browser or shared with other users.

You control what's connected

You can disconnect any provider at any time. You can mark any calendar as non-blocking so it never affects your availability, or deactivate it so it's excluded from your view entirely.

Public booking pages stay private

When you share a scheduling link, the public page shows only open time slots. It never exposes event titles, source calendars, attendees, or any private calendar detail.

Minimal logging

We avoid logging the contents of your calendar events. Operational logs are kept to what's needed to keep sync healthy and secure.

Your data ownership

Your connected accounts, calendars, and preferences belong to you. Every record is scoped to your user account and protected by row-level security so only you can access it.

This summary describes the product's intended data practices for the MVP and is not a substitute for a full legal privacy policy.