Privacy policy
Privacy you can verify.
MyCal.live is built to schedule meetings without turning calendars, contacts, or booking details into advertising data. This policy explains what we collect, why we use it, when it leaves MyCal, and the controls available to hosts and invitees.
Effective and last updated: August 20, 2026
1. Scope, operator, and scheduling hosts
This policy applies to MyCal.live and beta.mycal.live, operated by JAMD Technologies Inc. (together, “MyCal,” “we,” “us,” or “our”). It covers visitors, invitees who request or book meetings, hosts who operate scheduling pages, organization members, and administrators. Use of the service is also governed by the MyCal Terms of Service.
A host decides which event types, questions, contact rules, integrations, notifications, and recipients apply to the host’s scheduling page. MyCal processes invitee information to provide the service to that host. Hosts may have their own privacy obligations and policies; questions about a host’s use of booking information should also be directed to that host.
Controller and processor roles
MyCal acts as a controller or “business” for account administration, service security, abuse prevention, our public website, optional site analytics, and our own legal obligations. For booking information, host-created questions, imported contacts, routing, notifications, and integrations configured by a host or organization, that host or organization generally determines the purpose and means of processing and MyCal generally acts as its processor or “service provider.” The role can vary with the facts and applicable law.
2. Information we collect
Account and identity information
We collect names, verified email addresses, profile images, locale, public MyCal username, account role and status, login history, and security records. When Google, Microsoft, or Apple sign-in is used, we receive the provider’s verified account identifier and basic profile information authorized on the consent screen. Apple may provide a private relay email address. We never receive a Google, Microsoft, or Apple password.
Scheduling and calendar information
We process event types, availability schedules, time zones, holidays, calendar identifiers, selected conflict calendars, free/busy windows, event details needed to detect conflicts or protect travel time, and events MyCal creates or updates. Booking records can include an invitee’s name, verified email, optional phone number and consent, selected time, answers, guests, approval status, meeting history, and rescheduling, cancellation, reconfirmation, or attendance information.
Contacts and relationship controls
For connected Google and Microsoft address books, MyCal reads contact email addresses and supported Google contact-group labels to create host-specific, one-way keyed match values. MyCal does not retain readable provider contact names, phone numbers, notes, or a browsable copy of the provider address book. A host may separately add readable contacts manually or import a Calendly CSV; those records and imported fields are encrypted at rest and remain visible to that host.
Company, travel, and public-source information
When enabled by a host, MyCal derives a business domain from an invitee’s verified email and may collect public company facts, source URLs, industry, size, revenue range, headquarters, and public domain-registration timing. Hosts may correct, exclude, or pin company facts. Travel protection can process a host-provided origin and calendar event locations to estimate travel time.
Messages, files, integrations, and support
We process notification preferences, email delivery information, Telegram connection identifiers, optional SMS numbers and consent, delivery status, host-created follow-up content and attachments, API tokens, webhook destinations, organization and team settings, meeting polls, routing forms, and support questions and feedback.
Usage, analytics, and security information
We collect service events such as account creation, login, administrative actions, feature usage, bookings, delivery outcomes, provider errors, and privacy-safe request identifiers. Server logs may include IP address, user agent, timestamps, and request details needed for security, fraud prevention, reliability, and troubleshooting. If analytics consent is granted, Google Analytics and Clicky may also receive page visits, browser and device information, approximate location, referrer, and interaction data.
Information comes from you, the host whose page you use, connected identity/calendar/contact providers, organization administrators, configured integrations, and public business or domain-registration sources.
3. Google and Microsoft API data
Depending on the connection selected, MyCal requests basic OpenID profile and email data; permission to list calendars; read free/busy availability and calendar events needed for conflict and travel protection; create, update, or delete MyCal-managed events and conferencing on the selected booking calendar; and read contacts for private relationship matching. Connected-account tokens are encrypted at rest and used only to provide these host- or invitee-facing scheduling features.
MyCal’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google calendar, contact, and profile data is not used for advertising, sold, or provided to AI company-research providers or site analytics. It is shared only as necessary to provide or secure the requested feature, with the user’s affirmative direction, or when legally required.
Microsoft
Depending on the connection selected, MyCal requests basic profile information through User.Read, offline access, Calendars.ReadWrite to check selected calendars and manage MyCal-created bookings, and Contacts.Read for private relationship matching. Microsoft tokens are encrypted at rest and used only for the user-facing scheduling functions described here. Microsoft calendar and contact content is not used for advertising or sent to AI company-research providers or site analytics.
A host can choose conflict calendars, connect availability-only accounts, change the booking calendar, and delete private provider-contact match values from MyCal. A user can also revoke MyCal’s authorization from the Google or Microsoft account to stop new provider access. Previously created calendar events and booking records are not automatically erased from the provider’s calendar or from MyCal’s required booking history.
4. How and why we use information
We use information to authenticate users; determine which event types a verified invitee may see; calculate availability; prevent double booking; create and maintain calendar invitations and conferencing; answer booking questions; route, approve, reschedule, cancel, or reconfirm meetings; apply contact and domain controls; produce host analytics; import and export host data; deliver notifications and host-configured follow-ups; provide support; prevent abuse; maintain audit history; enforce plan limits; and improve service reliability.
We do not sell personal information. We do not use calendar, contact, booking, or authentication information for targeted advertising. We do not use Google Workspace or Microsoft Graph data to train general-purpose AI models.
Legal bases where GDPR or similar law applies
- Contract and requested steps: to create and administer a host account, verify an invitee, calculate availability, process a booking request, deliver invitations, and provide features the user requests.
- Legitimate interests: to secure and operate MyCal, prevent fraud and abuse, troubleshoot failures, maintain audit records, understand aggregate service performance, and improve reliability, balanced against the rights of affected people.
- Consent: for optional site analytics, SMS, and other processing where the interface or applicable law asks for consent. Consent can be withdrawn prospectively without affecting earlier lawful processing.
- Legal obligations and claims: to comply with applicable law, respond to valid legal process, keep required records, and establish, exercise, or defend legal rights.
- Host instructions: when MyCal acts as a processor, we process personal information under the host’s or organization’s documented configuration and instructions, subject to our security and legal obligations.
5. Optional AI company research and product guide
Hosts with Company Intelligence can use a platform-provided connection or connect an encrypted API key for supported providers, including Anthropic, DeepSeek, Kimi, OpenAI, OpenRouter, Perplexity, or xAI. For company research, MyCal sends the business domain and public-research instructions—not the guest’s full email, provider contact matches, booking answers, calendar contents, or private host notes. MyCal caches the resulting company facts and source links so later meetings can reuse them without another lookup. Provider processing is also governed by the provider account, routed model provider, and provider terms selected by the host or platform.
Company briefing quality feedback
A signed-in host may rate a briefing helpful or not helpful and change that choice later. We retain the response with the provider, model, and briefing revision to compare aggregate quality without showing administrators the guest identity, briefing text, booking answers, or private host notes in the quality report. A host’s own responses are included in the downloadable account export.
The optional public product guide answers from approved MyCal material and does not perform account actions. Common contact details and secret-shaped values are removed before processing. Questions, answers, and sources are encrypted at rest and normally expire after 30 days; operational metadata such as provider, model, token totals, latency, result status, estimated cost, and optional usefulness feedback may be retained longer for security and service measurement.
6. Analytics and cookies
Google Analytics and Clicky remain off unless a visitor accepts analytics. If accepted, MyCal sends only the site origin and page path; URL query strings are removed so OAuth codes, invitation values, and other query parameters are not reported. Analytics is not given stored contact matches, calendar details, AI keys, booking answers, or message contents.
The preference lasts six months and is shared between live and beta subdomains. Declining keeps Google analytics storage denied and prevents Clicky pageview, interaction, ping, and cookie activity. Essential session, security, and preference storage may still be used to operate the site.
MyCal also recognizes an enabled Global Privacy Control or browser Do Not Track signal by keeping optional analytics disabled and suppressing the analytics-consent prompt while the signal remains active. Because MyCal does not sell personal information or share it for cross-context behavioral advertising, no separate advertising opt-out is required to stop such activity.
8. Security
MyCal uses HTTPS in transit, access controls, scoped permissions, rate limits, one-time verification codes, encrypted sessions and queue jobs, and encrypted storage for sensitive fields including provider tokens, email addresses, booking identities and answers, imported contacts, AI keys, notification destinations, webhook secrets, and company briefings. Private contact matching uses a host-specific keyed value rather than a readable provider address book. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.
9. Retention, export, and deletion
We keep account settings, booking history, host-created content, connected-account information, imported contacts, cached company research, and security records while the account is active and afterward only as reasonably needed to provide the service, meet legal obligations, resolve disputes, prevent abuse, and maintain reliable records. Hosts can remove imported contacts, cached companies, attachments, connections, API tokens, webhooks, and other configurable data from the dashboard.
Specific short-lived records have shorter schedules: unconsumed email and SMS verification challenges are removed after one day; SMS webhook event records after 90 days; public product-guide content normally after 30 days; and company-research operation logs after 400 days. Expired booking holds cease blocking availability. Backups and protected security logs may remain until their normal rotation completes.
A signed-in host can download an account export from Account settings. A confirmed account-deletion request starts a seven-day recovery period, disables the public host page, revokes connected Apple authorization where applicable, removes the profile image, and then deletes the host account and dependent MyCal records. Information already delivered to guests, calendar providers, host-selected integrations, or other meeting participants must be removed from those systems separately.
10. Your choices and rights
You can decline analytics; revoke provider access in the Google or Microsoft account; delete private provider-contact match values; change selected calendars; disable AI research, notifications, SMS, Telegram, webhooks, and optional features; correct profile and company information; export host data; and request account deletion. SMS recipients can reply STOP to opt out and START to resume.
Depending on where you live, you may have rights to know or access personal information; correct inaccurate information; delete information; restrict or object to processing; receive a portable copy; withdraw consent; opt out of certain sale, sharing, targeted advertising, or profiling; and appeal a denied request. MyCal does not currently sell personal information, share it for cross-context behavioral advertising, or use it for decisions producing legal or similarly significant effects.
We may verify identity and authority before acting and may retain information permitted by law, including records needed for security, legal obligations, disputes, and completed transactions. An authorized agent may submit a request where law permits, but we may require proof of authority and direct identity verification. Invitees should identify the host and meeting because the host may control the booking record. If MyCal denies an appeal, residents of jurisdictions that provide the right may contact their state attorney general or other identified regulator. EEA and UK residents may complain to their local data-protection authority. We will not discriminate against anyone for exercising a privacy right.
11. International processing
MyCal and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws; where required, we use appropriate contractual or legal safeguards for transfers.
12. Supplemental U.S. state privacy notice
This section describes categories of personal information MyCal may have collected and disclosed for a business purpose during the preceding 12 months. Actual collection depends on whether someone is a visitor, invitee, host, administrator, or user of an optional feature.
- Identifiers and customer records: name, email, username, provider account ID, optional telephone number, IP address, account and booking identifiers, and similar contact or account information.
- Commercial and service activity: plan or entitlement, bookings, event types, feature usage, notification history, imports, exports, and support interactions.
- Internet and device activity: login and audit events, browser and device data, diagnostic logs, pages and interactions collected after analytics consent, and security signals.
- Location and professional information: approximate analytics location, host-entered origins or event locations used for travel protection, and public company, industry, role, revenue, size, headquarters, and domain-registration facts.
- Contents and inferences: booking answers, messages, attachments, calendar event details needed for the feature, relationship rules, company briefings, and limited inferences used to display an eligible event type or prepare a host.
- Potentially sensitive information: provider authorization tokens, verification and security data, optional exact event or origin locations, and message contents. MyCal uses these only to authenticate, secure, and provide requested features—not to infer characteristics for advertising.
Sources include the individual, the host or organization, connected providers, configured integrations, and public company or registration sources. Business purposes and recipient categories are described in Sections 4 and 7. MyCal has not sold personal information or shared it for cross-context behavioral advertising during the preceding 12 months and does not knowingly do so for people under 18.
13. Children and minors
MyCal is a business scheduling service. A person must be at least 18 and legally able to contract to operate a host or administrator account. Invitees under the age of majority may use a host’s booking page only with the involvement and permission required from a parent, guardian, school, employer, or other responsible organization. MyCal does not knowingly sell or share the personal information of minors. Contact us if you believe a child’s information was submitted without appropriate authority so we can investigate and take appropriate action.
14. Changes to this policy
We may update this policy as MyCal’s features, providers, or legal obligations change. We will post the revised policy at this same public URL and update the date above. If a change materially affects how existing account data is used, we will provide additional notice through the service or by email when appropriate.
15. Contact us and submit a request
For privacy questions, rights requests, consent withdrawal, or appeals, email privacy@mycal.live or use the MyCal Help page. State whether you are a host, invitee, or authorized agent and identify the relevant account, host page, or meeting without sending unnecessary personal information. We will acknowledge and respond within the period required by applicable law.
Please do not send passwords, API keys, verification codes, government identifiers, payment-card details, or other secrets. MyCal.live is operated by JAMD Technologies Inc. The privacy contact above handles data-protection inquiries; MyCal has not represented that it has appointed a statutory data protection officer or regional representative.