CALLY NOTES / PRIVACY
Your plans are personal.
Here’s where your data goes.
A little clarity on what we keep, what we share to make Timebird work, and the choices that stay yours.
THE QUICK MAP
What goes where.
Different features use different pieces of your information.
- Booking links
- Timebird + Google + Resend
Offered windows, guest details, booking status, email codes and calendar invitations.
- Your account
- Supabase
Email, account identity and sign-in sessions.
- Your calendar
- Google + Timebird
Google holds your events. Timebird reads them to display and work with your plans.
- Tasks & reminders
- Timebird’s database
Task records, reminder schedules and delivery status.
- AI requests
- Timebird + OpenAI
Your question, recent conversation and relevant planning context.
- Slack DMs
- Slack + Timebird
Messages to the bot, replies and the link to your Timebird account.
- Uploaded files
- Google Drive
File bytes pass through Timebird to Drive; events keep attachment links.
When you share a booking link
A booking link publishes its title, description, host display name, appointment duration, guest question and available appointment times. It does not publish your calendar IDs, account emails, private event titles, locations or notes. Timebird uses Google’s availability API on the server to check the calendars you selected.
Guests do not need a Timebird account. We store their name, verified email address, timezone, optional note and question answer, appointment time and booking status. Resend delivers verification and booking emails and receives the recipient address and email content. Google receives the appointment details and guest email to create the calendar invitation and Google Meet.
Verification codes are stored as signed hashes, expire after 10 minutes and allow at most five attempts. Successful verification can be used for 30 minutes. Expired verification records and request rate counters are cleaned up daily. Rate counters use hashed request identifiers; they are not a copy of your calendar.
Booking tables and reservation functions are restricted to the server. Host actions check your signed-in identity. Guest cancellation and rescheduling require a private signed booking link. Anyone you share that private management link with can manage the booking, so keep it for yourself. Public booking links are designed to be shared; pausing one stops new bookings while existing bookings remain manageable.
Confirmed booking records remain in Timebird to support management, retries and booking history. We do not promise a fixed deletion period for these records. Removing a Google connection stops Timebird from accessing that account, but does not cancel existing invitations or delete booking history.
So, is my data private?
Your calendar isn’t published by Timebird or available to other Timebird users just because you connect it. Access to your account is checked before our server reads your connected calendars, tasks or reminders.
Running those features does involve processing personal information. Timebird, and the providers behind the features you use, handle some of your data. For example, asking “Am I free tomorrow?” sends calendar context to OpenAI so it can answer. This page explains those paths and the protections in the current product.
Your existing sharing settings still matter. A calendar shared in Google stays shared there, invited guests can see the event information you send them, and Slack messages follow your workspace’s settings.
Signing in and connecting your calendar
Supabase handles account authentication. If you use email and password, the credentials go to that authentication service. If you choose Google or Apple, Timebird receives the identity information you authorize, such as your account identifier and email address. Connecting Google doesn’t give Timebird your Google password.
Google Calendar access lets Timebird read your calendar list and events, then create, move, edit or delete events when you request it. The permission is broad Calendar access, including writing and deleting events; it isn’t a read-only connection. You can review the permissions on Google’s consent screen.
Google remains the source of your calendar events. Timebird fetches events for the dates being displayed and preloads nearby dates into the app. The assistant also uses a brief server cache to avoid repeating calendar reads. Timebird doesn’t maintain a permanent database copy of your entire calendar, although event details can be saved as part of an assistant action or reply.
Tasks are saved against your Timebird account. Reminder records include their title, scheduled time, delivery status and any linked event or task. This lets your plans stay available and scheduled reminders run in the background.
What the AI gets when you ask Timebird
Chat in the app and in Slack uses OpenAI’s API. A request can include your message, recent conversation, local date and time zone, relevant calendar events, your task list and pending reminders. It also includes identifiers needed to connect an answer or action to the right event.
For events, we send a compact version of the relevant date window: titles, start and end times, calendar names and locations. Notes or guest details may be included when your question asks about them. We trim the context instead of automatically sending every field from every event. Your messages can also contain personal information you choose to type.
Your passwords and Google or Slack access tokens aren’t part of the model prompt. Simply viewing the calendar doesn’t trigger a chat request. You can use the calendar and event editor without asking the AI.
Timebird sets store: false on its OpenAI requests. That opts out of saving a stored Response object; it doesn’t make the request disappear from all provider systems. OpenAI says API data is not used for model training by default unless the API customer opts in. Its default abuse-monitoring logs can retain prompts and responses for up to 30 days, with exceptions, and some caching can still retain application state. We don’t claim a special Zero Data Retention arrangement. See OpenAI’s data controls for the full provider explanation.
Timebird also saves assistant plans and results in its own database to support retries and prevent duplicate actions. These can contain reply text, event references and the fields involved in a requested change. Closing the chat panel doesn’t delete those records.
Slack, attachments and meeting invitations
Connecting Slack is a separate choice
A one-time account-linking flow connects your Slack user and workspace to your Timebird account. Timebird stores that link, the DM channel and the preferences needed to use your calendar. The current bot handles direct messages to Timebird; it doesn’t scan your whole workspace to answer a calendar question.
DM messages, replies and processing records are saved by Timebird to provide conversation context, retry work and avoid duplicate replies. Slack also processes the messages and reminders delivered there. Your workspace’s retention and administrative controls apply; a DM shouldn’t be treated as an end-to-end encrypted vault.
Files stay in your Google Drive
Drive uploads are optional and ask for the narrower Google Drive file permission, rather than access to browse your whole Drive. Upload bytes pass through Timebird’s server to your Drive, while the event stores the file’s link and attachment metadata. Adding a link doesn’t send the file’s contents to the AI.
Removing an attachment from an event, cancelling the editor or disconnecting Timebird doesn’t delete a file already uploaded to Drive. Manage the file and who can open it in Drive. Attaching a file doesn’t automatically grant every guest permission to read it.
Invitations share information on purpose
When you add guests and send event changes, their email addresses and event details go to Google to deliver invitations or updates. Availability searches send the guest identifiers to Google, and Google decides which free/busy information your account can access. Meeting links and event visibility follow the connected calendar’s settings.
How access is protected
- Authenticated requests. Private calendar, task and reminder routes verify the signed-in account, and server queries are scoped to that account’s records.
- Restricted database access. Sensitive connection, assistant, task and Slack tables have row-level security enabled and direct access revoked for browser client roles. Privileged server credentials stay on the server. That server is responsible for checking ownership before using them.
- Encrypted connection tokens. Stored Google access and refresh tokens and Slack installation bot tokens use AES-256-GCM encryption. The server decrypts them when it needs to call a provider.
- Protected connection flows. OAuth state and one-time linking tokens help bind a connection to the right account. Incoming Slack event signatures are verified before the bot accepts them.
- Encrypted connections in transit. The hosted site and provider API connections use HTTPS.
These controls reduce exposure, but Timebird is not end-to-end encrypted. Our servers and providers need to process calendar and chat information to deliver the features. Token encryption doesn’t mean every task, message or event field is separately encrypted with a key only you hold. Authorized service operators may have access to stored records.
No internet service can promise perfect security. This explanation describes implemented controls; it isn’t a claim that Timebird has completed an independent security audit or holds a compliance certification.
Your device and the services behind Timebird
The website uses authentication cookies, and the Mac app persists a sign-in session in its webview storage. Device storage can also hold preferences, such as zoom, and cached task information. These records are protected by your browser, device and macOS account; we don’t describe them as a separate encrypted offline vault.
Timebird also saves a limited calendar snapshot on your device so your plans appear immediately when you reopen it. The snapshot contains event titles, times, locations, notes and display information, and is scoped to your Timebird account. Fresh events are checked in the background. Snapshots expire after seven days and are removed on sign-out; disconnecting a Google account removes its saved events. Google connection tokens, full guest records and file contents are not included in this snapshot. Editing an event still loads its latest Google details before a change is saved.
macOS reminders can show event titles and times in notifications. Choose whether previews appear on your lock screen in macOS notification settings. Slack reminders appear in your conversation with the bot, where Slack’s settings apply.
Vercel hosts the website and server routes. Supabase provides authentication and the database. Google provides Calendar, optional Drive uploads and meeting features; Apple handles sign-in when chosen. OpenAI handles AI requests, and Slack handles the optional bot and its messages. Each provider has its own processing and retention practices.
Hosting and authentication services can process technical information such as IP addresses, device information and request logs to operate and protect the service. The current website has no advertising trackers or third-party analytics SDK. Operational logs and authentication storage still exist.
What disconnecting and deleting actually do
Remove a Google account in Timebird: this deletes that connection and its stored tokens from Timebird’s live database. Your events and Drive files stay in Google. To withdraw the provider grant too, remove Timebird’s access in your Google account’s third-party connection settings.
Disconnect Slack: send disconnect to the bot to unlink your Timebird account. Unlinking removes the account link and its linked Slack reminder records. It doesn’t erase messages already delivered to Slack or Timebird’s previous processing history, and it doesn’t uninstall the workspace app.
Delete an event or task: deleting an event changes the connected Google Calendar. Deleted tasks are currently marked as deleted in Timebird’s database rather than immediately erased. Saved assistant results or Slack messages may still mention the event or task.
Timebird hasn’t yet published fixed retention periods for all account records, assistant history, processing logs and backups. There isn’t a one-click control that purges every copy across Timebird and its providers. Disconnecting, signing out and hiding chat are different from requesting data deletion.
For a copy of your information, an account deletion request or help removing stored records, email hello@timebird.space. We’ll need to verify that the account is yours. We’ll explain what can be removed and any provider, backup or legal limits that apply to the request.
A few things you can control right now
- Connect only the Google accounts you want to use, and review their sharing settings.
- Use the calendar without chat whenever you don’t want to send planning context to the AI. There isn’t currently a per-event AI exclusion switch.
- Keep passwords, access tokens and other secrets out of chat messages and event notes.
- Choose whether to link Slack, allow Drive uploads and show notification previews.
- Disconnect unused accounts, revoke provider access when needed, and contact us about stored-data requests.
This article reflects the product as of October 6, 2026. We’ll update it when data flows or controls change. You can also read the privacy notice. If anything here leaves you wondering, just ask — your plans deserve a clear answer.