Privacy & Data

Last updated: June 2026

What we read from your calendar

iCal/ICS feeds: Hey Julius reads event start and end times to compute free/busy availability. Other team members only ever see whether you are busy during a slot — not what the event is.

Your own event titles are opt-in and off by default. If you turn on "Show my own event titles" in Settings, Julius reads your own iCal event titles so you can see your own schedule with names (e.g. "Team standup") — never other team members' titles, regardless of this setting. Titles are displayed only to you, are never written to our database, and are never shared with other team members or sent to the AI scheduling engine. You can turn this off at any time, and event descriptions, locations, and attendee details are never read regardless.

Separately, when you book a meeting through Hey Julius, the title you type for that meeting is stored (see "What we store" below) and shared with the people you invite — that's the meeting's name, not something read from an existing calendar.

Google and Microsoft OAuth: When you connect via Google or Microsoft, we request free/busy access and — when you use native meeting invites — calendar write access to create events on your behalf. Free/busy data is fetched live when scheduling; we do not build a persistent copy of your calendar. Native event creation uses write access only at the moment you confirm a meeting.

What we store

  • • Your name and email address (provided when you join a team)
  • • Your iCal URL — stored encrypted (AES-128 Fernet). The raw URL is never written to disk in plain text.
  • Google and Microsoft OAuth tokens — if you connect via OAuth, your access token and refresh token are stored encrypted on your account. These allow Julius to read your free/busy data without you re-authorising every session. You can disconnect these at any time from your profile page.
  • • Your timezone and work-hours preference
  • • A secure session cookie so you stay signed in (encrypted, httpOnly, expires in 30 days)
  • • Meeting records created when a meeting is confirmed (title, start/end time, attendee emails)

Who can see your data

Your iCal URL and OAuth tokens are never displayed to other team members — only a masked label is shown (e.g. "Calendar 1 — calendar.google.com"). Team members can see the same free/busy overlay that you can, but no event details.

Team dashboards require login. Access is restricted to team members and the team owner. Only share your team link with people you trust.

Data retention and deletion

We keep your account, calendar connection, and meeting data for as long as your account exists — we do not automatically delete it after a fixed period, since you may return to use the service at any time. Free/busy data itself is never stored at all; it is fetched live from Google/Microsoft/iCal each time and discarded after the request completes.

You can disconnect your Google or Microsoft calendar, or remove an iCal calendar link, at any time from your personal page. Disconnecting removes the stored tokens or URL immediately; Julius will no longer use that calendar.

To remove all of your data across every team, sign in and use the "Delete my data" option on your profile page. This removes your name, email, calendar connections, OAuth tokens, and session from our database immediately and permanently.

How we protect your data

Hey Julius is served over HTTPS. OAuth access and refresh tokens, and any stored iCal calendar URLs, are encrypted at rest before being written to our database — the raw values are never stored in plain text. Session cookies are encrypted, HttpOnly, and scoped to your browser. Access to team data requires sign-in and is restricted to that team's members and owner; there is no public endpoint that returns calendar or meeting data without authentication.

Third-party services

  • Anthropic Claude — used for AI scheduling suggestions. Only free/busy slot summaries are sent, never raw calendar data or event details.
  • Resend — used to send sign-in emails. Only your email address is shared.
  • • No analytics, ad networks, or tracking pixels.

Contact

For privacy questions, data requests, or to request deletion of your account, email [email protected]. We will respond within 5 business days.

Google API data use disclosure

Hey Julius's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google Calendar data solely to display free/busy availability within Hey Julius and to create calendar events when you confirm a meeting. We do not transfer Google user data to third parties except as necessary to provide this scheduling service. We do not use Google user data for advertising, and we do not allow humans to read your Google Calendar data except when required by law or with your explicit permission.