Privacy, in plain language
Updated July 2026 · Beta. Short version: we never see your inbox, original emails are kept only until you triage them, and you can delete everything with one confirmation.
What we can — and can't — see
SchedYOUall has no connection to your email account. We receive only the messages you (or a Gmail filter you set up and control) forward to your private @in.schedyouall.com address. The only Google permissions we request are calendar ones: reading your calendar list and creating events. No Gmail scopes, ever.
How long forwarded emails live
- Once you've decided every event from an email (added or dismissed), the original — body and attachments — is deleted by the next daily cleanup run.
- If an event's date passes while it's still waiting, it archives itself and its original email is deleted the same way.
- Events we couldn't date are kept at most 30 days, then archived and their originals deleted.
- Emails that contained no events — or that we couldn't read at all — are deleted after 7 days (you see a notice on the dashboard first — nothing disappears silently).
- Gmail's forwarding-verification emails are confirmed and never stored at all. (If automatic confirmation fails, we keep that one message so you can read the code — it's visible in the setup wizard.)
What stays: events you add to your calendar, plus a one-way fingerprint used to spot duplicates. Events you dismiss, or that age out without a decision, are kept for 30 days so you can still find them, then permanently deleted — or clear them yourself, sooner, from the Dismissed and Archived tabs. Not the emails: those are already gone on the schedule above.
The one exception: emails you flag
When you click "Something looks off," we ask before keeping anything. Flagging exists for one purpose only — helping us find and fix mistakes in how we read events — and a flagged email is never used for anything else. If you confirm, with or without a note, here is exactly what happens:
- The full email becomes visible to the SchedYOUall team. The complete forwarded email — subject, body, attachments, the original sender's details, and anything you wrote when forwarding it — is kept past the normal deletion schedule, and a small number of authorized team members read it alongside your note to understand the mistake. No one outside that team has access.
- A stripped-down copy may be kept to prevent the mistake recurring. To make sure the same error stays fixed, we may add the email to our internal test set — but only after a person reviews it and removes or replaces the personal details we can identify (names, email and postal addresses, phone numbers, and similar identifiers, for both you and the original sender). What we keep is the shape of the email, not the people in it. We review the test set periodically and drop cases we no longer need.
- About the person who sent it. A forwarded email also contains information about whoever sent it to you, who hasn't interacted with SchedYOUall themselves. We treat their details with the same care as yours: used only to fix the mistake, stripped from any retained test case, and deletable on request.
Flagging is always optional — an email is never kept this way without your confirmation. You can withdraw a flagged email at any time by writing to privacy@schedyouall.com; we'll delete the full copy we're holding. Deleting your account also removes any flagged emails we still hold. An already-anonymized test case may remain, because it no longer identifies you or anyone else.
Feedback you send us
The app has a "Share feedback" button. Anything you send through it — your message and any screenshots you attach — is stored with your account, is read by the SchedYOUall team, and may also be emailed to the founder. Screenshots are yours to choose: crop out anything you'd rather we not see before attaching. Feedback is kept while we work from it; deleting your account deletes your feedback and its screenshots with everything else, and you can ask us to remove a specific submission sooner at privacy@schedyouall.com.
The waitlist, and what the founder sees
Joining the beta waitlist stores your email address and its status (pending, approved, or blocked) so we can let you in — that's the whole record. To run the beta, the founder also has an admin view of account-level activity: how many emails and events each tester has, whether onboarding finished, and whether the calendar connection is healthy. Those are counts and statuses — it does not give anyone a way to browse the contents of your forwarded emails beyond the flagged-email exception above.
Who processes your data
- Google Gemini (paid tier) reads each forwarded email to extract events. We use the paid API tier specifically because Google does not train models on paid-tier data.
- Supabase (database and file storage), Vercel (app hosting), and Cloudflare (email receiving) run the infrastructure.
- Sentry collects crash reports — with email content, addresses, and tokens scrubbed out before anything is sent.
- PostHog collects product analytics and, during beta, session replay of the app itself — clicks and screens with all typed input masked. Your forwarded emails are never part of a recording.
- Resend delivers the emails we send you (sign-in links and optional reminders) — it sees your email address, how many events are waiting, and the one-time sign-in link inside the message, nothing else.
Your Google tokens are encrypted at rest (AES-256-GCM) and never shown to your browser after sign-in. We don't sell data, run ads, or share anything beyond the processors above.
Deleting everything
Settings → "Disconnect & delete account" removes your events, any stored originals, and your profile, and asks Google to revoke our calendar access — immediately, with one typed confirmation. There's no retention afterward. The only thing that can outlive deletion is a flagged email we've already stripped of personal details for our test set — because at that point it no longer identifies anyone.
Beta honesty
SchedYOUall is in beta. Everything is free right now; features we expect to be paid later are labeled in the app today. If this policy ever changes, the change lands here first, in the same plain language.