🎉 AI Scheduling is live!Try free
HomeLegal
Legal

Privacy Policy

How Diurnly collects, uses, and protects your data. We believe privacy is a feature, not a footnote — this policy is written in plain language so you always know where you stand.

Last updated: September 2026
1

1. Our Privacy Commitment

Your privacy is foundational to Diurnly. We collect only what we need to run a world-class scheduling platform, we never sell your personal data, and we give you full control over what is visible and what is kept private. This policy explains, in plain language, what we collect, how we use it, and the choices you have.

2

2. Information We Collect

We collect information you provide directly and data generated as you use the platform:

  • Account data: your name, email, company, and profile details you choose to add.
  • Calendar data: when you connect Google Calendar, we receive read-only access to busy/free times only — never event titles, attendees, or content.
  • Booking data: invitee name, email, selected times, and answers to your custom intake questions.
  • Technical data: IP address, browser type, device information, and aggregated usage analytics.
3

3. How We Use Your Information

Your data is used to:

  • Provide and improve scheduling, booking, notification, and AI-powered features.
  • Display your public booking page to your invitees — only the information you choose to show.
  • Send booking confirmations, reminders, and platform notifications.
  • Process subscription and paid-event payments through Stripe.
  • Detect, prevent, and address fraud, abuse, and security issues.
4

4. Calendar Data Handling

Google Calendar integration uses OAuth 2.0 with the narrowest scope required to function. We store only busy-time blocks (start and end timestamps) — never event summaries, descriptions, or attendee lists. Synced busy-time data is stored in an isolated, encrypted record scoped to your account. When you disconnect calendar sync, all synced busy-time blocks are permanently deleted within 24 hours. Public availability endpoints return only free slots; no calendar metadata is ever exposed to invitees.

5

5. Data Storage & Security

We protect your data with industry-leading safeguards:

  • Encryption in transit using TLS 1.2+ and at rest using AES-256.
  • Role-based access control with full audit logging on all database operations.
  • Regular security reviews and SOC 2 Type II control maintenance.
  • Encrypted vault storage for sensitive credentials (Stripe keys, OAuth tokens) — never exposed to the frontend.
6

6. Payment Data

Payment information is processed entirely by Stripe, a PCI-DSS Level 1 certified provider. Diurnly never sees or stores your full card number, CVC, or raw payment credentials. We retain only transaction metadata (amount, status, plan type) for billing and record-keeping. See Stripe's privacy policy for details on how they handle card data.

7

7. Data Sharing

We share data only in limited circumstances:

  • Service providers who help operate the platform (Stripe, Google, our email provider) under strict data processing agreements.
  • Legal authorities when compelled by valid legal process or to protect the rights, property, or safety of Diurnly, our users, or others.
  • Your public booking page is visible to anyone with the link — only the information you choose to display (name, bio, event types, availability) is shown. Reviews you approve are public.
8

8. Your Rights & Choices

You are in control of your data. At any time you can:

  • Access, export, or delete your personal data from Settings → Profile and Settings → Danger Zone.
  • Request a full data export by contacting us.
  • Disconnect Google Calendar sync — synced data is deleted within 24 hours.
  • Toggle marketing, booking, and reminder email preferences in your notification settings.
  • Exercise GDPR rights (EU/UK) or CCPA rights (California) — including access, rectification, erasure, portability, and objection — via the Contact page.
9

9. Cookies & Tracking

We use essential cookies for authentication and session management. We use analytics cookies to understand product usage and improve features. You can manage cookie preferences in your browser settings or via our cookie consent banner. We do not use cookies for cross-site advertising tracking.

10

10. Data Retention

We retain account data for as long as your account is active. Booking and meeting records are retained for the life of your account for history and analytics. Deleted accounts have their data permanently removed within 30 days, except where retention is required by law (e.g., financial records for tax compliance).

11

11. Children's Privacy

Diurnly is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it immediately.

12

12. International Data Transfers

Your data may be processed in countries other than your own. We rely on Standard Contractual Clauses and adequate safeguards for international data transfers in compliance with GDPR and other applicable data protection laws.

13

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated via email or in-app notification at least 14 days before they take effect. The "Last updated" date above reflects the most recent revision.

diurnly

Questions about this document? Our team is here to help — reach out and we'll respond within two business days.

Read our Terms of Service