How Diurnly collects, uses, and protects your data. We believe privacy is a feature, not a footnote — this policy is written in plain language so you always know where you stand.
Your privacy is foundational to Diurnly. We collect only what we need to run a world-class scheduling platform, we never sell your personal data, and we give you full control over what is visible and what is kept private. This policy explains, in plain language, what we collect, how we use it, and the choices you have.
We collect information you provide directly and data generated as you use the platform:
Your data is used to:
Google Calendar integration uses OAuth 2.0 with the narrowest scope required to function. We store only busy-time blocks (start and end timestamps) — never event summaries, descriptions, or attendee lists. Synced busy-time data is stored in an isolated, encrypted record scoped to your account. When you disconnect calendar sync, all synced busy-time blocks are permanently deleted within 24 hours. Public availability endpoints return only free slots; no calendar metadata is ever exposed to invitees.
We protect your data with industry-leading safeguards:
Payment information is processed entirely by Stripe, a PCI-DSS Level 1 certified provider. Diurnly never sees or stores your full card number, CVC, or raw payment credentials. We retain only transaction metadata (amount, status, plan type) for billing and record-keeping. See Stripe's privacy policy for details on how they handle card data.
We share data only in limited circumstances:
You are in control of your data. At any time you can:
We retain account data for as long as your account is active. Booking and meeting records are retained for the life of your account for history and analytics. Deleted accounts have their data permanently removed within 30 days, except where retention is required by law (e.g., financial records for tax compliance).
Diurnly is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it immediately.
Your data may be processed in countries other than your own. We rely on Standard Contractual Clauses and adequate safeguards for international data transfers in compliance with GDPR and other applicable data protection laws.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated via email or in-app notification at least 14 days before they take effect. The "Last updated" date above reflects the most recent revision.

Questions about this document? Our team is here to help — reach out and we'll respond within two business days.
Read our Terms of Service