Privacy
Last updated 13 August 2026
What we access, and why
Your calendars. We read events to work out when you are busy, and write time blocks for your tasks. We request the narrowest scopes that allow this: permission to see your calendars and to manage events. We do not read attachments or attendee lists beyond checking whether you declined an invitation.
Your task lists. We read open tasks — their title, priority, due date and estimated duration — so we can schedule them, and we mark a task complete when you delete its calendar block. Where that task list is Google Tasks, this is the same Google account you connected for your calendar: one connection, and we ask for the narrowest scope that still lets us tick a task off. We never create or edit tasks you did not write.
We do not access anything else in your account, and we never write to your calendar except to create, move and remove the blocks we ourselves created. Those blocks are identifiable by a marker in their description.
What we store
Your email address, time zone and scheduling preferences. A copy of your open tasks and where we scheduled them. A record of recent scheduling runs and the reasoning behind them, kept for 30 days. Access tokens for the services you connect, encrypted at rest.
We do not store the contents of your calendar events. Busy time is read, used to compute a schedule, and discarded.
We use your email address to write to you about your own account — at present, only to tell you when a connection has stopped working and your calendar is no longer being updated. We do not send marketing, and there is no list to be added to. Mail is sent from keith@getdiarized.com through Google, the same provider named above — no one new holds your address because of it.
How we protect it
Everything travels encrypted. All connections to Diarized use TLS, and we tell browsers to never fall back to an unencrypted connection.
The access tokens that let us read your calendar and task list are encrypted at rest with a dedicated key that is not stored in the database — someone with a copy of the database alone cannot use them. The contents of your calendar events are not stored at all: busy time is read, used to compute a schedule, and discarded.
Access to the systems holding your data is restricted to the people who operate Diarized, and security procedures are in place to protect the confidentiality of your data. No human looks at it in the normal course of running the service — the Google user data section below sets out the narrow exceptions.
When you disconnect a service or delete your account, we ask the provider to revoke the token where the provider offers a way to — Google does. Several offer no such endpoint at all, and for those the most we can do is destroy our copy, which we do. The list below says which is which, because "we revoke your tokens" would read as a promise we cannot keep everywhere. And if we ever become aware of a breach affecting your data, we will tell you promptly.
Who else sees it
We do not sell data, share it with advertisers, or use it to train anything. But "nobody" would be untrue, so here is the full list of companies that process some of your data in order to run the service:
- Fly.io — hosts the application and the database. All of it passes through here.
- Cloudflare R2 — holds the nightly database backup. That backup contains everything the database does, and copies are kept for 30 days before being deleted.
- GitHub — runs the job that takes that backup, so the dump passes through GitHub Actions on its way to storage.
- Sentry — receives error reports when something breaks. Credentials are stripped before sending and we do not send personal data deliberately, but an error report can carry the identifiers involved in whatever failed.
- Google Workspace — delivers the few emails we send you, such as the notice that a connection has stopped working.
- Stripe — only if you pay us. Stripe handles card details directly and we never see them.
- Google Analytics and PostHog — count visits to these pages and which links get used. Both are set up to store nothing on your device, and neither records your screen.
That last line is the reason this site asks you to accept no cookies. We use the two analytics tools in a mode where they store nothing on your computer or phone: no cookie, no identifier that follows you between visits. Every visit looks new to us, which makes our own numbers less useful and is a trade we chose.
Session recording is turned off. PostHog can replay what a person did on screen, and on a page that shows your task names that would send your work to somebody else. We do not switch it on. If you are signed in, the only thing that identifies you to these tools is your account's internal id — a string of characters that means nothing outside our own database, and never your email address or the contents of a task.
Sending a task to your own agent
If you set up an agent on the settings page and press Hand to agent on a block, we send that task to the address you gave us. That means its title, its due date, its priority, how long we had booked for it, and the line explaining why it ranked where it did. We send nothing until you press the button, and only for the task you pressed it on.
This is the only case where your task text leaves us for anywhere other than your own calendar. Whoever runs that address decides what happens to it next, and that is not us. Removing the agent on the settings page stops it, and taking a task back cancels one that is already in flight.
Google user data
Diarized's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means we use your Google Calendar and Google Tasks data only to provide the scheduling feature you connected them for: reading events to find the time you are already busy, reading open tasks to know what needs doing, writing back the blocks we schedule, and marking a task complete when you delete its block. We do not transfer it to anyone, do not use it for advertising, do not sell it, and do not use it to train machine learning models. No human at Diarized reads your calendar or your tasks, except where you have explicitly asked us to look at something to resolve a support issue, or where the law requires it.
Your control
Download everything we hold, or delete your account entirely, from your account page. Deletion is immediate here: calendar watches are canceled, tokens are revoked where the provider offers a way to revoke them, and your rows are removed at once.
It takes up to 30 days to be complete everywhere, and the reason is the nightly backup. Those copies are what protect you from us losing your data, so they cannot be edited after the fact — a backup somebody has reached into is not a backup. Each one expires 30 days after it was taken, so the last trace of a deleted account is gone within 30 days of the deletion. We do not restore from backup to bring an account back.
Blocks already written to your calendar are left alone when you delete your account — they belong to your calendar now, and removing them silently would be its own kind of data loss. Delete them there if you want them gone.
When you delete your account or disconnect a service, we tell that provider to revoke the token we were given — where the provider offers a way to. Google does, and there the grant disappears from your account rather than merely being forgotten here. Microsoft, Todoist, Linear, Notion, TickTick, ClickUp, Asana and Jira do not offer us one, so for those we destroy our copy and that is genuinely all we can do from this side.
Which is worth knowing, because it means the grant may still be listed in your account with that provider. You can revoke it yourself at any time, from their settings, without telling us — and after disconnecting from a provider on that list, that is the step that actually finishes the job.
If you would rather not use the account page — or you have already deleted your account and want confirmation — email keith@getdiarized.com and we will confirm deletion within 30 days.
Wherever you are
Diarized is sold internationally and the same rules apply to everyone: we collect the minimum needed to schedule your work, we do not sell it, and you can take it with you or delete it at any time from your account page.
Depending on where you live you may have specific rights — to access a copy of your data, to correct it, to delete it, to object to how it is handled, or to know whether it has been sold or shared. We do not sell or share personal information, and the access, export and deletion rights are already available to everyone directly in the product rather than on request. For anything not covered by those, email keith@getdiarized.com.
Data is processed and stored on servers in the United Kingdom, and by Stripe if you pay us. Using Diarized from elsewhere means your data is handled there.
Contact
Questions about any of this: keith@getdiarized.com