Privacy Policy

Last updated: August 12, 2026

Fugit automatically creates Focus and Do Not Disturb blocks on your Google Calendar so your time for deep work is protected. To do that it needs limited access to your calendar. This policy explains exactly what it accesses, why, and how it’s stored.

What we access

  • Your Google profile — name, email address, and profile image, to identify your account.
  • Calendar events — via the calendar.events scope. Fugit reads the timesof your events to find free space, and creates, updates, and deletes its own Focus / Do Not Disturb events. For your real meetings we store only start/end times and Google’s event identifiers — not descriptions, attendees, or locations. Fugit never edits or deletes events it did not create.
  • Event titles — only if you turn on calendar mirroring. If you link more than one Google account and mark a second calendar as one Fugit should account for, Fugit copies those busy times onto your main calendar so your availability is accurate in one place. Only in that case does it read and store the titleof the event being mirrored, so the copy is recognizable to you; the copy is created with Google’s private visibility, so other people looking at your calendar see only that you are busy. Turn mirroring off, or disconnect the second calendar, and the stored titles and the copies are deleted. If you never link a second calendar, Fugit never reads a single event title.
  • OAuth tokens — the access and refresh tokens Google issues so Fugit can act on your behalf between visits.
  • Your settings — timezone, working hours, weekly focus target, and the like.
  • Booking details — if you share a Fugit scheduling link, visitors who book a time with you submit their name and email address. We store them so the booking exists, create the calendar event with the visitor as a guest (Google sends them the invitation), and use them for nothing else. Visitors to a booking page see only open time slots — never your events, nor whether a given time is a meeting, focus time, or anything at all.

How we use it

Your data is used solely to operate Fugit’s scheduling for you: reading busy times to find free space, and creating, updating, and deleting the Focus / Do Not Disturb events Fugit manages. It is not used for advertising, profiling, or any purpose unrelated to these user-facing features. See Data sharing & transfer below for the only parties that process it.

Data sharing & transfer

We do not sell, rent, or trade your Google user data, and we do not transfer it to data brokers, advertisers, or for advertising, credit, or lending purposes. Your calendar data is never shared with other Fugit users.

The only parties that ever process your data are the infrastructure providers Fugit runs on, acting on our behalf and solely to deliver the service:

  • Google — the Calendar API itself, to read your busy times and create the events Fugit manages.
  • Vercel (United States) — application hosting; processes data in transit to run the app.
  • Neon (United States) — the managed PostgreSQL database where your settings, encrypted tokens, and event times are stored.
  • Resend(United States) — transactional email only. It receives your email address to deliver account notices such as “a calendar needs reconnecting.” It never receives your calendar data.

We may also disclose data if legally required to do so. If Fugit is ever transferred to another owner, we will give you notice and the opportunity to delete your data first.

AI and machine learning

We do not use your Google user data — raw, aggregated, or anonymized — to develop, improve, or train any artificial intelligence or machine learning models, and we do not transfer it to third-party services that would do so. Fugit’s scheduling is deterministic: it’s ordinary code applying the settings you configure, with no model involved.

Google API Limited Use

Fugit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not transfer or use Google user data for serving ads, and no humans read your calendar data except where you explicitly ask us for support.

Storage & security

Data is stored in a managed Postgres database (Neon, US region) and the app is hosted on Vercel. OAuth access, refresh, and ID tokens are encrypted at rest with AES-256-GCM before they touch the database; the encryption key is held only in server configuration, never in the database.

Retention & deletion

You can delete your account and all associated data at any time from your Fugit settings. Deletion revokes Fugit’s Google access, removes your tokens, settings, and stored event times, and deletes the Focus / Do Not Disturb events Fugit created. This is immediate and irreversible.

You can also disconnect a single calendar without deleting your account; that revokes Fugit’s access to it and deletes the data synced from it. While your account is active we keep only what the service needs: your settings, encrypted tokens, event start/end times (plus mirrored titles, if you enabled mirroring) for a rolling window of roughly two weeks back and four weeks ahead — older synced times are deleted automatically. Revoking Fugit’s access from your Google account permissions page also stops all access immediately.

Contact

Questions or requests: jap@josepalomares.com.

← Back to Fugit·Terms of Service