Privacy Policy

Last updated: July 2026

What Google Calendar data we access, and why

When you connect Google Calendar, Unstuck requests read-only calendar.readonly scope — the most restricted calendar permission Google offers. On each check, we read: your events' start and end times (to detect free gaps), event titles (so we can show you what's coming up next, e.g. "25 min before Team Standup"), and whether you personally declined an event (so declined meetings don't block a gap). We do not read other attendees' identities or RSVPs, meeting descriptions, locations, conferencing links, attachments, or recurrence rules — our Calendar API requests are field-masked so Google never sends us that data in the first place. Unstuck never creates, edits, moves, or deletes anything on your Google Calendar.

How calendar data is used and retained

Calendar data is used solely, in real time, to compute your current gap and decide which of your tasks is safe to start. We fetch a rolling 8-hour window of events live from Google on each check and do not store raw event data — no titles, times, or RSVP data are written to our database. The only calendar-derived information we persist is minimal metadata needed to avoid double-sending a notification (a scheduled time and delivery status) for a task you've already been alerted about; this is deleted along with your account. We do not use calendar data for advertising, and we do not sell it or share it with third parties.

How we protect your data

We protect your data — including Google Calendar data and your Google account tokens — with the following safeguards:

  • Encryption in transit. All data exchanged between you, Unstuck, and Google travels over encrypted HTTPS/TLS connections. We never transmit your data over unencrypted channels.
  • Encryption at rest. Everything we store (in Google Cloud Firestore) — your profile, tasks, and Google refresh token — is encrypted at rest at the infrastructure level using Google Cloud's managed encryption.
  • Minimal storage of sensitive data. Calendar events are fetched live on each check and are never written to our database, so there is no stored copy of your event titles, times, or RSVP status that could be exposed (see "How calendar data is used and retained" above).
  • Access controls. Stored data is scoped to your authenticated account: our application enforces per-user authorization on every request, so one user can never read another user's data. Administrative access to production systems is restricted and used only for security, maintenance, or legal compliance.
  • Revocable access. You can revoke Unstuck's access to your Google data at any time, which immediately stops all further access (see "Your Google account tokens" below).

Your Google account tokens

Your Google refresh token is stored in our database (Firestore) so we can check your calendar without asking you to sign in again. Firestore encrypts all data at rest at the infrastructure level; we do not apply additional field-level encryption to the token today. The token is retained until you delete your account or revoke access — there is no separate expiration. We do not currently offer a standalone "disconnect Google" button; deleting your account (see below) automatically revokes our access via Google's token revocation endpoint, and you can also revoke Unstuck's access at any time directly from Google, independently of us, at myaccount.google.com/permissions.

Account deletion

Deleting your account from Settings → Delete account immediately: revokes our Google access token via Google's revocation endpoint, cancels any active subscription, and permanently deletes your profile, tasks, task templates, routines, notification records, API tokens, gap history (including the calendar event names stored with it), any beta or Coach Space feedback you submitted, and your coach/client relationships, session notes, and suggestions from our database. This does not and cannot delete anything from your actual Google Calendar, because Unstuck never had write access to it — there was nothing there for us to remove.One exception, stated plainly: comments you posted publicly on the blog are not removed automatically, because deleting them would tear holes in conversations other people replied to. Email adhabnr@gmail.com and we will remove them for you.

Coach and client data

(Only applies if you use a Coach-tier connection.)Coaches and clients connect only by explicit invite: a coach can never see your data until you accept their invite link. Once connected, your coach can see your name, email, avatar, and aggregated activity — total hours recovered, task counts, and days since your last completed task. Your coach never sees your task titles, task descriptions, or any calendar data. Coaches can keep private notes about clients; you cannot see these notes. Either side can disconnect at any time, which immediately cuts off the coach's visibility into your activity.

Focus Room

Focus Room is a Pro feature that shows other signed-in users a live presence card while you're in a session: your first name, avatar, how many minutes your current task is set for, and when you joined/were last active. It never shows your task's title or content, and never shows any calendar data. Leaving Focus Room removes your presence card.

Third parties we use to run Unstuck

We use a small number of service providers to operate Unstuck, each limited to the data they need to do their job:

  • Google Cloud / Firestore (our database — stores your profile, tasks, and tokens)
  • Google (Calendar API for read-only calendar access, and OAuth for sign-in)
  • Stripe (payment processing — receives your email, user ID, and plan selection; Stripe handles your card details directly, we never see them)
  • Resend (delivers transactional emails — welcome, weekly report, coach digest — using only your email address)
  • Your browser/device's push notification service (delivers hard stop and reminder alerts; receives only notification text and a device-specific delivery address)
  • Vercel (hosts and runs our application code)
We do not use any AI/LLM provider to process your data. Analytics (PostHog) is integrated in code but is not currently active on our production deployment.

Google API Services User Data Policy

Unstuck's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we use Google Calendar data only to provide and improve the user-facing calendar-gap features described in this policy, we do not use it for advertising, we do not sell it, and we do not allow humans to read it except as necessary for security, legal compliance, or with your explicit consent for support.

Contact

Questions about this policy or your data? Email adhabnr@gmail.com.