Privacy Policy
Effective date: July 26, 2026
Remicita ("we", "us") is an appointment scheduling service available at remicita.com. This policy explains what information we collect, how we use it, and the choices you have. We keep it short because we collect little: only what the service needs to work.
Information we collect
- Account information — when a host creates an account: name, email address, a password (stored only as a salted hash — we never see or store the plain password), timezone, and the URL slug for your booking page.
- Scheduling settings — your event types, availability hours, buffers, and related preferences.
- Booking information — when an invitee books a time: their name, email address, timezone, the chosen time, and any notes they choose to include. Invitees do not need an account.
- Google Calendar data — only if a host connects Google Calendar; see the dedicated section below.
- Technical logs — our web server keeps standard access logs (IP address, requested URL, browser user agent) for security and troubleshooting. These are routinely rotated and deleted.
We use only cookies that are strictly necessary to operate the service: a session cookie to keep hosts logged in and a token to protect forms against cross-site request forgery. We use no analytics, advertising, or tracking cookies.
How we use information
- To provide the service: show availability, take bookings, prevent double bookings, and let invitees manage their bookings.
- To send transactional email: booking confirmations, calendar invites, reminders, and cancellation or reschedule notices.
- To secure and maintain the service.
We do not sell or rent personal information, and we do not use it for advertising or profiling.
Google Calendar data
Hosts can optionally connect their Google account so Remicita can sync with Google Calendar. If you connect, we request two permissions (OAuth scopes):
- Manage calendar events
(
calendar.events) — used solely to create a calendar event on your calendar for each booking made through Remicita, and to update or remove that event if the booking is rescheduled or cancelled. We only ever modify events that Remicita itself created. - Read calendar availability
(
calendar.readonly) — used solely for free/busy lookups so that times you are already busy are not offered on your booking page. Free/busy results contain only busy time intervals; we do not read the titles, descriptions, attendees, or other contents of your existing events, and we do not store free/busy results — they are used for the moment of the availability check and discarded.
What we store: the OAuth tokens needed to keep the connection alive, the ID of the calendar you chose, and the IDs of the events Remicita created (so we can update or delete them later). Nothing else from your calendar is stored.
You can disconnect Google Calendar at any time in Settings → Google Calendar → Disconnect. Disconnecting deletes our stored tokens and revokes Remicita's access with Google. You can also revoke access from your Google account security settings.
Remicita's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
When we share information
We share personal information only with:
- The other party to a booking — hosts see their invitees' booking details; invitees see the host's name and meeting details. That is the point of the service.
- Service providers — an email delivery provider sends our transactional email (recipient address, name, and the booking details contained in the message), and our hosting provider runs the server the service lives on. These providers process data only on our behalf.
- Google — if you connect Google Calendar, booking details (title, time, invitee name and email) are written to your calendar as described above.
- Legal requirements — if we are required to by law.
Data retention and deletion
We keep your account and booking data for as long as your account is active. To delete your account and its data, or to request a copy of your data, email us at the address below and we will act on it promptly. Invitees can ask the host or us to delete their booking information. Disconnecting Google Calendar deletes stored Google tokens immediately.
Security
All traffic is encrypted with HTTPS. Passwords are stored as salted hashes. Access to the server and database is restricted. No method of transmission or storage is 100% secure, but we work to protect your information with practical, proven measures.
Children
Remicita is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes to this policy
If we make material changes we will update this page and the effective date above, and where appropriate notify account holders by email.
Contact
Questions or requests about privacy: [email protected].