Privacy Policy
Effective July 22, 2026
1. Who we are
Meetera (“Meetera”, “we”, “us”) is a scheduling service operated by Ruthvik Bathala. For the purposes of the GDPR, the data controller is Ruthvik Bathala, reachable at privacy@meetera.org.
2. What we collect
We collect the email address you provide at sign-in, calendar event data from the calendars you connect — either a Google account you authorize via Google OAuth, or an ICS feed URL you provide — and booking records created through Meetera. From each calendar event we read its start time, end time, busy/free status, and event title. We use event titles to render your own merged calendar to you and to power scheduling features such as focus-time detection. We do not read event descriptions, notes, or attendee email lists from your feeds.
3. How we use it
Calendar data is used to compute your availability, prevent double-bookings, and provide scheduling features. Your email is used to send magic-link sign-in codes and booking confirmations. People viewing your booking page never see your event titles — they see only free or busy time. We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Google user data (Limited Use)
When you connect a Google Calendar, Meetera accesses your calendar through the Google Calendar API using only the read-only scope (calendar.readonly), solely to read your busy/free times and event details so we can compute your availability and prevent double-bookings. Meetera never modifies your Google Calendar.
Meetera's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Userequirements. Specifically, we do not use Google user data for advertising; we do not sell it; we do not transfer it to third parties except as necessary to provide or improve the service, for security, or to comply with applicable law; and we do not use it to train generalized or personalized AI/ML models. You can revoke Meetera's access at any time from your Google Account permissions page or by disconnecting the calendar in Settings, after which we delete the associated cached data.
5. Data retention
Calendar events synced from connected calendars are refreshed periodically and retained for 30 days after your last sync. Booking records are retained for 12 months. You can request deletion at any time by emailing us, or delete your account from Settings.
6. Sub-processors
We share the minimum data necessary with infrastructure providers who process it on our behalf under contract: Neon (database hosting), Vercel (application hosting), and Resend (transactional email). If you use Aria, our AI scheduling assistant, event titles may be sent to Anthropic to classify events; Anthropic does not train models on this data. We do not use any other third-party processors without updating this list.
7. International transfers
We are based in the United States and our sub-processors may process data in the US and EU. Where personal data is transferred out of the European Economic Area, we rely on the European Commission's Standard Contractual Clauses as the transfer mechanism.
8. Your rights (GDPR)
If you are in the European Economic Area or the UK, you have the right to access, correct, port, restrict, object to, or erase your personal data. To exercise any of these rights, email privacy@meetera.org and we will respond within 30 days. You may also lodge a complaint with your local data protection authority.
9. Your rights (California)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to request deletion, and to correct it. We do not sell or share your personal information as those terms are defined under California law, and we do not process it for cross-context behavioral advertising. To exercise your rights, email privacy@meetera.org. We will not discriminate against you for doing so.
10. Children
Meetera is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email us and we will delete it.
11. Security
Calendar access tokens and ICS feed URLs are stored encrypted at rest. All fetches are made server-side over HTTPS. ICS URLs that use private, loopback, or link-local network addresses are rejected at the fetch layer. We use Neon Postgres with per-user data isolation, and event titles can be stored in an encrypted form for privacy-restricted sharing modes.
12. Cookies
We use a single session cookie to keep you signed in. No third-party tracking cookies are set.
13. Changes
We will email registered users at least 14 days before making material changes to this policy.
14. Contact
Questions? Email privacy@meetera.org.