Who you are dealing with
Privacy here is the responsibility of our Privacy Officer. Write to privacy@whenabouts.me and a person reads it.
That's a job title rather than somebody's name. Ask at that address who currently holds it and we will tell you.
What we hold
Not much, and this table is all of it.
| What | Why we have it |
|---|---|
| The name you type when you respond | So the group can see who is coming or who has taken what. It is the only thing we insist on. |
| An email address, if you give one | To send you your own link back, a reminder, or a note from the organizer. It is never shown on a page anybody shares, and only the organizer can download it. |
| Your response itself, and any note | The answer is what the page is for. |
| What you set up, if you made the page | The title, the description, your name, the dates and the options. |
| A scrambled version of your IP address | To stop one machine flooding us. It is put through a one-way function with a secret that changes itself every 30 days, so it cannot be turned back into an address, and it stops matching its old self within a month. |
| Your time zone, if your browser tells us | So times read correctly the first time a page loads, rather than jumping. |
| An email address and a plan, for an account | Only if you make one. You sign in with a link we email, so there's no password here to lose. |
| Your usual week, if you fill one in | Which hours you are usually free and which you are usually busy, so a page can be half-filled for you. When you're busy, never why. |
| Dates you marked as different | "Away that week", "free that Saturday". There's no field for a reason, and we didn't build one. |
| Busy times from a calendar you connected | A start and an end, and nothing else: no title, no location, no guest list. Fourteen days ahead at most, and thrown away when you disconnect. |
| Your name on a list somebody made | If an organizer puts you on a roster: the name they typed, and an address if they had one. You can take yourself off any of them without asking them. |
| A count of turns taken, on a schedule | So "who has done the fewest" is a fact rather than an argument. A number and a date, against a name already on the list. |
| Who you have agreed to share your usual week with | One row per named group, with when you agreed and when you stopped. See Sharing your usual week. |
We never ask for a phone number, a date of birth, a postal address, or anything about somebody's health. Please keep those out of a note as well. Every page that asks for a note says so.
We never store why anybody is busy. Not the title of a meeting, not where it is, not who else is going. There are no fields for any of that, the calendar code discards it before it reaches us, and a test feeds that code a calendar full of titles and checks that none of them survive.
If you connect a calendar
Connecting one is optional, and the only thing it buys you is not having to paint the same week in by hand.
- We ask for the narrowest read-only permission the provider offers, and we use it to read free/busy time only: a start, an end, and nothing else.
- We keep at most fourteen days ahead, so the answer to "when are you usually free" is current without us holding a diary.
- A connection fills in your own screen. Nobody else sees it. An organizer sees what you submit, exactly as if you had picked them yourself.
- The credentials are encrypted before they are stored, with a key that can be rotated, and they are never shown back to you in full.
- Disconnect and the stored times go at the same moment, not on a nightly sweep. You can also cut us off from your Google or Microsoft account settings directly, which is worth knowing.
What we read from your calendar shows you your own availability. We don't advertise with it or sell it, and there is nothing here to train: this product contains no machine learning of any kind.
The formal version, which Google asks every app using their calendar to publish: Whenabouts' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing your usual week
By default nobody sees it at all. What an organizer sees is whatever you pressed submit on, and nothing behind it.
You can let a named group see your usual availability, so they stop asking you the same question every month. Three rules keep that from turning into something you didn't agree to:
- You share with a group you can name, such as "Riverside Youth Choir". Never with "organizers" as a class, and never as part of making an account.
- Responding to anything on this site never depends on it. Nothing anywhere is gated behind saying yes.
- Your own page lists every live agreement in plain words with the date it started, and one press ends it. That takes effect on the next read rather than whenever a cache happens to expire.
An agreement nobody has used for a year stops by itself, and we tell you when it does.
There is no "is this person free right now". The question this answers is "when is this person usually free", worked out from a pattern and two weeks of busy times. The gap between those two questions is the gap between a scheduling tool and a tracking one, and it is an easy line to cross without meaning to, so we've written it down.
Decisions worked out by arithmetic
If you're on a list that takes turns, the order can come out of a sum: who has done the fewest, who is free, who is on the list. When a number rather than a person decides something about you, you're entitled to know how. Here is how.
- Nothing is ever published without a person pressing publish. The arithmetic proposes; the organizer decides.
- Every proposal carries its reason, in one sentence you can read. "Sam has done two, the group average is four, and Sam is free." That sentence sits on the page as ordinary text, not tucked inside a tooltip.
- You can ask a person to look again. Every page like that carries a way of reaching the organizer. They made the decision and they can change it. We're not in the middle of that conversation.
No artificial intelligence is involved anywhere in this. It's addition and sorting, which is why it can always account for what it did.
What we never do
- We never sell, rent or trade anything about you.
- We show no adverts. There's no advertising network anywhere in this product.
- A page you share loads nothing from anybody else: no fonts, no analytics, nothing embedded. Every byte of it comes from us.
- We don't follow you around other sites. We have nothing on them to do it with.
- We don't read your notes to build a picture of you. Nobody here reads them at all.
Cookies, and what sits on your device
Four cookies. Each one is needed for something you asked for, which is why this site has no banner to click through.
| Name | What it does | How long |
|---|---|---|
| wa_session | Keeps you signed in, if you have an account. | 90 days, extended while you keep using it |
| wa_participant | Remembers which response on a page is yours, so you can change it on this device without hunting for the emailed link. It holds a reference and a signature, not the link itself. | 90 days |
| wa_theme | Light or dark, if you pick one by hand on a page somebody shared with you. Those pages run no scripts at all, so the choice is remembered here instead of in your browser's own storage. | A year |
| wa_tz | Your time zone, so times are right on the first paint. | A year |
One more thing sits on your device and never reaches us. If you pick light or dark by hand, your browser stores that choice locally. Clearing your site data removes it.
Who else touches any of it
Four companies in every case, plus up to four more if you connect something yourself. None of them may use what they see for any purpose of their own.
| Who | What for | What they can see |
|---|---|---|
| Cloudflare | Running the site, storing the database, and checking that a visitor is a person | Everything we store, because they store it |
| Resend | Sending email | The address we are writing to, and what the message says |
| Paddle | Taking payment. They are the seller of record, so they handle the card and the sales tax | Your billing details. We never see a card number |
| Sentry | Telling us when something breaks | What went wrong and where. Addresses, names and links are stripped out before a report leaves us |
| Google or Microsoft | Only if you connect that calendar. They tell us when you are busy | Nothing new: it's their calendar. We read free/busy and drop the rest |
| Discord or Slack | Only if somebody adds Whenabouts to that server or workspace | What is posted in the channel: the title, the counts, the link. Never an address |
Cloudflare runs on machines around the world, so what we store may sit outside Canada. The safeguards for that are the standard contractual terms in each company's data processing agreement.
How long we keep it
- A page nobody has touched for 12 months is deleted, along with every answer on it. If there is an address on file we write 14 days before that happens.
- A page on a paid plan is kept while the plan is paid for. If a plan stops, the 12-month clock starts again from that day, with the same warning.
- A page that never got a single answer is deleted after 30 days.
- Something deleted on purpose can be put back for 7 days, and after that it is gone for good.
- Busy times read from a connected calendar are never more than two weeks ahead, and they go the moment you disconnect it.
- A record of any breach is kept for two years, because Canadian law requires it. It holds what happened, not who was in it.
- The record that you agreed to share your usual week, and that you later stopped, deliberately outlives your account. It's the proof of what you chose. It keeps the date and the name of the group, and nothing that points back at you once the account is gone. A privacy record that erases itself the moment somebody uses a privacy right would be no use to anyone.
None of this depends on somebody remembering to do it. A sweep runs every night, and the tests behind it check what survives as well as what gets removed.
What you can do about any of it
- Wipe every response you have ever given. Use this form. Give the address you responded with, click the link we send back, and every response tied to it goes everywhere at once. You don't need an account for this.
- Change or cancel one response. Use the personal link you landed on after responding, or open the page again on the same device.
- Stop the email. Every message carries an unsubscribe link, and one click does it. Sign-in links still come through, since those are ones you asked for on the spot.
- Ask for a copy of what we hold. Write to privacy@whenabouts.me and we will send it within 30 days.
- Stop sharing your usual week with somebody. One press on your own page, effective on the next read. You don't have to ask them first.
- Take yourself off a list. Every page you're on has a way to remove yourself without going through the organizer. What you've already done stays on the record. You just stop being asked.
- Download everything we hold about you. Start from your own page. We send you a fresh link to prove it's you, then email the file.
- Delete an account. From your account settings, or by writing to us. That removes the account, your usual week, your dated exceptions, every calendar connection and the times read from it, and every sign-in. It does not remove answers you have already given. Those belong to the pages they were given to, and pulling them out would quietly change other people's results. They are unlinked from you instead, and you can delete any of them yourself from their own link. The deletion screen spells all of this out before you confirm.
If we've got something wrong and our answer doesn't satisfy you, you can take a complaint to the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information du Québec if you are in Quebec.
Children
This isn't a service for children to sign up to. A page marked as being for a school, a youth team or a faith group says plainly that adults' names and details are what belong on it, and it loads nothing whatsoever from anybody else.
Think a child's details have ended up on a page here? Write to privacy@whenabouts.me and we'll take it down.
If something goes wrong
We're required to keep a register of every breach from day one, harmless ones included, and we do. If one could put you at real risk, we'll tell you and the regulator as fast as we can and no later than the law allows. You'll get what happened, what it means for you, and what we've done about it.
If this page changes
The date at the top changes with it. Some changes matter more than that: something new being collected, or something kept for longer. Those go by email to everyone with an account before they take effect, and sit at the top of this page for a month afterwards.