Secundant
Privacy Policy
This policy explains the information Secundant handles while helping owners and participants schedule meetings through public portals. It is plain-language MVP guidance and should be reviewed by the product owner before public reliance.
Last updated: August 7, 2026
Information Secundant collects
Secundant stores the information needed to create and use meeting portals: owner account identity, portal titles and descriptions, offered time windows, participant names and email addresses, timezone choices, booking selections, availability responses, and final group meeting selections.
Google sign-in
Owners sign in with Google so Secundant can identify the account that creates and manages portals. Google returns basic profile information such as name, email address, and account image when available. Secundant does not receive your Google password.
Google Calendar
Google Calendar access is optional and is used only for user-initiated calendar actions. Secundant stores the account connection details required by the sign-in provider and keeps token values server-side. Calendar events are not created silently, and Secundant does not add attendees or send Google-generated invitations without a user action.
Public portals and guest links
Public portal URLs are meant to be shared with intended participants. Guest booking confirmation links can act as bearer links, so anyone with the link may be able to recover that confirmation. Share these links carefully and avoid putting sensitive content into portal titles, descriptions, or participant inputs.
Email notifications
When transactional email delivery is enabled, Secundant may send booking confirmations, owner booking notifications, availability receipts, and group final meeting confirmations. These emails include only the practical details needed for the scheduling workflow, such as the portal title, participant identity, selected time, or portal link.
Local browser storage
Secundant may store small browser-local preferences and recovery hints, such as theme preference and minimal guest booking recovery state. The guest booking recovery cache is limited to version, portal slug, and booking id. Clearing browser storage may remove these local conveniences.
Operational logs and security
Secundant aims to keep operational logs purpose-bound. Email delivery logs should use redacted recipients and must not include full message bodies, bearer confirmation links, OAuth tokens, Calendar token health, provider secrets, or stack traces intended only for server diagnostics.
Data sharing and providers
Secundant relies on infrastructure and identity providers to run the product, such as hosting, database, Google sign-in, optional Google Calendar APIs, and any accepted transactional email provider. Secundant does not sell participant information or use it for marketing emails in the current MVP.
Questions
For privacy questions or requests, contact the product owner through the support channel shared with your account or invitation. Some account deletion, export, or retention workflows may require manual handling while Secundant is in its early MVP stage.