Privacy
Short version: Hotline collects what scheduling needs and nothing more. We don’t run ads, we don’t sell data, and no one ever sees your whole calendar — you hand-pick the times people can book.
Effective August 30, 2026
What we collect
- If you host meetings: your email address and name (for sign-in), the display name and timezone you set, your meeting proposals, and — if you install the mobile app and turn on notifications — a device token used only to deliver them. Your connected calendar credentials are held by our scheduling engine solely to check conflicts and write the meetings you book. If you add a Proton Calendar share link, our server reads that feed only to show your own events back to you.
- If you’re invited to a meeting: your name and email (entered by the person who invited you), the time you confirm — or a note if none of the times work. No account, no password.The person who invited you also keeps your name, email and timezone, so their booking form suggests you next time. That list is theirs alone — no other organisation using Hotline can see it — and they keep it until they delete you from it or close their account. It is never used to market anything to you. Ask us and we’ll remove you.
- If you join the beta list: your email address, used only to contact you about Hotline.
- To keep Hotline working: when something breaks, an error report (what went wrong and where in the app) goes to our error-monitoring service. And for signed-in hosts only, we count feature usage — which screens are visited and how often the core scheduling flow is used — under a random account identifier, never your name or email. Invitation pages carry no usage analytics at all.
What we deliberately don’t do
- No advertising, no ad trackers, no sale of data. Ever.
- We never market to the people you schedule with. Their details fill in your booking form; they are not a mailing list, and Hotline cannot send them anything but the meeting emails they are already expecting.
- The only cookie that identifies you is the sign-in session for hosts. Our usage measurement sets no cookies and stores nothing on your device. Invitees are not tracked — invitation pages load no analytics.
- If you optionally connect Google or Outlook on an invitation page to check for conflicts, that check runs in your browser — read-only, and your calendar data never reaches our servers.
- Invitees never see a host’s calendar, and hosts never see an invitee’s. Only the hand-picked times travel.
How we use it
To do the thing you asked: create the booking, put it on the right calendars, email the confirmations and calendar invites, deliver the notifications you turned on, and remind hosts to follow up after a meeting ends. That’s the list.
Services we rely on
Hotline runs on a small set of infrastructure providers that process data on our behalf: Vercel (hosting), Neon (database), Resend (email delivery), Google Firebase Cloud Messaging (push-notification routing — message routing only), Mapbox (address lookup — only what you type into a location field is sent, and only while you type it), Sentry (error monitoring — technical error reports, not tied to your identity), and PostHog (usage measurement for signed-in hosts, hosted in the EU — feature usage under a random identifier, with no names, emails, or meeting content). Scheduling, availability, and calendar sync are handled by Hotline itself, not a third-party scheduling service. When a host connects a Google or Apple calendar, that connection is governed by the provider’s own terms and can be revoked there at any time.
Retention and deletion
Invitation links expire on their own (72 hours by default). Booking history is kept so hosts can see their past meetings. A host’s contact list has no automatic expiry: an entry stays until the host deletes it or closes their account. Hosts can see, correct and delete every contact they hold, and you can ask us to remove yours at any time.
You can delete your account yourself, from the app: Profile → Personal Information → Delete account. It erases your personal information and the names, email addresses and notes of everyone you’ve scheduled with, destroys your connected calendar credentials, and signs you out everywhere. Meetings keep their shape — how many, how long, when — with the identifying details removed. Two things survive on purpose, and the app says so before you confirm: a dated record that the erasure happened, holding a one-way fingerprint of your address rather than the address itself, and any meeting already copied into your own Google or Apple calendar, which only you can delete from that calendar account. Deletion is immediate and cannot be undone.
Taking your data with you
You can download a copy of your account at any time: Profile → Account → Export my data. It arrives as a single file holding your meetings and the people invited to them, your calendar entries, tasks, focus history, contacts, profile and settings. It deliberately leaves out your sign-in codes and your connected-calendar credentials — those are no use anywhere else, and a copy of them in a file is a risk with nothing to gain. Because the file includes the names and email addresses of the people you’ve scheduled with, look after it as you would your own address book; the copy at our end stays until you delete it or close your account. Organization data — shifts, worked time and your place on a roster — follows in a later release.
If you don’t have a Hotline account
Someone may hold your details here because they invited you to a meeting — you don’t need an account to see what that is, or to have it deleted. Email privacy@hotlinecal.com from the address in question. We check the request is genuine, then tell you what is held and remove it.
One limit: if a host copied the meeting into their own Google or Apple calendar, that copy lives in their account and only they can delete it. We’ll tell you if that applies.
Security
Everything travels over TLS, data at rest lives in managed encrypted stores, and each host’s data is scoped to their own account.
Changes and contact
If this policy changes materially, we’ll note it here. Questions or deletion requests: privacy@hotlinecal.com.
August 30, 2026. Contact lists no longer clear automatically after 24 months. Hosts can now see, correct and delete every contact they hold, so an entry stays until the host removes it or closes their account rather than expiring on a timer. Nothing new is collected, and the promise never to market to the people you schedule with is unchanged. If someone holds your details and you want them gone, ask us.