Hotline

Privacy

Short version: Hotline collects what scheduling needs and nothing more. We don't run ads, we don't sell data, and no one ever sees your whole calendar — you hand-pick the times people can book.

Effective July 3, 2026

What we collect

  • If you host meetings: your email address and name (for sign-in), the display name and timezone you set, your meeting proposals, and — if you install the mobile app and turn on notifications — a device token used only to deliver them. Your connected calendar credentials are held by our scheduling engine solely to check conflicts and write the meetings you book. If you add a Proton Calendar share link, our server reads that feed only to show your own events back to you.
  • If you're invited to a meeting: your name and email (entered by the person who invited you), the time you confirm — or a note if none of the times work. No account, no password, nothing else.
  • If you join the beta list: your email address, used only to contact you about Hotline.

What we deliberately don't do

  • No advertising, no third-party trackers, no sale of data. Ever.
  • The only cookie that identifies you is the sign-in session for hosts. Invitees are not tracked.
  • If you optionally connect Google or Outlook on an invitation page to check for conflicts, that check runs in your browser — read-only, and your calendar data never reaches our servers.
  • Invitees never see a host's calendar, and hosts never see an invitee's. Only the hand-picked times travel.

How we use it

To do the thing you asked: create the booking, put it on the right calendars, email the confirmations and calendar invites, deliver the notifications you turned on, and remind hosts to follow up after a meeting ends. That's the list.

Services we rely on

Hotline runs on a small set of infrastructure providers that process data on our behalf: Vercel (hosting), Neon (database), Resend (email delivery), and Google Firebase Cloud Messaging (push-notification routing — message routing only). Scheduling, availability, and calendar sync are handled by Hotline itself, not a third-party scheduling service. When a host connects a Google or Apple calendar, that connection is governed by the provider's own terms and can be revoked there at any time.

Retention and deletion

Invitation links expire on their own (72 hours by default). Booking history is kept so hosts can see their past meetings. Want something gone? Email us and we'll delete your data.

Security

Everything travels over TLS, data at rest lives in managed encrypted stores, and each host's data is scoped to their own account.

Changes and contact

If this policy changes materially, we'll note it here. Questions or deletion requests: privacy@hotlinecal.com.

Privacy · Hotline