Back to home

Privacy

Privacy and Data Retention

This page explains the MVP data boundaries for Schedule Share. It is a product and engineering disclosure, not final legal advice. Before broad public launch, the policy should be reviewed against the target regions, ad providers, and operating entity.

What We Store

The current MVP does not require account registration and does not ask for email, phone, social account, or calendar-account access by default.

  • Schedule title, description, time zone, date range, available daily time windows, and slot length entered by the organizer.
  • Participant display names and selected availability or candidate-time vote responses.
  • Local browser memory for a recently used display name, edit link, weekly template, and create-schedule defaults.
  • Random identifiers or hashed access keys needed for share links, management links, and edit links.
  • Schedule creation time, update time, expiration time, and status.

How We Use the Data

  • Create and display shared scheduling pages.
  • Let participants submit or edit their own availability.
  • Calculate full-group overlap, partial overlap, and candidate-time voting results.
  • Let organizers review, lock, archive, export, or confirm a final time.

The current MVP does not use core scheduling data for ad targeting, third-party marketing, or model training.

Cookies and Local Storage

  • Core scheduling works without account cookies, and the current MVP does not set first-party cookies for its own scheduling flow.
  • The site uses browser local storage to remember language preference, create-schedule defaults, a recently used display name, same-browser edit links, and local weekly templates.
  • Local storage stays in the current browser and is not automatically sent with every request like cookies. Users can clear it through their browser settings or use a private browsing session.
  • Future third-party ads, login sessions, or safer management-link handling may require cookies or consent controls. Real ads remain disabled until the provider, region-specific consent approach, and privacy disclosures are ready.

Ads and Third-Party Technology

The site has reserved display-ad placements and an /ads.txt route, but real production ads remain disabled. If Google AdSense or another display-ad provider is enabled later, this page will be updated with the actual provider, opt-out path, and region-specific consent approach.

  • Real third-party display ads are off by default. They require production configuration, provider review, allowed hosts, and privacy or consent readiness before launch.
  • Future ad providers may process ad request data such as page URL, browser, device, network, region, cookies or ad identifiers, web beacons, ad impressions, ad interactions, and invalid-traffic signals.
  • Schedule Share should not intentionally send schedule titles, participant names, availability, uploaded images, recognition text, management keys, or edit keys to ad providers as ad-targeting fields.
  • Pages that expose management or edit keys in the URL do not load third-party ad scripts before the key exposure risk is removed.

Users do not need to click ads to support the site. Automated refreshing, induced ad clicks, or fake traffic should not be used.

AI Image Recognition

Image recognition for screenshots of schedules or shift tables is treated as a cost-sensitive advanced path, not as a public default feature.

  • Image schedule recognition is not publicly open. An OpenAI API key alone does not enable it.
  • When a user actively uses image recognition, the image may be sent to the configured AI provider to generate an editable availability preview.
  • Recognition output is only a draft. The user must review and submit it before it becomes schedule data.
  • The system is designed not to store original images, full OCR text, or unconfirmed recognition details by default. Cost and credit records only keep necessary metadata and status.

Links Act as Permissions

A public share link lets someone view the schedule and submit availability. A management link lets the organizer view results, export, lock, or archive the schedule. An edit link lets a participant modify their own submission.

Please do not publish management links or participant edit links in public places.

Retention

New schedules expire by default after 90 days. The maintenance job can archive expired schedules and later hard-delete archived records after a grace period. Before broad public launch, production monitoring, backup-retention notes, and deletion-failure alerts still need to be finalized.

Operator and Contact

Public operator: Toni Liu (Australia). For feedback, archive requests, or deletion requests, use the contact page.

Related Pages

You can also read About, Terms, and Contact and deletion requests. Chinese version: 隐私与数据保留说明.