Privacy Policy
This Privacy Policy explains how Weekloom Inc. ("Weekloom", "we", "us", or "our") collects, uses, discloses, and protects your personal information when you use the Weekloom website at https://www.weekloom.com, our applications, and related services (the "Service"). It should be read together with our Terms of Service and EULA.
By using the Service you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Information we collect
We collect the following categories of information:
- Account information: your email address and authentication credentials. Your password is handled by our authentication provider (Supabase Auth) and stored only in hashed form — we never see or store your plaintext password.
- Content you create: your boards, blocks, tasks, per-day steps, notes, labels, deadlines, and related metadata.
- Settings and preferences: such as theme, accent color, font, layout sizes, pinned items, and notification preferences.
- Activity data: a log of actions you take in the app, which we use to power features such as your weekly summary and to operate and secure the Service.
- Collaboration and presence data: when you use shared boards, your email and display name, online presence, live cursor position, drag state, and chat messages are shared in real time with other members of that board.
- Google Calendar data: only if you choose to connect Google Calendar. This includes your Google account's email address, the list of your calendars, and the events on the calendars you select to sync. See section 4a for exactly what we receive, what we store, and what we do not.
- Payment information: when you purchase a paid plan, payments are processed by Stripe. We receive limited billing details (such as your plan, subscription status, and Stripe customer/subscription identifiers) but we do not collect or store your full payment card number.
- Technical data: standard log and device information (such as IP address and browser type) and cookies or local storage used to keep you signed in and remember your preferences.
2. How we use your information
We use personal information to:
- provide, operate, maintain, and improve the Service;
- create and authenticate your account and keep it secure;
- process payments and manage subscriptions and trials;
- enable real-time collaboration features you choose to use;
- power product features such as summaries, reminders, and notifications;
- detect, prevent, and address fraud, abuse, and security issues;
- send you service and transactional communications; and
- comply with legal obligations and enforce our Terms.
2a. Legal bases
Where applicable law requires a legal basis for processing, we rely on: the performance of our contract with you (to provide the Service); your consent (for example, accepting these policies at signup or enabling browser notifications); our legitimate interests in operating, securing, and improving the Service; and compliance with legal obligations. You may withdraw consent at any time, though some features may not work without it.
3. Cookies and local storage
We use cookies and similar technologies that are essential to the Service — for example, session cookies that keep you signed in, and local storage that remembers preferences such as your theme. We do not use third-party advertising cookies or cross-site tracking.
4. How we share information
We do not sell your personal information. We share it only as follows:
- Service providers (processors): we use trusted vendors that process data on our behalf, including Supabase (database, authentication, and hosting of your data), Stripe (payment processing), Vercel (application hosting and delivery), and Cloudflare (delivery of demo media). They may only use the data to provide services to us.
- Other users: information you place on a shared board, and your presence data on that board, is shared with the other members of that board.
- Google (only if you connect Google Calendar): we send your timed tasks to your own Google account so they appear as calendar events, and we read events from the calendars you select. This is a transfer to your own account at your direction, not a disclosure to a third party. See section 4a.
- Legal and safety: we may disclose information if required by law or legal process, or to protect the rights, property, or safety of our users, the public, or us.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
4a. Google Calendar
Connecting Google Calendar is optional and off unless you turn it on. This section describes that feature specifically; if you never connect a Google account, none of it applies to you.
What the feature does: it keeps your timed Weekloom tasks and the events on the Google calendars you choose in sync, in both directions — each Gantt board with the one calendar you pick for that board. A change in one appears in the other.
Permissions we ask Google for:
- See, create, change, and delete events on your Google calendars (calendar.events). This is what makes two-way sync possible, and it applies to the calendars you select — which may include your primary calendar.
- Create and manage a secondary calendar of our own (calendar.app.created). If you choose to have us create a dedicated calendar for a board, this is how we make that "Weekloom" calendar in your account.
- See the list of your calendars, read-only (calendar.calendarlist.readonly), so we can show you which ones you can choose from.
- See your Google account's email address (userinfo.email), so we can show you which account is connected.
Permissions we deliberately do not ask for: we do not request full Calendar access (calendar) or calendar-management access (calendar.calendars). Weekloom therefore cannot delete a calendar, change a calendar's sharing settings, or change who has access to it. We can only read and write events on the calendars you select, and manage any Weekloom calendars we created for your boards.
You choose which calendars sync. Turning a calendar off stops us reading it. Nothing already imported is deleted when you do.
Information about other people. This is important and we want to be direct about it. Google's API returns whole event records, so when you sync a calendar that contains meetings, we necessarily receive the full record for those events — which can include the names and email addresses of other people invited, the organizer, meeting titles, descriptions, locations, and conferencing links. Those people are not Weekloom users and have not agreed to our Terms. We receive that information because there is no way to ask Google for part of an event; we minimize what we do with it, as follows.
What we actually store. From each synced event we store only the fields a Weekloom task can hold: its title, its description, its start time, its end time, and identifiers that link the event to the task. We do not store attendees, organizers, other people's names or email addresses, conferencing links, attachments, or guest lists. Attendee information passes through our servers in memory only, so that we can process the event, and is never written to our database. Our activity logs record only an event's title, start, and end — never the full event record.
One exception, stated plainly: for an event you have not created in Weekloom, we store how many guests it has — the number alone, never who they are. We store it so that we can warn you, before you delete or move that event, that real people will be emailed about it. It is the only thing we keep about the guests, and we keep it precisely so we can tell you about them.
What we write, and where. Each of your Gantt boards syncs with one Google calendar that you pick for that board: a dedicated calendar we create for the board (a "Weekloom" calendar), or an existing calendar of your own that you select for it. A calendar syncs with at most one board, and a board with at most one calendar. Your timed Weekloom tasks — their titles, notes, dates, and times — are written as events onto the calendar mapped to their board. When you edit or delete such a task in Weekloom, we make the corresponding change on that calendar in Google.
Deleting an event we did not create. If you remove a mirrored event from Weekloom, we ask you first, every time, and we only delete it from Google Calendar if you explicitly choose that for that specific event. If you don't choose it, the event stays in your Google Calendar and we simply stop mirroring it.
We never delete one of your events by inference. If a task disappears for any reason other than you answering that question — you delete a whole board, a block, or shorten a task; or anything else removes it indirectly — we take that as no instruction at all, and we leave your Google Calendar event exactly where it is. Delete your entire Weekloom board and the appointments you did not create in Weekloom survive untouched. Disconnecting never deletes them either (see below).
Deleting an event notifies its guests. If an event you delete through Weekloom has other people invited, Google sends them a cancellation email — the same as if you had deleted it in Google Calendar yourself. The same is true if you move such an event in Weekloom: Google notifies the guests of the new time. We tell you how many guests are affected before you confirm a deletion.
How the connection is secured. Google issues us a refresh token so we can keep syncing while you are away. We encrypt it with AES-256-GCM before storing it, and the encryption key is held outside the database, so the token is unreadable to anyone holding only a copy of our database.
Disconnecting and deletion. You can disconnect at any time in Settings, and you choose what happens to your calendar data: keep everything, or remove the events Weekloom created. Disconnecting revokes our access token and stops all reading and writing. We never delete a calendar, and we never delete an event you created — only ones we created, and only if you ask us to. Deleting your Weekloom account removes the connection and all synced calendar data we hold; it does not alter your Google Calendar.
Google API Limited Use. Weekloom's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google Calendar data only to provide the calendar-sync feature you enabled; we do not sell it; we do not use it for advertising; we do not use it to train generative or machine-learning models; we do not allow humans to read it except with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data is aggregated and anonymized; and we do not transfer it to others except as necessary to provide the feature, to comply with applicable law, or as part of a merger or acquisition as described in section 4.
5. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal information within a reasonable period, except where we must retain certain records to comply with legal, accounting, or tax obligations or to resolve disputes.
6. Data security
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and database row-level security that isolates each user's data. Access tokens for connected third-party accounts, such as Google Calendar, are additionally encrypted at rest with AES-256-GCM using a key held outside the database. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
7. International data transfers
Our providers may store and process your information in the United States and other countries, which may have different data-protection laws than your own. Where required, we take steps to ensure your information receives an adequate level of protection.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, update, port, or delete your personal information, and to object to or restrict certain processing. You can update much of your information in the app, or contact us at hello@weekloom.com to make a request. If you are in Canada and have an unresolved concern, you may contact the Office of the Privacy Commissioner of Canada.
If you enable browser notifications, you can turn them off at any time in your browser or device settings, or from the app's settings.
9. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us so we can delete it.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, for material changes, take reasonable steps to notify you.
11. Contact us
If you have questions about this Policy or our handling of your information, contact Weekloom Inc. at hello@weekloom.com.