Legal
Privacy Policy
Last updated July 14, 2026
Your calendar is deeply personal. This policy explains what BraveDay collects, why, and the control you have. In short: we collect the minimum needed to run scheduling for you, we never sell your data, and sensitive tokens are encrypted at rest.
What we collect
- Account data — your name, email, timezone, and booking handle.
- Calendar data — connections and busy/free times we sync to compute your availability. OAuth tokens are encrypted at rest with AES-256-GCM.
- Booking data — event types, bookings, attendee names and emails, and any intake answers.
- Usage data — basic product analytics and anonymous view counts on public booking pages to power your funnel analytics.
- Payment data — handled by Stripe. We store only a customer or subscription reference, never card numbers.
How we use it
We use data to provide scheduling — syncing calendars, computing availability, creating bookings, sending reminders and confirmations — and to operate, secure, and improve the Service. We process data to perform our contract with you and for our legitimate interest in running a reliable product.
Beaver, our AI assistant
When you use Beaver, the message you send and relevant scheduling context are sent to BraveDay's configured AI provider to generate a response. Beaver is confirm-first: it drafts a change and waits for your explicit confirmation. It never books, moves, or cancels anything on its own. We do not use Beaver conversations for advertising. AI features are optional; if you never use Beaver, none of your data is sent to an AI provider.
How we share it
We share data only with processors needed to run the Service. We never share it for advertising and never sell your personal data.
Subprocessors
We rely on a small set of vendors to operate the Service:
- Calendar and conferencing — Google, Microsoft, Apple, and Zoom, for the accounts you choose to connect.
- AI providers — OpenAI or Anthropic powers Beaver's responses, depending on the server configuration and only when you use Beaver.
- Stripe — payments and subscription billing.
- Resend — transactional email, confirmations, and reminders.
- Twilio — SMS one-time codes and reminders, if you enable them.
- Cloudflare — bot protection on public booking pages.
Some processors are based in the United States. Where required, international transfers rely on standard contractual clauses.
Security
OAuth tokens, notification secrets, and webhook signing keys are encrypted at rest. API keys are stored only as hashes. Access is scoped per user and organization. See our security page for details.
Cookies
We use a session cookie to keep you signed in and, where enabled, a bot-protection cookie on public booking pages. We do not use advertising or cross-site tracking cookies.
Retention
We keep your data while your account is active. When you delete data or your account, we remove it within a reasonable period, except where records must be retained for legal or accounting reasons.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your data, and to object to certain processing. You can export bookings from the app, manage connections and channels in settings, or email us to exercise a right.
Deployments on your own infrastructure
If BraveDay runs on infrastructure you control, your data lives there and this policy does not apply. You are the data controller, and the data-processing terms of that engagement govern instead.
Contact
Privacy questions or requests? Email hello@ravefox.dev.
This is a plain-language template, not legal advice.