Security & Data Handling
Last updated 15 August 2026
Minimal calendar access
The strongest protection we offer is not holding the data in the first place. We request the narrowest calendar permissions that exist:
- Free/busy only. We can see that a period is busy. We cannot see the event's title, description, location, attendees, or attachments.
- Only our own events. We can create and remove events this service created. We cannot read, edit, or delete anything else in your calendar.
These are technical limits enforced by your calendar provider, not promises about our behaviour. Even if our systems were fully compromised, the access tokens we hold could not retrieve your event contents.
Storage and encryption
- All traffic is served over HTTPS/TLS.
- Data is encrypted at rest by our hosting provider.
- Calendar access tokens are stored encrypted and are revocable by you at any time from your calendar provider.
- Free/busy information is deleted within 7 days of the period it describes having passed.
Isolation between people
The rule that one person cannot see another's availability is enforced in the data layer, beneath every interface — the website, the text-message assistant, and any AI agent acting on your behalf all go through the same checks. An assistant cannot be talked into revealing another person's schedule, because the systems it calls will not return it to anyone.
Assistants and agents
- An agent acts only within the permissions you granted, and you can revoke them at any time.
- Agent permissions are granular — reading your plans is separate from committing you to one.
- Text messages are treated strictly as data. Instructions embedded in a message cannot expand what the assistant is allowed to reach.
Access
Administrative access is limited to the operator of the service and used only for support and debugging. Production secrets are held in the hosting provider's secret store, never in source control.
Reporting a vulnerability
If you find a security problem, please email security@seemyfriends.net. Tell us what you found and how to reproduce it, and give us a reasonable chance to fix it before publishing.
We will acknowledge within 3 business days. We will not pursue legal action against anyone who reports a problem in good faith, does not access other people's data beyond what is needed to demonstrate the issue, and does not degrade the service for others.
Breaches
If a breach creates a real risk of significant harm, we will notify affected people and the Office of the Privacy Commissioner of Canada, as PIPEDA requires.
Honest limits
seemyfriends is an early beta run by one person. It has not had an independent security audit, and it holds real information about when you are free and who your friends are. The architecture is built to hold as little of that as possible — but you should weigh that when deciding what to connect.