Security and privacy

Calendar access designed around least privilege and user control

Meeting Guardian requests read-only calendar access, encrypts provider tokens at rest, minimizes retained meeting data, and gives users clear disconnect and account-deletion controls.

Free to start · No credit card · Calendar connection optional

Critical meeting alarm

Client strategy review

5 min

Today · 10:00 AM · 45 minutes

The alarm stays active in this browser tab until you choose what happens next.

Join meetingSnooze 5 min
Product preview: browser alarm with timing, join, and snooze actions.

What Meeting Guardian adds

Read-only calendar scopes

Google calendar.readonly and Microsoft Calendars.Read do not allow the app to modify provider events.

Encrypted provider tokens

OAuth access and refresh tokens are encrypted at rest and sent only over encrypted transport.

Short meeting retention

Ended meetings are eligible for automated removal after the configured retention period, currently 24 hours by default.

Deletion controls

Disconnecting clears provider tokens and imported meetings; account deletion removes account data and cascading records.

Data Meeting Guardian uses

Account data includes an email address, optional name, password hash, preferences, and verification state. Connected-calendar data can include provider account identifiers and upcoming event titles, descriptions, times, durations, and supported meeting links.

Meeting Guardian does not request provider passwords, store attendee lists, sell calendar data, or use calendar data for advertising or general AI model training.

Access and storage safeguards

Calendar connections use official Google and Microsoft OAuth flows. Refresh and access tokens are encrypted before database storage. Passwords are hashed with bcrypt, verification and reset tokens are stored as hashes, and application traffic uses HTTPS in production.

No system can promise absolute security. Meeting Guardian uses administrative and technical safeguards appropriate to the service and keeps its privacy policy aligned with current behavior.

Control, retention, and deletion

Users can disconnect a provider at any time. The app then removes imported meetings for the connection, wipes stored provider tokens, and stops synchronization. Users can also revoke access from Google or Microsoft.

Self-service account deletion requires password confirmation and permanently removes the user record and dependent product data. Limited security audit records and infrastructure backups may remain for defined operational or legal periods.

Frequently asked questions

Can Meeting Guardian change my calendar events?
No. It requests read-only Google and Microsoft calendar scopes and does not create, edit, or delete provider events.
How are calendar tokens stored?
OAuth access and refresh tokens are encrypted at rest. They are cleared when the connection is disconnected.
What happens to old meetings?
Ended meetings are eligible for automated deletion after the configured retention period, which defaults to 24 hours.
Can I delete my account?
Yes. Non-owner users can permanently delete their account from Settings after confirming their password.

Give the next important meeting a stronger reminder

Start with a manual test meeting or connect one Google or Outlook calendar.

Create free account