Legal

Privacy Policy

Last updated August 31, 2026

1. Who we are

This Privacy Policy describes how Gryfin Tech (“we”, “us”, or “our”), based in Goa, India, collects, uses, stores, and shares information when you use cael (the “Service”), including our website, hosted booking views, embeds, feedback forms, and related applications.

Questions about this policy or your data: hello@getcael.com.

2. Scope

This policy covers information we process about account holders, people who submit feedback, and visitors who interact with public cael views or embeds. It does not cover the privacy practices of third-party scheduling platforms where bookings are completed (for example Calendly, Cal.com, or Microsoft Bookings). Those providers process booking and invitee data under their own policies.

3. Information we collect

Account and profile. When you sign in or create an account, we collect your email address and authentication identifiers via our auth provider. We may store a display name or similar profile fields associated with your workspace membership.

Workspace and product data. We store settings you configure in cael, including combined calendar views, branding and accent preferences, embed and share settings, connected calendar metadata, and source colors.

Integration credentials and connection data. When you connect a scheduling tool with OAuth or an API key, we store encrypted tokens or keys needed to read availability, along with connection metadata (provider type, account labels, and related identifiers). When you add a Calendly profile by public link, we store the profile identifier and related metadata only — no OAuth tokens or API keys for that connection.

Availability data. We cache availability windows retrieved from connected sources so we can render combined calendars. We design the Service to read availability — not invitee or booking PII from source platforms.

Billing. If you subscribe to a paid plan, our payment processor collects payment and billing details. We store subscription status, plan entitlements (including complimentary access we may grant), and processor customer or subscription identifiers needed to manage your account. We do not store full payment card numbers on our servers.

Feedback and support. When you send feedback from the website or dashboard, we collect your email address, category, message, and (for signed-in users) the related workspace. We use this to respond, improve the Service, and notify our team.

Technical and usage data. We may collect IP address, browser and device information, approximate location derived from IP, pages or views accessed, referring URLs, product interaction events, session recordings (with sensitive inputs masked), and diagnostic logs needed to operate, improve, and secure the Service.

Cookies and similar technologies. We use cookies and similar storage for authentication sessions, security (such as OAuth state), optional visitor Google FreeBusy tokens for calendar overlays, theme preference, optional product analytics (only after you accept analytics cookies), error diagnostics, and essential product operation. We do not sell personal information.

Visitor calendar checks.If a visitor connects Google Calendar or pastes an ICS link to hide conflicting times on a public view, that check is ephemeral: Google tokens are kept only in a browser cookie (not as a cael account), ICS addresses stay in the visitor's browser, and we process busy intervals in memory without storing them as account data. Google connect requests FreeBusy access only — not event titles or attendees. A pasted ICS feed may include event titles; we show those only in that visitor's browser and do not store them as account data.

4. How we use information

We use the information described above to:

  • Provide, operate, maintain, and improve the Service
  • Authenticate users and manage workspaces
  • Connect to third-party scheduling tools and refresh availability
  • Process subscriptions, invoices, plan entitlements, and complimentary access
  • Receive and respond to feedback, help requests, and related communications
  • Communicate about the Service, including transactional email and support
  • Monitor reliability, prevent abuse, and protect security
  • Understand product usage and improve the Service through analytics
  • Comply with legal obligations and enforce our Terms of Service

5. Third-party services

We rely on subprocessors and integrations to run cael. Depending on how you use the Service, this may include:

  • Supabase — authentication, database, and related infrastructure
  • Dodo Payments — subscription billing and payment processing
  • Resend — email delivery for feedback and related notifications to our team
  • Calendly — OAuth or public-link connection and availability via Calendly’s APIs or public booking pages
  • Cal.com — API-key connection and availability via Cal.com’s APIs
  • Microsoft — OAuth connection for Microsoft Bookings availability
  • Google Calendar — visitor FreeBusy overlay (busy times only) when a booker connects Google on a public view
  • Outlook and other ICS feeds — visitor busy-time overlays when a booker pastes a feed URL. Visitor overlays may show event titles from the feed in their browser only.
  • PostHog — product analytics, session replay, and related diagnostics
  • Hosting and infrastructure providers — to serve the website and application

These parties process data under their own terms and privacy policies. Connecting an integration authorizes us to exchange the data needed for that integration’s features. Submitting feedback authorizes us to email the contents to our team via our email provider.

6. Sharing of information

We may share information:

  • With subprocessors who help us operate the Service, under appropriate agreements
  • With third-party providers you choose to connect, as needed for those integrations
  • With workspace owners and admins for membership and billing administration
  • If required by law, regulation, legal process, or governmental request
  • To protect rights, safety, and security of Gryfin Tech, users, or the public
  • In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality
  • With your consent or at your direction

We do not sell personal information.

7. Data retention

We retain account, workspace, integration, feedback, and billing records for as long as your account remains active and as needed to provide the Service and respond to inquiries. Cached availability and busy intervals may be refreshed or discarded on a rolling basis. We may retain certain records after account closure where required for legal, security, dispute-resolution, or accounting purposes, then delete or anonymize them when no longer needed.

8. Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS), access controls, and encryption at rest for integration credentials and workspace ICS feed URLs. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

9. International transfers

Gryfin Tech is based in India. Your information may be processed in India and in other countries where our subprocessors operate. Those locations may have different data protection laws than your own. Where required, we take steps intended to provide appropriate safeguards for such transfers.

10. Your rights and choices

Depending on applicable law, you may have rights to access, correct, update, delete, or export personal information, or to object to or restrict certain processing. You can disconnect integrations from your dashboard, update account details where the product allows, choose Essential only or Accept analytics in the cookie banner, and request deletion of account or feedback data or other assistance by emailing hello@getcael.com.

You may also control cookies through your browser settings. Disabling essential cookies may prevent sign-in or core features from working.

11. Children

The Service is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

12. Public views and embeds

Hosted pages and embeds you publish may be accessible to anyone with the link or to visitors of sites where you place the embed. Do not publish information you are not comfortable making available in that context. Visitor interactions with source booking pages are governed by those providers.

13. Changes

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Continued use of the Service after changes become effective constitutes acceptance of the updated policy where permitted by law.

14. Contact

Gryfin Tech
Goa, India
hello@getcael.com

See also our Terms of Service.