This Privacy Policy explains how Duolyx (“Duolyx”, “we”) collects, uses, and shares information about you when you use our scheduling platform, websites, and services (the “Service”).
1. Information we collect
Account information
When you sign up, we collect your name, email address, profile photo (if you use Google sign-in), and time zone. This is used to create your account and let you sign in.
Content you submit
Event types, availability schedules, workflow messages, meeting details, and any other data you enter into the Service.
Booking data from your attendees
When someone books time with you through the Service, we collect their name, email, chosen time slot, and any answers to the custom questions you set on your event type. This data is used to send booking confirmations and reminders, and is visible to you (the host).
Payment information
Payment information is collected and processed by Stripe, Inc. Duolyx never sees or stores your card details. Stripe returns to us only the information we need to service your subscription (customer ID, subscription status, invoice history).
Calendar data
If you choose to connect Google Calendar, we access data from your Google Account under the scopes you approve on Google’s consent screen. A full description of the scopes we request, the data we receive, how we store and protect that data, and how you can revoke access is provided in Section 11 (Google user data) below. Duolyx’s general security measures (encryption in transit and at rest, access controls, monitoring, incident response) are described in Section 5 (How we protect your data).
Usage and technical data
We log IP addresses, user agents, and request timestamps for security, debugging, and abuse prevention. We may use cookies or similar technologies for authentication and analytics.
2. How we use information
- To provide the Service and its features.
- To communicate about your account, billing, and product updates.
- To improve the Service through aggregate analytics.
- To detect, prevent, and respond to abuse, fraud, or security incidents.
- To comply with legal obligations.
We do not sell your personal information. We do not use your data to train AI models. We do not send you unrelated marketing emails.
3. Sharing
We share information only with:
- Service providers who help us operate the platform (Supabase for database and authentication, Vercel for hosting, Resend for email delivery, Stripe for payments, Google APIs for calendar sync).
- Your attendees, only insofar as required to complete a booking (their name and time slot show on your calendar; your name and email show on their confirmation).
- Authorities when compelled by valid legal process.
4. Data retention
Account data is retained while your account is active. When you delete your account, we permanently remove your profile, event types, availability, and workflows within 30 days. Booking records (including attendee information) are retained for up to 12 months after account deletion for tax and dispute-resolution purposes.
5. How we protect your data (Security)
Duolyx applies technical and organisational measures designed to protect the personal information we handle, including data received from Google APIs, from unauthorised access, disclosure, alteration, and destruction. This section describes those measures.
Encryption in transit
All traffic between your browser, the Duolyx application, our hosting provider (Vercel), our database (Supabase), and third-party APIs we rely on - including Google APIs, Stripe, and Resend - is encrypted using HTTPS with TLS 1.2 or higher. Plaintext HTTP is redirected to HTTPS at the edge and HTTP Strict Transport Security (HSTS) is enforced on the primary domain.
Encryption at rest
Personal information and OAuth tokens are stored in a managed Postgres database provided by Supabase, which is hosted on Amazon Web Services. Database storage volumes are encrypted at rest using AES-256, the standard block-level encryption used by Amazon RDS. Automated backups inherit the same encryption. Application logs that may transit personal identifiers are stored on encrypted volumes at our hosting provider.
Access controls
Access to production systems that hold personal information is restricted to Duolyx personnel who need it to operate, secure, or support the Service. Administrative consoles for our hosting, database, email, and payment vendors require multi-factor authentication. Inside the database, sensitive tables (for example the table that stores Google OAuth tokens and the table that stores booking records) are protected by Postgres Row-Level Security so that a user session can only read rows belonging to that user. Attendees and other end users never have direct database access.
Monitoring and logging
We log authentication events, administrative actions, API errors, and requests to sensitive endpoints. Logs are used to detect anomalous activity, investigate incidents, and support the integrity of the Service. Log retention is limited to what is needed for these purposes.
Vulnerability management and secure development
Duolyx applies security updates to its application dependencies and to the operating environments provided by Vercel and Supabase on an ongoing basis, following vendor advisories and automated dependency alerts. Code changes are reviewed prior to deployment and go through an automated build and type-check pipeline. Secrets (API keys, OAuth client secrets, database credentials) are stored in the encrypted environment-variable stores of our hosting and database vendors and are never committed to source control.
Incident response
If we become aware of a security incident that affects your personal information, we will investigate promptly, take reasonable steps to contain the incident, and notify affected users and, where required, regulators, in accordance with applicable law. To report a suspected vulnerability or security concern, please email security@duolyx.com.
Personnel and vendors
Duolyx personnel with access to production systems are bound by confidentiality obligations and are expected to follow secure working practices, including the use of multi-factor authentication and access limited to what is necessary for their role. We use a small set of established sub-processors (Supabase, Vercel, Stripe, Resend, and, when you connect it, Google) that publish their own security programmes and certifications. We review the security posture of these vendors before onboarding them and periodically thereafter.
The measures described above apply to all personal information we handle. For the specific application of these measures to data received from Google APIs (Google Sign-In and Google Calendar), see Section 11 (Google user data).
6. Your rights
Depending on your jurisdiction, you may have rights to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information.
- Export a copy of your data.
- Object to certain processing.
Email privacy@duolyx.com to exercise any of these rights. We will respond within 30 days.
7. International transfers
Duolyx is based in the United States. Data we collect may be transferred to and processed in the US. By using the Service you consent to this transfer.
8. Children
The Service is not directed to children under 16 and we do not knowingly collect information from them. If you believe a child has provided us information, contact privacy@duolyx.comand we will delete it.
9. Changes to this Policy
We may update this Policy from time to time. The current version is always at this URL with the “Effective” date at the top. Material changes will be announced via email or in-app notice.
10. Contact
Duolyx
Email: privacy@duolyx.com
11. Google user data
Duolyx integrates with Google Sign-In and Google Calendar. This section describes how Duolyx accesses, uses, stores, protects, and shares data obtained from your Google Account. It applies in addition to, and does not replace, the rest of this Privacy Policy.
11.1 OAuth scopes we request
When you connect a Google Account, Google presents a consent screen listing the permissions Duolyx requests. Duolyx currently requests the following scopes:
- openid, userinfo.email, userinfo.profile - used solely to authenticate you and identify the Google Account you have connected. We receive your Google Account ID, primary email address, name, and profile photo.
- https://www.googleapis.com/auth/calendar.calendarlist.readonly - used to list the calendars available in your Google Account so that you can select which one Duolyx should check for availability and write bookings to.
- https://www.googleapis.com/auth/calendar.freebusy - used to check which time windows in your selected calendar are already busy, so Duolyx can offer only free time to people booking meetings with you.
- https://www.googleapis.com/auth/calendar.readonly - used to read the time boundaries and busy status of events on your selected calendar in order to prevent double bookings that free/busy alone cannot detect. Duolyx uses this scope only to determine when you are available; we do not persist event titles, descriptions, attendees, attachments, or meeting notes.
- https://www.googleapis.com/auth/calendar.events - used to create a Google Calendar event when someone books time with you through Duolyx, to update that event if the booking is rescheduled, and to delete that event if the booking is cancelled. Duolyx only modifies events that Duolyx created; it does not edit or delete events created by you or by other applications.
The Google Calendar connection is optional. You create your Duolyx account first and then choose whether to connect Google Calendar. Duolyx never accesses your Google Account without your prior consent through Google’s OAuth flow.
11.2 What we store
From your Google Account, Duolyx stores:
- Your Google Account email address, name, and profile photo, used to identify the connected account and display it in your settings.
- An OAuth refresh token and short-lived access token issued by Google, so Duolyx can continue to check availability and write bookings on your behalf between browser sessions.
- The identifier of the calendar you selected as your Duolyx availability calendar.
- The Google Calendar event IDs of events Duolyx has created on your behalf, so we can update or delete them when a booking changes.
- The time boundaries (start and end) of events on your selected calendar are read on demand to compute availability. Duolyx does not maintain a long-term copy of your calendar contents; results are held only for as long as needed to render the current availability page.
Duolyx does not store the content of your existing Google Calendar events - titles, descriptions, attendees, attachments, meeting notes, or conferencing links from events Duolyx did not create.
11.3 How we protect Google user data
- In transit. All communication between your browser, Duolyx servers, and Google APIs is encrypted using HTTPS with TLS 1.2 or higher.
- At rest. Google user data is stored in our managed Postgres database (Supabase, hosted on Amazon Web Services). Database storage is encrypted at rest at the storage layer using AES-256, which is the standard encryption for Amazon RDS-backed Postgres.
- Row-level access. The database table that holds Google OAuth tokens and connection metadata has row-level security enforced by Postgres, so a given user’s tokens are only readable in the context of that user’s authenticated session.
- Personnel access. Access to production systems that store Google user data is restricted to Duolyx personnel who need it to operate, secure, or support the Service, and administrative access is protected by the multi-factor authentication provided by our hosting and database vendors.
11.4 Who can access Google user data
Google user data received by Duolyx is accessible to:
- You, through the Duolyx interface.
- The people you book with, only to the extent necessary to display the confirmed meeting on their calendar (their view is written by Google Calendar itself, not by Duolyx directly).
- Duolyx personnel, only when necessary to operate, secure, or support the Service, or to comply with a legal obligation.
- The sub-processors listed below, only to the extent required to provide their portion of the Service.
Sub-processors that may process Google user data on Duolyx’s behalf:
- Supabase - managed Postgres database and authentication.
- Vercel - application hosting and compute.
- Google LLC - as the source of the data. API calls flow back to Google to read availability and write events on your calendar.
Duolyx does not sell Google user data, does not transfer it to data brokers, and does not share it with advertising networks.
11.5 What we do NOT do with Google user data
Duolyx does not use Google user data to:
- Serve advertising, either on Duolyx or on any other service.
- Train, retrain, fine-tune, or evaluate generalised artificial intelligence or machine-learning models.
- Build user profiles for purposes unrelated to the scheduling features you enabled.
- Sell, rent, or otherwise transfer to third parties for their own independent use.
11.6 Retention and deletion
- OAuth tokens and Google Account identifiers are retained for as long as your Google Calendar connection is active.
- When you disconnect Google Calendar inside Duolyx, we delete the OAuth tokens and the connection record from our database immediately.
- When you delete your Duolyx account, all Google user data associated with your account is deleted in accordance with the account-deletion timeline in Section 4 of this Policy.
- Google Calendar events that Duolyx created on your behalf remain on your Google Calendar after disconnection. Duolyx cannot delete events after our tokens are removed; you can delete them from Google Calendar directly if you wish.
11.7 How to revoke Duolyx’s access to your Google Account
You can disconnect Duolyx from your Google Account at any time in two ways:
- Inside Duolyx. Open Apps & integrations from your account menu, locate the connected Google Calendar row, and clickDisconnect. This immediately removes the tokens and connection record from Duolyx’s database.
- From Google directly. Visit https://myaccount.google.com/permissions, locate “Duolyx”, and choose Remove access. We recommend performing this step in addition to the in-app disconnect so that any tokens Google still associates with your account are revoked from Google’s side as well.
11.8 Google API Services User Data Policy - Limited Use
Duolyx’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Duolyx:
- Only uses Google user data to provide or improve user-facing features that are prominent in Duolyx’s user interface - the scheduling and calendar-sync features described in Section 11.1.
- Does not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- Does not use Google user data for serving advertisements, including retargeting, personalised, or interest-based advertising.
- Does not allow humans to read Google user data unless (a) we have obtained your affirmative agreement to view specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data is aggregated and used for internal operations in accordance with applicable privacy requirements.
11.9 Contact for Google-data questions
For questions specifically about Duolyx’s handling of Google user data, contact privacy@duolyx.com.