SANDBOX — test environment, data may be wiped

Privacy Policy

Effective: 2026-10-03

1. Who we are

Busypus (the “Service”) is operated by Andres Canella, an individual based in Miami, Florida, USA. We control how your personal data is processed in connection with the Service. Contact: meet@busypus.com.

2. What we collect

To operate Busypus we collect the following:

  • From hosts: email address, password (stored only as a one-way argon2id hash), chosen username, IANA timezone, optional newsletter opt-in.
  • From guests: chosen nickname, optional email address, IANA timezone, optional newsletter opt-in. Email is not required to use the Service as a guest.
  • Meeting data: meeting titles, availability windows, time intervals you mark as available, and finalized meeting times.
  • Connected accounts (optional): if you connect Google Calendar or Zoom, or connect an AI assistant to your account, see sections 5 and 6 for what that involves.
  • Technical: IP address and request metadata (HTTP method, path, timestamp, user agent) processed by AWS for service delivery, security, abuse prevention, and rate limiting.

3. What we don’t do

  • We don’t use third-party advertising or behavioral tracking pixels.
  • We don’t sell your data.
  • We don’t share your data with advertisers or data brokers.
  • We don’t store your password in plain text or in any reversible form.
  • We don’t read your calendar unless you connect one, and when you do we read only the start and end times and titles of events — we never store event titles, never show them to anyone but you, and never read descriptions, locations, or attendees (see section 5).

4. How we use your data

  • Operating the Service: creating meetings, displaying availability, computing overlap, and finalizing times.
  • Sending transactional email related to your account (verification, password reset) and your meetings (host notifications when guests respond, calendar invite emails with .ics attachments when a meeting is finalized; delivery is not guaranteed).
  • Sending occasional product newsletters via Amazon SES, only if you opt in.
  • Security, abuse prevention, debugging, and meeting our legal obligations.

5. Connected calendars and Zoom (optional)

Hosts can connect a Google Calendar or Zoom account from the account page. Nothing is connected unless you choose to.

  • Google Calendar: we ask Google for read-only access to your calendar events and calendar list, plus your Google account email address (to label the connection). When you use the availability grid, or someone opens your one-on-one booking link, we read the start and end times of timed events on the calendars you have selected in Google Calendar. All-day events, cancelled events, and events marked “free” are ignored. We use these busy times only to grey out times on your own availability grid and, for one-on-one links, to hide times you’re busy from the person booking — who therefore sees which times inside the meeting window are not available, but never what the events are.
  • Event titles: we also read the title of each of those events (events marked private or confidential in Google Calendar have no title for us). Titles are used only to show you your own busy blocks on your own availability grid, and to let an AI assistant you have connected (section 6) explain to you which event blocks a time. Titles are never stored and never shown to guests or anyone booking your links. We don’t read event descriptions, locations, or attendees, and we don’t write to your Google Calendar.
  • Zoom: we ask Zoom for permission to create meetings and read your basic Zoom profile (to label the connection). When you choose Zoom as the video option, we create a scheduled Zoom meeting on your account with the meeting’s title, start time, and length, and delete it if you reschedule or cancel.
  • Tokens: the access and refresh tokens these providers issue are stored in our database so the connection keeps working. When you disconnect an account or delete your Busypus account, we ask the provider to revoke the tokens (best-effort) and delete them from our database.

Your use of Google and Zoom is also governed by their own privacy policies.

6. AI assistants (MCP)

You can connect an AI assistant (for example Claude, ChatGPT, or Cursor) to your Busypus account through our MCP server. Setup instructions are on the MCP page.

  • Connecting requires you to log in to Busypus and approve the assistant. Once approved, it can read and act on your account within the same limits as the website: list and view your meetings, guests’ responses, and connected-calendar busy times, including the titles of the events that make a time busy (so it can tell you which event blocks a slot; see section 5 — guests’ assistants never get them); create, change, finalize, reschedule, or cancel meetings (which can send emails to your guests); and respond to meetings you’re invited to as you.
  • When you respond to someone else’s meeting through an assistant, we store that meeting’s guest access token with your account so later requests can act as that guest.
  • Anything the assistant reads from Busypus is sent to that AI provider and is handled under the provider’s own terms and privacy policy, not this one. We don’t control what the provider does with it.
  • Access lasts up to 30 days before the assistant must ask you to log in again. To disconnect one assistant, remove the Busypus connector in that app. To disconnect every assistant at once, reset your password.
  • Some actions are only available on the website, including deleting your account and connecting Google Calendar or Zoom.

7. Service providers and disclosures

We share the minimum data necessary with the following service providers to operate the Service:

  • Amazon Web Services (AWS), USA: hosts the application and stores data (DynamoDB, Lambda, API Gateway, Amplify, Route 53, ACM). Primary region: US-East-1 (Northern Virginia). Some AWS edge and DNS services are global. AWS Simple Email Service (SES) delivers transactional email and stores the newsletter contact list (email addresses of users who opted in).
  • Resend (resend.com), USA: our email provider until October 3, 2026; may retain delivery logs and contact lists from before that date.
  • Google and Zoom: only if you connect them (section 5).
  • AI providers you connect: only if you connect an AI assistant (section 6); data goes to the provider you chose, at your request.

We may also disclose your data: (a) to comply with applicable laws, court orders, subpoenas, or other legal process; (b) to protect the rights, property, or safety of Busypus, our users, or the public, including to prevent or investigate fraud or abuse; or (c) in connection with a sale, merger, financing, or transfer of all or part of the Service, in which case the recipient will be bound by terms at least as protective as these. We do not sell your data to third parties.

8. Cookies

We use a small number of essential cookies. None are used for advertising, cross-site tracking, or third-party analytics:

  • bp_session — host authentication token (httpOnly, Secure, SameSite=Lax). Keeps you logged in for up to 30 days.
  • bp_username — your username, used to render “logged in as <username>” without a server round-trip. Not used for authentication and readable by the page’s scripts.
  • bp_guest_<host>_<meeting> — guest authentication token, scoped to a single meeting. Lets you return to edit your availability without re-entering your nickname.
  • bp_guest_nick_<host>_<meeting> — your guest nickname for that meeting, used for display.

Authentication cookies use the SameSite=Lax attribute to mitigate cross-site request forgery; we do not use a separate CSRF cookie.

9. Your controls

We provide the following controls over your data, subject to verification of your identity and any applicable legal exceptions:

  • Access: view your account profile at any time via the account page.
  • Delete: use the “delete my account” control on the account page. This removes your profile, every meeting you created, and your guest responses from our active database. Best-effort removal from our newsletter contact list (Amazon SES) is also performed.
  • Disconnect: disconnect Google Calendar or Zoom from the account page at any time. Disconnect AI assistants as described in section 6.
  • Newsletter opt-out: click the unsubscribe link in any newsletter email, or toggle the newsletter setting off on the account page. We will stop sending you newsletters within a reasonable time.
  • Data export: not yet self-serve. Email meet@busypus.com and we will provide a copy of your data within a reasonable time, subject to verification.
  • Other requests (correction, restriction, objection, portability): contact us at the email above.

Depending on where you live, additional rights may apply under laws such as the GDPR (EU/UK), the CCPA/CPRA (California), or similar state laws. We will respond to verified requests as required by applicable law.

10. Data retention

We retain account data for as long as your account is active. Meetings you create are retained until you or we delete them.

When you delete your account, your profile, username reservation, and all meetings you created are removed from our active database promptly. Database backups, application logs, and email-delivery logs (Amazon SES) may retain copies for a limited period (typically up to 90 days) before they age out naturally. We may also retain data longer where required by law or for legitimate purposes such as fraud prevention, dispute resolution, security, or enforcing our agreements.

11. International users

Busypus is operated from the United States and primarily stores data in AWS’s US-East-1 (Northern Virginia) region. If you access the Service from outside the US, you consent to your data being transferred to and processed in the United States.

12. Children

Busypus is not intended for and may not be used by anyone under the age of 13, whether as a host or a guest. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Security

We implement reasonable technical and organizational measures to protect your data, including: hashing passwords with argon2id (a memory-hard hashing function), signing authentication cookies and serving them with the httpOnly, Secure, and SameSite=Lax attributes, and serving the Service over HTTPS. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If you suspect unauthorized access to your account, contact us immediately.

14. Changes

We may update this Privacy Policy. Material changes will be communicated by posting the updated policy on the Service and updating the effective date above.

15. Contact

Privacy questions and requests can be sent to meet@busypus.com.