Back to home

Privacy Policy

Last updated: September 26, 2026

1. Introduction

Voischedule (the “Service”) values your privacy. This policy explains what information the Service collects and uses, and how that information is handled.

2. Information We Collect

2.1 Google Account Information

When you sign in, we obtain the following information through Google OAuth:

  • Email address
  • Profile name
  • Profile image URL
  • Access token for Google Calendar (temporary)

2.2 Input Data

We process the following information that you enter:

  • Text input (natural language text describing an event)
  • Voice input data (temporary audio data used for speech recognition)

2.3 Automatically Collected Information

To operate the Service, access logs (IP address, browser information, and access date and time) may be recorded at the server level.

In addition, to prevent abuse (rate limiting), we record the number of API requests per user and per endpoint. We record only the number and times of recent requests; this record contains no speech, input text, or event details whatsoever.

3. How We Use Information

We use the information we collect only for the following purposes:

  • Adding events to Google Calendar (providing the core feature)
  • Natural language processing by AI (text is sent to the Anthropic Claude API, and audio to the Google Gemini API)
  • Billing, and managing your subscription status and free-use count
  • User authentication and session management
  • Improving the Service and fixing problems

4. Sharing Information with Third Parties

The Service sends user data to the following third-party services:

ServiceData sentPurpose
Google OAuthAuthentication informationUser authentication
Google Calendar APIEvent dataAdding events to the calendar
Anthropic Claude APITextNatural language processing
Google Gemini APIAudioNatural language processing (audio only)
StripeEmail address, payment information (entered directly by you on Stripe’s payment page), subscription statusPayments and subscription management
SupabaseEmail address, subscription status, usage counts (including your Stripe customer ID)Storing your account and subscription status
Vercel Web AnalyticsPages viewed, referrer, country, device typeUnderstanding usage (anonymous)

We do not provide user information to any third party other than those listed above, except when we receive a request for disclosure based on laws or regulations.

AI Processing and Google User Data

The Service uses AI for natural language processing, but the only data it sends to AI is the speech or text that you enter. The only permission the Service requests from Google is calendar.events, which is needed to create events, and it does not have permission to read your existing events. Therefore, the Service never sends data obtained from Google Workspace APIs to AI. AI providers also do not use data received through the Service to train their models.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

5. Data Retention

  • Text and voice input: discarded immediately after processing (not stored permanently on our servers)
  • Session information: managed as a JWT token and invalidated when you sign out
  • Access token: kept only within the session and expires automatically after its validity period
  • Account information (email address, subscription status, free-use count, and Stripe customer ID): stored in Supabase and kept after you sign out
  • API usage counts (counters for preventing abuse): only the recent count is kept per user and per endpoint, and it is deleted automatically when your account is deleted

6. Data Protection

The Service takes the following measures to protect user data:

  • HTTPS encryption for all communication
  • A secure authentication flow using OAuth 2.0
  • Server-side rate limiting and input validation
  • Encrypted storage of access tokens (kept in your browser’s cookie as an encrypted session, and not stored in our database)

7. Your Rights

You have the following rights:

  • Revoking access: You can revoke the Service’s access at any time from your Google Account settings
  • Deleting data: The text and audio you enter and the details of your events are not stored, so nothing remains once processing is finished. Signing out removes the session (including the access token) from your device. Your email address, subscription status, and usage counts (in Supabase) and your payment information (in Stripe) remain after you sign out. To request their deletion, please contact us using the contact information below
  • Inquiries: For questions about privacy, please contact us using the contact information below

8. Use of Cookies

The Service uses only the minimum cookies necessary for session management and for remembering your display language. It does not use cookies for tracking or advertising.

To remember the display language you choose, the Service uses a cookie named vs_locale. Its value is only ever ja or en, and it expires after one year. Your browser sends it to our servers as usual, but the servers do not store it.

We use Vercel Web Analytics to understand how the Service is used. It uses neither cookies nor identifiers that work across devices, and it does not track individual users. It collects only anonymous, aggregated information such as pages viewed, referrer, country, and device type, and never includes event details or speech text.

9. Changes to This Policy

We may change this policy as necessary. If there are significant changes, we will notify you on this page.

10. Contact

For inquiries about privacy, please contact the Service’s support desk.

© 2026 Voischedule