PRIVACY · LAST UPDATED AUGUST 1, 2026
Your calendar should stay yours.
Boons helps an existing group choose a time. This notice explains what the accountless beta handles, what the group can see, and how to remove it.
01 · THE PLAN
What Boons handles
A plan contains the activity description, candidate times, expected group size, response target and deadline, participant display names, and yes/maybe/no choices. A participant may optionally provide a coarse starting area for future travel balancing. After confirming a time, the organizer may add a public venue name, public address or cross streets, and a public HTTPS venue or reservation link. The organizer may later record only whether the gathering happened or was cancelled.
“Your Plans” keeps a small index in that browser so someone can reopen plans they organize or join without an account. It contains only the plan ID, organizer-or-participant role, a timestamp, and the organizer secret when applicable. Titles, prompts, times, responses, starting areas, calendar data, and provider credentials are not cached in the index; the page loads current plan details fresh.
After at least two people respond, a later round may use the strongest saved group pattern to choose one preferred time of day. The new plan copies no names, votes, calendar data, areas, capabilities, deadline, or link to the original plan.
Boons does not ask for an account, email address, phone number, contacts, home address, group-chat history, or payment information. Public venue details are optional, visible to everyone holding the invite, and must never identify someone’s home or include a personal reservation-management link. Please do not put sensitive personal information in a plan description or display name.
02 · VISIBILITY
A link is the guest list
Anyone holding the guest link can see the plan idea, proposed times, response progress, participant names, votes, aggregate rankings, a confirmed time, any public venue details, and the organizer’s coarse happened-or-cancelled outcome. Keep the separate organizer link private: it can confirm, add or remove the public place, record or correct the outcome, reopen, create a later round, or delete the plan.
Individual starting areas never appear in the shared plan. After three private inputs, the group may see three shared NYC meeting hubs based on typical subway connectivity. Boons does not expose origins, input counts, per-person results, internal scores, transfer counts, or travel-time estimates. Calendar-assisted and manual answers look the same to everyone else.
03 · CALENDARS
Busy, without the backstory
Calendar connection is optional and belongs to that browser, not to the group. Google access is limited to free/busy checks and, only when enabled, a read-only list used to choose calendars. Microsoft labels Outlook’s delegated permission “read your calendars.” Boons still requests only start, end, busy status, and cancellation state from the default calendar, immediately reduces the response to busy windows, and discards every richer event field.
Apple Calendar users can export individual calendars from a Mac and select those standard iCalendar files together. Up to 20 files totaling 5 MB are merged only in their browser and are never uploaded or stored by Boons. Filenames and event details are discarded there after busy windows become editable yes/can’t suggestions. Direct Apple Account access is not enabled, and Boons never asks for an Apple Account or app-specific password.
Provider tokens and selected Google calendar identifiers are encrypted. Calendar names are shown transiently to the connected browser and are not stored. Provider busy windows exist only in request memory long enough to suggest editable yes/can’t answers. Boons does not collect event titles, descriptions, attendees, conferencing links, or locations.
04 · RETENTION
How long things last
- Plans, responses, public places, and outcomes
- Deleted immediately by the organizer or automatically 30 days after creation. Reopening or changing the confirmed time removes its saved place and outcome. A precise outcome-recording time stays only in this expiring plan history and is never shown to invite holders.
- Managed backups
- Deleted plan data can remain in encrypted point-in-time backups for up to seven additional days and is used only for disaster recovery.
- Calendar connections
- Kept separately from plans so the same browser can reuse one. The encrypted token and consent record remain until that browser disconnects the provider or the provider definitively invalidates the connection.
- OAuth setup
- Pending connection state expires after ten minutes and is removed when used, replaced, or disconnected.
- Availability checks
- Provider busy windows and access tokens are not stored. Selected iCalendar files never leave the browser. Only choices a participant reviews and saves become part of the plan.
- Your Plans
- Local references remain in that browser until hidden, cleared with site storage, or removed automatically when a plan is deleted, expired, or unavailable.
- Anonymous counters
- Daily totals may outlive a plan because they contain no plan, person, prompt, destination, location, or calendar identifier. Outcome totals count accepted happened-or-cancelled actions, so a correction can increment both types.
- Support email
- If you contact Boons, Google Workspace processes the message. It is kept only as long as needed to answer, operate the beta, or handle a security or privacy request.
05 · SERVICES
Who helps operate Boons
DigitalOcean hosts the application, database, and backups. Google or Microsoft handles authorization only when someone chooses that calendar provider. Google Workspace handles messages sent to Boons support addresses. These providers necessarily process network or account information under their own terms.
Boons does not sell personal data, build advertising profiles, use third-party behavioral analytics, or disclose one person’s calendar details to another participant.
06 · CONTROL
Delete without asking
A participant can update or remove their response from the same browser. The organizer can delete the full plan and its responses. A connected browser can disconnect each calendar independently; Boons then deletes its encrypted token and consent relationship and attempts provider revocation where supported.
Because there are no Boons accounts, losing both the organizer link and the browser that remembered it means losing control of that data. Clearing browser storage also removes the local plan list and participant edit control. Boons stores only hashed capabilities on the server and cannot reconstruct a lost secret. For questions or a privacy concern, email [email protected].
07 · SECURITY
Report carefully
Boons uses encrypted provider tokens, hashed possession keys, scoped provider permissions, rate limits, content-free error records, automated checks, and managed backups. No internet service can promise perfect security.
Report a suspected vulnerability to [email protected]. Please avoid disrupting the service or accessing another person’s data, and do not send live tokens, calendar content, or private plan links in the first message.
QUESTIONS OR CONCERNS