Security & data

To keep your calendars in sync, allmymeetings needs permission to read and change them. This page explains exactly what that permission covers, what we store, and how to take it back.

What access we ask for

You connect each calendar provider yourself, and you can disconnect it at any time.

ProviderHow it connectsWhat we can access
Google Calendar Google sign-in (OAuth 2.0). We never see your Google password. Your calendars, plus your name and email address to label the account.
Outlook and Microsoft 365 Microsoft sign-in (OAuth 2.0). We never see your Microsoft password. Your calendars, plus your mailbox time zone setting so events land at the right time. We don't read email, contacts, or files.
Apple iCloud CalDAV with an app-specific password that you create at Apple and can revoke there. Your iCloud calendars. An app-specific password can't be used to sign in to your Apple Account itself.
ICS feeds A calendar feed URL you provide. Read-only. We never write to a feed.

Calendar access is read-and-write because sync has to create, update, and delete the copies it makes. Sync only ever changes copies it created. Your own events change only when you ask for it, for example when an AI agent you connected creates or edits an event, or when someone books time on one of your scheduling pages.

What we store

  • Credentials. OAuth access and refresh tokens, iCloud app-specific passwords, and ICS feed URLs and logins are encrypted by the application before they are written to the database.
  • Calendar events. To detect changes and keep copies current, we keep a copy of the events inside each calendar's sync window (30 days back and 180 days ahead by default). Events outside that window aren't fetched.
  • Sync history. A record of what was copied, updated, or removed, so you can see where any event came from.
  • Your account. Name, email address, and a bcrypt-hashed password if you set one. Card details stay with Stripe; we keep only the card type and last four digits.

All traffic to and from allmymeetings uses HTTPS. We do not sell your personal information, and calendar data is used only to run the service. The privacy policy lists retention periods and every company that processes data on our behalf.

What crosses between your calendars

Each sync has a privacy mode, and the mode decides what the copy shows:

  • Full Details copies the title, location, and description. Attendees are never copied, so a synced copy never sends invitations.
  • Free/Busy creates a block titled "Busy" with no other details.
  • Private creates a "Busy (Private)" block marked private.

Every copy carries a hidden tag recording which event it came from, so allmymeetings recognises its own copies and never copies them again. A copy you delete on its calendar stays deleted.

Removing access

  • Disconnect an account from the Calendar Accounts page. allmymeetings removes the copies it made on your other calendars, deletes the account's stored events and credentials, and stops its change notifications.
  • Revoke access at the provider at any time: Google account connections, Microsoft My Apps, or the App-Specific Passwords section of your Apple Account. Disconnecting inside allmymeetings first lets it clean up its copies.
  • Delete your allmymeetings account from Settings to delete your stored calendar data. Copies already written to your calendars stay there, so disconnect your accounts first if you want those removed.

Protecting your allmymeetings account

  • Sign in with Google, Microsoft, or Apple, with a password, or with a passkey.
  • Two-factor authentication is available for every account.
  • Accounts are isolated from each other: every request that reads or changes calendars, sync pairs, or bookings is checked against the signed-in owner.

AI agent and API access

AI agents such as Claude connect to allmymeetings through its MCP server using an API token you create in Settings. Each token expires after 30, 90, or 365 days and is either read-only or read-and-write. A read-only token can't see or use any tool that changes calendars, events, sync pairs, or billing. You can revoke a token at any time, and it stops working immediately.

Where it runs

allmymeetings is operated by Wolfgang Solutions, LLC in the United States and hosted on Laravel Cloud in Amazon Web Services' us-east-2 region. Payments are processed by Stripe.

Reporting a security issue

If you find a vulnerability or think your data has been exposed, email [email protected]. Please include steps to reproduce it. We read every report and reply as quickly as we can.

Ready to stop double-booking?

Sync your calendars in under two minutes. Free plan available — no credit card required.