OnlyBusy

Privacy policy

Last updated 25 September 2026

OnlyBusy mirrors when you are busy across the calendars you connect. It is built so the details of those events never have to enter the service.

Who this covers

This policy describes the OnlyBusy service at onlybusy.com, operated as OnlyBusy. It applies to the website, the account you create, and the calendar connections you authorize. Questions about this policy go to privacy@onlybusy.com.

Account information

When you create an account we store:

  • Your email address.
  • A password hash. We do not store the password itself.
  • Whether you have finished the setup guide.

A session cookie named gb_session keeps you signed in. It is httpOnly, lasts seven days, and is marked secure in production.

What we request from calendars

Google Calendar and Microsoft 365 are asked for the event id, title, start, end, and busy status so OnlyBusy can show your own events. Descriptions, locations, and attendees are not requested. Titles are not stored and are not written onto the Busy blocks on your other calendars.

The delegated permissions used are:

  • Google: openid, email, calendar list read, and calendar events.
  • Microsoft: openid, email, offline access, User.Read, and Calendars.ReadWrite.

We also store the account email returned by the provider, the calendar name and color, and the settings you choose for that calendar, including the placeholder label, whether all-day events are mirrored, and any buffer.

What we write

On calendars you turn on for mirroring, OnlyBusy creates private events that show you as busy. Each event uses the label you chose for that calendar, has no guests, no notes, no location, and no reminders. A private marker identifies events OnlyBusy created so they are not mirrored again. Disconnecting an account deletes those events and stops further updates.

What we store to keep sync working

To update and remove those busy blocks we keep:

  • OAuth access and refresh tokens, encrypted with AES-256-GCM before they are written to the database.
  • The start and end of each mirrored block, and an id for the event OnlyBusy wrote.
  • Sync state, including the last successful sync, webhook channel identifiers, and the last error if a calendar needs attention.

The window we read is the past 7 days through the next 60 days. Busy blocks are written only for events that have not ended. Older mirrored records are dropped as they leave that window.

Who else processes data

We do not sell personal information.

Google and Microsoft process the sign-in and calendar calls under the permissions you grant. OnlyBusy stores its data in PocketBase. Hosting providers that serve the website and the database see traffic and stored records as needed to run the service. Webhook notifications from Google and Microsoft contain calendar change signals, not event titles.

How long we keep it

Account and calendar data stay while your account is open and a calendar stays connected. Disconnecting a calendar account removes the busy blocks OnlyBusy created, stops listening for changes, and deletes the stored tokens for that account. To delete the OnlyBusy account itself, email privacy@onlybusy.com from the address on the account. We delete the account record and the calendar data tied to it, except where we must keep a record to meet a legal obligation or resolve a dispute.

Your choices

You choose which calendars are mirrored and the label each one shows. You can disconnect a provider at any time from Accounts. You can sign out, which clears the session cookie. You can ask for a copy of the account data we hold, or for correction or deletion, at privacy@onlybusy.com.

Changes

If this policy changes, the updated version will be posted on this page with a new date. Continued use of OnlyBusy after that date is acceptance of the updated policy.