Plainly: what we store, how it’s scored, and how it’s kept.

The plain-English version of the privacy policy and terms: what FairlyRemote™ holds, what it doesn’t, and the controls you get.

At a glance

Free stays in your browser

On the Free plan, your boards, members, and fairness history live in local storage. No account, and nothing about your schedule reaches us.

Math, not AI

Rankings come from a deterministic algorithm you can predict and override, never a black box.

Busy-Only by default

Synced events show that you’re busy, not what, until you say otherwise.

Export & cancel freely

One button downloads everything as JSON. One click cancels: no retention friction.

The short list, and the long list of what we don’t

On Free, boards, members, and fairness history stay in your browser’s local storage; the only network calls are static assets and cookieless analytics. On Team and above, we hold just enough for your history to survive a device wipe and be shared with your team:

Two different things get called “your data,” so we split them below. What we read from your connected calendar is treated as borrowed and mostly discarded. What you create inside FairlyRemote, a proposal or a team meeting, is yours and is stored, because the feature cannot work otherwise.

Stored (Team+)

  • Account emailSign-in, billing, and the messages you’d expect.
  • Fairness historyThe four scores plus weekly / monthly rollups.
  • Board & member configNames, cities, working hours, chronotype.
  • Calendar tokenEncrypted at rest; reads free/busy, writes only events you confirm.

× Not taken from your calendar

  • Meeting descriptionsRead transiently to score, never kept.
  • Attendees & responsesWe never copy the invitee list or RSVPs off a synced event.
  • Locations & video linksNot read, not stored.
  • Meeting titlesDropped on the Busy-Only default; kept only if you raise an event to Shared.

Stored when you create it here (Team+)

  • Proposal name & timesThe title you type, the candidate slots, and the duration.
  • Who you invitedTeammates by account. External guests by the email address you enter, so we can send the invitation.
  • VotesHeld per person so nobody votes twice, and shown to the team as counts.
  • Team meetings you confirmTitle, date, time, and duration for the meetings booked on a board.

You typed these into FairlyRemote, so there is no version of the feature where they stay on your device. Delete a proposal and its invitees and votes go with it.

How long fairness history is kept

Enforced server-side by a daily cleanup job: what the product does, not a stated intention.

TierRaw recordsWeekly aggregatesMonthly summaries
Free14 days (local)2 weeks (local)14 days (local)
Team365 days52 weeks365 days
Business365 days52 weeks365 days

Who else touches data

The services we rely on and what each handles. The privacy policy’s table is canonical for the active region; a DPA is available on request.

ServiceWhat it handlesRegion posture
SupabaseAccount email, fairness data, encrypted tokensRegion selectable
StripeBilling email, payment method, invoicesUS; EU data under DPF / SCCs
ResendRecipient address & content of account / billing emailRegion selectable
Fly.ioEncrypted application traffic onlyMulti-region
CloudflareRequest metadata; no application dataGlobal edge
PlausiblePage URL, referrer, device class; no cookies, no IP retentionEuropean Union
SentryStack traces & request metadata when something breaksRegion selectable

Regions are configurable on most providers; the privacy policy lists the currently active one.

It’s deterministic math, not AI

FairlyRemote ranks meeting times with a deterministic algorithm, not a machine-learning model. That’s deliberate: it’s what makes the tool trustworthy to act on.

Predictable

The same inputs always produce the same ranking. Nothing shifts under you between one look and the next.

Auditable

Every ranking traces back to four named numbers. You can see why a slot ranks where it does.

Yours to override

It advises; your team decides. A vote or a manual booking always wins over the suggestion.

The four things it scores, all per-person, all about meeting timing:

Accommodation

How many awkward-hour meetings someone has absorbed this period.

Rest

Whether a meeting would land in someone’s sleep window.

Flexibility

How much availability someone has offered.

These roll into one label per candidate time, decaying on a 30-day half-life. Vote weights run 0.5× to 2× from the trailing accommodation score, so whoever’s taken the awkward calls gets more say in the next one.

Low Modest Neutral Notable High impact

What it is not

It doesn’t measure whether anyone was “active” in a meeting, doesn’t track keyboard, screen, or attention, and produces no productivity score. It describes how meeting timing is distributed across a team, nothing more. It is advisory, and is not designed to inform performance reviews, pay, or hiring. See the feature in detail →

Busy-Only by default. Title-visible only when you say so.

Imported calendar events wait in your review screen with Busy Only pre-selected: teammates see nothing until you confirm an event, and a confirmed one shows that an hour is taken, never what it is. You lift or drop that per event; admins can set a board default, and the review screen bulk-updates in one pass.

Private Blocks the slot for you only
Teammates see nothing Private
Busy Only Pre-selected for synced events
Teammates see a “busy” block Default
Shared Full details to the group
Teammates see full details Shared

Board admins set the default via a preset (Privacy First, Standard, or Open Team). Under Standard and Open Team you can raise or lower a single event within what the preset allows. Privacy First is locked: every event stays Private and the per-event control is switched off.

Exactly which permissions we ask for

Connecting a calendar (Team and above) requests these scopes, all shown together on the provider’s consent screen.

Google Calendar & Tasks 4 scopes
calendar.readonly

Read free/busy and event titles to detect conflicts. Descriptions, attachments, and attendee responses are not read.

calendar.events

Create an event when you confirm a winning time, or when a shift is assigned to you. We change or remove only the events FairlyRemote created; the server checks that before every write.

tasks.readonly

Read your Google Tasks (title and due date) to show them as to-do blocks. We never create, modify, or delete your tasks.

userinfo.email

Identify which account is connected.

Microsoft Outlook read-only
Calendars.Read

Read free/busy and event titles to detect conflicts. We do not write to your Microsoft calendar. Outlook sync is not available yet.

User.Read

Identify which Microsoft account is connected.

Never requested: contacts, Gmail, Drive, or admin-directory scopes. Disconnecting drops the token immediately; you can also revoke at myaccount.google.com/permissions.

How your data is kept

The posture behind the promises above. For how to report a vulnerability, see our responsible-disclosure policy.

In transit

TLS 1.3 on all customer-facing endpoints, HSTS enabled.

At rest

AES-256 at the database layer; backups inherit the same encryption.

Connection tokens

Encrypted with a separate application-layer key, so database access alone can’t use them.

Row-level security

Tenant isolation is enforced in Postgres. An app-layer mistake returns zero rows, not another team’s data.

Sessions

Short-lived access tokens, refresh tokens in HttpOnly cookies, a strict CSP on the app surface.

Operations

Dependency scanning triaged within 7 days, PII-scrubbed logs, 7-day PITR + 30-day backups, recovery tested quarterly.

What we don’t claim

FairlyRemote is not SOC 2 or ISO 27001 certified, and isn’t designed to handle PHI (no HIPAA / BAA). Need certification documentation for a review? Get in touch: a DPA, security questionnaire, and architecture review are available in the interim.

Reporting & incidents: email security@fairlyremote.com; we acknowledge within 48 hours and target a fix within 14 days for high-severity issues. Customer-impacting incidents are disclosed to affected customers within 72 hours.

Leave with everything, whenever

Two commitments that make trying FairlyRemote low-risk.

Export anytime

One button in settings downloads everything (every board, member, and fairness record) as one JSON file, in the same stable schema the importer accepts.

Deleting your account? The export is offered again on the confirmation step.

Cancel anytime

Cancelling stops renewal at the end of the current period; you keep access until then. UK and EU consumers also have the statutory cancellation rights set out in our Terms.

One confirmation email: no retention friction.

See it on a sample team

Five people, five timezones, a month of meetings already in place. No signup, no card.

Try the sample team