What Timelap handles
Timelap handles the minimum information needed to create and resolve a scheduling decision: poll details, display names, availability intervals, response status, timezone, and private capability-link digests.
If a participant explicitly opts into notifications, contact information is encrypted at rest and used only for the requested scheduling messages. Scheduling Rooms may also retain a member-owned weekly availability profile after explicit consent.
Capability links are bearer secrets
Organizer, participant-edit, event, Room, and Room-member links grant access to the action named by that link. Anyone who receives one may be able to use it until it expires, is rotated, or is revoked.
- Keep private links out of public channels and screenshots.
- Share the public response link—not the organizer or edit link.
- Rotate a Room or member link if it may have been exposed.
Calendar boundary
Live calendar connections are not yet part of the public service. When they launch, Timelap’s integration boundary is designed to accept busy intervals only. Event titles, descriptions, attendees, locations, and meeting notes must not enter poll responses.
Connecting a calendar will remain optional. Manual availability is the authoritative guest-first path.
Visibility and sharing
Public poll links expose the poll context and aggregate scheduling results needed by invitees. They do not expose private edit links or another participant’s individual availability. Room activity is deliberately limited to aggregate status and event timing.
Organizers choose whom to invite and are responsible for sharing links with the intended people.
Retention, deletion, and operational records
Polls and guest Rooms carry explicit retention boundaries. Expiry revokes access, and bounded maintenance jobs permanently remove retained scheduling records according to the selected policy. A Room can expire independently while its already-created polls continue to their own retention boundary.
Minimal security, idempotency, suppression, and audit records may remain only as long as required to prevent replay, abuse, duplicate delivery, or unsafe restoration. Raw capability tokens are not stored.
Performance measurement boundary
Timelap includes a default-off Vercel Speed Insights integration for anonymous, aggregate Core Web Vital measurement on the home, demo, privacy, terms, and changelog pages only. If owner and legal review approve activation, Vercel may process the measurement time, the exact allowed public page, coarse browser, device, operating-system, network, country, deployment-environment, and Web Vital attribution fields described for that service.
Timelap rejects every other page before transmission and replaces accepted event URL and route fields with one of those five code-owned paths. Poll creation, Rooms, capability links, unknown routes, query strings, fragments, referrers, scheduling content, identities, release fingerprints, and custom analytics events are excluded. Timelap does not configure Web Analytics, cookies, drains, or exports in this tranche.
The integration remains disabled unless an explicit Production-only switch is approved. Before activation, owner and legal review must confirm the legal basis, Vercel processor terms, operator access, reporting window, and a documented disable or withdrawal path.
Product commitments and requests
Timelap does not currently sell scheduling data or use it for targeted advertising. Sensitive values must not be written to application logs or analytics.
A verified privacy-request channel and owner-approved final policy are required before public Production launch. Until then, this Preview policy documents the product’s operating commitments but is not presented as a final legal notice.