Operator and privacy contact
Miyo LLC, United States, operates Timelap. Send privacy questions and applicable data-rights requests to timelapsupport@gmail.com. Start with your request category and do not include private scheduling links.
What Timelap handles
Timelap handles the minimum information needed to create and resolve a scheduling decision: poll details, display names, availability intervals, response status, timezone, and private capability-link digests.
If a participant explicitly opts into notifications, contact information is encrypted at rest and used only for the requested scheduling messages. Scheduling Rooms may also retain a member-owned weekly availability profile after explicit consent.
Capability links are bearer secrets
Organizer, participant-edit, event, Room, and Room-member links grant access to the action named by that link. Anyone who receives one may be able to use it until it expires, is rotated, or is revoked.
- Keep private links out of public channels and screenshots.
- Share the public response link—not the organizer or edit link.
- Rotate a Room or member link if it may have been exposed.
Calendar boundary
Live calendar connections are not yet part of the public service. When they launch, Timelap’s integration boundary is designed to accept busy intervals only. Event titles, descriptions, attendees, locations, and meeting notes must not enter poll responses.
Connecting a calendar will remain optional. Manual availability is the authoritative guest-first path.
Visibility and sharing
Public poll links expose the poll context and aggregate scheduling results needed by invitees. They do not expose private edit links or another participant’s individual availability. Room activity is deliberately limited to aggregate status and event timing.
Organizers choose whom to invite and are responsible for sharing links with the intended people.
Retention, deletion, and operational records
Polls and guest Rooms carry explicit retention boundaries. Expiry revokes access, and bounded maintenance jobs permanently remove retained scheduling records according to the selected policy. A Room can expire independently while its already-created polls continue to their own retention boundary.
Minimal security, idempotency, suppression, and audit records may remain only as long as required to prevent replay, abuse, duplicate delivery, or unsafe restoration. Raw capability tokens are not stored.
Performance measurement boundary
Timelap includes a default-off Vercel Speed Insights integration for anonymous, aggregate Core Web Vital measurement on reviewed static pages and the core guest scheduling journey. If owner and legal review approve activation, Vercel may process the measurement time, a code-owned route class, coarse browser, device, operating-system, network, country, deployment-environment, and Web Vital attribution fields described for that service.
Accepted poll, participant-edit, organizer, and finalized-event pages are replaced with fixed labels such as /p/[publicToken] before transmission. Raw capability values, complete URLs, query strings, fragments, referrers, scheduling content, identities, release fingerprints, Rooms, series, unknown routes, and custom analytics events are rejected or excluded. Timelap does not configure Web Analytics, cookies, drains, or exports in this tranche.
The integration remains disabled unless an explicit Production-only switch is approved. Before activation, owner and legal review must confirm the legal basis, Vercel processor terms, operator access, reporting window, and a documented disable or withdrawal path.
Product commitments and requests
Timelap does not currently sell scheduling data or use it for targeted advertising. Sensitive values must not be written to application logs or analytics.
Support receives privacy requests at the address above. Messages you send are processed by Gmail and should contain only the information needed to explain your request. This policy remains a draft pending final policy review.