Privacy Policy
Last updated: 2026-09-14
Skedulus (“we”, “us”) is a scheduling service at skedulus.online that lets service
providers take appointments through a public page and a Telegram Mini App. This policy
explains what data the service handles and why. Questions and requests:
support@skedulus.online.
What we collect
- Account details. When you sign in with Telegram we receive your Telegram
identifier and display name. If you sign in with Google we receive your name and email
address. If you sign in with an email code or link a phone number, we store that email
address or phone number.
- Bookings. Appointment times, the chosen service and staff member, the
optional comment you attach to a booking, and cancellation details.
- Business content (for providers): your business name, description, address,
services, staff names, working hours, and images you upload.
- Calendar connections (for providers): access credentials for the calendar
you connect — Google or Microsoft sign-in tokens, or your CalDAV server address,
username and app password.
- Reviews you leave after an appointment (rating and text).
- Notification settings and, if you enable browser push, the push
subscription details your browser issues (delivery endpoint, keys, browser type).
- Technical records. Server logs and an audit trail of significant account
actions — what was done, when, and from which IP address and browser. We keep these
for security and troubleshooting.
How we use it
- Running the service: showing availability, creating and managing appointments.
- Sending notifications and reminders through the channels you enable — Telegram
messages, email, and browser push.
- Keeping a provider’s connected calendar in sync with their appointments.
- Preventing abuse and answering support requests.
We do not run advertising, do not use analytics trackers, and do not sell personal
data. The only third-party script on our pages is Telegram’s Mini App script, required
for the Telegram integration.
Google user data
If a provider connects Google Calendar, Skedulus requests access limited to calendar
events. We use it solely to create, update and remove the events that represent that
provider’s appointments, and to notice when those events are moved or deleted so the
appointment stays in sync. Events that Skedulus did not create are ignored. Signing in
with Google shares only your name and email address.
Skedulus’ use and transfer of information received from Google APIs adheres to the
Google
API Services User Data Policy, including the Limited Use requirements. In
particular: this data is used only to provide the calendar features described here; it
is never used for advertising; it is never sold; and no human reads it except with your
permission, for security purposes, to comply with the law, or as part of resolving a
support request you initiated.
Microsoft and CalDAV calendars
Connecting an Outlook / Microsoft 365 calendar grants Skedulus read-and-write access
to calendar events, used for the same purpose and nothing else. Connecting a CalDAV
calendar (iCloud, Fastmail, Nextcloud or another server) stores the server address,
username and app password you provide, used only to talk to that server.
What is shared, and with whom
- With the business you book. The provider sees your name, the contact
details on your account, and the comment you attached to the booking.
- With the provider’s connected calendar. Appointment details — the client’s
first name with a last-name initial, the phone number on file, and the comment —
become part of the calendar event stored with Google, Microsoft, or the provider’s
CalDAV host, under that service’s own terms.
- With processors that deliver the service: Telegram (messages and the Mini
App), our email delivery provider (for email codes and notifications), and your
browser vendor’s push service (for push notifications).
- When the law requires it — in response to valid legal requests.
Cookies
| Cookie | Purpose | Lifetime |
ksiva | Keeps you signed in | 30 days |
lang | Remembers your language | 1 year |
theme | Remembers light/dark theme | 1 year |
There are no tracking or advertising cookies.
What is public
- A provider’s public page (business name, services, staff photos, published
reviews) is visible to anyone with the link and to search engines.
- Uploaded images are served from unguessable public URLs.
- A provider may create a read-only calendar feed reachable by a secret link; the
link can be regenerated or deleted at any time.
Security and retention
All traffic uses HTTPS. Calendar sign-in tokens and CalDAV passwords are encrypted
at rest (AES-256-GCM). Sign-in sessions expire after 30 days. Account and appointment
data is kept while your account is in use; write to us to have your personal data
deleted or anonymized.
Your choices
- Ask for a copy, correction or deletion of your data:
support@skedulus.online.
- Unlink sign-in methods on your profile page.
- Disconnect a calendar at any time — events Skedulus created are then removed
from it.
- Turn notification channels on and off, and unsubscribe from browser push.
Children
Skedulus is not directed to children under 16 and we do not knowingly collect their
data.
Changes
We will post any changes on this page and update the date at the top.