Privacy
Plain language. No legal fog.
Updated 18 August 2026
Secundo is made by BSide Tech. This page is what we actually do with your data, including Google user data from Google Calendar.
What we keep
Your email, and the work you create in Secundo: projects, tasks, notes, settings, generated images, and meeting notes (the transcript, summary, takeaways, and next steps).
How we use Google user data
Connecting Google Calendar is optional. When you connect, Google shares Calendar data with Secundo so we can show your calendars in the web app and the Mac app, and so you can create, edit, move, RSVP to, and delete events, including adding or removing a Google Meet link. We also read your Google account email so we can label the connected account in Settings.
We request only the Calendar permissions needed for that: view and edit events on calendars you can access, and see which calendars are on your Google Calendar list so you can choose which ones to show. We do not create, share, or delete calendars, and we do not change who a calendar is shared with.
We do not store Google Calendar event contents (titles, times, guests, descriptions, locations, or Meet links) on our servers. Those stay in your Google account. The apps fetch events to display them, and keep a short-lived local cache on your device so the calendar grid does not flash empty. On our servers we only store that you connected Google: OAuth access and refresh tokens, the Google account email, which calendar IDs you turned on, and display preferences (colors and nicknames) that you set in Secundo.
Who we share Google user data with
We do not sell Google user data. We do not use it for ads. We do not share, transfer, or disclose Google Calendar event contents to other users, to advertisers, or to AI providers.
We disclose Google user data only as follows:
- Google. We send API requests to Google’s Calendar API to read and write the events you ask us to show or change. Writes (create, edit, RSVP, delete, Meet links) happen in your Google account.
- Infrastructure. Encrypted OAuth tokens, your Google account email, selected calendar IDs, and display preferences are stored with our hosting and database providers (currently Vercel and Neon) solely to run Secundo for you. They are not used to train models.
- Optional MCP. If you connect Secundo’s MCP server to your own AI client, that client can list and change your calendars using the same permissions you granted. That transfer is initiated by you. We do not send Google Calendar data to AI providers on our own.
- Legal. We may disclose data if required by law.
Natural-language event creation sends only the text you type (for example “lunch with Sam tomorrow at 1”) to our AI providers so we can turn it into event fields. That prompt is your input, not data read from Google Calendar. The created event is then written to Google.
Retention and deletion of Google user data
Google Calendar events are retained by Google, under Google’s policies, not by Secundo. We do not keep a server-side copy of event contents.
Connection metadata (tokens, account email, selected calendar IDs, colors, nicknames) is kept only while Google Calendar is connected. Access tokens expire and are refreshed until you disconnect. The on-device event cache is overwritten as you move around the calendar and is cleared when you sign out or remove the app.
Disconnect Google in Settings and we delete that account’s tokens and connection record from our database. Delete an event in Secundo and we delete it in your Google Calendar — that change is in Google, not a copy we kept. To delete your whole Secundo account, ask us and we will remove what we stored for you, including Google tokens and connection metadata. Google Calendar itself is unchanged except for edits you already made through Secundo.
Limited Use of Google Workspace data
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We do not use Google Workspace user data to create, train, or improve generalized AI or ML models. We do not transfer Google Calendar data to third-party AI services for training. We do not sell it. Features that use AI (meeting notes, task titles, daily plan emails, image generation, parsing a typed event description) run on Secundo content or on text you type — not on events fetched from Google Calendar.
Calendar (Outlook and ICS)
Outlook works the same way as Google: events stay in Outlook; we store the connection, not the events. ICS feeds are read-only. For ICS we may cache the fetched feed briefly so the overlay can load.
Meetings and audio
When you record a meeting, the audio is uploaded just long enough to turn it into a transcript. As soon as that finishes, we delete the audio. We keep the transcript and the notes so you can read them later. Live transcription happens in the Mac app while you record; we don’t keep that audio either.
How we use AI
We use AI to:
- Transcribe meetings (live, and after you stop recording)
- Turn a transcript into a short summary, takeaways, and next steps
- Turn a rough task dump into a clear title and description
- Turn a typed event description into title, time, guests, and location fields (not by reading your Google Calendar)
- Draft your daily plan email from your Secundo tasks
- Generate images you ask for
Text and meeting AI goes through Vercel AI Gateway to Anthropic models on Amazon Bedrock, with routing limited to Bedrock and with zero-data-retention / no-prompt-training flags set. Meeting audio goes to OpenAI’s API for transcription only. Image prompts go to the image model you pick. We don’t train our own models on your content, and we don’t use Google user data to train anyone else’s.
What we don’t do
We don’t sell your data. We don’t run ads.
If you want out
Disconnect Google Calendar in Settings at any time. Ask us to delete your account and we’ll remove what we stored for you.