WhenPactPrivacy Notice
繁中Secure link
Privacy Notice

We only collect what is needed to schedule a meeting

WhenPact does not require an account and does not use AI to analyze meeting content. This notice explains how the current beta handles data.

What we store

  • Meeting titles, descriptions, candidate dates, times, time zones, and meeting length.
  • Participant display names, submitted availability, and—during a cross-time-zone meeting—the time zone confirmed when the response is submitted. The organizer can see that zone to help verify responses.
  • Hashed admin passwords, recovery codes, sessions, and private edit credentials. Readable admin passwords are not stored.
  • Short-lived request records and network-address-derived values used to prevent abuse, plus Cloudflare Turnstile verification results.

How data is used

Data is used only to create meetings, collect and edit responses, rank candidate times, let organizers manage meetings, and prevent automated abuse. We do not currently sell personal data or use advertising trackers.

Retention and deletion

Meetings expire 90 days after creation by default and are scheduled for permanent deletion 30 days after expiration. Organizers may delete an entire meeting or individual participants at any time. Admin sessions last up to 12 hours, and abuse-prevention records are retained only briefly. To help detect unauthorized changes, the service retains the admin action type, sign-in method, and time, scheduled for deletion after 120 days. This record excludes names, meeting titles, passwords, private links, tokens, and IP addresses, and is not included in operational backups. For disaster recovery, the service creates public-key-encrypted operational backups and rotates them after no more than 35 days. Deleted data may remain in an encrypted backup during that window and is used only to restore the service.

Links, devices, and third-party services

Anyone with a participant link can view and respond to that meeting. Cross-time-zone mode reads the device zone from the browser. A manually selected preference is stored on that device only for that meeting, and the zone confirmed at submission is also recorded with the response. Private edit permission is stored in the participant’s browser by default. Cross-device private edit links and required-participant links can modify specific responses and should not be published. The site uses Cloudflare for hosting, the database, and Turnstile verification, so related requests are also subject to Cloudflare’s services and privacy practices.

Questions, deletion requests, or reports

Organizers can delete data directly from the admin page. Participants who no longer have access from their original device or private link can ask the organizer to remove their response. For reports, data requests, or privacy questions, email togethr@proton.me with the relevant meeting link and a description of the issue. Do not send an admin password or recovery code. See Help for operating instructions.

Last updated: September 1, 2026