Skip to content
schedule-bit
HomeWhat you can doPartnersPricingDevelopers
Public beta Try it ↗(opens in a new tab) Start free ↗(opens in a new tab)
HomeWhat you can doPartnersPricingDevelopers
Start free ↗(opens in a new tab) Try it ↗(opens in a new tab)

Legal

Privacy Policy

This policy explains what personal data we collect when you use schedule-bit, why, who we share it with, and the rights you have. It is written for the UK GDPR and the Data Protection Act 2018.

Last updated: 2 October 2026

On this page

  1. 1 Who we are
  2. 2 Your data and your customers’ data
  3. 3 What we collect, why, and our legal basis
  4. 4 The AI assistant
  5. 5 Cookies and storage in your browser
  6. 6 Who we share data with
  7. 7 International transfers
  8. 8 How long we keep it
  9. 9 Security
  10. 10 Your rights
  11. 11 Children
  12. 12 Changes to this policy
  13. 13 Contact

In short

  • We collect what we need to run your workspace, and nothing for advertising.
  • We don’t sell personal data, and we don’t use cookies to track you.
  • Card details stay with Stripe. Your access keys are stored only in hashed form.
  • You can ask us for a copy of your data, or to delete it, at [email protected].

Who we are

The controller of your personal data is MindCache LTD, a private company limited by shares, registered in England and Wales with company number 16468302. Our registered office is Office 12, Initial Business Centre, Wilson Business Park, Manchester, M40 8WN, United Kingdom.

This policy covers this website, the schedule-bit console, the live playground and the schedule-bit API. For anything about your personal data, email [email protected].

Your data and your customers’ data

We handle personal data in two roles:

  • As controller, for the data about you as our customer: your account, keys, usage and billing. This policy describes that.
  • As processor, for personal data you put into your schedules, such as the names of the people you book. You decide what goes in and why, and we process it only to run the service for you, under our Terms of Service. If you are booked through a business that uses schedule-bit, please ask that business about your data first.

What we collect, why, and our legal basis

WhatWhyLegal basis
Your sign-up email address and workspace name To create and run your workspace, send the sign-up link, and tell you about your account, billing and changes to the service. Contract
Access keys To check that each request comes from your workspace. We keep keys only in hashed form (a one-way fingerprint), so we cannot read them back. A key is shown once, when it is made. Contract; legitimate interests (keeping the service secure)
The schedules you create: calendars, resources, bookings, labels and the history of changes To provide the service. This is your data; we use it only to run the service for you. Contract
Usage counts: requests, bookings and changes, resources and assistant runs each month To apply your plan’s limits and show you your usage. Contract
Billing references: your Stripe customer and subscription ids, your plan, and the subscription’s status and dates To match payments to your workspace and set your plan. Card details are collected and kept by Stripe; we never see or store them. Contract; legal obligation (keeping accounting records)
Notification (webhook) addresses you register, and their signing secrets To send your systems notifications when something changes, signed so that you can check they came from us. Contract
Request logs: the IP address a request came from, the time, the address requested, the result, and the workspace To keep the service secure, stop abuse, and find and fix faults. Legitimate interests (security and reliability)
The sign-up check: signals from your browser, read by Cloudflare’s check that you are a person To stop automated sign-ups. Legitimate interests (preventing abuse)
Emails you send us To answer you, and to keep a record of what we agreed. Legitimate interests; contract where it concerns your account

“Contract” means we need the data to provide the service you signed up for. “Legitimate interests” means we use it for a reasonable purpose of ours, such as security, that does not override your rights; you can object to it, as your rights explain.

On this website we run no analytics and no advertising. The service-status line on our pages asks our own service whether it is running, and sends nothing about you. Our pages, the console and the playground load their fonts from Google Fonts, so your browser connects to Google, which receives your IP address and browser details to deliver them.

We don’t sell personal data, and we don’t make decisions about you by automated means that have legal or similarly significant effects.

The AI assistant

The assistant is optional. Only when you run it, we send Anthropic your prompt and the schedule data that the run reads, so that its model can answer. Our logs of a run keep its id, your workspace, its steps, the number of tokens, why it stopped and whose key it used; never your prompt.

If you give the assistant your own Anthropic key, we use it for that run only. It is sent to Anthropic as the run’s key and nowhere else, and we never store or log it.

Cookies and storage in your browser

We don’t set cookies on this website, the console or the playground, and we use no tracking or advertising tools. Some features keep small items in your browser’s own storage, which stays on your device and is not sent to us:

  • This website remembers your light or dark theme choice.
  • The console keeps your access key for the browser tab you are using, and forgets it when the tab closes. It remembers the address of the service you connected to.
  • The playground keeps your access key, and your own Anthropic key if you give one, for the browser tab only; disconnecting or closing the tab removes them. It remembers your display preferences (such as theme and sound), the name and colour others see, and the examples you save.

These items exist only to do what you asked for, so we don’t ask for consent with a banner. You can clear them at any time in your browser’s settings.

Cloudflare, which hosts our services, may set a strictly necessary security cookie if it needs to check that traffic is not automated. The sign-up check runs only on the sign-up screen.

Who we share data with

We use these sub-processors to run the service. Each processes personal data only on our instructions, under a written contract.

CompanyWhat forWhere
Cloudflare Hosting, compute, storage and logs for the service and this website; the sign-up check United States, with servers worldwide
Stripe Payments, invoices and the billing portal United States and other countries
Resend Sending the sign-up email United States
Anthropic The AI assistant, only when you run it: it receives your prompt and the schedule data the run reads United States

We will update this list before we add or replace a sub-processor. We may also share personal data when the law requires it, to protect our rights or the safety of others, or with a company that takes over our business, which would then be bound by this policy.

International transfers

Some of our sub-processors are in, or reach data from, countries outside the UK, mainly the United States. When personal data leaves the UK, we make sure it is protected by one of the safeguards UK law allows: UK adequacy regulations where they apply, or the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum. Email us for more detail on the safeguard for a given transfer.

How long we keep it

DataHow long
Your workspace, schedules, usage counts, webhooks and key records While your workspace is open. When you ask us to close it, we delete them within 30 days.
Billing records (invoices, payments and the references that link them to you) Six years after the end of the financial year they relate to, as UK tax and company law requires.
Request logs Up to 30 days.
An unfinished sign-up The link expires after 30 minutes; an unused request is not kept as a workspace.
Emails with us Up to two years after our last exchange, unless we need them longer for a legal claim.

Deleting on request

You can revoke access keys and remove notification addresses yourself, in the console or through the API. Deleting a calendar, a resource or a whole workspace isn’t yet possible in the API, so do that on request: email [email protected] from your sign-up address, say what you want deleted, and we will delete it within 30 days. We keep only what the law requires us to keep, such as billing records.

Security

We protect your data with measures that fit a service like ours:

  • Every connection to the service is encrypted (HTTPS).
  • Access keys are stored only in hashed form, and each key is shown once, when it is made.
  • Every request is checked against its key, and one workspace cannot read or change another’s data unless it was given access.
  • Each schedule’s history is chained, so a change to its past can be detected.
  • Notifications to your systems are signed, so you can check that they came from us.
  • Card details never reach our systems, and your own Anthropic key is never stored.
  • Rate limits protect the service from overload and abuse.
  • Only the people who run the service can reach its production systems.

No system is perfectly secure. If a breach puts your personal data at risk, we will tell the Information Commissioner’s Office within 72 hours where the law requires it, and tell you without undue delay.

Your rights

Under UK data protection law, you have the right to:

  • get a copy of your personal data (access);
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict how we use it;
  • object to our use of it based on legitimate interests;
  • receive data you gave us in a machine-readable form, or have it sent to another provider (portability).

To use any of these rights, email [email protected], ideally from your sign-up address. We may need to confirm who you are. We answer within one month, and it is free in most cases.

Complaints

If you are unhappy with how we handle your data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator: ico.org.uk/make-a-complaint, or 0303 123 1113. If you live in the EU, you can also complain to the data protection authority in your country.

Children

schedule-bit is a service for businesses and developers and is not meant for anyone under 16. We don’t knowingly collect personal data from children. If you think a child has given us personal data, email [email protected] and we will delete it.

Changes to this policy

We may update this policy when the service or the law changes. The date at the top shows when it last changed. If a change materially affects how we use your personal data, we will email you before it takes effect.

Contact

Privacy questions and data requests: [email protected]. Anything else: [email protected]. By post:

MindCache LTD
Office 12, Initial Business Centre
Wilson Business Park
Manchester
M40 8WN
United Kingdom

Also read

  • Terms →
  • Refunds →
schedule-bit

Scheduling that never double-books.

Product

What you can do Partners Pricing and sign-up Start free ↗ Try it: live playground ↗

Developers

Developer docs

Legal

TermsPrivacyRefunds

Public beta. Start free; paid plans from $19 a month.

© MindCache LTD · Company no. 16468302 · Registered in England and Wales