Last updated: 2026-06-11
This privacy policy describes how Doublebook ("the Service", "we") handles personal data. The Service is operated by Left Blank, LLC ("Left Blank", "us") and reachable at hello@leftblank.co.
Doublebook lets you connect your Google Calendar and/or Microsoft 365
calendar accounts and republishes the events on those calendars as two
iCalendar (.ics) feeds:
When you connect a calendar account we receive and store:
https://www.googleapis.com/auth/calendar.readonly
plus the standard OpenID Connect scopes (openid,
email) to identify your account. We do not request write
access. We do not access Gmail, Drive, Contacts, or any other Google
service.Calendars.Read,
User.Read, offline_access, openid,
email. We do not request write access. We do not access
Outlook mail, OneDrive, or any other Microsoft service..ics) to your account, we periodically fetch it as an
unauthenticated HTTP request (or with HTTP Basic credentials you
supply). The URL and any credentials are stored encrypted at rest.The data is used solely to render your two iCalendar feeds. We do not:
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Trusted feed URLs contain a long random token. Anyone you share a trusted feed URL with can read the full details of the events on that feed until you revoke the token in your account dashboard. Treat trusted feed URLs like passwords. Busy feed URLs are designed to be safe to share publicly: they reveal only the time blocks during which you are busy, with no other event details.
Data is stored in a managed PostgreSQL database hosted by a US-based cloud infrastructure provider. All data in transit is encrypted with TLS. OAuth refresh tokens are additionally encrypted at rest at the application layer, as described above.
Calendar event data is retained as long as your account is active and is re-fetched on each sync. When you disconnect a calendar, all stored events and tokens for that account are deleted immediately. When you delete your account entirely, all of your data is deleted immediately. HTTP request logs are retained for up to 30 days.
You can at any time:
We set one HTTP-only, Secure, SameSite=Lax session cookie used to keep you signed in and to validate OAuth state during the sign-in flow. We do not use analytics, advertising, or third-party tracking cookies.
The Service is not directed to children under 13 and we do not knowingly collect personal information from children.
If we make material changes to this policy we will update the date at the top of this page and, when feasible, notify connected users by email at the address associated with their primary account.
Questions, concerns, or data deletion requests: hello@leftblank.co.