Legal
Privacy Policy
Effective August 26, 2026. Last updated August 26, 2026.
This policy describes what GridHour collects, why, where it lives, and the choices you have. It covers Google account and Calendar data, tasks, attachments, logs, and optional programmatic access. Short version: we use your data to run the app you asked for. We do not sell it, and we do not use Google user data for ads.
01
Who we are
GridHour is a personal time-management service at https://gridhour.app, operated by Matthew Tims (“GridHour,” “we,” “us”). This policy applies to the website, the progressive web app, and the GridHour MCP endpoint.
02
Google user data
Sign-in and Calendar sync use Google OAuth. Depending on what you approve, we request:
- Email and basic profile — to create your session and show who is signed in (
userinfo.email,userinfo.profile). - Calendar list and event read — to display calendars and events in GridHour (
calendar.readonly). - Event write — to create, update, and delete events when you (or an agent you authorized) ask us to (
calendar.events).
We use Google user data only to provide and improve GridHour’s user-facing features: showing your week, tagging and categorizing events, time analytics, and writing back to the calendars you enable.
Limited Use
GridHour’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not:
- Sell Google user data.
- Use Google user data for advertising, including retargeting, or to serve ads.
- Use Google user data to train generalized AI or machine-learning models.
- Transfer Google user data to third parties except to provide or improve the user-facing features of GridHour, for security, or to comply with law.
- Allow humans to read Google user data unless we have your affirmative consent, it is necessary for security or abuse investigation, it is required by law, or the data is aggregated and no longer associated with you.
We store OAuth access and refresh tokens on our server so GridHour can sync and write to Calendar on your behalf. Disconnect Google Calendar in Settings to revoke that access. We then delete the stored tokens and calendar-connection records.
03
Account and session
When you sign in, we store your Google email and display name in an encrypted session cookie named gridhour_session. The cookie is HTTP-only, SameSite=Lax, marked Secure in production, and lasts 30 days. It is required to keep you signed in. We do not use advertising cookies or third-party tracking pixels.
04
App data you create
In our database we keep copies and records needed to run the app, including:
- Mirrored Google Calendar events (title, times, location, description, status).
- Which calendars you enabled in GridHour.
- Tasks and assignments (title, due date, type, notes, completion).
- Categories, keywords, tags, and event types you configure.
- Your timezone preference.
Google Calendar remains the source of truth for events we write. GridHour’s copy exists so the week view, tags, and analytics still work when you open the app.
05
Attachments
Files you attach to tasks are stored on GridHour’s server. Allowed types: PDF, JPEG, PNG, WebP, plain text, and Markdown. Maximum size 10 MB per file. We use attachments only to show them back to you (and to any agent using a token you control). We do not scan them for advertising.
06
Programmatic access (MCP)
GridHour can be driven by a machine client at https://gridhour.app/mcp using a bearer token you (or the operator) configure. That client can read and write tasks, tags, and Google Calendar events through the same GridHour paths the app uses.
Treat the token like a password. Anyone who has it can act on your GridHour data, including writing to Google Calendar. We do not send that token to Google. Revoke or rotate it if it leaks.
08
Where data lives and how long
Application, database, tokens, and attachments live on a DigitalOcean server in the United States. Google receives OAuth and Calendar API traffic on Google’s infrastructure under Google’s terms.
We keep your data while your account is active. You can delete tasks and attachments in the app, and disconnect Google in Settings. To delete the rest of your GridHour data, email us. We may keep limited logs or backups for a short period for security and disaster recovery, then drop them in the ordinary backup cycle.
09
Your rights
You can:
- Access and correct profile and app data in GridHour.
- Disconnect Google Calendar in Settings, which deletes stored Google tokens.
- Sign out, which clears the session cookie on that browser.
- Request a copy or deletion of your GridHour records by emailing hello@gridhour.app.
If you are in the EEA or UK, we process data to perform the service you requested (contract), to keep the service secure (legitimate interests), and, for Google Calendar access, based on the consent you give Google and us during OAuth. You may withdraw Calendar access at any time in GridHour Settings or in your Google account permissions.
If you are in California: we do not sell or share personal information as those terms are used in the CCPA/CPRA, and we do not use Google user data for cross-context behavioral advertising.
GridHour is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
If we change this policy in a material way, we will update this page and the “Last updated” date. Continued use after an update means you accept the revised policy.
10
Contact
Privacy and data requests: hello@gridhour.app
Operator: Matthew Tims
Service: GridHour · https://gridhour.app
Related: Terms of Service · Home