Legal

Privacy Policy

Effective and last updated September 6, 2026

This is the Privacy Policy for the RecallHaven study and productivity application available at recallhaven.com.

This Privacy Policy describes how RecallHaven ("RecallHaven," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the RecallHaven website, study workspace, and connected services.

Information RecallHaven collects

How RecallHaven uses information

RecallHaven uses this information to:

RecallHaven does not sell personal information and does not use personal information for targeted or interest-based advertising.

Google API data: access, use, storage, and sharing

This section specifically explains every Google integration currently offered by RecallHaven.

Google Sign-In

RecallHaven requests the openid, email, and profile permissions. We access your Google account identifier, name, email address, email-verification status, and profile image. We use this data only to authenticate you, create or link your RecallHaven account, display your profile, and protect the sign-in process.

The temporary Google access token used to retrieve this profile is not stored after sign-in. The linked Google account record and profile data are retained with your RecallHaven account until you delete the account.

Read-only Google Calendar

Calendar connection is optional and separate from Google Sign-In; you may connect a different Google account. RecallHaven requests only https://www.googleapis.com/auth/calendar.readonly. This permits viewing Calendar data but does not permit RecallHaven to create, edit, or delete Google Calendar events.

When you open Calendar or Day Plan, RecallHaven fetches events from your primary Google Calendar for the displayed time range. Event titles, times, status, availability, and links are used to show those events to you and detect scheduling conflicts. Event records are processed on demand and are not written to RecallHaven's application database or persistent browser query cache.

To keep the connection working, RecallHaven stores the Google OAuth refresh token and granted scope in its database. The refresh token is encrypted at rest and is used only to obtain a short-lived access token when RecallHaven needs to fetch your events.

If you explicitly ask the AI planner to propose or apply a schedule, busy start times and durations derived from Calendar events may be sent to RecallHaven's contracted AI-processing provider solely to avoid time conflicts and provide that user-requested feature. Event titles, descriptions, identifiers, and links are not included in that AI planner context.

Google data commitments

RecallHaven's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How information is shared

We disclose information only in the following circumstances:

Processors may handle information in countries other than yours and are permitted to use it only to provide their contracted service to RecallHaven.

Cookies, local storage, and analytics

RecallHaven uses browser storage for authentication, appearance and editor preferences, offline-capable workspace data, and selected application caches. We use essential storage to operate the service. PostHog analytics may use cookies or local storage for product analytics and diagnostics; where consent is required, this analytics collection is optional until you consent.

Retention and deletion

Your controls and deletion instructions

You can disconnect Google Calendar inside RecallHaven by opening Calendar and selecting Disconnect Google. This deletes the stored Calendar credential and scope from RecallHaven. You can separately revoke RecallHaven from your Google Account connections.

You can delete your RecallHaven account from Settings. Account deletion removes the account, linked Google credentials, and associated application content from active systems, subject to temporary backup and legally required retention described above. You may also contact us to request access, correction, deletion, restriction, objection, or portability where applicable.

Security

RecallHaven uses HTTPS in transit, access controls, password hashing, encrypted Google Calendar refresh tokens, and other reasonable technical and organizational safeguards. Access to production data is limited to what is needed to operate and secure the service. No online service can guarantee absolute security.

Children

RecallHaven is not directed to children under 13 or under the minimum age required to consent to an online service in their country. If you believe a child supplied personal information without appropriate permission, contact us so we can investigate and delete it.

Policy changes and contact

We will keep this Policy current with RecallHaven's data practices. If our handling of Google user data or other personal information materially changes, we will update the effective date and provide additional notice when appropriate.

For privacy questions, requests, or complaints, contact the RecallHaven development team at support@recallhaven.com.