The short version
- We read your calendar so the app can tell when you are free. We also write to it, because that is how an agreed plan lands in your diary.
- You decide what each person sees of you, per person and per calendar. The default is the least: busy or free, with no titles.
- Nobody can see who else you know. Your connections are invisible to each other, and there is no way to ask the app who somebody else knows.
- We do not sell anything, we do not advertise, and we do not share your data with anybody except the calendar provider you connected.
What we read from your calendar
When you connect a Google account we ask for two things: permission to read your calendars, and permission to create and change events. The second is not optional for the app to work, because agreeing a plan means putting it in both diaries.
We read the events in the windows the app is currently showing, which is usually the next few weeks. We read the start, the end, the title, the place and the description, because those are what the app can show you about your own day.
What we store, and for how long
We do cache your calendar. Answers from your calendar provider are kept for five minutes so that moving between screens does not re-read the same week over and over. After five minutes the cached copy is ignored and replaced. It is a cache and not an archive, but it is real storage and it would be dishonest to describe it as anything else.
Permanently, we store: your name and email from the account you signed in with, your timezone, which calendars you connected and what you set each one to show, your connections and the settings on them, the plans you make, the messages you send in the app, and the teams and lists you create.
We also count sign-ins. Each attempt writes down the time, which provider it used, and whether it produced an account, matched an existing one, or failed. No name, no email and no account id is attached to any of it, so a row says an attempt happened and never says whose. We keep it because someone can finish signing in with Google and still never arrive here, and without counting we have no way to know.
What we write to your calendar
One thing: an event, when a plan is accepted. It carries the title, the time, the place if there is one, and a link back into the app. If the plan is moved or called off we change or delete that same event. We never touch anything else in your diary.
What other people can see
Three separate controls, and they combine so that the strictest one wins.
Per person. Each connection is set to show busy and free only, or titles, or full detail. It is directional: what you show somebody is a different setting from what they show you, and neither of you is told what the other chose.
Per calendar. Each calendar you connect can show its real titles, show a label you choose like Work or Kids, show only as busy, or be switched off. A calendar setting can only ever show less than a person setting allows, never more.
Per event. You can hide a single event from everybody, or reveal a single event to one person. A hidden event still blocks the time so nobody can book over it, but nothing on screen says why that hour is unavailable.
Who else you know
Your connections cannot see each other, and the app is built so they cannot work it out either. There are no follower lists, no mutual friends and no activity feed. Where a screen would otherwise reveal a number, it says nothing instead: empty states never count what is missing, because a count can be compared against a later count.
There are two exceptions, and you opt into both. A team lists its members to its members, because a shared event needs a guest list. And an event you are hosting shows its guest list to the people who have said they are interested, after they have said so and not before.
Your phone number
Optional. If you add it, it is used to let people you are connected to text you from their own phone, and to include you in a group text. The message is composed on your friend's device and sent by their phone: we never send messages, and your number goes nowhere except to the connections you have shared it with.
Location
Only used by "I'm here now" and when you look up a place, and only if you allow it. Your coordinates are rounded to about eleven metres before they leave your device: enough to find a pub, not enough to say which table.
Attaching an exact point to something you are hosting is a separate switch that is off by default, so a place name can stay deliberately vague.
Place searches go through our server to OpenStreetMap, never from your browser directly, so no third party sees your address or your device.
The same is true of the small map shown after you pick a place: our server fetches that picture and passes it on, so the map provider never sees you either. It is only ever a map of the PLACE you chose, which is a pub or a park and public knowledge. A location you share from your own device is never sent to draw a map.
Everyone else who is involved
The complete list of companies this app can reach on your behalf, what each one gets, and when. Nothing here is optional to us and hidden from you: if a name is missing from this list, that is a bug, and there is a test that fails when the code can reach somebody this page does not name.
Google, Microsoft or Yahoo, whichever you signed in with. They tell us your email address and name so we know who you are. Google also holds the calendar we read your busy times from and write your accepted plans to.
OpenStreetMap and Photon answer place searches. Photon is run by komoot and reads OpenStreetMap data. Both are asked by our server, never by your browser, so neither sees your address or your device: they get the words you typed and, if you shared a location, a coordinate rounded to about eleven metres.
Geoapify draws the small map shown after you pick a place. Our server fetches that picture and passes it on, so it reaches you from us, and it is only ever a map of the PLACE you picked rather than of where you are.
Anthropic is the one that is not switched on. The app can ask a model to reword a suggestion, and there is no API key set, so it has never run and nothing has ever been sent. If it is ever turned on, what goes is the line of text you wrote and the first names of the people it might mean, and only when you ask for it. Nothing about anyone's calendar goes with it: when everybody is free is worked out here and never leaves.
Where you usually are, if you tell us. Settings lets you pick your town so place search looks near you instead of guessing from your time zone, which for the whole US East Coast means New York. What we keep is the town you picked and about as precise as its name: it is not your location, we never sense it, it never becomes an event's coordinate, and nobody else is ever shown it. Remove it in settings and searches go back to guessing.
A calendar you subscribe us to. If you paste the secret address of a calendar, our server fetches it from whichever company hosts it, and that company sees the request coming from us rather than from your device. We keep that address encrypted and never show it again, and we only ever read: nothing is added to that calendar, ever. Remove it in settings and we stop reading it straight away.
Resend sends email, and only ever because somebody asked it to. Nothing here emails you on its own: there is no newsletter, no digest and no notification by email. Two things send. Tapping “send it” on an invite, where what goes is the address you typed, the invite's title, when and where it is, the host's name and the link, which is exactly what the invite page already shows anybody holding that link. And asking for a sign-in link, where what goes is a link that works once within fifteen minutes and nothing else. Anybody can type an address into that box, so the message says so plainly and receiving one does not mean you have an account here. Nothing about anyone's calendar goes with it, and no guest list ever does. We keep a record that the email was sent, and the address in it is stored only as a fingerprint we cannot read back, so a copy of our database is not a list of other people's contacts.
Vercel and Neon run the app and the database. They hold what this page already describes because it has to live somewhere.
What we do not do
We do not sell or rent anything. There is no advertising and no tracking. There are no analytics scripts and no third party fonts: your browser loads nothing from anywhere but this app itself and your calendar provider. The one picture that comes from elsewhere, the map of a place you picked, is fetched by our server and passed on, so it reaches you from us. We do not read your email, contacts or files.
Google user data, and the Limited Use rules
NOMOFOMO's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, and to be specific about what that means here:
- Your calendar data is used for one thing: showing when you and the people you have connected to are free, and putting an agreed plan on your calendar. Both are the app's main screens, not a side feature.
- We do not transfer it to anyone. The only place it goes is between you and the calendar provider you connected.
- We never sell it, and it is never used for advertising, profiling, credit decisions, or training any model.
- No person reads it. Access is by the running app alone, except where you have asked for help with something specific, or where the law requires it.
- We keep only the busy windows the app is currently showing, and we delete them when you disconnect. Revoking access in your Google security settings stops all of it immediately.
Deleting things
Ending a connection stops all sharing between you both immediately and in both directions. Plans you already agreed stay in your calendars, because they are your events; delete them there if you want them gone.
To delete your account and everything in it, email [email protected] and it will be done. You can also disconnect NOMOFOMO from your Google account at any time in your Google security settings, which immediately stops all calendar access.
Getting in touch
NOMOFOMO is run by one person. Questions, corrections and complaints go to [email protected].
