Security

Linemerge holds calendar data for people who trust us with it. We treat that as the product's first requirement, not a feature. Here is how we protect it.

Minimization by design

The best protection is not storing data in the first place. Calendars you mark private contribute only free/busy intervals to your merged availability — the titles, notes, attendees, and locations of those events are never written to our database. Only calendars you explicitly mark public have event details stored, and only so we can show them to you.

Encryption

  • All traffic is encrypted in transit with TLS.
  • OAuth tokens and stored event data are encrypted at rest using envelope encryption — per-record data keys wrapped by a separately managed master key.
  • Backups are encrypted and expire on a rolling schedule.

Least-privilege access

  • We request the narrowest Google and Microsoft OAuth scopes that make the product work, and we adhere to the Google API Services User Data Policy, including its Limited Use requirements.
  • Production access is restricted to the minimum set of people and systems, protected by strong authentication, and audit-logged.
  • The application runs with an isolated database role that cannot reach other systems' data.

Revocation and deletion

  • Disconnecting a calendar immediately deletes its mirrored data and tokens from our systems.
  • You can revoke Linemerge's access directly from your Google or Microsoft account at any time — revocation works even if you never log back in to Linemerge.
  • Deleting your account (available in-app and by email) removes your tokens, mirrored calendar data, and personal information, and you can export your data first. See the Privacy Policy.

Operational security

  • Infrastructure sits behind Cloudflare; origin servers accept traffic only from it.
  • Secrets are stored in encrypted secret-management tooling, never in code or plain files.
  • Dependencies are scanned in CI; systems are patched and monitored, with alerting on anomalies.
  • Booking endpoints are rate-limited and bot-protected.

Reporting a vulnerability

If you believe you have found a security issue in Linemerge, please email [email protected] with the details. We will acknowledge your report promptly, keep you informed as we investigate, and will not pursue good-faith security research.

Stop answering “when are you free?” by hand

Linemerge is onboarding a small group of people who run more than one line.