Plainly: what we store, how it’s scored, and how it’s kept.
The plain-English version of the privacy policy and terms: what FairlyRemote™ holds, what it doesn’t, and the controls you get.
At a glance
Free stays in your browser
On the Free plan, your boards, members, and fairness history live in local storage. No account, and nothing about your schedule reaches us.
Math, not AI
Rankings come from a deterministic algorithm you can predict and override, never a black box.
Busy-Only by default
Synced events show that you’re busy, not what, until you say otherwise.
Export & cancel freely
One button downloads everything as JSON. One click cancels: no retention friction.
The short list, and the long list of what we don’t
On Free, boards, members, and fairness history stay in your browser’s local storage; the only network calls are static assets and cookieless analytics. On Team and above, we hold just enough for your history to survive a device wipe and be shared with your team:
Two different things get called “your data,” so we split them below. What we read from your connected calendar is treated as borrowed and mostly discarded. What you create inside FairlyRemote, a proposal or a team meeting, is yours and is stored, because the feature cannot work otherwise.
✓ Stored (Team+)
- Account emailSign-in, billing, and the messages you’d expect.
- Fairness historyThe four scores plus weekly / monthly rollups.
- Board & member configNames, cities, working hours, chronotype.
- Calendar tokenEncrypted at rest; reads free/busy, writes only events you confirm.
× Not taken from your calendar
- Meeting descriptionsRead transiently to score, never kept.
- Attendees & responsesWe never copy the invitee list or RSVPs off a synced event.
- Locations & video linksNot read, not stored.
- Meeting titlesDropped on the Busy-Only default; kept only if you raise an event to Shared.
How long fairness history is kept
Enforced server-side by a daily cleanup job: what the product does, not a stated intention.
| Tier | Raw records | Weekly aggregates | Monthly summaries |
|---|---|---|---|
| Free | 14 days (local) | 2 weeks (local) | 14 days (local) |
| Team | 365 days | 52 weeks | 365 days |
| Business | 365 days | 52 weeks | 365 days |
Who else touches data
The services we rely on and what each handles. The privacy policy’s table is canonical for the active region; a DPA is available on request.
| Service | What it handles | Region posture |
|---|---|---|
| Supabase | Account email, fairness data, encrypted tokens | Region selectable |
| Stripe | Billing email, payment method, invoices | US; EU data under DPF / SCCs |
| Resend | Recipient address & content of account / billing email | Region selectable |
| Fly.io | Encrypted application traffic only | Multi-region |
| Cloudflare | Request metadata; no application data | Global edge |
| Plausible | Page URL, referrer, device class; no cookies, no IP retention | European Union |
| Sentry | Stack traces & request metadata when something breaks | Region selectable |
Regions are configurable on most providers; the privacy policy lists the currently active one.
It’s deterministic math, not AI
FairlyRemote ranks meeting times with a deterministic algorithm, not a machine-learning model. That’s deliberate: it’s what makes the tool trustworthy to act on.
Predictable
The same inputs always produce the same ranking. Nothing shifts under you between one look and the next.
Auditable
Every ranking traces back to four named numbers. You can see why a slot ranks where it does.
Yours to override
It advises; your team decides. A vote or a manual booking always wins over the suggestion.
The four things it scores, all per-person, all about meeting timing:
Accommodation
How many awkward-hour meetings someone has absorbed this period.
Rest
Whether a meeting would land in someone’s sleep window.
Flexibility
How much availability someone has offered.
These roll into one label per candidate time, decaying on a 30-day half-life. Vote weights run 0.5× to 2× from the trailing accommodation score, so whoever’s taken the awkward calls gets more say in the next one.
What it is not
It doesn’t measure whether anyone was “active” in a meeting, doesn’t track keyboard, screen, or attention, and produces no productivity score. It describes how meeting timing is distributed across a team, nothing more. It is advisory, and is not designed to inform performance reviews, pay, or hiring. See the feature in detail →
Busy-Only by default. Title-visible only when you say so.
Imported calendar events wait in your review screen with Busy Only pre-selected: teammates see nothing until you confirm an event, and a confirmed one shows that an hour is taken, never what it is. You lift or drop that per event; admins can set a board default, and the review screen bulk-updates in one pass.
Board admins set the default via a preset (Privacy First, Standard, or Open Team). Under Standard and Open Team you can raise or lower a single event within what the preset allows. Privacy First is locked: every event stays Private and the per-event control is switched off.
Exactly which permissions we ask for
Connecting a calendar (Team and above) requests these scopes, all shown together on the provider’s consent screen.
calendar.readonlyRead free/busy and event titles to detect conflicts. Descriptions, attachments, and attendee responses are not read.
calendar.eventsCreate an event when you confirm a winning time, or when a shift is assigned to you. We change or remove only the events FairlyRemote created; the server checks that before every write.
tasks.readonlyRead your Google Tasks (title and due date) to show them as to-do blocks. We never create, modify, or delete your tasks.
userinfo.emailIdentify which account is connected.
Calendars.ReadRead free/busy and event titles to detect conflicts. We do not write to your Microsoft calendar. Outlook sync is not available yet.
User.ReadIdentify which Microsoft account is connected.
Never requested: contacts, Gmail, Drive, or admin-directory scopes. Disconnecting drops the token immediately; you can also revoke at myaccount.google.com/permissions.
How your data is kept
The posture behind the promises above. For how to report a vulnerability, see our responsible-disclosure policy.
In transit
TLS 1.3 on all customer-facing endpoints, HSTS enabled.
At rest
AES-256 at the database layer; backups inherit the same encryption.
Connection tokens
Encrypted with a separate application-layer key, so database access alone can’t use them.
Row-level security
Tenant isolation is enforced in Postgres. An app-layer mistake returns zero rows, not another team’s data.
Sessions
Short-lived access tokens, refresh tokens in HttpOnly cookies, a strict CSP on the app surface.
Operations
Dependency scanning triaged within 7 days, PII-scrubbed logs, 7-day PITR + 30-day backups, recovery tested quarterly.
What we don’t claim
FairlyRemote is not SOC 2 or ISO 27001 certified, and isn’t designed to handle PHI (no HIPAA / BAA). Need certification documentation for a review? Get in touch: a DPA, security questionnaire, and architecture review are available in the interim.
Reporting & incidents: email security@fairlyremote.com; we acknowledge within 48 hours and target a fix within 14 days for high-severity issues. Customer-impacting incidents are disclosed to affected customers within 72 hours.
Leave with everything, whenever
Two commitments that make trying FairlyRemote low-risk.
Export anytime
One button in settings downloads everything (every board, member, and fairness record) as one JSON file, in the same stable schema the importer accepts.
Deleting your account? The export is offered again on the confirmation step.
Cancel anytime
Cancelling stops renewal at the end of the current period; you keep access until then. UK and EU consumers also have the statutory cancellation rights set out in our Terms.
One confirmation email: no retention friction.
See it on a sample team
Five people, five timezones, a month of meetings already in place. No signup, no card.
Try the sample team