privacy policy
Your calendar is yours.
effective 2026-07-11
Axis is a personal task scheduler operated by Beau Leach. It connects to your calendar to place work around your existing commitments. This policy describes exactly what data Axis touches and what happens to it. The short version: your data is used to schedule your tasks, and for nothing else.
What we collect
- Account details. When you sign in with Google or Microsoft, we receive your email address, display name, and avatar from that provider. We never see your password.
- Calendar data. Axis reads events from your primary Google Calendar or Microsoft 365 calendar within a rolling scheduling window (roughly the past week through the coming months) — start and end times, titles, and identifiers — so the scheduler can place work around them. Axis also writes the blocks it schedules to that calendar, marked private.
- Task content. The tasks, projects, notes, tags, deadlines, and journal entries you create in Axis.
- OAuth tokens. The access and refresh tokens that authorize calendar access. They are stored server-side only and are never sent to your browser.
- Operational logs. Our hosting providers keep standard request logs (IP address, timestamps, request paths) for debugging and abuse prevention. Axis runs no analytics or advertising trackers.
How we use it
One purpose: scheduling your tasks into your calendar. Calendar events are read to compute free time; scheduled blocks are written back; task content drives what gets placed and when. Axis does not sell data, does not show ads, does not build advertising or behavioral profiles, and does not use your data to train AI models.
Google API Limited Use disclosure
Axis’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data obtained through Google APIs is used only to provide the scheduling features described above, is never transferred to third parties except as necessary to operate the service, and is never used for advertising. The same standard is applied to data obtained through Microsoft Graph.
Where it lives
Data is stored in a Supabase-hosted Postgres database and served through Vercel. All traffic is encrypted in transit (TLS), and storage is encrypted at rest by those providers. Access to production data is restricted to the operator. OAuth tokens are held server-side and used only to call the Google Calendar and Microsoft Graph APIs on your behalf.
Who we share it with
Nobody, beyond the infrastructure that runs the service: Supabase (database and authentication), Vercel (hosting), Cloudflare (scheduled jobs), and Google / Microsoft (the calendar APIs you connect). No data brokers, no advertisers, no analytics vendors. We would disclose data if legally compelled to, and would tell you unless prohibited.
Retention and deletion
Your data is kept while your account is active. You can revoke Axis’s calendar access at any time from your Google account permissions or Microsoft account permissions, which immediately stops all calendar reads and writes. To delete your account and all associated data — tasks, blocks, tokens, journal entries — email beau@beauleach.com and it will be removed within 30 days. Calendar events Axis created remain on your calendar unless you delete them or Axis removes them before access is revoked.
Your rights
You can request a copy of your data, correct it, or have it deleted at any time via the contact address above. If you are in a jurisdiction with statutory data rights (GDPR, UK GDPR, CCPA or similar), those rights are honored on request.
Changes
If this policy changes materially, the effective date above will be updated and signed-in users will be notified in the app. Questions: beau@beauleach.com.