Your privacy is the whole point of Vaila. Here's exactly what we collect, why, and what we never do with it.
What we collect
- Your name and email when you create an account
- Your phone number if you verify it, and an invitee's phone number if you add one to a plan
- Your connected calendar events (Google, Outlook, or Apple) to find open times and manage confirmed plans
- The plans and messages you create — who they're with, what kind of plan, what time was confirmed
- Subscription status, purchase identifiers, and billing portal/customer identifiers needed to manage Pro access
- Your profile photo, if you upload one, which is shown to the people you make plans with
- A device token, if you turn on notifications, so we can send push alerts
- Basic usage, diagnostics, and security data to keep the app working
What we never do
- We never sell your data to anyone
- We never share your calendar events with other participants in a plan
- We never use your data for advertising
- We never use calendar access beyond what's needed to find and manage plan times
How we use your data
- To suggest times that work for everyone in a plan
- To send notifications and emails about your plans, and a text-message verification code when you ask us to verify your own phone number. We do not text your invitees — you send them the invite yourself, from your own phone
- To remember your time preferences so suggestions get better over time
- To provide subscriptions, prevent abuse, troubleshoot bugs, and keep your account secure
Calendar access
When you connect Google, Outlook, or Apple Calendar, Vaila reads events to find free windows. If Google Calendar is connected, Vaila can also create confirmed plan events. We store busy-time summaries and never share your schedule with other participants. You can disconnect calendars, clear synced calendar data, or delete your account from Settings.
How we protect your data
- All data moves over encrypted connections (TLS/HTTPS) between your device, our servers, and every service we use
- Your data — including calendar information and connection tokens — is stored on managed infrastructure that encrypts data at rest
- Calendar connections use OAuth with the minimum scopes needed; we never see or store your Google or Microsoft password
- Access to your data requires your authenticated session; production access is restricted and limited to operating the service
- Sensitive credentials (like calendar tokens) are never shared with other users or third parties, and are deleted when you disconnect a calendar or delete your account
AI features and your data
Vaila's time suggestions are ranked by an AI model accessed through the OpenAI API. To rank suggestions we send only what the feature needs: the plan description you typed and availability information derived from connected calendars (busy times, and for the plan organizer, event titles and times). OpenAI processes this data as a service provider and, per its API data-usage policy, does not use data submitted through the API to train its models unless an API customer explicitly opts in. Abuse-monitoring logs may be retained by OpenAI for up to 30 days by default unless a different retention control or legal requirement applies. We do not use your data — including any Google user data — to create, train, or improve any AI or machine-learning models, and we do not permit any third party to do so.
Service providers
We use service providers to run Vaila, including hosting/database infrastructure, Apple and Stripe for subscriptions, Google and Microsoft for calendar/auth integrations, Twilio for phone verification, email delivery providers, OpenAI for scheduling suggestions, Cloudinary for storing and delivering profile photos, Vercel for web hosting and analytics, Google Analytics for aggregate website measurement, and error-monitoring tools. These providers process data only so they can provide services to Vaila and must protect it consistently with this policy.
Analytics
The Vaila website uses Vercel Web Analytics, Vercel Speed Insights, and Google Analytics 4 to understand aggregate page traffic and performance. All of them receive page URLs (with invite links, sign-in codes, and other sensitive tokens removed before sending), referrer, and coarse device/browser information. Google Analytics is configured for measurement only: Google Signals and ad personalization are turned off, so nothing we measure is used for advertising or shared with advertising products. Vercel's tools set no cookies; Google Analytics sets first-party cookies, which the next section explains — including why visitors in the EEA, UK, and Switzerland get none. Like any web host or analytics provider, Vercel and Google see your IP address when your browser makes the request: Vercel uses it only transiently to count unique visits and does not store it, Google Analytics 4 uses it to derive coarse location and does not log or store it, and Vaila never receives it from either.
Cookies and browser storage
The web app does not use advertising or third-party tracking cookies. Google Analytics sets first-party cookies (named _ga and _ga_*) that tell us whether a visit is new or returning; they hold a random identifier, never your name, email, or phone number. We use Google Consent Mode, and because Vaila shows no cookie banner, visitors in the EEA, UK, and Switzerland default to denied: no analytics cookie is set there and Google receives only cookieless, aggregated pings. Advertising storage and ad personalization are denied for everyone, everywhere. You can block or clear these cookies in your browser settings or with Google's opt-out browser add-on. Separately, we use your browser's local storage for things the app needs to work: your signed-in session, onboarding progress, which chats you've read, and a pending invite link if you sign in through one. This data stays in your browser and is cleared when you log out; you can also clear it any time through your browser settings.
Google user data and Limited Use
Vaila's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will likewise adhere to the Google User Data Policy, including the Limited Use requirements: Google user data is used only to provide and improve Vaila's user-facing scheduling features, is never sold, is never used for advertising, and is never used to train AI or machine-learning models.
Notifications and email
If you allow notifications, we store a device token to send push alerts for new requests, messages, and plan updates. We also send emails tied to your plans — invites, confirmations, and cancellations. You can turn email notifications off individually in Settings, and push notifications off in your device settings. If someone invites you by email and you do not have a Vaila account, every email we send you carries links to stop updates for that plan or to block all Vaila email to your address; we honour either one without you needing to sign up for anything.
Data retention
We keep your data while your account is active unless you clear a specific category from Settings. When you delete your account, your login, contacts, calendar data, profile (including any profile photo, which is deleted from our image host), device tokens, and meetings you created are removed from active systems. Plans or group chats that belong to other participants may remain with you shown as “Deleted user.” We may retain limited records if required for security, fraud prevention, tax, accounting, dispute, or legal obligations. If you unsubscribe from our emails, we keep a minimal suppression record (the email address and the date) even after account deletion — that record is what stops us from emailing you again.
Your rights
You can view an account data summary, download a copy of your data, clear synced calendar data, clear learned preference history, disconnect calendars, block someone, report a plan or conversation, and delete your account from Settings. You can also email support@vailaapp.com to request access, correction, deletion, or help with any privacy request.
Contact
Questions about privacy? Email us at support@vailaapp.com