Security & Privacy

MeetingScheduled — reach.meeting-scheduled.com

Google API Services — Limited Use

MeetingScheduled's use of data obtained from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

  • Gmail data is used only to provide the outbound email sending and reply-detection features you use within MeetingScheduled.
  • Gmail data is not sold or transferred to data brokers, advertising networks, or any third party for purposes unrelated to operating the service.
  • Gmail data is not used to serve advertisements or build advertising profiles.
  • Gmail data is not used to train or fine-tune any AI or machine learning model. Outbound emails you author through MeetingScheduled may be processed by AI models only to draft, review, and generate follow-ups to those same emails on your behalf; they are not used to train models.
  • No MeetingScheduled employee or contractor reads the content of your Gmail messages.

Gmail Permissions We Request

ScopeWhy it is needed
gmail.sendTo send outbound sales emails from your Gmail account on your behalf.
gmail.readonlyTo detect when a prospect replies, when an email bounces, or when a recipient requests to unsubscribe, using Gmail's history API. Only message headers and a server-generated preview are read — the full message body is never fetched.
userinfo.emailTo identify and display your sender email address.
userinfo.profileTo display your name within the application.

What Gmail Data Is Stored

Outbound emails you send through MeetingScheduled

When you send an outbound email, the subject line and body of that email are stored in our database. These are application-generated messages that you have reviewed and approved — they are not copies of your personal email.

Inbound Gmail messages

When a prospect replies, bounces, or requests to unsubscribe, MeetingScheduled fetches only the message headers (From, Subject) and a short server-generated preview (approximately 160 characters) from Gmail's API. The full inbound message body is never requested or stored.

From inbound messages we store:

  • The sender's email address (already in your contact database).
  • The reply subject line.
  • The server-generated message preview (≈160 characters, produced by Gmail's servers). This is the inbound metadata snippet used for reply and unsubscribe detection.

OAuth tokens that authorise MeetingScheduled to access your Gmail account are stored encrypted (AES-256-GCM) in our database.

What We Do Not Do with Your Gmail Data

  • We do not read your personal inbox, inbox history, or messages unrelated to outbound sales activity within MeetingScheduled.
  • We do not sell your Gmail data or any data derived from your Gmail account.
  • We do not use your Gmail data to serve you advertisements or build advertising profiles.
  • We do not use your Gmail data to train or fine-tune any AI or machine learning model. Outbound emails you author through MeetingScheduled may be processed by AI models only to draft, review, and generate follow-ups to those same emails on your behalf; they are not used to train models.
  • No MeetingScheduled personnel reads the content of your Gmail messages.

Third-Party Service Providers

Providers that may process Gmail-derived data

ProviderData and purpose
SupabaseDatabase storage — stores encrypted OAuth tokens, outbound email content, and inbound reply metadata as described above.
VercelApplication hosting — processes all server-side requests; OAuth tokens and derived metadata pass through server memory transiently during request handling.

Providers that do not receive Gmail-derived data

ProviderWhat they receive instead
AnthropicWorkspace profile, prospect research, and ICP context for drafting outbound emails. Inbound Gmail content is not passed to Anthropic.
Grok / xAIProspect search queries and buying-signal research. No Gmail data.
ContactOut / RampedUpProspect enrichment requests (name, title, company). No Gmail data.
PerplexityCompany research queries. No Gmail data.
TwilioVoice call routing for the in-app dialer, and storage of call recordings in Twilio's cloud. No Gmail data.
GroqOn-demand transcription of your call recordings; the transcript is returned to your browser and not stored on our servers. No Gmail data.
EnrichLayerProspect research enrichment from a public LinkedIn profile or company page. No Gmail data.
TelegramInternal operational alerts to our team (system health and quality notices). No Gmail data.

Your Rights

  • Revoke access:You can revoke MeetingScheduled's access to your Google Account at any time by visiting myaccount.google.com/permissions. After revoking, MeetingScheduled will no longer send emails or process Gmail events on your behalf.
  • Delete your data: You may request deletion of your account and associated data by contacting us at support@meeting-scheduled.com. We will process deletion requests within 30 days.

Privacy Policy

Our full Privacy Policy, including disclosures required under GDPR and CCPA, is available at www.meeting-scheduled.com/privacy.

Reporting a Security Vulnerability

If you believe you have found a security vulnerability in MeetingScheduled, please report it responsibly. Do not open a public GitHub issue.

Email: support@meeting-scheduled.com

Please include a description of the vulnerability, steps to reproduce, and the affected component or URL. We will acknowledge receipt within 48 hours and aim to resolve confirmed high-severity issues within 30 days.


MeetingScheduled — reach.meeting-scheduled.com