Privacy Policy — Meet Gesty

Last updated: September 3, 2026

What changed in this update

September 3, 2026: we added a Zoom Data section — what Meet Gesty receives from Zoom if you connect it, what it creates on your behalf, and how to disconnect. The advertising note below is from August 17.

We measure how well our advertising works. In the app: the app tells Meta (Facebook and Instagram) that you installed it, created an account, created a schedule, shared a link, or received a booking — counts of your own activity, nothing about the people who book with you. What changed: if you are in the EU, EEA, UK or Switzerland the app still asks first and shares nothing until you agree; everywhere else this measurement is now on by default, and you can turn it off at any time in Settings → Notifications. To tell which applies, the app uses the approximate country of your internet connection and your device's region setting. On the website: Google Analytics is unchanged — it waits for your acceptance of a cookie notice. See Advertising & Analytics for exactly what is shared and how to turn it off. Your calendar contents are never included.

What We Collect

We do not collect sensitive personal information unrelated to the core functionality of the app. The data we process is limited to information necessary for account creation, authentication, and scheduling features, such as profile details, calendar availability, and meeting-related data required to operate the service.

Account Information

  • name
  • email address
  • sign-in details via Apple, Google, or email authentication
  • device locale and time zone settings

Scheduling Information

  • meeting titles
  • availability preferences
  • available time slots
  • confirmed appointments
  • participant details necessary for scheduling

Calendar Data

With your permission, Meet Gesty connects to your Google Calendar to display your availability and prevent scheduling conflicts. During Google's OAuth consent flow we request Google's broad Calendar scope because that's what Google requires to list multiple calendars and read events.

What we read: events on the calendars you select in Settings. We use the start and end times of those events to mark the corresponding slots as unavailable on your booking grid, so invitees can only pick times when you're free.

What we write: when someone successfully books a slot through one of your booking links, we create a single event for that booking on your Google Calendar's primary calendar. The event contains the invitee's name. We don't modify or delete any of your existing events.

On disconnect or data deletion we stop creating new events, but we don't remove events we've previously written — you own your calendar and may want to keep the history.

Google API Services User Data Policy

Meet Gesty's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Meet Gesty uses Google Calendar data only to provide the user-facing scheduling features described above. We do not:

  • transfer this data to third parties except as needed to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets (with notice to affected users);
  • use the data for serving advertisements;
  • allow humans to read the data, except (a) with the user's explicit consent for support, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for internal operations when the data has been aggregated and anonymized;
  • use the data to develop, improve, or train generalized AI or machine-learning models.

Zoom Data

With your permission, Meet Gesty connects to your Zoom account so that a booking link can offer the “Generate Zoom link” option. During Zoom's OAuth consent flow we request three permissions and nothing more: create a meeting, delete a meeting, and read your own Zoom profile. We do not request access to your other meetings, recordings, chats, or contacts.

What we receive: an access token and a refresh token that let us perform those three actions on your behalf, the email address of your Zoom account, your Zoom user id, and whether your account is free or paid. The tokens are stored encrypted (AES-256-GCM) in our database. Clerk, which handles your sign-in, never sees any of this. We read the account type only so the app can tell you that meetings on a free Zoom account end after 40 minutes.

What we create: when someone books a slot through a booking link where you chose “Generate Zoom link”, we create one Zoom meeting for that booking. The meeting's join link and passcode are shown to the invitee and stored on the booking. If the booking is cancelled, we delete that meeting. We do not read, modify, or delete any other meeting in your Zoom account.

On disconnect or removal: you can disconnect Zoom in the app or at gesty.ai/meet/zoom, or remove Meet Gesty from inside your Zoom account. In every case we revoke the token with Zoom and delete our copy immediately. Meetings we have already created stay in your Zoom account — you own them, and disconnecting does not delete them. If you cancel a booking after disconnecting, we can no longer delete its meeting for you; the app marks the deletion as pending, and you can retry it after reconnecting.

Data received from Zoom is used only to provide the scheduling features described above. It is never used for advertising and is never shared with advertising partners. See our Zoom help page for step-by-step instructions.

Technical Information

  • device type and operating system
  • IP address (retained in network request logs)
  • approximate country, derived from the IP address of your request and your device's region setting — used only to decide whether the app must ask before advertising measurement (see Advertising & Analytics) and stored together with the record of that choice
  • server logs — request timestamps, response codes, and error messages used for debugging and abuse prevention

We do not collect contacts, photos, precise location data, health data, or other sensitive personal information beyond what is required for scheduling functionality.

Adults

Meet Gesty is intended for adult users and is not directed to children. We do not knowingly collect personal data from children.

How We Use Your Data

Your data is used only to:

  • schedule and confirm meetings
  • synchronize calendar events
  • create and remove Zoom meetings for your bookings, if you have connected Zoom
  • send reminders and service notifications
  • improve platform stability and user experience
  • provide customer support
  • protect account security and prevent fraud
  • measure how effective our advertising is — only as described in Advertising & Analytics, which also explains when we ask first and how to turn it off

Calendar and Zoom access are requested only to provide scheduling functionality and only with your permission. Calendar contents and data received from Zoom are never used for advertising or shared with advertising partners.

Advertising & Analytics

We advertise Meet Gesty on Meta platforms (Facebook and Instagram). To understand which adverts actually bring people to Meet Gesty, the Meet Gesty app shares a small number of events with Meta Platforms, Inc. Whether this is on from the start or only after you agree depends on where you are — see Your choice below.

What the app shares while measurement is on

  • that the app was installed
  • that an account was created
  • that a booking schedule was created
  • that a booking link was shared
  • that a booking was received on your schedule

These are counts of your own activity, sent from your device. They tell Meta that someone using Meet Gesty took one of these actions — nothing about who, and nothing about the content. On iPhone and iPad no advertising identifier is used at all; on Android one is included, as described below.

What we never share

  • your calendar contents, events, or availability
  • meeting titles, notes, or participant lists
  • your email address, or anyone else's
  • any data received from Google or Zoom APIs

If someone books a meeting with you, nothing about them is shared with Meta. Their name, email, and the details of your meeting stay between the two of you. The only thing recorded is that a booking happened on your schedule, and that is sent from your device, not theirs. People who book with you are never asked to accept advertising cookies, because none are set for them.

Your choice

In the app, for the Meta events above, what happens depends on where you are:

  • In the EU, EEA, UK or Switzerland (including their dependent territories) the app asks you first — a notice on first launch. Until you answer it, Meta's software is not started at all and nothing is sent. If you agree, you can withdraw at any time in Settings → Notifications.
  • Everywhere else measurement is on by default from first launch. You can turn it off at any time with the Ad measurement switch in Settings → Notifications; turning it off stops all future sharing.
  • How we tell which applies: the app derives an approximate country from the IP address of its request to our server and from your device's region setting. If either points to the EU, EEA, UK or Switzerland, we ask first. If we cannot determine a country, nothing is started until we can. We do not use precise location. The derived country is stored together with the record of your choice — or of the default that applied — so we can show that the right rule was used.

On the website, for Google Analytics, we ask separately with a cookie notice. Until you accept it, no analytics cookies are set and no analytics script is loaded. This is separate from the app, and it does not involve Meta. The booking pages carry no analytics at all — if you are booking a meeting with someone, you are not tracked and you are not asked about cookies.

If you decline, or turn measurement off, we do not send these events, and Meet Gesty works exactly the same.

On iPhone and iPad we do not use your device's advertising identifier at all, and the app never asks Apple's “allow tracking” permission — advert performance is measured in aggregate using Apple's own SKAdNetwork. On Android, where the identifier is available without a separate system prompt, it is included with these events, and only while measurement is on.

You can turn measurement off, or withdraw your consent, at any time — in the app's Settings → Notifications, or on the website via the Cookie settings link in the footer. This stops all future sharing. Events already sent to Meta before that are governed by Meta's Privacy Policy; you may also request their deletion by contacting us.

Where the law requires consent as the legal basis for this processing (the EU, EEA, UK and Switzerland), we rely on your consent, and nothing is shared before it is given. Elsewhere we rely on our legitimate interest in measuring our own advertising, with the off switch described above.

Third-Party Services

We rely on the following third-party processors to operate Meet Gesty. Each processes only the minimum data required to perform its function:

  • Clerk — authentication, session management, and identity (email, Apple ID, Google sign-in linkage)
  • Google Analytics — aggregate website usage statistics (pages visited, approximate location, device type) for the Meet Gesty website only. It is not present in the mobile app. It sets cookies, so it only runs if you accept them in the website's cookie notice.
  • Vercel — application hosting, edge network, and request/error logging
  • Supabase — primary database (Postgres) for account records, booking links, bookings, availability windows, cached calendar metadata, and encrypted Zoom connection tokens
  • Google Calendar API — read-and-write access to the calendars you connect, only when you have explicitly connected your Google account
  • Zoom (Zoom Video Communications, Inc.) — creation and deletion of Zoom meetings for your bookings, only when you have explicitly connected your Zoom account. Receives the meeting details needed to create the meeting; we receive the join link and passcode in return.
  • Expo Push Notification Service (via Apple Push Notification Service on iOS and Firebase Cloud Messaging on Android) — delivery of booking confirmations and reminders to your device
  • Telegram Bot API — optional alternative notification channel, used only if you opt in to Telegram notifications inside the app
  • RevenueCat — handling of in-app subscription status and App Store or Google Play receipt verification (only when paid plans become available)
  • Meta Platforms, Inc. — advertising measurement for the mobile app only: on by default outside the EU, EEA, UK and Switzerland (you can turn it off in Settings), and only with your consent inside those regions. It is not present on this website: no Meta pixel or Meta cookie is used here. Receives the limited events listed in Advertising & Analytics. Unlike the processors above, Meta is an independent controller of this data and may use it for its own purposes under its own privacy policy — which is why we ask first where the law requires it and why you can turn it off at any time.

With the exception of Meta, described above, these processors are bound by contract to use your data solely to provide their services to Meet Gesty. They are not permitted to use your data for their own purposes.

Internal Ecosystem Access

Meet Gesty is part of the Mamagesty Universe ecosystem. Your account may be used across affiliated applications within this ecosystem to enable single sign-on (SSO) and consistent account management.

Sharing your account across the ecosystem is for single sign-on and account management only. It does not itself involve advertising partners; any advertising measurement is limited to what is described in Advertising & Analytics and can be turned off at any time.

Data Sharing

We never sell or rent your personal data.

Data is shared only when necessary to provide Meet Gesty functionality, when required by law, or — for advertising measurement — limited to the events and subject to the choices described in Advertising & Analytics. We do not share your calendar contents, meeting details, or any data received from Google or Zoom APIs for advertising or marketing purposes, under any circumstances.

Data Storage

Your data is stored securely for as long as your account remains active.

After account deletion, personal data is permanently removed within 30 days, except where retention is required for legal, billing, or security purposes. Temporary backup copies may remain for technical recovery.

Connection credentials for Zoom are an exception to the account-lifetime rule: they are deleted immediately when you disconnect Zoom or remove Meet Gesty from your Zoom account, without waiting for account deletion.

Subscriptions & Payments

Meet Gesty is currently free and does not offer any paid plans or charges.

If subscription features are introduced in the future, payments will be processed through the Apple App Store, Google Play, and/or authorized providers such as RevenueCat. We do not collect, store, or have access to users' full payment details, including Apple or Google payment information.

Any free trial, if offered, will automatically renew into a paid subscription unless canceled before the trial period ends.

This Privacy Policy will be updated accordingly if paid features are introduced.

Security

We use industry-standard security measures, including encrypted connections, secure authentication, access-controlled storage, and regular security reviews. Zoom access tokens are stored encrypted (AES-256-GCM).

Your Rights

You may access, update, or delete your personal information at any time within the app.

You can also ask us to provide, correct, or delete the personal data we hold about you by emailing support@gesty.ai. We respond to every such request.

You can also change language, timezone, and notification preferences in the app or your device settings.

Calendar access can be revoked at any time through device or calendar provider settings, which will disconnect the integration and remove cached calendar data.

Zoom access can be revoked at any time — in the app, at gesty.ai/meet/zoom, or by removing Meet Gesty from your Zoom account. Each of these revokes our token with Zoom and deletes our copy immediately. Meetings already created remain in your Zoom account.

You may delete your account from within the app. Depending on the selected option, this may remove Meet Gesty-specific data or permanently delete your entire account and all associated data across the Mamagesty Universe ecosystem.

You may turn analytics and advertising measurement on or off at any time — in the app's Settings → Notifications, or on the website via the Cookie settings link in the footer — without affecting any other functionality. See Advertising & Analytics.

Changes to This Policy

We may update this Privacy Policy from time to time. Continued use after such updates means you acknowledge the revised Policy.

Contact

For privacy-related questions or requests: support@gesty.ai