Privacy, security and end-to-end encryption

You’re trusting an app with your calendar and with what your clients tell you. Appointmentist asks only for the access it needs, encrypts what it keeps and, if you choose, locks your client records so that only you and your team can read them.

A therapist’s notes, for her eyes only

A therapist writes notes she would never want anyone else to read. On every plan, they’re encrypted before they’re stored. She also turns on end-to-end encryption, so her notes open only in her own browser, after she enters her passphrase. Her security settings show where things stand: records end-to-end encrypted, this browser unlocked and her keys set up.

What you get

  • Connecting a calendar only reads it; writing to it needs a separate permission
  • Client details, notes and appointments encrypted before they’re stored, on every plan
  • Optional end-to-end encryption, so only you and your team can read your client records
  • Master keys that protect your data, replaced regularly
  • Stored data encrypted to hold up against future quantum computers
  • No ads, no selling data, no training models on your content

Only the access it needs

Connecting a calendar lets Appointmentist read it, and nothing more. Writing to a calendar asks for its own permission later, and unlinking an account (keep one way to sign in) ends our access to it. Google user data is handled in line with the Google API Services User Data Policy, including its Limited Use requirements: it’s used only for the features you use and the extras you choose, and never for advertising.

Encrypted before it’s stored

Your clients’ names, contact details and notes, and the appointments read from your calendar, are encrypted before they’re saved, and backups hold only the encrypted copy. Your calendar connections and your own AI key are encrypted too. The master keys that protect all of this are replaced regularly, and what we store is encrypted to hold up against the quantum computers of the future, not just today’s. All of it comes with every plan.

End-to-end encryption, if you want it

Turn it on and your client records, contacts and notes are locked with keys that only you hold, and any teammates you share them with. They open only in your browser, after you enter your passphrase. Not even we can read them. In every mode, the times of your appointments and your list of services stay readable to us.

End-to-end encryption comes with some paid plans. If your plan changes later, an encrypted workspace keeps working.

You choose how your calendar is read

Keep automatic scanning (recommended)
Appointments and reminder text stay readable to us, so finding follow-ups, scheduling and full reminders keep working on their own. By default we also keep a readable copy of your rules and their message templates, so reminders are scheduled the moment an appointment arrives; you can keep those to yourself instead. Your client records, contacts and notes stay end-to-end encrypted. Reminders on Telegram or in your browser start out with times only; adding names is your choice.
Seal everything
We read each new appointment in memory only while we seal it, and keep none of its details readable. New appointments then wait until someone opens the app, and reminders sent outside the app carry only a link to it.
Seal everything, and never send us the details
Only appointment times reach us. Details fill in while the person who connected the calendar has the app open.

Before you turn it on

  • It can’t be undone. Once your records are end-to-end encrypted, they stay that way.
  • Only you can get back in. Your passphrase can’t be reset. Your 24-word recovery phrase is the only way back, and if you lose both, your records are gone for good. We can’t recover them.
  • Each tab asks for your passphrase. Your records unlock one browser tab at a time. Nothing is stored, so reloading the page asks again.
  • Support can’t look at your records. If something goes wrong, we can’t open them to help.
  • AI needs your say-so. In every mode, automatic AI stays off until you turn on both “Use AI for scheduling” and “AI under end-to-end encryption”. Then appointment details, and the wording of your rules and templates, go to your AI provider. When you ask AI for something yourself, the app tells you first what it will send.
  • Teammates need their own keys. Everyone who should keep access sets up their keys first. Anyone who hasn’t is locked out until you give them access.
  • Key changes happen in your browser. When your key is due to be replaced, the app asks you to do it, because only your browser can.

One limit to know: the app itself comes from us. End-to-end encryption protects what’s stored; it can’t protect you from a version of the app built to hand your keys over.

How to set it up

  1. Encryption before storage needs no setup: it’s on for every workspace from the start.

  2. For end-to-end encryption, open “Encryption” under “Security & privacy” in your workspace settings.

  3. Press “Set up my keys”, choose a passphrase and keep your recovery phrase somewhere safe.

  4. Press “Turn on end-to-end encryption” and choose how your calendar is read.

Encryption before storage comes with every plan. End-to-end encryption comes with some paid plans.Compare plans

Privacy & security: common questions

Is my calendar data used for advertising or AI training?

No. Your calendar data is used only for the features you use and the extras you choose, like AI help or a booking page. It is never sold, never used for ads, and never used to train models.

What happens when I unlink an account or delete my data?

Unlinking an account (keep one way to sign in) ends our access to it and deletes the appointments read from it. For a Google account, we also ask Google to cancel the access you gave; for an Outlook or Microsoft 365 account (beta), you can remove the app in your Microsoft account settings. Deleting your account closes it at once and deletes your data 30 days later, apart from the few records the Privacy Policy lists, such as security audit logs.

Can anyone at Appointmentist read my client notes?

Not with end-to-end encryption on: then only you, and any teammates you give access, can open them. Without it, your notes are still encrypted before they’re stored, but the service can open them, which is how support can look into a problem for you.

Related features

  • Multiple calendars

    Link several Google and Outlook (beta) accounts, and pick the calendars that count from each.

  • Bring your own AI key

    Run AI on your own OpenRouter or Google AI Studio key, stored encrypted and always shown masked.

See it on your own calendar

Connect Google or Outlook (beta) in a couple of minutes.