How we protect your data

You’re trusting us with your calendar and with what your clients tell you. Here’s what protects it on every plan, what end-to-end encryption adds, when AI sees any of it, and how to tell us about a problem.

On every plan

  • Only the access it needs

    Connecting a calendar lets Appointmentist read it. Writing to a calendar asks for its own permission, and you can unlink an account at any time (keep one way to sign in), which ends our access to it.

  • Encrypted before it’s stored

    Client details, notes and appointments are encrypted before they’re saved, backups included.

  • Keys that change on a schedule

    The master keys that protect your data are replaced regularly. With end-to-end encryption on, the app tells you when it’s time.

  • Stored data, ready for tomorrow’s computers

    What we store is encrypted to hold up against the quantum computers of the future, not just today’s.

  • Reminders say what you choose

    A reminder on Telegram or your phone can say only that something is due, the times, or everything, including who it’s about.

End-to-end encryption, if you want it

Turn it on and your client records, contacts and notes are locked with keys that only you hold, and any teammates you share them with. They open only in your browser, after you enter your passphrase. Not even we can read them. In every mode, the times of your appointments and your list of services stay readable to us.

One limit to know: the app itself comes from us. End-to-end encryption protects what’s stored; it can’t protect you from a version of the app built to hand your keys over.

End-to-end encryption comes with some paid plans. If your plan changes later, an encrypted workspace keeps working. Read what changes when you turn it on before you do.

AI, only when you choose it

Automatic AI runs only after you turn on “Use AI for scheduling”, and other AI features only when you press their button. Then only what it needs from an appointment goes to the AI provider. With end-to-end encryption on, automatic AI also needs “AI under end-to-end encryption” turned on, in every mode.

AI comes with paid plans. Some include a managed AI key; with the rest, you connect your own. Read more about AI suggestions and drafting.

How we use and keep your data is set out in the Privacy Policy.

Report a vulnerability

Think you’ve found a security problem in Appointmentist? Email us, with “Security” in the subject line.

What to include

  • What you found, and where: the page, screen or address.
  • The steps that reproduce it.
  • What someone could do with it.

While you look

  • Test only with your own account and your own data.
  • Don’t disrupt the service or anyone’s data, and don’t use spam or social engineering.
  • Give us time to fix the problem before you tell anyone else about it.

Research done in good faith that follows these guidelines isn’t a breach of our Terms of Service. We don’t promise a fixed response time or offer a reward.

The same contact details are also published in machine-readable form: security.txt