Privacy Policy
Last updated: July 16, 2026
Simple Appointments Inc. ("Simple Appointments," "we," "our," or "us") is committed to protecting the privacy and security of the personal information entrusted to us by the individuals and organizations who use our platform. This Privacy Policy describes in detail how we collect, access, use, store, share, and protect information — with particular emphasis on data obtained through integrations with Google services — in connection with your use of the Simple Appointments platform (the "Service").
1. Information We Collect
Simple Appointments collects only the minimum personal information necessary to deliver a secure, functional, and personalized experience. The categories of information we collect include:
- Account Registration Data: When you create an account — whether via direct registration or Google OAuth sign-in — we collect your email address. If you choose to provide a display name, that is optional and used solely for profile personalization.
- Google Account Identity: When you authenticate using your Google Account, we receive your verified Google email address for the purpose of securely establishing and maintaining your account identity. No other Google profile data (such as contacts, profile photo, or other personally identifiable metadata) is accessed, stored, or retained beyond the email address.
- Usage and Operational Data: We collect data you generate through your use of the Service, such as appointments scheduled, contacts added, folders created, emails sent, and call logs generated through the platform's telephony features.
- Payment Information: Subscription payments are processed by Stripe. We do not collect, store, or process raw payment card data on our servers. Stripe's handling of payment data is governed by their own privacy policy.
2. Google Services Integration — Overview
Simple Appointments integrates with several Google APIs to deliver core functionality to users who voluntarily opt in. All Google integrations are strictly opt-in and require explicit user authorization via Google's OAuth 2.0 consent flow. Each integration is scoped to the minimum permissions necessary to perform the functions described below, and no Google user data is ever accessed beyond the specific, declared purposes herein.
Simple Appointments' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Google Calendar Integration
Users may optionally connect their Google Calendar account to Simple Appointments to enable intelligent appointment scheduling. When this integration is authorized, we access the following Google Calendar data:
- Read Access — Existing Calendar Events: We query your Google Calendar events in real-time to identify scheduling conflicts and verify your availability before presenting open time slots. This prevents double-bookings and ensures accuracy in your appointment calendar.
- Write Access — Event Creation: When an appointment is successfully booked through the Simple Appointments platform — by you, a member of your team, or an authorized setter — we create a corresponding calendar event in your connected Google Calendar. This entry includes the appointment details, participants, and relevant notes.
We do not store the content of your Google Calendar events in our systems. Calendar data is queried transiently, in real-time, solely for the purposes stated above. We do not read, process, or retain calendar event details beyond what is strictly necessary for conflict detection and event creation. At no point do Simple Appointments personnel have access to your calendar content.
4. Gmail Integration — Direct Email Sending
Users may optionally connect their Gmail account to Simple Appointments to send professional emails directly from within the platform on their behalf. When this integration is authorized, we request the following Gmail access:
- Send-on-Behalf Access: We use your connected Gmail account to transmit emails that you explicitly compose and initiate within the Simple Appointments CRM interface. Emails are sent only when you take a direct action to do so — either from an individual contact card or in bulk from within a contact folder.
- Template-Based Personalization: The platform provides a template engine that allows you to define reusable email structures containing dynamic variables (e.g., recipient name, business name, address). These variables are resolved at send time and are drawn exclusively from data you have stored within the platform. Template content is never transmitted to or processed by Google; it is rendered locally within our system before being dispatched via the Gmail send API.
- Email Signature Retrieval: To ensure that emails sent through the platform maintain professional consistency, we retrieve your Gmail account's configured email signature via the Gmail Settings API. This signature is appended to outbound emails. We do not modify, store, or redistribute your Gmail signature data beyond this narrow use case, and we do not alter any Gmail account settings whatsoever.
All emails dispatched through this integration are user-initiated. Simple Appointments does not autonomously send emails through your Gmail account in the context of this standard integration. You retain full control over all email communications at all times.
5. Gmail Integration — SA Agent (Superagent) AI Email Automation
Simple Appointments offers an advanced, opt-in AI-powered email automation feature known as the "SA Agent" or "Superagent." This feature requires a separate and distinct Gmail authorization from the standard send integration described in Section 4, and must be explicitly activated by the user. When authorized, the SA Agent integration accesses the following Gmail capabilities:
Gmail Data Accessed
- Thread Content (read-only): When a prospect replies to an outbound email, we fetch the full thread using the Gmail Threads API (
threads.get). We access the message body text, headers (From, Subject, Date), and the Gmail thread ID. We access only threads that correspond to outreach emails sent through the platform to known leads. We do not read, scan, or index any other email messages in the inbox. - Sender/Recipient Metadata: We read the "From" header of inbound messages to verify that the reply originates from the expected lead email address before processing it.
- Gmail Signature: We retrieve your configured Gmail signature via
gmail.settings.basic solely to append it to outbound automated responses.
How Gmail Data Is Used
- Reply Detection: Thread content is read to identify whether a prospect has responded to a prior outreach email.
- AI Response Generation: The text of the inbound reply — along with the outreach thread context — is sent to Anthropic's Claude API solely to generate a contextually appropriate reply on the closer's behalf. Anthropic does not use API-submitted data to train its models; this is governed by Anthropic's Privacy Policy and their API Terms of Service.
- Outbound Sending: AI-generated replies are dispatched via the Gmail Send API through the closer's connected account.
- Conversation Logging: Reply text (stripped of quoted history) is stored in our database to maintain coherent conversation threading within the SA Agent workflow. This data is retained only as long as the lead exists in the system and is deleted when the lead is removed.
Scopes Requested
The SA Agent requests gmail.modify (to read reply threads and reliably compose outbound emails with correct signature formatting), gmail.send (to dispatch AI-generated replies), and gmail.settings.basic (to retrieve the email signature). The gmail.modify scope is the minimum scope necessary to ensure correct email composition and signature handling — we do not archive, label, or delete any Gmail messages at any time.
Data Transfer to Anthropic
When a prospect reply is detected, the text content of that reply (along with the outbound context from our system) is transmitted to Anthropic's API for AI response generation. This is the sole third-party transfer of Gmail-derived content. Anthropic's API Terms explicitly state that data submitted via the API is not used to train Anthropic's models. No Gmail data is transferred to any other third party.
Users may pause, disable, or fully deactivate the SA Agent at any time from their dashboard. Upon deactivation, all automated email activity ceases immediately. Users may also revoke Gmail access entirely through Google's own account permissions interface (myaccount.google.com/permissions).
Gmail data accessed through the SA Agent integration is used solely to operate the SA Agent feature as described above. This data is never used for advertising, marketing profiling, data mining, or any purpose unrelated to the SA Agent's direct operational function. Gmail data is never used to train, fine-tune, or otherwise improve any artificial intelligence or machine learning model, whether operated by Simple Appointments or any third party.
6. How Google User Data Is Used
All Google user data accessed by Simple Appointments is used exclusively for the purposes enumerated in this Privacy Policy. Specifically:
- Google Account email address → Account authentication and identification only.
- Google Calendar data → Real-time availability checking and appointment event creation only.
- Gmail send access → Dispatching user-initiated emails from the CRM only.
- Gmail signature data → Appending your signature to outbound emails only.
- Gmail read-only access (SA Agent) → Fetching reply thread content from known lead threads only, to detect prospect responses.
- Gmail send access (SA Agent) → Dispatching AI-generated replies to prospects within the SA Agent workflow only.
We do not use Google user data to build user profiles for advertising purposes, nor do we aggregate Google user data across users for any commercial purpose. We do not sell, rent, or license Google user data to any third party under any circumstances.
7. Google User Data Sharing
Simple Appointments does not share Google user data with third parties, with the following strictly limited exceptions required for operational delivery of the Service:
- Anthropic (SA Agent only): When the SA Agent detects a prospect reply, the text of that reply and the outbound thread context are transmitted to Anthropic's Claude API to generate a contextually appropriate response. Anthropic processes this data solely for inference (generating the reply) and does not use API-submitted data to train its models, as governed by Anthropic's API Terms of Service. No other email content is transmitted to Anthropic or any other AI provider.
- Infrastructure Providers: Our application is hosted on secure cloud infrastructure. Data in transit and at rest may pass through or reside on servers operated by our infrastructure provider, subject to binding data processing agreements. These providers do not have permission to access or use your data for their own purposes.
No Google user data is ever shared with advertisers, data brokers, analytics platforms, or any other third parties for commercial purposes.
8. Google User Data Storage & Protection
We implement industry-standard security measures to safeguard all data processed through the Simple Appointments platform, including Google user data:
- OAuth Token Encryption: Google OAuth access and refresh tokens are encrypted at rest within our database using strong encryption standards. These tokens are never exposed in application logs, error messages, or client-facing interfaces.
- Secure Transmission: All communications between Simple Appointments, your browser, Google's APIs, and our infrastructure are conducted over HTTPS/TLS, ensuring data is encrypted in transit.
- Principle of Least Privilege: Only the specific application processes that require access to OAuth tokens are permitted to retrieve them. No internal personnel have routine access to individual user tokens.
- No Persistent Storage of Content: Google Calendar event content and Gmail message content (outside of SA Agent conversation logs, which are stored to maintain reply context) are not persistently stored in our systems. Data is queried in real-time and discarded after use.
- No Modification of Google Account Settings: Simple Appointments does not, under any circumstances, modify the settings of any connected Google service (Google Calendar, Gmail, or any other Google product). Our platform reads from and writes to your Google data only within the explicitly scoped, user-authorized parameters described in this policy.
9. Google User Data Retention & Deletion
- OAuth Tokens: Google OAuth tokens are retained only for the duration that a user maintains an active Google service connection within Simple Appointments. Tokens are immediately and permanently deleted from our systems when a user disconnects the corresponding Google service.
- SA Agent Conversation Logs: Email conversation context stored by the SA Agent (to maintain coherent reply threading) is retained for the duration of the lead's presence in your system. When a lead is deleted or when the SA Agent is deactivated for a folder, associated conversation context is purged.
- Account Deletion: Upon deletion of your Simple Appointments account, all associated Google OAuth tokens, email conversation logs, and any other Google-derived data are permanently and irrevocably deleted from our systems within a reasonable timeframe.
- User-Initiated Disconnection: You may disconnect any Google service integration at any time from your profile settings within the Simple Appointments dashboard. You may also independently revoke access through Google's Account Permissions page (myaccount.google.com/permissions). Simple Appointments provides a direct link to this page within the dashboard for user convenience.
- Data Deletion Requests: To request deletion of your personal data, including any Google-related data retained by our systems, please contact us at carl.worthy@simpleappointments.com. We will fulfill all verified deletion requests within 30 days.
10. Third-Party Services
In addition to Google APIs, Simple Appointments integrates with the following third-party services to deliver platform functionality:
- Stripe: Payment processing for subscription billing. Stripe collects and processes payment card data directly. We do not store raw payment credentials. Governed by Stripe's Privacy Policy.
- Twilio: Telephony infrastructure for outbound calling, call recording, and SMS. Call data (phone numbers, duration, recordings) is processed by Twilio solely to facilitate communications and support billing. Governed by Twilio's Privacy Policy.
11. Limited Use Compliance
Simple Appointments' access and use of information received from Google APIs is limited to the practices disclosed in this Privacy Policy. We do not use Google user data to serve advertisements. We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes (such as investigating abuse), the use is necessary to comply with applicable law, or our use is limited to internal operations and the data has been aggregated and anonymized such that it cannot be reasonably associated with a specific user. Our use of Google user data fully complies with the Google API Services User Data Policy.
12. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right of Rectification: Request correction of inaccurate or incomplete data.
- Right of Erasure: Request deletion of your personal data, subject to our legal obligations.
- Right to Withdraw Consent: Revoke any consent-based data processing, including Google integrations, at any time without affecting the lawfulness of prior processing.
- Right to Data Portability: Request your data in a structured, machine-readable format where technically feasible.
To exercise any of these rights, contact us at carl.worthy@simpleappointments.com.
13. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this document and, where appropriate, notify affected users directly. Your continued use of the Service following such notification constitutes your acceptance of the revised Privacy Policy.
14. Contact Information
For privacy-related inquiries, data deletion requests, or questions regarding our Google API integrations, please contact: