← FIND TIMEPRIVACY POLICY
LAST UPDATED 9 SEPTEMBER 2026
This policy explains what personal data Find Time collects, why, who it is shared with, and the rights you have under the GDPR. It covers the marketing site, the waitlist, and the Find Time web app.
1. Who is responsible
Find Time is operated by the individual trading as Lexora. For any privacy question or to exercise a right below, contact privacy@findtime.ai.
If the operating entity is based in Germany, a separate Impressum is published as required by §5 DDG.
2. What we collect
Waitlist: your email address, the page the sign-up came from (a short "source" label), and a salted, irreversible hash of your IP address used only for spam and rate-limit protection. Your raw IP is not stored.
Account: when you sign in, identity and session data are handled by our authentication provider (Clerk) — typically your email address and name. We keep a minimal mirror of your Clerk user id, email and name so the app can attach your calendars and events to you.
Google Calendar (optional): if you connect a Google account, we request read-only access to your calendars and store the events we read, plus encrypted OAuth tokens. We never request write access without asking.
AI scheduling: the text you type into "Ask Find Time" is sent to our AI provider (Anthropic) together with the busy/free times needed to place a block. We do not send event titles or descriptions beyond what the request needs.
Operational logs: standard security and error logs (timestamps, coarse request metadata) generated by our host.
3. Why we can process it (legal bases)
Waitlist — your consent (Art. 6(1)(a)). You can withdraw it any time by asking us to remove your email.
Running the app for you — performance of a contract (Art. 6(1)(b)).
Spam prevention, rate limiting and security logging — our legitimate interest in keeping the service available and abuse-free (Art. 6(1)(f)).
Connecting Google Calendar — your consent, given through Google’s own permission screen.
4. Processors we use
Clerk — authentication and session management.
Neon — managed PostgreSQL database (EU region).
Google — Calendar API, only when you connect an account.
Anthropic — processes the scheduling prompt to produce a structured request.
Railway — application hosting and infrastructure logs.
Each acts as a processor under a data-processing agreement and only on our instructions.
5. How long we keep it
Waitlist entries: until launch invitations are complete or you ask for removal, whichever is first.
Account and calendar data: for as long as your account exists. Deleting your account removes your user row and cascades to your profile, connected accounts, calendars and events; associated Clerk data is deleted too.
Rate-limit counters: rolling, cleared automatically after about two days.
Logs: retained for a short period by our host for security and debugging.
6. International transfers
Data is stored in the EU where possible (Neon EU region). Some processors (Google, Anthropic, Clerk) may process data outside the EU under Standard Contractual Clauses or an adequacy decision.
7. Your rights
You have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. Where processing is based on consent, you can withdraw it at any time.
To exercise any of these, email privacy@findtime.ai. You also have the right to lodge a complaint with your local data protection supervisory authority.
8. Cookies
The site sets only strictly necessary cookies: your sign-in session and security tokens. There are no analytics, advertising or tracking cookies. If that changes, this policy and the cookie notice will be updated and consent asked for first.
9. Changes
We may update this policy as the product changes. The date at the top reflects the last revision (currently 9 September 2026).