Attaché is a calendar app made by Snizyx Software LLC (“Snizyx”, “we”, “us”), based in Nashville, Tennessee. It brings Google Calendar, Microsoft 365, Outlook.com and Zoho Calendar into one view and lets you give other people, your delegates, carefully limited access to your calendars. This policy explains what information we collect, how we use and share it, how long we keep it and the choices you have. It covers the Attaché web app at app.tryattache.com, the Attaché desktop apps and this website, tryattache.com.
The short version
- We use your calendar data only to run Attaché for you and the delegates you choose.
- We never sell your data, never use it for advertising and never use it to train generalized AI or machine-learning models.
- Delegates never get your Google, Microsoft or Zoho passwords, and your calendar access tokens are encrypted with AWS KMS.
- You can export or delete your data at any time.
1. Information we collect
Account information
When you create an account we collect your name, email address and sign-in details, such as the identifier your sign-in provider gives us if you sign in with Google, Microsoft or Apple, or the public key of a passkey you register. We also store your settings, such as your time zone, calendar colors and notification preferences.
Connected calendar accounts
When you connect a Google, Microsoft or Zoho account, you sign in on that provider’s own page and grant Attaché access. We never see or store your password for that account. We receive and store:
- the email address or name of the connected account, so you can tell your accounts apart;
- OAuth access and refresh tokens that let Attaché reach your calendars on your behalf. Refresh tokens are encrypted with AWS Key Management Service (KMS) envelope encryption before they are stored. Provider tokens are never sent to your browser, your devices or your delegates.
Calendar data
To show and manage your calendars, we copy from the calendars you connect:
- the list of calendars: names, colors, time zones and your access level; and
- events on those calendars: titles, dates and times, locations, descriptions, attendees and their responses, organizers, conferencing links, recurrence rules, categories and whether an event is marked private.
We keep a cached copy of events within a rolling window of about 6 months in the past and 18 months in the future, so Attaché can show your calendars quickly. Events that fall outside that window are removed from our cache.
Delegation data
When you invite a delegate we store their email address, the permissions you grant them for each calendar, any expiry date you set and the status of the invitation. When a delegate proposes a change, we store the proposal and your decision. If you are a delegate, the owner who invited you can see your name, your email address and the actions you take in their calendars.
Audit log
Attaché records the actions taken in your calendars through Attaché, by you or by your delegates, in an audit log: who acted, what they did, when, and copies of the event before and after the change so that it can be undone.
Billing information
If you subscribe to Pro, your payment is handled by Stripe (for purchases on the web or in our direct-download apps) or by Apple (for App Store purchases). We never receive or store your full card number. We store billing identifiers, such as customer, subscription and transaction IDs, together with your plan, its status and its renewal dates.
Device, log and usage information
Our servers record technical information when you use Attaché, such as your IP address, browser or device type, app version and the time and outcome of each request. We use it to keep the service secure and reliable. If you turn on notifications, we store the push subscription or device token needed to deliver them.
If enabled, crash reporting sends us technical details about an error and the device it happened on; we configure it not to collect calendar content. If enabled, a cookieless analytics service counts page views and feature use in aggregate, without cookies or tracking you across other sites.
Communications
If you email us, we keep your message and our reply so we can help you. Email sent to our @tryattache.com addresses is received by Amazon SES, which stores the raw message in AWS for 30 days, and is forwarded to the mailbox our team uses to read and answer it. If you join the waitlist, we use your email address only to tell you when Attaché is available, and we delete it when you ask.
Cookies
The Attaché app uses cookies, or similar storage in your browser or app, only where they are strictly necessary to keep you signed in and secure. We don’t use advertising cookies or cross-site tracking. This website, tryattache.com, does not set cookies.
2. How we use information
We use the information described above to:
- provide Attaché: show your calendars together, keep them in sync with your providers, and create, change or delete events when you, or a delegate acting within the permissions you set, ask us to;
- apply each delegate’s permissions, filters and approval rules, so that they see and do only what you allow;
- send service messages, such as sign-in links, invitations, proposal and approval notifications, security alerts and billing notices;
- keep Attaché secure, prevent abuse and investigate problems;
- help you when you contact us;
- manage subscriptions and billing;
- comply with the law and enforce our terms of service; and
- understand and improve Attaché using aggregated usage information that does not include the content of your calendars.
We don’t sell personal information, we don’t use it for advertising and we don’t share it for cross-context behavioral advertising. We don’t use calendar data to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.
3. Google user data
This section explains how Attaché handles information it receives from Google APIs (“Google user data”).
What we access
With your permission, Attaché uses Google’s APIs to:
-
sign you in with Google, if you choose to: your name, email address and profile picture
(the
openid,emailandprofilescopes); -
read the list of calendars in your Google account (
calendar.calendarlist.readonly); and -
read, create, change and delete events on the calendars you connect (
calendar.events), when you, or a delegate acting within the permissions you set, ask Attaché to.
How we use it
We use Google user data only to provide and improve Attaché’s user-facing features: showing your Google calendars alongside your others, keeping them in sync, making the changes that you or your authorized delegates request and showing each delegate the parts of your calendars you have chosen to share.
How we share it
We share Google user data only:
- with the delegates you invite, limited to the calendars and details your permissions allow. This is the core feature you control, and you can change or revoke it at any time;
- with Amazon Web Services, which hosts Attaché’s servers, database and backups for us;
- when necessary for security purposes, such as investigating abuse;
- to comply with applicable law; or
- as part of a merger, acquisition or sale of assets of Snizyx, and only after obtaining your explicit prior consent.
Limited Use
Attaché’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We do not use Google user data for advertising, including retargeting and personalized or interest-based advertising.
- We do not sell Google user data, or transfer it to advertising platforms, data brokers or other information resellers.
- We do not use Google user data to determine credit-worthiness or for lending purposes.
- We do not use Google user data, including data obtained through Google Workspace APIs such as the Google Calendar API, to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.
- People at Snizyx do not read your Google user data unless you have given us your explicit agreement to view specific data (for example, a particular event you ask us to look at while helping you), it is necessary for security purposes such as investigating a bug or abuse, or it is necessary to comply with applicable law.
- Everyone who works on Attaché, including our contractors and agents, and any successor to our business, must follow these commitments.
Removing access
You can disconnect a Google account in Attaché’s settings at any time, or remove Attaché’s access from your Google Account at myaccount.google.com/permissions. When you disconnect, we revoke our token with Google, stop syncing and delete the calendar data we cached from that account.
4. Microsoft and Zoho data
We apply the same rules to calendar data from Microsoft 365 and Outlook.com (through Microsoft Graph) and from Zoho Calendar. We use it only to provide Attaché’s features to you and the delegates you authorize. We don’t sell it, use it for advertising or use it to train generalized AI or machine-learning models, we transfer it only in the circumstances listed for Google user data above, and people at Snizyx don’t read it except with your explicit agreement, for security purposes or to comply with the law. Microsoft’s and Zoho’s own terms and privacy policies continue to apply to your accounts with them, and you can also remove Attaché’s access from your Microsoft or Zoho account settings.
5. What delegates can see
- Delegates see only what your per-calendar permissions allow: free/busy, titles only or full details, minus anything your private, keyword or category filters hide.
- Permissions are enforced on our servers before any data is sent, so a delegate’s app never receives details you haven’t shared.
- Delegates never receive your provider passwords or tokens.
- Everything a delegate does in your calendars is recorded in your audit log.
- You can change or revoke a delegate’s access at any time.
6. How we share information
We don’t sell personal information. We share it only as follows:
- With delegates you invite, as described above.
- With the calendar providers you connect. When you or a delegate make a change, we send it to Google, Microsoft or Zoho so that your calendar is updated. Their privacy policies govern what they do with it.
- With service providers that help us run Attaché, under contracts that limit their use of your information to providing their service to us:
| Provider | What they do for us | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, file storage, encryption keys (AWS KMS) and email delivery (Amazon SES) | United States (us-east-2, Ohio) |
| Stripe, Inc. | Payments for purchases on the web and in our direct-download apps | United States |
| Apple Inc. | Payments for App Store purchases (Apple acts as the seller under its own privacy policy) | United States |
| Crash reporting provider, if enabled | Error diagnostics for our apps, without calendar content | Named here before it is enabled |
| Cookieless analytics provider, if enabled | Aggregate page and feature usage, without cookies or cross-site tracking | Named here before it is enabled |
| The mailbox provider our team uses | Receiving and answering the email you send us | Named here before publication |
| Your browser’s or device’s push service (for example Apple, Google, Microsoft or Mozilla) | Delivering the notifications you turn on | Depends on your browser or device |
- For security and legal reasons: when necessary to investigate abuse or protect the security of Attaché and its users, or when required by law, such as a valid subpoena or court order.
- In a business transfer: if Snizyx is involved in a merger, acquisition or sale of assets, and, for calendar data from any provider, only after obtaining your explicit prior consent.
7. Where we store data
Attaché’s servers and data are hosted by Amazon Web Services in the United States (the us-east-2 region, in Ohio). If you use Attaché from outside the United States, your information is transferred to and processed in the United States.
8. Security
We protect your information with measures that include KMS envelope encryption of provider tokens, TLS encryption in transit, encryption at rest for our database and backups, least-privilege access controls and an append-only audit log. No system is perfectly secure; if a breach affects your information, we will notify you as the law requires. Our security page has the details.
9. Retention and deletion
- Cached calendar events are kept within a rolling window of about 6 months in the past and 18 months in the future.
- Audit log entries are kept for 12 months by default, then deleted.
- Server logs are kept for about 30 days.
- Email you send us: the raw copy received by Amazon SES is deleted after 30 days; the forwarded copy stays in our team mailbox for as long as we need it to help you.
- Disconnecting a calendar account revokes Attaché’s access token with the provider where the provider supports revocation, stops syncing and deletes the tokens and the calendar data we cached from that account.
- Revoking a delegate ends their access to your calendars. The actions they took stay in your audit log until those entries expire.
- Deleting your account revokes our access to your connected accounts where the provider supports it and deletes your account and calendar data from our systems within 30 days. Copies in our encrypted backups are deleted as those backups expire, within a further 35 days. We keep limited records longer only where the law requires it, such as billing records for tax purposes.
10. Your rights and choices
You can:
- access and export your data, including your calendar data in portable formats;
- correct your account information in settings, or ask us to correct it;
- delete your account, disconnect any calendar account or revoke any delegate at any time; and
- withdraw the access you gave Attaché to a calendar account by disconnecting it in Attaché or in that provider’s account settings.
Depending on where you live you may have further rights, for example under the GDPR in the European Economic Area and the United Kingdom, or under US state privacy laws such as California’s. They can include the right to object to or restrict some processing and to complain to your local data protection authority. Where the GDPR applies, we process your information to provide Attaché under our contract with you, for our legitimate interests in keeping it secure and improving it (without using the content of your calendars), to meet legal obligations, and with your consent when you connect a calendar account, which you can withdraw at any time by disconnecting it.
To exercise any of these rights, email privacy@tryattache.com. We will verify your request and respond within 30 days, or sooner where the law requires. We won’t treat you differently for exercising your rights.
11. Children
Attaché is not directed to children under 13, and we don’t knowingly collect personal information from children under 13. If you believe a child under 13 has given us personal information, email privacy@tryattache.com and we will delete it.
12. Changes to this policy
We will post any changes to this policy on this page and update the effective date. If we make a material change, we will tell you by email or in the app before it takes effect, and we will ask for your consent before using your information in a new way where the law or the Google API Services User Data Policy requires it.
13. Contact us
Snizyx Software LLC
Nashville, Tennessee, United States
privacy@tryattache.com