Privacy Policy
Effective July 28, 2026
In short: WhenWhen stores what a scheduling poll needs and deletes it on a schedule. No ads, no trackers, and we do not sell your personal data. Third-party code runs in your browser in two places: the anti-bot check when you create an event, and Paddle's checkout if you buy a paid subscription.
WhenWhen is operated by Red Ninja LLC, a Minnesota limited liability company ("Red Ninja", "we", "us"). This policy explains what data the service at whenwhen.io handles and why.
What we collect
- Event data - the titles, descriptions, locations, and proposed times that organizers enter.
- Participant data - the name a participant enters with their votes, and an email address if one is provided. The address itself is never shown to anyone, we never use it for marketing, and it is deleted with the event.
- Account data - accounts are optional; nobody needs one to create, vote in, or finalize an event. If you make one, sign-in is handled by our identity provider, and we store the account identifier it hands back, which plan you are on, and when the account was created. We never store your email address for your account. It stays with the identity provider, and in your own browser so the site can show who is signed in. The one place an account holder's email address is stored on our side is a support ticket.
- API tokens - if you create a token so software can make events on your behalf, we store the name you gave it, a one-way hash of the token, its last four characters, when it was created, and when it last created an event. We cannot recover the token itself, which is why it is shown only once.
- Support requests - your message and its subject, the email address you give us for replies, and diagnostics: your account identifier, plan, active event count, and browser User-Agent. Filing a request also sends a notification email with the same details to our support mailbox.
- Abuse reports - if you report an event, we store the event's identifier, the reason you picked, and anything you type in the description. We ask for no contact details and none are stored, so we cannot reply to a report.
- Technical data - IP addresses are used for rate limiting and abuse prevention, including the anti-bot check on event creation. Records that include an IP address are short-lived and purged automatically, and none of them is attached to your events or votes. For usage statistics we record a country code derived from the connection, never the address.
Who can see what
A scheduling poll is a shared page. Anyone with an event's share link sees the event details, every participant's name, and their votes - that is what the link is for, and whoever the organizer shares it with sees them too. If you would rather not be recognizable, you can vote under any name you like. An email address left with a vote is never exposed through any page or API response, and admin and edit links are never revealed to anyone who does not already hold them.
Cookies and your browser
There is no cookie banner because nothing we place in your browser tracks you. We set two cookies, both for sign-in: __Host-ww_session keeps you signed in for 30 days, and __Host-ww_auth_state protects the sign-in handshake and lasts only minutes. Neither is set unless you use sign-in.
Your browser's localStorage keeps the links to events you created and votes you cast, so you can get back to them, and - if you sign in - your email address, so the site can show who is signed in. These stay on your device; our database holds no copy of the email unless you submit it yourself, for example as the reply address on a support request. The anti-bot widget on the create page is Cloudflare's code, and any state it keeps is Cloudflare's, used to tell humans from bots.
Usage statistics
We count usage with aggregate counters recorded on the server. No analytics script runs in your browser, and no identifier is recorded - no account id, token, event id, name, email address, or IP address - so a count can never be tied back to a person. A counted page view records the type of page (never which event), the hostname of the referring site, campaign tags if the link carried them, a country code, and whether a sign-in cookie was attached. The cookie's value is never recorded, only that one was present. A counted action records what kind of thing happened, on which tier, whether the request was anonymous, signed in, or made with an API token, and the campaign tag of the page you came from. Where a count could be specific enough to pick out a single event, we record a range in place of the number. We also count what serving a page of event data costs us: the type of request, how many database rows it read, and how many bytes we sent back. Our host keeps these counters for about three months.
What we do not do
- No advertising, no third-party trackers, and no analytics scripts in your browser.
- We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
- We do not use email addresses collected by the service for marketing.
Service providers
These companies process data to run the service, on our instructions:
- Cloudflare, Inc. (USA) - hosts the application and the database, runs the anti-bot check and the usage counters, and routes inbound support email. Data may be processed across Cloudflare's global network.
- WorkOS, Inc. (USA) - runs sign-in for optional accounts, including sending the sign-in code emails itself. WorkOS holds your account email address; we deliberately do not. If you never create an account, WorkOS never sees you.
- Resend, Inc. (USA) - delivers the email the service sends. Today that is the notification to our own support mailbox when you file a support request.
Independent of us, each under its own privacy policy:
- Paddle - paid subscriptions are sold by Paddle.com as merchant of record. Paddle holds your payment details; we never see your full card number. The checkout page runs Paddle's code.
- Google or GitHub - if you pick one of them to sign in with, the sign-in happens with that provider, and it will know you use WhenWhen.
- Our support mailbox - support email is answered from a standard Gmail mailbox we operate, so messages you send us come to rest there like ordinary email.
Where data goes
Our providers are in the United States, so using the service moves personal data there. Where EU or UK law applies to a transfer, we rely on recognized safeguards: our providers participate in the EU-US Data Privacy Framework or offer the European Commission's Standard Contractual Clauses, as set out in each provider's own privacy documentation.
Our legal bases
Where the law where you live - the EU and UK among them - requires a legal basis for each use of personal data, ours are these. Event, participant, account, API-token, and support data: providing the service you asked for. Rate limiting, the anti-bot check, and the aggregate usage counters: our legitimate interest in keeping the service working and free of abuse. An email address you choose to leave with a vote: consent, which you can withdraw by asking us to remove it. And we process data where a law requires us to.
How long we keep data
- Events - with their options, participant names, any email addresses left with votes, and votes - are deleted by a daily sweep. While no time has been picked, that is 30 days after the event expires, or 30 days after its last proposed time if that is later. Once a time has been picked, it is 30 days after the time that was picked, so the finalized page and its calendar file outlive the meeting and are then removed, which on a long lifetime happens well before the event would have expired. Picking a time that has already passed still leaves 30 days from the moment it was picked. Lifetimes by tier: an Instant event expires 10 days after creation, a free account event after 30 days, a Pro event after a year.
- Sign-in sessions last 30 days. API tokens last until you revoke them or delete your account.
- Support tickets are kept while open and deleted no later than 90 days after we close them.
- Abuse reports are kept while open and deleted no later than 90 days after we finish with them. The event a report names follows its own schedule above, so a report often outlives the event it was about.
- Short-lived technical records - rate-limit counters and duplicate-request protection - are purged automatically within days.
- Usage counters are kept for about three months, as described above.
- Deleted rows can persist for a limited time in our infrastructure provider's automatic backups, and in the database exports we take so the service can be restored after a failure. We keep about two weeks of those exports and use them for nothing else.
Deleting data
Organizers can delete an event at any time from its admin page, which removes the event, its participants, and their votes from the live database immediately. Deleting your account removes the account record, every session, and every API token immediately, and removes your reply address from your stored support tickets. Events you created are not deleted with the account - other people may be mid-vote - but they stop being linked to you and age out on their normal schedule. Notification emails already sent still exist in our support mailbox.
Your rights
To access, correct, or delete personal data, email support@whenwhen.io. You do not need an account, and we do not ask for identity documents for routine requests - we verify you through what you already hold: an edit link, an admin link, or the email address a record carries. If someone else entered your email address into the service, write to us from that address and we will remove it. Depending on where you live you may have statutory rights to access, correct, delete, or object, and to complain to your local data-protection authority. We honor reasonable requests wherever you live.
Children
The service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
Updates are posted here with a new effective date, and we give notice on the site before a material change. Changes work forward: we will not use data we already collected in a way this policy did not allow when we collected it, unless we ask you first.
Contact
Red Ninja LLC, Minnesota, USA · support@whenwhen.io