Privacy Policy
Effective August 5, 2026
In short: WhenWhen stores what a scheduling poll needs and deletes it on a schedule. No ads, no trackers, and we do not sell your personal data. Third-party code runs in your browser in two places: the anti-bot check when you create an event, and Paddle's checkout if you buy a paid subscription.
WhenWhen is operated by Red Ninja LLC, a Minnesota limited liability company ("Red Ninja", "we", "us"). This policy explains what data the service at whenwhen.io handles and why.
What we collect
- Event data - the titles, descriptions, locations, and proposed times that organizers enter.
- Participant data - the name a participant enters with their votes, and an email address if one is provided. We use the address for two things: sending that person their private edit link, and telling them when a time is picked. The address is never shown to anyone, is never used for marketing, and is deleted with the event.
- Account data - accounts are optional; nobody needs one to create, vote in, or finalize an event. If you make one, sign-in is handled by our identity provider, and we store the account identifier it hands back, which plan you are on, and when the account was created. We never store your email address for your account. It stays with the identity provider, and in your own browser so the site can show who is signed in. When we email you about an event you organized, we ask the identity provider for your address at that moment and keep no copy. If you unsubscribe from our email we also keep a one-way fingerprint of the address, described under How long we keep data.
- API tokens - if you create a token, we store the name you gave it, a one-way hash of the token, its last four characters, when it was created, and when it last created an event. We cannot recover the token itself, which is why it is shown only once.
- Support requests - your message and its subject, the email address you give us for replies, and diagnostics about your account (plan, active event count) and browser. Filing a request opens a ticket in our helpdesk, which emails you to confirm it arrived. If the helpdesk cannot be reached, a notification with the same details goes to our support mailbox instead.
- Abuse reports - the event's identifier, the reason you picked, and anything you type in the description. No contact details are asked for or stored, so we cannot reply to a report.
- Technical data - IP addresses are used for rate limiting and abuse prevention, including the anti-bot check on event creation. Records that include an IP address are short-lived and purged automatically, and none of them is attached to your events or votes. For usage statistics we record a country code derived from the connection, never the address.
Who can see what
A scheduling poll is a shared page. Anyone with an event's share link sees the event details, every participant's name, and their votes - that is what the link is for. If you would rather not be recognizable, you can vote under any name you like. An email address left with a vote is never exposed through any page or API response, and admin and edit links are never revealed to anyone who does not already hold them.
Email we send
The service sends four kinds of email, each to someone it already has a reason to write to:
- To an organizer with an account, when their event is created: the links to that event.
- To an organizer with an account, once a day at most: a summary of the votes cast on their events since the last one. A day with no votes sends nothing.
- To a participant who gave an address, when they vote: their private edit link.
- To a participant who gave an address, when the organizer picks a time: the time that was picked.
A message to a participant carries two ways out. One stops email about that event, by deleting the address we were using for it. The other stops all email from WhenWhen, now and later; to keep not emailing you we remember that you asked, as the one-way fingerprint described under How long we keep data. A message to an organizer carries the all-email link. The unsubscribe button built into your email program stops everything. Unsubscribing costs you no access: the links you hold keep working either way.
If you have an account you can turn all email off and back on from your account page. If you have no account and want email again, write to us.
Cookies and your browser
There is no cookie banner because nothing we place in your browser tracks you. We set two cookies, both for sign-in: __Host-ww_session keeps you signed in for 30 days, and __Host-ww_auth_state protects the sign-in handshake and lasts only minutes. Neither is set unless you use sign-in.
Your browser's localStorage keeps the links to events you created and votes you cast, and - if you sign in - your email address, so the site can show who is signed in. Your dashboard reads those stored links to list the events you created. These stay on your device. The anti-bot widget on the create page is Cloudflare's code, and any state it keeps is Cloudflare's, used to tell humans from bots.
Usage statistics
We count usage with aggregate counters recorded on the server. No analytics script runs in your browser, and no identifier is recorded - no account id, token, event id, name, email address, or IP address - so a count can never be tied back to a person. Counters record things like the type of page viewed (never which event), the hostname of the referring site, campaign tags if the link carried them, a country code, and what kind of action happened on which tier. Our host keeps these counters for about three months.
What we do not do
- No advertising, no third-party trackers, and no analytics scripts in your browser.
- We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
- No other party collects data about your activity over time and across other sites through the service, outside the two third-party scripts described under Service providers.
- We do not use email addresses collected by the service for marketing.
Service providers
These companies process data to run the service, on our instructions:
- Cloudflare, Inc. (USA) - hosts the application and the database, runs the anti-bot check and the usage counters, and delivers and routes the email the service sends and receives. Data may be processed across Cloudflare's global network.
- WorkOS, Inc. (USA) - runs sign-in for optional accounts and holds your account email address. If you never create an account, WorkOS never sees you.
- Zoho Corporation (USA) - runs the helpdesk we answer support requests in. Your message and reply address are filed there so we can respond.
Independent of us, each under its own privacy policy:
- Paddle - paid subscriptions are sold by Paddle.com as merchant of record. Paddle holds your payment details; we never see your full card number. The checkout page runs Paddle's code.
- Google or GitHub - if you pick one of them to sign in with, the sign-in happens with that provider, and it will know you use WhenWhen.
- Our support mailbox - support email is answered from a mailbox we operate, so messages you send us come to rest there like ordinary email.
Where data goes
Our providers are in the United States, so using the service moves personal data there. Where the law where you live restricts such transfers, our providers offer recognized safeguards, set out in each provider's own privacy documentation.
How long we keep data
- Events - with their options, participant names, any email addresses left with votes, and votes - are deleted by a daily sweep 30 days after they end. While no time has been picked, an event ends when voting closes: once its last proposed time has passed. Once a time has been picked, the 30 days run from the time that was picked. Picking a time that has already passed still leaves 30 days from the moment it was picked.
- Sign-in sessions last 30 days. API tokens last until you revoke them or delete your account.
- A support request is deleted from our own database no later than 90 days after you send it; the message, its subject, and the reply address leave that database sooner, once our helpdesk provider confirms it has the request. The helpdesk holds the conversation after that, and we delete tickets there once we no longer need them.
- Abuse reports are kept while open and deleted no later than 90 days after we finish with them.
- Short-lived technical records - rate-limit counters and duplicate-request protection - are purged automatically within days.
- Usage counters are kept for about three months, as described above.
- Deleted rows can persist for a limited time in our infrastructure provider's automatic backups, and in the database exports we take so the service can be restored after a failure. We keep about two weeks of those exports and use them for nothing else.
- If you unsubscribe from our email, we keep a one-way fingerprint of your address for as long as the service runs, so that we can keep not emailing you. It cannot be turned back into your address, though someone holding both our secret key and a list of addresses to test could check whether one of them is on the list, so we treat it as personal data rather than as anonymous data. We use it for nothing else. Ask us and we will delete it, which means we could email you again.
- Our email provider keeps a delivery record of each message we send, so we can tell whether it arrived.
Deleting data
Organizers can delete an event at any time from its admin page, which removes the event, its participants, and their votes from the live database immediately. Deleting your account removes the account record, every session, and every API token immediately, and clears any reply address our database still holds with one of your support requests. The helpdesk keeps your support history filed under the address you gave for replies; ask us and we will delete it. Events you created are not deleted with the account - other people may be mid-vote - but they stop being linked to you and age out on their normal schedule. Deleting an event does not unsend email the service already sent about it.
Your rights
To access, correct, or delete personal data, email support@whenwhen.io. You do not need an account - we verify you through what you already hold: an edit link, an admin link, or the email address a record carries. If someone else entered your email address into the service, use the unsubscribe link in the message you received to stop all WhenWhen email: no more will be sent to that address, and what we keep to enforce that is the one-way fingerprint described under How long we keep data, never the address itself. Depending on where you live you may have statutory rights to access, correct, delete, or object, and to complain to your local data-protection authority.
Children
The service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
Updates are posted here with a new effective date. Changes work forward: we will not use data we already collected in a way this policy did not allow when we collected it, unless we ask you first.
Contact
Red Ninja LLC, Minnesota, USA · support@whenwhen.io