Privacy Policy
Last updated: 17 June 2026
This policy explains how Zeitgeist Mesh ("we", "the platform") handles your information across all of its apps, with particular attention to data accessed through third-party APIs such as Google.
Information we access
- Account identity — when you sign in (including via Google sign-in), your email address and basic profile, used solely to identify your account.
- Content you create — the plans, notes, time blocks, logs and other data you create within the apps, stored in your own account.
- Connected services (only what you link) — connecting any external account is optional, initiated by you, and we access only the data needed for that feature, with your explicit consent:
- Google Calendar — the read-only scope
https://www.googleapis.com/auth/calendar.readonly, used to (a) list the names of your calendars so you can choose one, and (b) read the title, start time, and end time of timed events in the calendar you select, so they can be imported as time blocks. We never create, edit, or delete anything in your Google Calendar.
- Wearables / health (e.g. Garmin) — with your consent, your readiness/energy and activity metrics, so they can be shown alongside your own data and used by features you enable.
- Bank accounts (Open Banking) — with your consent, read-only access to account and transaction information for the accounts you choose to link. We do not initiate payments or move money.
How we use your data
We use your data solely to provide the features you ask for — for example, importing your selected calendar's events into your schedule, or showing your readiness alongside your plans.
AI / assistant features. Some apps use AI to help you — for example turning your notes into a structured plan. When you use such a feature, the content you submit to it (such as your notes or plan text) is sent to a large language model, which may be operated by a third-party AI provider, solely to generate the result you asked for. Data from connected services — including Google Calendar data — is never sent to any AI feature or AI provider.
We do not use your data for advertising, we do not sell it, and we do not use it to train generalized AI/ML models.
Security — how we protect your data
- Encryption at rest. All third-party authorization tokens and credentials (Google, wearables, bank connections, AI provider keys) are encrypted with AES-256-GCM (256-bit authenticated encryption) — never stored in plaintext.
- Per-account isolation. Your content, connections and imported data are protected by database row-level security keyed to your identity; one account can never read another's data, even internally.
- Read-only external access. Where we read from a connected account (Open Banking, Google Calendar), access is read-only — we cannot move money, and we never create, edit or delete anything in your external accounts.
- Regulated / official providers. External connections are made only through official or regulated providers (for example FCA-authorised Open Banking Account Information Service Providers, and Google OAuth) using their own hosted consent screens — you enter your credentials on the provider's site, never on ours.
- Scoped, expiring consent. You authorise exactly what is shared; consent is scoped to that data and time-limited (Open Banking consents typically last ~90 days), and we never silently renew it.
- Encrypted transport & authenticated access. All traffic is served over HTTPS with HSTS, and access requires a signed-in OpenID Connect session.
- Immediate deletion on disconnect. Disconnecting a service deletes its stored tokens and the data imported from it straight away.
Sharing
We do not sell your personal data or share it with third parties for their own purposes. We share it only with the service providers that help us operate the platform — for example secure hosting we run, our Open Banking data provider, our payment processor, and the AI provider(s) that power assistant features — and only as needed to deliver the service you asked for, or where required by law.
Google user data is used only to provide the Google Calendar import feature; it is not shared with any AI provider or any other third party.
Some apps let you create an explicit, revocable public share link for a specific item you choose; only that item is then viewable, and your identity is not shown.
Workspaces
Outside of shared workspaces, your data is private to you. If you create or join a shared workspace (team), data in that workspace is visible to its members according to the access you grant them; you can change or remove that access.
Payments
Paid plans are processed by a third-party payment provider (Stripe). Your card details are handled by that provider and are not stored by us; we keep only the subscription status needed to provide your plan.
Retention and deletion
- You can disconnect any connected service (Google Calendar, a wearable, or a bank) at any time; this immediately deletes the stored authorization tokens and stops further access.
- You may also revoke Google access directly at myaccount.google.com/permissions.
- Content you create is yours to delete from within the apps, and you may request deletion of your account and all of its data.
Limited Use disclosure
Zeitgeist Mesh's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about this policy or your data: raise them through our feedback hub.