ATOL PRIVACY POLICY

EFFECTIVE 2026.09.17

01 OPERATOR

ATOL is operated by Beesa Ltd ("we", "us"). Questions about this policy or about data held about you go to info@atol.co.

02 WHAT WE COLLECT

Account data: the email address you use to sign in to ATOL, and the tasks, calendar entries and notes you write in ATOL.

Google Calendar data, only when you choose to link a Google account. We store the email address and the Google account identifier of the account you link — which is not necessarily the address you sign in to ATOL with — together with the list of calendars on it.

For events on the calendars you switch on, we store the complete event record as Google returns it, and we keep it in full rather than only the fields ATOL displays. That record includes the title, start and end times, time zone, attendees, the organizer's email address, your RSVP status, location, description, recurrence rules, the event's link on Google, its status, and the identifiers Google uses for the event and its series.

This access is read-only. ATOL never creates, edits or deletes anything on a linked Google Calendar.

03 WHY WE COLLECT IT

Account data is used to operate your ledger. Google Calendar data is used for one purpose: to display your own events inside your own ledger so that you can triage them by hand into tasks and entries. It is not used for advertising, profiling, or training machine-learning models.

04 WHERE IT IS STORED

All data is stored in our Supabase database, where row-level security scopes each account's data to that account. There are two exceptions: an administrator account operated by Beesa Ltd can read and write records in any account, including notes and attachments; and a task you share by public link, together with its notes and attachments, can be read by anyone holding that link.

The Google Calendar import tables carry no administrator bypass. Every access rule on them is scoped to the owning account.

Google OAuth refresh tokens are encrypted in Supabase Vault and are read only by our server routes. Short-lived Google access tokens are held in memory for the duration of a request and are never written to storage.

05 SHARING

We do not sell your data and we do not share it with third parties. It is not transferred to anyone other than the infrastructure providers that host the service on our behalf.

06 GOOGLE LIMITED USE

ATOL's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

07 RETENTION

Imported calendar events are kept until your account is deleted. When you unlink a Google account, its stored refresh token is deleted immediately and no further data is read from that account.

08 REVOKING ACCESS

You can unlink a Google account inside ATOL at any time. You can also revoke ATOL's access from your Google account permissions page at myaccount.google.com/permissions. To have your ATOL account and its data deleted, write to info@atol.co.

09 CHANGES

If this policy changes, the revised version is published on this page with a new effective date.