Privacy Policy
Last updated: 2026-08-24
This Privacy Policy explains how ComingUp Today (“we”, “us”) collects, uses, and shares information when you use our website and services (the “Service”).
Privacy, in plain English
Do you sell my data?
No. ComingUp Today does not sell your personal information or household data to anyone, for any reason.
Do you sell information from my connected calendars or other services?
No. We do not sell data obtained from any connected calendar, account, or third-party service. This applies to every connected account and calendar, including work and personal calendars. This includes services such as Google Calendar and iCloud.
What information does ComingUp store?
We collect and retain only the information we need to provide and operate the ComingUp features you use. That includes showing the information you expect to see, keeping your account secure, keeping integrations working, and operating the Service reliably. We design ComingUp to minimize the information we collect and retain.
What do you do with information from connected services?
We use information from connected services to provide and operate the ComingUp features you requested, such as displaying and synchronizing your schedule. We do not sell it or use it for advertising. Connecting a service does not transfer ownership of its information to ComingUp. Provider-owned external calendar events remain externally owned and read-only in ComingUp.
What happens when I disconnect a service?
ComingUp stops retrieving new information through that connection and removes the connected credentials and locally stored provider-derived information for that connection. We attempt Google revocation where supported. Microsoft or Apple users may also need to remove ComingUp access or revoke an app-specific password through the provider’s own account controls.
What happens if I connect an AI assistant?
AI platforms receive data only when a user connects and invokes the ComingUp MCP integration. Private MCP tools require your authorization and use the ComingUp permissions you grant; supported write actions require separately granted write permissions. Merely connecting the integration does not cause ComingUp to automatically receive or store your complete AI conversation. ComingUp receives only the bounded ComingUp requests, data, and actions needed to perform what you authorize, with limited authorization, security, replay, and audit information. The AI provider handles the broader conversation under its own terms and privacy policy.
Information we collect
Information you provide
- Account information: email address and basic account settings.
- Household and workspace data: households or workspaces you create or join, members, events, lists, notes, contacts, recipes, and related settings. Information you add to a shared household is available to other household members according to their access.
- Support reports and communications: messages you send to us, private support reports submitted through the application or MCP, and sanitized diagnostic information included with those reports.
- Published Product Content: product guidance and other content submitted for publication can be made available publicly and accessed anonymously, including through the two public MCP content tools.
Information from connected services
- Connected account and integration information: account metadata and the tokens or keys required to keep each connection working.
- Calendar data you authorize: calendar list information (such as calendar name and primary/secondary status), event details needed to display your schedule (such as event time, title, and participants where provided), and availability/busy information where applicable.
- Visibility settings: which calendars you choose to show or hide inside ComingUp Today.
Information used with compatible AI assistants
- Approved ComingUp data and actions: when you explicitly authorize a compatible AI assistant connection, it may receive the connected account's name, email, and status; household name, role, timezone, and people; schedule and event details, locations, and attached contacts; lists and items; note content, tags, and people; saved contact names, emails, phone numbers, addresses, and notes; private recipe ingredients, instructions, private notes, and people; plan and feature availability; and connected calendar status.
- Permissions and ComingUp-owned writes: you authorize the connection, and ComingUp permissions govern its read and write access. Write permissions are granted separately. When you grant the applicable permissions, supported AI assistant actions can create or modify ComingUp-owned events, lists, notes, and recipes, save new ComingUp-owned contacts, and modify existing ComingUp-owned contacts.
- What we do not provide through this connection: third-party calendar provider access tokens, passwords, signing secrets, raw database IDs, and other provider credentials are excluded. Provider-owned external calendar events, including connected Google and iCloud events, remain externally owned and read-only.
- AI conversation data: ComingUp does not automatically receive or store your complete conversation merely because the integration is connected. When you invoke ComingUp, we receive the bounded requests and data needed to perform the ComingUp actions you authorize, along with limited authorization, security, replay, and audit information. The AI provider separately handles the broader conversation under its own terms and privacy policy.
- Private MCP support reports: support reports submitted through MCP are private ComingUp support records. Issue-pattern assessment does not expose other users, households, reports, diagnostics, or exact prevalence counts.
Information collected automatically
- Authentication, security, and operational data: session and authorization records, request timestamps, pages or actions, bounded error diagnostics, replay records, and audit records used to operate and secure the Service.
- Cookies and similar storage: we use cookies/local storage for authentication/session management and to support basic UI behaviors (for example, one-time notifications).
- Optional Weather settings: if you turn on local Weather, the location you choose is stored in that browser's local storage and is not shared with your household. We do not use browser geolocation for this feature. If you turn on event Weather, we use the location included with an event to request weather context for that event.
Payment information
If paid service becomes available, a third-party payment provider may process payment-card, billing, transaction, fraud-prevention, and related information. ComingUp does not need to store complete payment-card details to provide the Service.
How we use information
- Provide the Service: authenticate users, retrieve updates from connected services, show upcoming events, and enable shared views within a household or organization.
- Maintain safety and reliability: prevent abuse, debug issues, and monitor performance.
- Communicate with you: send important notices (such as security or operational updates) and respond to support requests.
- Improve the Service: understand how features are used so we can make them better.
- Provide approved AI assistant access: authenticate the connection, apply the permissions you approve, perform requested ComingUp-owned actions, and operate, secure, and audit that access.
- Provide support: receive private support reports, review sanitized diagnostics, identify broad issue patterns without exposing other users, and respond when appropriate.
How we share information
ComingUp shares information in the limited situations described below: to provide and operate the Service, follow the law, protect users and the Service, or as part of a business transfer. Sharing information to perform a feature you requested is not the same as selling it.
- Service providers: infrastructure and vendors that help us host, authenticate, store, secure, communicate about, and operate the Service. They process information for those purposes under applicable safeguards.
- Connected-service providers: when you connect a calendar, account, or other service, we exchange information with that provider as needed to keep the connection working and provide the features you requested. This includes services such as Google Calendar and iCloud.
- Weather services: when optional Weather is enabled, we may send the selected device location or an event's location to weather and location-resolution services to provide that context.
- Compatible AI assistant providers: only when you connect and invoke the ComingUp MCP integration, the approved ComingUp data and results of approved actions are shared with that assistant provider to fulfill your request. This sharing is not a sale. After transmission, that provider's handling is governed by its own terms and privacy policies.
- Payment providers: if paid service becomes available, payment and related information may be shared with a third-party payment provider to process transactions, prevent fraud, and meet its legal obligations.
- Other household members and the public: household content is shared with authorized members of that household. Product Content intentionally submitted for publication can be accessed anonymously.
- Legal and safety: to comply with law, enforce our terms, or protect the rights, safety, and security of users and the Service.
- Business transfers: if we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
ComingUp Today does not sell your personal information, household data, or information obtained from connected third-party services. We do not sell information because it is accessed through an AI assistant. We do not use information from connected services for advertising. This includes Google user data.
Data retention
Account and household content is retained while needed to provide the Service or until it is deleted through the application or an approved account-deletion request.
Temporary technical, authorization, security, replay, and audit records are generally retained for no more than 90 days. Support reports and related correspondence may be retained for up to 24 months after the last activity.
ComingUp does not create or retain separate external database exports, log archives, or backup copies. Short-lived backups and provider-controlled copies may remain temporarily under the provider’s controls. We do not use one universal retention period for every record.
Your choices
- Disconnect connected services: first disconnect a calendar, account, or other provider through ComingUp. We remove the connected credentials and locally stored provider-derived information for that connection and stop retrieving new information. Google revocation is attempted where supported. Microsoft or Apple users may also need to remove ComingUp access or revoke an app-specific password through the provider’s account controls.
- Revoke AI assistant access: review permissions during the ComingUp authorization flow, and remove ComingUp through the connected AI platform's supported connector or app controls to revoke that platform's access. ComingUp honors OAuth revocation for the connected client. After revocation, that client can no longer use the revoked authorization.
- Visibility controls: you can choose which calendars are shown or hidden within ComingUp Today.
- Access / deletion requests: request access to or deletion of your personal information by emailing us from the address associated with your account. We will verify the request before processing it.
Account deletion
When you submit a verified account-deletion request, we generally delete or de-identify personal information associated with your account from systems under our control within 30 days. Some information may be retained when necessary to preserve content shared with other household members, satisfy legal or financial obligations, prevent fraud or abuse, resolve disputes, document completion of the request, or complete deletion from backups and service providers.
Shared household content may remain available to remaining members after one account is erased, while the departing user’s private data and attribution are removed or de-identified. A sole household owner may need to transfer ownership before deletion can finish when other members remain, and the selected member must accept that transfer.
Connected calendar credentials and locally stored provider-derived information are removed when the applicable connection or account is deleted. We cannot promise immediate deletion from independent provider systems, provider-controlled backups, or legal records. Source calendar records remain controlled by their provider.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. AI assistant connections use authenticated authorization and permission checks; we use security controls intended to limit replay and retain authorization and write-action audit records for security and audit purposes. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
International users
We may process and store information in countries other than where you live. Those countries may have different data protection laws.
Children
The Service is not intended for children under 13 (or under the age required by your jurisdiction). If you believe a child has provided us personal information, contact us.
Changes to this policy
We may update this policy from time to time. We will update the “Last updated” date and, if changes are material, take reasonable steps to notify you.
Contact
If you have questions, need support, or want to request account deletion, contact us at support@comingup.today.
This page is provided for general informational purposes and is not legal advice.