Privacy Policy
Foyer is a personal productivity application operated by Max Riunge (“we”, “us”). It is a private, invite-only tool: accounts are created for a small number of named individuals rather than offered to the public. This policy explains what data Foyer holds, why it holds it, and how you can remove it.
Questions about anything below can go to riungemaina@gmail.com.
Data we collect
Account information
You sign in with Google. We receive and store your Google account identifier, email address, display name, and profile picture URL. We never receive or store your Google password.
Google Calendar data
Connecting a Google account to Foyer’s calendar feature is optional and separate from signing in. If you connect one, we request the https://www.googleapis.com/auth/calendar.readonly scope and store:
- Your calendar list — each calendar’s name, description, time zone, colour, and access role, so you can choose which ones Foyer shows.
- Events from the calendars you enable, limited to a window of roughly 30 days in the past to 90 days ahead. For each event we store the title, description, location, start and end times, recurrence identifier, busy/free status, organiser and your own attendance response, and any meeting link.
- OAuth tokens — the access and refresh tokens Google issues, so Foyer can keep the calendar in sync without prompting you on every visit.
The scope is read-only. Foyer cannot create, edit, or delete anything in your Google Calendar. Calendar data is used solely to display your events alongside your tasks inside Foyer.
Content you create in Foyer
Tasks, notes and their file attachments, projects, and any other item you capture. Depending on which features you use, this may also include weight logs, training and athlete-profile details, and personal finance records (accounts, transactions, savings goals, subscriptions, and bank statements you upload).
Optional connected services
If you connect them, Foyer pulls read-only work items from GitHub and from a local issue tracker (bd), and deployment or error-rate health signals from Vercel and Sentry for projects you configure. If you install the companion browser extension, Foyer records the sites you have chosen to block and the times you visited or were blocked from them.
Operational logs
We keep sync and error logs — timestamps, which integration ran, how many records changed, and any error message — to diagnose failures. Foyer runs no analytics, advertising, or third-party tracking scripts.
How we use your data
Your data is used only to operate Foyer for you: to display your items, run the syncs you have enabled, and keep you signed in. We do not use it for any other purpose. Specifically, we do not:
- sell, rent, or share your data with third parties;
- serve advertising or build advertising profiles;
- use your data to train machine-learning or AI models;
- read your data except where you ask us to fix a problem, or where required by law.
Bank statements you upload are parsed on our own server. Their contents are not sent to any third-party document-processing or AI service.
Google API Services Limited Use disclosure
Foyer’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to provide the calendar features visible to you in Foyer. It is never transferred to others, used for advertising, or used to train generalised AI or ML models, and no human reads it except with your explicit permission for support, for security purposes, or to comply with applicable law.
Where your data is stored
Foyer is hosted on Vercel. Application data, files, and authentication records are stored with Supabase (managed PostgreSQL and object storage). Both act as our infrastructure providers and process data on our behalf under their own security and privacy terms. Database access is scoped per user with row-level security so that one account cannot read another’s rows. Data is transmitted over HTTPS.
No system is perfectly secure. Foyer is a personal-scale project, not an enterprise service, and you should keep that in mind when deciding what to store in it.
Retention and deletion
- Disconnecting Google Calendar — use Settings → Google Calendar → Disconnect. This deletes the stored OAuth tokens, the calendar records, and the synced events for that account.
- Revoking access at Google — you can independently remove Foyer’s access at myaccount.google.com/permissions. Sync will then stop working until you reconnect.
- Deleting individual content — tasks, notes, logs, and finance records can be deleted from within the app.
- Deleting your account — email riungemaina@gmail.com and we will delete your account and its associated data. Operational logs and routine infrastructure backups may retain traces for a short period before they age out.
Data we hold for you is otherwise retained for as long as your account is active, because the app’s purpose is to keep a durable personal record.
Your rights
You may ask us what data we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. Write to riungemaina@gmail.com and we will respond within a reasonable period.
Children
Foyer is not directed at children and we do not knowingly create accounts for anyone under 18.
Changes to this policy
If this policy changes we will update the date at the top of the page. Material changes to how Google user data is handled will be communicated to affected account holders directly.