Privacy

Last updated: 9 August 2026

This page explains what personal data OLI2 ("we", "us", "our") collects, why, how long we keep it, and how to get it deleted. It covers https://oli2.com and the OLI2 application (together, the "Service").

Who is responsible for your data

The data controller is [to confirm: registered company name, registered address, and ICO registration number]. For any privacy question, or to exercise the rights described below, contact privacy@oli2.com.

Your calendar data

This is the most significant category of data we handle, so we want to be specific about it.

When you connect a Google or Microsoft calendar, we request read-only access to it. We cannot create, edit or delete anything in your calendar. For each meeting we read, we store:

  • the title, description and location;
  • the start and end time, duration, and whether it is all-day;
  • the email address, and name where the provider supplies one, of every attendee;
  • who organised it and each attendee's response (accepted, declined, tentative, no response);
  • any video-conferencing link on the meeting;
  • whether it is part of a recurring series.

We also store what you create inside OLI2: agenda items, action items, attachment links, meeting chat messages, shared meeting notes, and private notes that only you can see.

Data about people who are not OLI2 users

Because a meeting has attendees, connecting your calendar necessarily means we store the email addresses and names of people who have not signed up for OLI2 and may not know it exists. We use that data only to show you your own meetings and analytics. We do not email those people, we do not build profiles of them for anyone other than the users whose meetings they attended, and we do not sell or share it. If you are such a person and want your details removed, contact privacy@oli2.com.

Your account

We store your email address, your name as your calendar provider supplies it, and the preferences you set in the app: timezone, working hours and workdays, alternative email addresses, internal email domains, personal meeting-room links, your hourly rate if you enter one (used only to estimate meeting costs for you), and your theme choice.

We store an access token and a refresh token for your connected calendar so we can keep it in sync without asking you to sign in again. We never see or store your Google or Microsoft password.

How we use it, and our lawful basis

We use your data to provide the Service: syncing your calendar, categorising your meetings, producing your analytics, and running the collaborative features on a meeting page. We also use it to keep the Service secure and working, and to fix faults.

Our lawful basis is legitimate interests.

We do not sell your data. We do not use it to train machine-learning models. We do not use it for advertising.

Who we share it with

We share data only with the services needed to run OLI2:

  • Google and Microsoft — we read your calendar from whichever you connect.
  • Our hosting and infrastructure providers, who store the database and run the application.

We may also disclose data where we are legally required to.

Public sharing links

OLI2 can generate a link that shows your availability - when you are busy or free - without showing meeting titles, attendees or any other detail. These links are off by default. They only work while you have sharing switched on for that calendar, and you can switch it off at any time from the Calendars page, which immediately stops the link working.

How long we keep it

We keep your calendar data for as long as your account is open, so that your history and analytics remain available to you. Two specifics:

  • We import roughly two years of past meetings and one year ahead when you first connect a calendar, and keep it in sync from then on.
  • We do not keep the raw payloads returned by your calendar provider.

Beyond that, our retention period is [to confirm: how long meeting history is kept for an open account, and how long backups are retained after deletion].

Deleting your account and your data

You can delete your account yourself at any time, from the Account page. You can also ask us to do it by emailing privacy@oli2.com.

When an account is deleted we remove:

  • your login and account settings;
  • your connected calendars and the tokens for them;
  • every meeting that existed only on your calendars;
  • your private notes, and your meeting categories and rules;
  • your active sessions, so you are signed out everywhere.

One thing does not simply disappear, and we would rather be clear about it: a meeting you shared with other OLI2 users is also on their calendar, and is their own record of a meeting that genuinely happened. We do not delete their records. Instead we remove your identity from them — your email address and name are replaced with an anonymous placeholder, so their meeting stays intact but no longer holds your personal data.

Deletion is immediate and cannot be undone. Backups are retained for [to confirm: backup retention period] before your data is gone from those too.

Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased (see above);
  • receive your data in a portable form — you can export your meetings and the people you meet as CSV from the Meetings and People pages at any time;
  • restrict or object to our processing;
  • withdraw your calendar access at any time, from your Google or Microsoft account settings, which stops any further syncing.

To exercise any of these, email privacy@oli2.com. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies and local storage

We use only what the Service needs to function. We do not use advertising or tracking cookies, and we do not use third-party analytics.

  • sessionid — keeps you signed in. Without it you cannot use OLI2.
  • csrftoken — protects forms against cross-site request forgery.
  • A theme value in your browser's local storage, remembering whether you chose light or dark mode.

You can block cookies in your browser, but you will not be able to sign in.

Log data

Our servers and hosting provider record technical information about requests — IP address, browser type, the pages requested, and the time — which we use to diagnose faults and detect abuse. Retention is [to confirm: log retention period].

Security

Traffic to OLI2 is encrypted in transit. Access to meetings is restricted to their attendees by default. We take care with your data, but no internet service can promise perfect security, and we will not claim otherwise.

Children

OLI2 is a workplace tool and is not intended for anyone under 16. We do not knowingly collect data about children.

Changes to this policy

We may update this policy. If we make a material change we will tell you by email or with a prominent notice in the app, rather than relying on you to re-read this page.

Contact

Questions about this policy, or about your data: privacy@oli2.com.