Privacy Policy
Last updated: August 26, 2026
This policy explains what data dIme ("the Service") collects, why, and what happens to it. Your working data is used to operate your account and is never sold. Optional advertising measurement is off by default and is used only after you choose “Allow campaign measurement.” You can change that choice, export your data, or delete your account at any time.
1. What we collect
- Account: your name and email address from Google Sign-In. We never see your Google password.
- Your working data: projects, time entries, invoices, client names and billing details you enter, mileage records, and business profile details (business name, address, phone, payment handles) used on your invoices.
- Meeting notes (optional): if you connect Granola, the meeting notes and transcripts you choose to sync, plus the API key you provide (held in server-side storage only — never kept in your browser, exports, or backups).
- Google Calendar assistant (optional): if you connect Google Calendar, dIme reads the names of calendars you select and scheduled event details needed to apply your meeting filters and offer tracking prompts, including event title, start and end time, location or meeting link, organizer, and attendee email addresses used to identify meetings with participants and match a client workspace. Monitoring access is read-only. If you separately enable scheduling, dIme may create events only on calendars you own; event titles, times, attendee addresses, and your Google Meet choice are sent to Google only after you review and confirm the meeting. dIme does not retain invitee lists from meetings it creates. Google OAuth tokens are encrypted in server-only storage. Event contents are processed transiently; completed time entries retain only the calendar and event identifiers needed to prevent duplicate prompts, while an active timer temporarily retains the event title, schedule, suggested workspace and work stage for closeout.
- Subscription billing: your Stripe customer and subscription identifiers and billing status for the dIme plan. Card numbers are entered on Stripe's pages and never touch dIme.
- Payments metadata (optional): if you connect Stripe to receive invoice payments, your Stripe account identifier and payment-status events for your invoices.
- Campaign attribution (optional): only after you allow campaign measurement, campaign parameters such as UTM source, medium, campaign, content and term; the referring website's hostname; landing path; Meta browser identifiers; IP address; browser user agent; and events such as registration, checkout, trial, subscription, first workspace, first time entry and first invoice. Email addresses and account identifiers sent through Meta's server-side Conversions API are cryptographically hashed before transmission.
We do not use your projects, client details, time entries, invoice content, calendar event contents, meeting notes, payment-card data, or Granola content for advertising.
Google user data and Limited Use. dIme's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to provide the calendar features you turn on inside dIme. It is not sold, not transferred to anyone except as needed to provide those features or where required by law, not used for advertising or any form of ad targeting, and not used to develop, improve, or train generalized artificial-intelligence or machine-learning models. No human reads your Google Calendar data except with your explicit permission, to resolve a support issue you report, for security purposes such as investigating abuse, or where required by law.
2. Where it lives
Data is stored in Google Firebase (Firestore) in the United States, isolated per account. Local copies may be cached on your own device for offline use. Signing out prevents normal app access to that cache; you can also clear it through your browser or device data controls. Automated backups of the database are kept on a rolling schedule and purged as they age out.
3. Service providers
The Service relies on a small set of processors, each receiving only what it needs to function:
- Google Firebase — authentication and database hosting.
- Google Calendar — read-only calendar monitoring if you connect the assistant, plus event creation on calendars you own only if you separately enable scheduling and confirm a meeting.
- Netlify — application hosting and serverless functions.
- Stripe — payment processing on your own connected account.
- Granola — meeting-notes sync, only if you connect it.
- Google Gemini — generates short AI summaries of meeting notes you sync; note content is sent to the model for this purpose only.
- Meta Platforms — optional ad measurement, attribution and audience optimization through Meta Pixel and Conversions API, only after you allow campaign measurement. Meta may combine event data with information it already holds under its own Privacy Policy.
Your working data is never sold or rented. Information is disclosed only to providers needed to operate features you request, for optional advertising measurement you permit, or where required by law.
4. Cookies and local storage
The Service always uses essential browser storage for authentication, security, offline data, theme, dismissed calendar prompts and privacy-choice preferences. These functions are necessary to provide the Service.
If you allow campaign measurement, dIme stores first- and last-touch campaign attribution in your browser and may allow Meta Pixel to set or read identifiers such as _fbp and _fbc. These help attribute registrations, trials and subscriptions to ads and improve campaign delivery. Meta tracking is not loaded before consent. Choosing essential-only removes dIme's saved campaign attribution, attempts to remove Meta cookies available to this site, and stops future Meta events from dIme.
5. Your rights and controls
- Export: Settings → Backup & Restore downloads a complete copy of your data; the Accountant Export produces tax-year records.
- Deletion: Settings → Danger Zone → Delete Account cancels any active subscription, disconnects your Stripe account, and permanently removes your account, operational data, and server-side records (including stored integration keys). Backup copies are purged at deletion, with any stragglers expiring on the normal rolling schedule. Stripe retains transaction records independently as required by financial regulations.
- Disconnecting integrations: Google Calendar, Stripe and Granola connections can be removed in Settings at any time. Disconnecting Calendar attempts to revoke Google's token and immediately deletes dIme's encrypted token record.
- Access and correction: everything the Service stores about you is visible and editable in the app itself.
- Privacy choices: choose “Use essential only” in the privacy banner, use Configure → Privacy & Attribution, or open Privacy Choices. Refusing or withdrawing campaign measurement consent does not affect your access to the Service.
6. Sale, sharing and targeted advertising
dIme does not sell personal information for money. Some U.S. privacy laws may define consented disclosure to Meta for targeted advertising or cross-context behavioral advertising as “sharing.” You may opt out at any time through Privacy Choices. dIme does not knowingly sell or share personal information about anyone under 16.
7. Retention
Your data is kept for as long as your account exists or until you disconnect the relevant optional integration. After account deletion, live data and encrypted Calendar tokens are removed immediately and backup copies expire with the backup rotation.
One record deliberately outlives deletion: an irreversible cryptographic hash of your email address, kept solely to record that a free trial was used so trials cannot be claimed repeatedly. It contains no readable personal data, is never used for marketing or profiling, and cannot be used to reconstruct your address. Stripe also retains its own transaction records independently, as financial regulations require.
dIme's server-side campaign-attribution record is removed when you withdraw campaign measurement consent or delete your account. Meta controls information already transmitted to it and may retain event data as described in the Meta Business Tools Terms.
8. Legal bases and international processing
Where applicable law requires a legal basis, dIme processes essential account and working data to provide the Service, protect it, comply with law and pursue legitimate operational interests. Optional advertising measurement is based on your consent. Service providers may process information in the United States and other countries where they operate.
9. Security
Access is gated by Google authentication; database rules restrict every record to its owner; payment credentials are handled exclusively by Stripe. No internet service can promise perfect security, which is another reason the export tools exist.
10. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect data from children.
11. Changes
If this policy changes materially, the "Last updated" date will change and significant updates will be noted in the app.
12. Contact and privacy requests
To request access, correction, deletion or information about privacy rights, email Endeavor.Co.LLC@gmail.com. We may need to verify that you control the relevant account before fulfilling a request.