WellSent Reminders Privacy Policy

Last updated: August 14, 2026

What this service does

WellSent Reminders connects to your Google Calendar to spot upcoming occasions - birthdays, anniversaries, weddings, and similar events - and emails you reminders far enough ahead to send a real card.

What we access

With your permission, we request read-only access to your Google Calendar (the calendar.readonly scope). We can see event titles, dates, and calendar metadata. We cannot create, edit, or delete anything on your calendar, and we never request access to your email, contacts, or files.

What we store

Your email address, an encrypted token that lets us check your calendar on a daily schedule, and - for events we identify as occasions - the event title and date so we can time your reminders. We do not store your full calendar. Events that are not occasions are discarded immediately after each daily check.

How we use it

One purpose: sending the occasion reminders you signed up for. Reminder emails may link to the WellSent card shop. We do not sell your data, share it for advertising, use it to train AI or machine learning models, or allow humans to read your calendar data except with your explicit consent for support, for security, or where required by law.

Google API Limited Use disclosure

WellSent Reminders' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we share, transfer, and disclose Google user data

We do not sell your Google user data, share it for advertising, or use it to train AI or machine learning models.

We share Google user data only with the following service providers, who process it solely on our behalf and only in the United States: Vercel (application hosting), Supabase (encrypted database storage), and Resend (delivery of your reminder emails).

We disclose Google user data outside these providers in only two cases: with your explicit consent, or where required by law. No person at WellSent reads your calendar data except with your explicit consent for support, for a security investigation, or where required by law.

How we protect your data

Google user data is encrypted in transit using TLS and encrypted at rest by our database provider using AES-256. Your Google OAuth refresh token is stored encrypted and is never exposed to the browser or included in any email.

Database access is restricted at the database layer: row-level security is enabled on every table with no public access policies, so the database rejects all direct client access. Records are reachable only by our server, using a privileged credential stored in server-side environment variables and never exposed to a browser.

We request the narrowest scope our feature requires, calendar.readonly, and we discard every calendar event that is not an occasion immediately after each daily check, so non-occasion data is never retained.

Retention and deletion

Unsubscribing (link in every email or on the manage page) stops all reminders. Disconnecting deletes your stored token and cached occasion data. You can also revoke our access anytime at myaccount.google.com/permissions, or request full deletion at wellsentteam@gmail.com - completed within 30 days.

Changes and contact

Material changes get emailed to you. Questions: wellsentteam@gmail.com.