Privacy
How Trajectory OS handles data from the services you connect.
Last updated: August 29, 2026
If you connect Google Calendar, Trajectory OS accesses the Google account email address (via the userinfo.email scope) and reads your calendar event metadata — titles, times, attendees, locations, descriptions, recurrence rules, and free/busy information — using the calendar.events.readonly and calendar.calendarlist.readonly scopes. Read access is used to surface events inside the Trajectory OS calendar dashboard and to reconcile events with the rest of your life-structure, weekly-review, and family-deliverables views. Trajectory OS does not write to or modify your Google Calendar on your behalf, and does not use Google user data for advertising or for the development or improvement of AI/ML models.
We do not sell Google user data. We share it only with the following categories of recipients, and only as needed to operate the service:
In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, Google user data may be transferred as a business asset, subject to the same protections in this policy. We may also disclose Google user data if required by law, valid subpoena, court order, or to protect our rights, property, or safety, in which case we will limit disclosure to what is legally required.
Google Calendar event data, and Plaid bank-feed data, are treated as sensitive personal data. Specifically:
calendar.events.readonly, calendar.calendarlist.readonly, userinfo.email). Scope requests are narrowed to the minimum needed for the production feature.If you connect a financial account through Plaid, Trajectory OS receives account metadata, masked account identifiers, balances, and transaction data. This data is used to support dashboard visibility, reconciliation, monthly close, and reporting.
Plaid bank-feed data is evidence, not final proof. Final financial conclusions still depend on uploaded proof, reviewed ledger entries, reconciliation, and monthly close review.
Connected-service access tokens are encrypted before storage and are used only by server-side routes. Raw tokens and provider secrets are not returned to the browser. Cached account, balance, transaction, event, sync, webhook, and usage records are stored to make reconciliation and monthly close auditable.
You can disconnect Plaid bank sync or Google Calendar from Settings. Disconnecting marks the connection as disconnected, clears the encrypted token, stops future syncs, and attempts to revoke the access at the upstream provider.
You can also request deletion of stored Plaid account and transaction history or Google Calendar event metadata during disconnect. Some non-sensitive audit records may remain where needed for security, billing guardrails, or operational logs.
For privacy or security questions, contact privacy@trajectory-os.local.