Privacy

Privacy policy

How Trajectory OS handles data from the services you connect.

Last updated: August 29, 2026

Google account data (Calendar)

If you connect Google Calendar, Trajectory OS accesses the Google account email address (via the userinfo.email scope) and reads your calendar event metadata — titles, times, attendees, locations, descriptions, recurrence rules, and free/busy information — using the calendar.events.readonly and calendar.calendarlist.readonly scopes. Read access is used to surface events inside the Trajectory OS calendar dashboard and to reconcile events with the rest of your life-structure, weekly-review, and family-deliverables views. Trajectory OS does not write to or modify your Google Calendar on your behalf, and does not use Google user data for advertising or for the development or improvement of AI/ML models.

How we share, transfer, or disclose Google user data

We do not sell Google user data. We share it only with the following categories of recipients, and only as needed to operate the service:

In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, Google user data may be transferred as a business asset, subject to the same protections in this policy. We may also disclose Google user data if required by law, valid subpoena, court order, or to protect our rights, property, or safety, in which case we will limit disclosure to what is legally required.

Data protection mechanisms for sensitive data

Google Calendar event data, and Plaid bank-feed data, are treated as sensitive personal data. Specifically:

Plaid-connected financial data

If you connect a financial account through Plaid, Trajectory OS receives account metadata, masked account identifiers, balances, and transaction data. This data is used to support dashboard visibility, reconciliation, monthly close, and reporting.

Plaid bank-feed data is evidence, not final proof. Final financial conclusions still depend on uploaded proof, reviewed ledger entries, reconciliation, and monthly close review.

Storage and security

Connected-service access tokens are encrypted before storage and are used only by server-side routes. Raw tokens and provider secrets are not returned to the browser. Cached account, balance, transaction, event, sync, webhook, and usage records are stored to make reconciliation and monthly close auditable.

Disconnect and deletion

You can disconnect Plaid bank sync or Google Calendar from Settings. Disconnecting marks the connection as disconnected, clears the encrypted token, stops future syncs, and attempts to revoke the access at the upstream provider.

You can also request deletion of stored Plaid account and transaction history or Google Calendar event metadata during disconnect. Some non-sensitive audit records may remain where needed for security, billing guardrails, or operational logs.

Contact

For privacy or security questions, contact privacy@trajectory-os.local.