Privacy Policy
Last updated 19 August 2026
LetsMeet finds a meeting time that works for everyone. To do that it needs to know when people are busy — never what they are doing. This page describes what we actually collect today, why, how long we keep it, and how to have it removed.
The short version
- We read free/busy times only from a calendar you connect. We never receive event titles, attendees, locations, notes or attachments.
- We never write anything into your calendar.
- Contacts you pick from your phone's address book never leave your device. Only the single number you choose to invite is sent to us.
- We do not sell your data, and we do not use it for advertising or ad tracking.
- Your phone number is your account. Passcodes are never stored in readable form.
Who we are
LetsMeet is operated by Lets Group Serviços Ltda, a company registered in São Paulo, Brazil under CNPJ 68.619.136/0001-18. It is the data controller for everything described on this page. For any privacy question, or to exercise the rights below, write to [email protected].
What we collect, and why
| Data | Why we hold it | How long |
|---|---|---|
| Your phone number | It is your account, and it is how an invite reaches the right person. | For the life of the account. |
| One-time passcodes | To verify it is you signing in. | Minutes. They expire on their own and are never written to our logs. |
| Sign-in tokens | To keep you signed in without asking for a code every time. | Until they expire, you sign out, or you delete the account. |
| Busy/free intervals | The only calendar data we hold. Start and end times with no content attached, used to compute the times that work for a group. | A short window measured in hours, then automatically deleted. We re-read when we need them again rather than keeping a copy. |
| Calendar access tokens | To read those busy/free times from the provider you connected. Requested with the narrowest scope the provider offers for free/busy. | Until you disconnect or delete the account. Stored under envelope encryption with a managed key. |
| Meetings, participants and answers | The meeting itself: title, duration, candidate times, who accepted what. | Until the meeting or the account is deleted. |
| A device identifier | An opaque value created once per install, used to spot abuse of the passcode system. It does not name you and is not an advertising identifier. | For the life of the account. |
| Product analytics | Which steps people complete, so we can tell whether the product works. Events carry opaque references, never your phone number, name, or any calendar content. | Aggregated; the mapping back to you is deleted with the account. |
Calendars: exactly what we see
When you connect a calendar we ask the provider only for free/busy information. That is a list of intervals — "busy from 09:00 to 09:30" — with no title, no participants, no location, no description, and no attachments. This is enforced by the permission we request, not merely by our own restraint: we do not hold a permission that would let us read the contents of your calendar.
We normalize those intervals, keep them for a short period so a group's times can be computed, and then delete them. We never write to your calendar. When a meeting is settled, LetsMeet tells the participants; it does not create events on their behalf.
Connecting a calendar is optional. Without one you mark your busy times by hand.
Contacts
If you allow it, LetsMeet can show your phone's address book so you can pick someone instead of typing their number. That list is read on your device and held only in memory while the picker is open. It is never uploaded. The only thing that reaches us is the single phone number you choose to invite.
Text messages
We send SMS for two reasons: the passcode you use to sign in, and invites to people who do not have the app. Delivering those requires passing the destination number to an SMS provider. That is the only routine disclosure of a phone number we make.
Who else sees your data
We do not sell personal data and we do not share it for advertising. Data reaches third parties only where a service is required to operate the product: our cloud hosting provider, the SMS provider described above, the calendar provider you connected, and error and analytics tooling that receives no personal data. Each acts on our instructions.
Where your data is held
On cloud infrastructure in the United States (AWS, us-east-1), reached through a content and security network. If you are in a country whose law restricts such transfers, that is a transfer you should weigh before creating an account.
Your rights
You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. You can withdraw calendar access at any time by disconnecting in the app or revoking access with the provider.
How deletion works today: LetsMeet is early software, and account deletion is currently a request we perform by hand rather than a button that runs unattended. Write to [email protected] , from or naming the number on the account, and we will delete it and confirm when it is done. We would rather tell you that plainly than show you a button that does not do what it says.
Children
LetsMeet is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
Changes
If this policy changes in a way that affects what we collect or why, we will update the date above and, for a material change, tell you in the app before it takes effect.