Privacy & data · Whenly.software
A poll that finds a time should not become a directory.
whenly.software books time, not people. A poll is a set of candidate times and a set of answers from opaque handles — not a contact list, not an advertising profile. This page says what a poll would hold and, just as plainly, what it deliberately does not.
Because the product is early access, this describes the design the poll is being built to. Where a protection is a design property rather than a running feature, it is written as such.
What a poll holds
Times, answers, and the narrowest handle a response needs.
✓Candidate times, and how each person marked them
The times a coordinator proposed, and for each responder’s opaque handle, whether they marked a time available, if-need-be, or no. That is the substance of a find-a-time poll — a set of times and a set of answers.
✓The narrowest handle a response needs
A responder is referenced by an opaque handle, not a name or an email shown to the group. The design goal is that answering a poll needs no account at all, so the record carries as little about a person as the mechanism can work with.
✓The locked time, once a group agrees
When a time is locked, a booking row against the shared no-double-book floor: which time, in which state, held against capacity. Where a school roster is involved, every identity field routes through a consent chokepoint first — a suppressed person’s name is masked at the server; the row still counts, only the identity is stripped.
What whenly is not
No names, no ads, no profile, no sale.
✓No names in the poll, no directory built from it
A responder is an opaque handle. Opening a poll does not hand you a list of everyone else’s name and email — the exact thing the group-poll tools normalise. There is no contact list to harvest here.
✓No ads shown to the people you invite
The design commitment is that whenly shows no ads to anyone who opens a poll, on any tier. The free tier of the category is usually paid for with ads served to your invitees; this is not.
✓No names in the calendar feed
The subscribable .ics feed carries opaque labels only: no participant name, no organizer name, no real email address — only a non-PII handle. Subscribing to a meeting cannot turn your calendar into a directory.
✓No advertising profile, no data sale, no model training
We do not build an advertising profile from a poll, we do not sell or rent scheduling data, and no model is trained on anyone’s responses. There is no third-party analytics or advertising script on this site.
✓No automated decision about a person
Finding the overlap is a count of who is free; the coordinator decides. Nothing here scores, ranks, or profiles a person, and there is no eligibility determination about anyone.
Minors
The minor-safety floor binds even for adult coordination.
whenly is built for committees, chaperones, and staff — adults — but the minor-safety rules bind regardless. Minor scheduling data is consent-aware, access-controlled, and never made public. Where any surface touches a school roster, every identity field routes through a consent chokepoint: a suppressed person’s name is masked at the server, not by a UI filter a client request could disable, and the row still counts — only the identity is stripped. The calendar feed carries opaque labels only, and there are no names in a poll.
FERPA and COPPA are posture built in by construction, not retrofitted — and not a certificate we hold or claim. There is no facial recognition and no photo store here, because whenly holds no images: it schedules time.