Privacy & data · Whenly.software

A poll that finds a time should not become a directory.

whenly.software books time, not people. A poll is a set of candidate times and a set of answers from opaque handles — not a contact list, not an advertising profile. This page says what a poll would hold and, just as plainly, what it deliberately does not.

Because the product is early access, this describes the design the poll is being built to. Where a protection is a design property rather than a running feature, it is written as such.

What a poll holds

Times, answers, and the narrowest handle a response needs.

Candidate times, and how each person marked them

The times a coordinator proposed, and for each responder’s opaque handle, whether they marked a time available, if-need-be, or no. That is the substance of a find-a-time poll — a set of times and a set of answers.

The narrowest handle a response needs

A responder is referenced by an opaque handle, not a name or an email shown to the group. The design goal is that answering a poll needs no account at all, so the record carries as little about a person as the mechanism can work with.

The locked time, once a group agrees

When a time is locked, a booking row against the shared no-double-book floor: which time, in which state, held against capacity. Where a school roster is involved, every identity field routes through a consent chokepoint first — a suppressed person’s name is masked at the server; the row still counts, only the identity is stripped.

What whenly is not

No names, no ads, no profile, no sale.

No names in the poll, no directory built from it

A responder is an opaque handle. Opening a poll does not hand you a list of everyone else’s name and email — the exact thing the group-poll tools normalise. There is no contact list to harvest here.

No ads shown to the people you invite

The design commitment is that whenly shows no ads to anyone who opens a poll, on any tier. The free tier of the category is usually paid for with ads served to your invitees; this is not.

No names in the calendar feed

The subscribable .ics feed carries opaque labels only: no participant name, no organizer name, no real email address — only a non-PII handle. Subscribing to a meeting cannot turn your calendar into a directory.

No advertising profile, no data sale, no model training

We do not build an advertising profile from a poll, we do not sell or rent scheduling data, and no model is trained on anyone’s responses. There is no third-party analytics or advertising script on this site.

No automated decision about a person

Finding the overlap is a count of who is free; the coordinator decides. Nothing here scores, ranks, or profiles a person, and there is no eligibility determination about anyone.

Minors

The minor-safety floor binds even for adult coordination.

whenly is built for committees, chaperones, and staff — adults — but the minor-safety rules bind regardless. Minor scheduling data is consent-aware, access-controlled, and never made public. Where any surface touches a school roster, every identity field routes through a consent chokepoint: a suppressed person’s name is masked at the server, not by a UI filter a client request could disable, and the row still counts — only the identity is stripped. The calendar feed carries opaque labels only, and there are no names in a poll.

FERPA and COPPA are posture built in by construction, not retrofitted — and not a certificate we hold or claim. There is no facial recognition and no photo store here, because whenly holds no images: it schedules time.