Skip to content
Attaché Join the waitlist (opens your email app)

Attaché

Privacy policy

Effective date: October 2, 2026

On this page

Attaché is a calendar app made by Snizyx Software LLC (“Snizyx”, “we”, “us”), based in Nashville, Tennessee. It brings Google Calendar, Microsoft 365, Outlook.com and Zoho Calendar into one view and lets you give other people, your delegates, carefully limited access to your calendars. This policy explains what information we collect, how we use and share it, how long we keep it and the choices you have. It covers the Attaché web app at app.tryattache.com, in a browser or installed as an app; the Attaché apps for Mac, Windows, Linux, iPhone, iPad and Android, whether you get them from us or from an app store; and this website, tryattache.com.

The short version

  • We use your calendar data only to run Attaché for you and the delegates you choose.
  • We never sell your data, never use it for advertising and never use it to train generalized AI or machine-learning models.
  • Delegates never get your Google, Microsoft or Zoho passwords, and your calendar access tokens are encrypted with AWS KMS.
  • If you buy Pro, Polar, Apple or Google handles the payment, and we never see your card number.
  • You can export or delete your data at any time.

1. Information we collect

Account information

When you create an account we collect your name, email address and sign-in details, such as the identifier your sign-in provider gives us if you sign in with Google, Microsoft or Apple, or the public key of a passkey you register. We also store your settings, such as your time zone, calendar colors and notification preferences.

Connected calendar accounts

When you connect a Google, Microsoft or Zoho account, you sign in on that provider’s own page and grant Attaché access. We never see or store your password for that account. We receive and store:

  • the email address or name of the connected account, so you can tell your accounts apart;
  • OAuth access and refresh tokens that let Attaché reach your calendars on your behalf. Refresh tokens are encrypted with AWS Key Management Service (KMS) envelope encryption before they are stored. Provider tokens are never sent to your browser, your devices or your delegates.

Calendar data

To show and manage your calendars, we copy from the calendars you connect:

  • the list of calendars: names, colors, time zones and your access level; and
  • events on those calendars: titles, dates and times, locations, descriptions, attendees and their responses, organizers, conferencing links, recurrence rules, categories and whether an event is marked private.

We keep a cached copy of events within a rolling window of about 6 months in the past and 18 months in the future, so Attaché can show your calendars quickly. Events that fall outside that window are removed from our cache.

Delegation data

When you invite a delegate we store their email address, the permissions you grant them for each calendar, any expiry date you set and the status of the invitation. When a delegate proposes a change, we store the proposal and your decision. If you are a delegate, the owner who invited you can see your name, your email address and the actions you take in their calendars.

Audit log

Attaché records the actions taken in your calendars through Attaché, by you or by your delegates, in an audit log: who acted, what they did, when, from which IP address and browser or app, and copies of the event before and after the change so that it can be undone.

Billing information

If you buy Pro, you buy it from one of three sellers, which handle the payment under their own terms and privacy policies:

  • Polar (Polar Software, Inc., polar.sh), our merchant of record, on the web, in the apps you download from us and in the Microsoft Store app. Polar collects your payment details and e-mail address and charges any sales tax or VAT (Polar’s privacy policy);
  • Apple, in the apps from Apple’s App Store (iPhone, iPad and the Mac App Store); and
  • Google, in the app from Google Play.

We never receive or store your card number, and we don’t keep the name, e-mail address, billing address or country you give the seller. We give the seller an internal identifier that links the purchase to your Attaché account, and the seller tells us about your subscription. For each subscription you buy, from any of the three, we keep a record of the purchase: the seller’s identifiers for the subscription, for its latest payment and, for Polar, for you as its customer; which plan you bought; its status, such as active, in a grace period after a failed payment, refunded or ended; whether it renews; and its dates, such as when it started and when it renews or ends. We use this record to give you Pro and to show your subscription in Settings, and it is deleted with your account.

Device, log and usage information

Our servers record technical information when you use Attaché, such as your IP address, browser or device type, app version and the time and outcome of each request. We use it to keep the service secure and reliable. If you turn on notifications, we store the push subscription or device token needed to deliver them.

App store reviewers sign in to our demo accounts with a review code. To protect those accounts, we record every attempt to sign in with a review code: a one-way keyed fingerprint of the e-mail address typed (not the address itself), whether the attempt worked, and the IP address and browser or app identification it came from.

If enabled, crash reporting sends us technical details about an error and the device it happened on; we configure it not to collect calendar content. If enabled, a cookieless analytics service counts page views and feature use in aggregate, without cookies or tracking you across other sites.

Our apps and your devices

You can use Attaché in a web browser, install the web app from your browser, or use our apps. Where each one keeps your sign-in:

  • The web app at app.tryattache.com, in a browser or installed from it: in a cookie that the page’s own scripts cannot read.
  • Mac, from the Mac App Store or downloaded from us: in the macOS Keychain.
  • Windows, from the Microsoft Store or downloaded from us: in Windows Credential Manager.
  • Linux, as a .deb package from our apt repository or as an AppImage: in your desktop’s keyring, such as GNOME Keyring or KWallet, through the Secret Service.
  • iPhone and iPad, from the App Store: in the iOS Keychain, on that device only.
  • Android, from Google Play or downloaded from us: encrypted with a key that stays in the Android Keystore, on that device only.

Every version also keeps on your device a copy of what it needs to show your calendars, such as the events it has recently shown and your lists of calendars and connected accounts, so that it opens quickly and works offline. It keeps your display settings there too, such as the theme and the calendars you have hidden. Signing out deletes your sign-in and that copy of your calendars from the device. Your device’s own backups may include this data, except on Android, where the app is left out of backups. Our apps for Mac, Windows and Linux also keep a log of what the app did, for troubleshooting, in a file on your computer; it is not sent to us.

Depending on the version and where you got it:

  • Push notifications. If you turn them on in the web app, your browser gives us a push subscription: an address at your browser’s push service, keys to encrypt the notifications, and your browser’s identification (its user agent). Our apps for Mac, Windows, Linux, iPhone, iPad and Android don’t register for push notifications.
  • Updates. The Mac and Windows apps you download from us, and the Linux AppImage, regularly check updates.tryattache.com for a new version; the .deb package gets its updates from our apt repository there, through your system’s package manager. These requests carry your IP address and which platform the app is for, and no account information. The Android app you download from us doesn’t check for updates. Apps from an app store are updated by the store.
  • App stores. If you get an app from the App Store, the Mac App Store, the Microsoft Store or Google Play, the store handles the download and its updates under its own terms and privacy policy, and may give us statistics and crash reports that don’t identify you.

Communications

If you email us, we keep your message and our reply so we can help you. Email sent to our @tryattache.com addresses is received by Amazon SES, which stores the raw message in AWS for 30 days, and is forwarded to the mailbox our team uses to read and answer it. If you join the waitlist, we use your email address only to tell you when Attaché is available, and we delete it when you ask.

Cookies

The Attaché app uses cookies only where they are strictly necessary to keep you signed in and secure. The other data it keeps in your browser’s or app’s storage is described in “Our apps and your devices” above. We don’t use advertising cookies or cross-site tracking. This website, tryattache.com, does not set cookies.

2. How we use information

We use the information described above to:

  • provide Attaché: show your calendars together, keep them in sync with your providers, and create, change or delete events when you, or a delegate acting within the permissions you set, ask us to;
  • apply each delegate’s permissions, filters and approval rules, so that they see and do only what you allow;
  • send service messages, such as sign-in links, invitations, proposal and approval notifications, security alerts and billing notices;
  • keep Attaché secure, prevent abuse and investigate problems;
  • help you when you contact us;
  • manage subscriptions and billing;
  • comply with the law and enforce our terms of service; and
  • understand and improve Attaché using aggregated usage information that does not include the content of your calendars.

We don’t sell personal information, we don’t use it for advertising and we don’t share it for cross-context behavioral advertising. We don’t use calendar data to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.

3. Google user data

This section explains how Attaché handles information it receives from Google APIs (“Google user data”).

What we access

With your permission, Attaché uses Google’s APIs to:

  • sign you in with Google, if you choose to: your name, email address and profile picture (the openid, email and profile scopes);
  • read the list of calendars in your Google account (calendar.calendarlist.readonly); and
  • read, create, change and delete events on the calendars you connect (calendar.events), when you, or a delegate acting within the permissions you set, ask Attaché to.

How we use it

We use Google user data only to provide and improve Attaché’s user-facing features: showing your Google calendars alongside your others, keeping them in sync, making the changes that you or your authorized delegates request and showing each delegate the parts of your calendars you have chosen to share.

How we share it

We share Google user data only:

  • with the delegates you invite, limited to the calendars and details your permissions allow. This is the core feature you control, and you can change or revoke it at any time;
  • with Amazon Web Services, which hosts Attaché’s servers, database and backups for us;
  • when necessary for security purposes, such as investigating abuse;
  • to comply with applicable law; or
  • as part of a merger, acquisition or sale of assets of Snizyx, and only after obtaining your explicit prior consent.

Limited Use

Attaché’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We do not use Google user data for advertising, including retargeting and personalized or interest-based advertising.
  • We do not sell Google user data, or transfer it to advertising platforms, data brokers or other information resellers.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not use Google user data, including data obtained through Google Workspace APIs such as the Google Calendar API, to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.
  • People at Snizyx do not read your Google user data unless you have given us your explicit agreement to view specific data (for example, a particular event you ask us to look at while helping you), it is necessary for security purposes such as investigating a bug or abuse, or it is necessary to comply with applicable law.
  • Everyone who works on Attaché, including our contractors and agents, and any successor to our business, must follow these commitments.

Removing access

You can disconnect a Google account in Attaché’s settings at any time, or remove Attaché’s access from your Google Account at myaccount.google.com/permissions. When you disconnect, we revoke our token with Google, stop syncing and delete the calendar data we cached from that account. If you signed in with Google, Microsoft or Apple, you can also remove Attaché from that account’s connected apps.

4. Microsoft and Zoho data

We apply the same rules to calendar data from Microsoft 365 and Outlook.com (through Microsoft Graph) and from Zoho Calendar. We use it only to provide Attaché’s features to you and the delegates you authorize. We don’t sell it, use it for advertising or use it to train generalized AI or machine-learning models, we transfer it only in the circumstances listed for Google user data above, and people at Snizyx don’t read it except with your explicit agreement, for security purposes or to comply with the law. Microsoft’s and Zoho’s own terms and privacy policies continue to apply to your accounts with them, and you can also remove Attaché’s access from your Microsoft or Zoho account settings.

5. What delegates can see

  • Delegates see only what your per-calendar permissions allow: free/busy, titles only or full details, minus anything your private, keyword or category filters hide.
  • Permissions are enforced on our servers before any data is sent, so a delegate’s app never receives details you haven’t shared.
  • Delegates never receive your provider passwords or tokens.
  • Everything a delegate does in your calendars is recorded in your audit log.
  • You can change or revoke a delegate’s access at any time.

6. How we share information

We don’t sell personal information. We share it only as follows:

  • With delegates you invite, as described above.
  • With the calendar providers you connect. When you or a delegate make a change, we send it to Google, Microsoft or Zoho so that your calendar is updated. Their privacy policies govern what they do with it.
  • With the company that sells you Pro, if you buy it: Polar, Apple or Google, as described under “Billing information”. We give the seller an internal identifier that links the purchase to your account. Sellers act under their own terms and privacy policies, not on our behalf.
  • With service providers that help us run Attaché, under contracts that limit their use of your information to providing their service to us:
Provider What they do for us Location
Amazon Web Services, Inc. Hosting, database, file storage, encryption keys (AWS KMS) and email delivery (Amazon SES) United States (us-east-2, Ohio)
Crash reporting provider, if enabled Error diagnostics for our apps, without calendar content Named here before it is enabled
Cookieless analytics provider, if enabled Aggregate page and feature usage, without cookies or cross-site tracking Named here before it is enabled
Zoho Corporation (Zoho Mail) The mailbox our team uses to receive and answer the email you send us United States
Your browser’s or device’s push service (for example Apple, Google, Microsoft or Mozilla) Delivering the notifications you turn on Depends on your browser or device
  • For security and legal reasons: when necessary to investigate abuse or protect the security of Attaché and its users, or when required by law, such as a valid subpoena or court order.
  • In a business transfer: if Snizyx is involved in a merger, acquisition or sale of assets, and, for calendar data from any provider, only after obtaining your explicit prior consent.

7. Where we store data

Attaché’s servers and data are hosted by Amazon Web Services in the United States (the us-east-2 region, in Ohio). If you use Attaché from outside the United States, your information is transferred to and processed in the United States.

8. Security

We protect your information with measures that include KMS envelope encryption of provider tokens, TLS encryption in transit, encryption at rest for our database and backups, least-privilege access controls and an append-only audit log. No system is perfectly secure; if a breach affects your information, we will notify you as the law requires. Our security page has the details.

9. Retention and deletion

  • Cached calendar events are kept within a rolling window of about 6 months in the past and 18 months in the future.
  • Audit log entries are deleted 12 months after they were recorded, by a job that runs once a day, so an entry can stay up to a day longer. The job deletes only entries that our tamper-proof archive already holds and whose integrity it can check; if either check fails, it keeps that log’s expired entries until we have fixed the problem. The archive’s copy of an entry is deleted about a year and a day after it was made, and deleted entries stay in our encrypted backups for up to 35 more days.
  • Server logs are kept for about 30 days.
  • Attempts to sign in with a review code are kept for 90 days.
  • Email you send us: the raw copy received by Amazon SES is deleted after 30 days; the forwarded copy stays in our team mailbox for as long as we need it to help you.
  • Disconnecting a calendar account revokes Attaché’s access token with the provider where the provider supports revocation, stops syncing and, normally within minutes, deletes the tokens and the calendars and events we cached from that account, together with pending proposals and changes that had not reached those calendars yet. We keep the account’s address and the fact that it was disconnected, so you can reconnect it; the activity log keeps its history until those entries expire.
  • Revoking a delegate ends their access to your calendars. The actions they took stay in your audit log until those entries expire.
  • Deleting your account (how to delete it): when you ask, you are signed out everywhere and syncing with your calendar accounts stops, and if you signed in with Apple, we ask Apple at once to remove Attaché’s access to your Apple Account. Delegate access is suspended both ways: the people who help with your calendars can no longer see or change them through Attaché, and neither can you for the people you help; we tell them. Your account is deleted 7 days later. If you sign in before then, the deletion is cancelled and everything comes back as it was; Sign in with Apple comes back the next time you use it to sign in. After that nobody can sign in to it: we revoke our access to your connected accounts where the provider supports it and delete your account, calendar data, delegations and settings, normally within minutes and always within 30 days of your request. Copies in our encrypted backups are deleted as those backups expire, within a further 35 days. The activity log cannot be edited: its entries about your account, including what you did as someone’s delegate, stay until they are deleted 12 months after they were recorded, as described above, identified by an internal account number rather than your name or e-mail address. The archive’s copies of them are deleted about a year and a day after they were made. The archive’s daily index files list each log by its account number, with nothing about what happened in it; a deleted account’s number stops appearing in new ones once its log’s last entries are deleted, and the last file naming it is deleted about a year later, so up to about two years after the deletion. We keep a minimal record that the deletion happened (that account number, a one-way keyed fingerprint of your e-mail address and the dates) for 13 months, to show that we honoured your request. People you helped as a delegate keep their own records of the delegation and of the changes you made in their calendars. If you bought Pro, Polar, Apple or Google keeps its own records of your purchases under its privacy policy. We keep limited records longer only where the law requires it, such as billing records for tax purposes, or as described below.
  • If e-mail to an address bounces, or its owner marks our e-mail as spam, we stop e-mailing it: Amazon SES keeps the address on its suppression list, and we keep a one-way keyed fingerprint of it (not the address) with the reason and dates, also after an account is deleted, until you ask us to e-mail you again.
  • Exports you request are kept for one day and then deleted.

10. Your rights and choices

You can:

  • access and export your data, including your calendar data in portable formats (Settings → Account → Export my data: JSON and iCalendar files). An export includes what you did as a delegate, but not the calendars of the people you help, which are theirs to export;
  • correct your account information in settings, or ask us to correct it;
  • delete your account (here is how), disconnect any calendar account or revoke any delegate at any time; and
  • withdraw the access you gave Attaché to a calendar account by disconnecting it in Attaché or in that provider’s account settings.

Depending on where you live you may have further rights, for example under the GDPR in the European Economic Area and the United Kingdom, or under US state privacy laws such as California’s. They can include the right to object to or restrict some processing and to complain to your local data protection authority. Where the GDPR applies, we process your information to provide Attaché under our contract with you, for our legitimate interests in keeping it secure and improving it (without using the content of your calendars), to meet legal obligations, and with your consent when you connect a calendar account, which you can withdraw at any time by disconnecting it.

To exercise any of these rights, email privacy@tryattache.com. We will verify your request and respond within 30 days, or sooner where the law requires. We won’t treat you differently for exercising your rights.

11. Children

Attaché is not directed to children under 13, and we don’t knowingly collect personal information from children under 13. If you believe a child under 13 has given us personal information, email privacy@tryattache.com and we will delete it.

12. Changes to this policy

We will post any changes to this policy on this page and update the effective date. If we make a material change, we will tell you by email or in the app before it takes effect, and we will ask for your consent before using your information in a new way where the law or the Google API Services User Data Policy requires it.

13. Contact us

Snizyx Software LLC
Nashville, Tennessee, United States
privacy@tryattache.com