← Psst

Privacy Policy

Last updated: 6 June 2026

Psst is a cross-platform desktop application (macOS, Windows, and Linux) that shows you a full-screen reminder shortly before your meetings. This policy explains exactly what data Psst accesses and how it is used, stored, protected, and shared. The short version: Psst reads your calendar on your device, protects it with encryption, and never shares your calendar data with anyone. Psst also collects anonymous, opt-out usage analytics that never include your calendar contents — see Analytics below.

What we access

With your explicit consent on Google's sign-in screen, Psst requests the following Google OAuth scopes:

These scopes are read-only. Psst cannot create, modify, send, or delete anything in your Google Account.

How we use and store your data

How we protect your data

We use encryption to protect your information, and security procedures are in place to protect the confidentiality of your Google user data and to guard against unauthorized or unlawful access, use, alteration, loss, or disclosure. Specifically:

How we share, transfer, or disclose your data

We do not share, transfer, sell, rent, or disclose your Google user data to any third party. Your calendar data never leaves your device except to communicate directly with Google's own APIs. We never transfer or sell your data to advertising platforms or data brokers, and we never use it for advertising, profiling, or to determine credit-worthiness.

To sign in and manage your license, Psst relies on a few narrow service providers: RevenueCat and Stripe process your purchase and track which license you own (keyed by your email), and Resend delivers the one-time code we email when you sign in. These providers receive only your email address and purchase information. None of them ever receive any Google user data — not your calendar, or your Google tokens.

The only exceptions to the above are narrow and standard: where we are required to do so to comply with applicable law or a valid legal request, or as part of a merger or acquisition under equivalent privacy protections.

Limited Use

Psst's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide the user-facing reminder feature and is not transferred to others except as described in the section above.

Data retention & deletion

Cached events live only in memory and are cleared when you disconnect your account or quit the app. Your tokens and account email live only on your device; disconnecting your account in Psst, or quitting and removing the app, deletes this local data. You can revoke Psst's access at any time from your Google Account permissions.

Payments

License purchases are processed by RevenueCat and Stripe, our third-party payment and subscription-management providers. We receive order and entitlement information (such as your email and which license you own) to deliver and support your license; we never receive your full payment card details. This is separate from, and never combined with, your Google user data.

Analytics

To understand how Psst is used and where to improve it, we collect anonymous usage analytics via PostHog. This never includes your calendar contents (titles, times, attendees, or links), your email address, or your OAuth tokens.

Contact

Questions about privacy? Email support@heypsst.app.