Security at Timely
Timely is built so your calendar stays on your device. Here is exactly how the app works, what it can access, and what never touches our infrastructure.
Last updated: 21 July 2026
The short version
Timely is a local desktop application. It runs on your Mac or PC, reads your calendar using read-only permissions, and computes availability on your machine. We do not operate a backend that receives, stores, or processes your calendar data. Nothing about your schedule is uploaded to us.
No backend for your calendar
Timely does not have a server that sits in the middle of your calendar. When you generate availability, the app on your device talks directly to Microsoft or Google using their official APIs. Your free and busy times are processed locally, and the pasted result is copied to your clipboard on your machine.
We never receive your meetings, your attendees, your locations, or your pasted availability text. If our website or billing systems were unavailable, your connected calendars would still be readable by the app on your device through the credentials stored in your operating system keychain.
Calendar permissions
You choose which calendars to connect. Timely only requests the access it needs to read availability, and it cannot create, edit, or delete events on your behalf.
Microsoft 365 and Outlook
Timely uses Microsoft's OAuth sign-in and requests read-only calendar access through Microsoft Graph. That allows the app to see when you are free or busy so it can calculate open slots. It does not grant permission to change your calendar.
Google Calendar
Timely uses Google's OAuth sign-in and requests read-only access to the calendars you connect. Again, this is limited to reading availability information. Timely cannot modify events in your Google Calendar.
What Timely reads
- For availability: free and busy times only. Not meeting titles, attendees, locations, or notes.
- For calendar quick-view: event details are read only to draw the on-screen agenda grid, and only on your device.
- For multi-calendar workflows: only calendars you have explicitly connected or that are shared with a connected account.
What Timely never does
- Write, move, or delete calendar events.
- Send your calendar data to Timely servers.
- Sell or use your calendar data for advertising.
- Share your calendar with other Timely users.
How your credentials are stored
When you connect a calendar, the OAuth tokens that let Timely talk to Microsoft or Google are stored encrypted in your operating system keychain (macOS Keychain or Windows Credential Manager). They are not stored in plain text and are not sent to us.
Your license key is also stored locally and encrypted in the same way. Activating a subscription does not give us ongoing access to your calendar.
What leaves your device
Calendar data stays local. The only routine connections Timely makes outside your machine are:
- Direct calls to your calendar provider (Microsoft or Google) to read availability.
- License verification when you activate or renew a subscription, which does not include calendar contents.
Payments are handled by Polar. Polar receives billing information you provide at checkout. That is separate from your calendar and is covered in our Privacy Policy.
Provider compliance
Timely connects to Microsoft and Google using their official APIs and follows their platform policies. Our use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Questions
If you have security questions, or need help reviewing what Timely can access on your machine, email support@trytimely.co.