Privacy Policy

    Last updated: September 22, 2026

    This Privacy Policy explains how Shastia, LLC, doing business as Breaker1 ("Breaker1," "we," "us," or "our"), collects, uses, shares, and protects information when you use our websites, scheduling service, applications, browser extension, and related integrations (the "Service").

    1. Information We Collect

    1.1 Account and profile information

    We collect your name, email address, username, authentication information, profile photo, biography, time zone, availability, meeting preferences, and other settings you provide. If you sign in with Google or Microsoft, we receive basic identity information such as your name, email address, and profile image. Your name, username, profile image, biography, meeting types, and scheduling settings may appear on public booking pages as you configure them.

    1.2 Booking, guest, team, and support information

    We collect information needed to arrange and manage meetings, including guest names and email addresses, meeting purpose, participants, time zone, proposed and selected times, approval status, booking history, cancellation or reschedule details, and video-conference links. Team and group features also process team membership, invitations, routing rules, participant details, and combined availability. Other participants see the scheduling result, not the private details of events that caused a person to be busy.

    If you contact support, we process your email address, message, account identifier when signed in, and information you choose to include. If SMS alerts are enabled, we store your verified phone number and alert preference.

    1.3 Technical and activity information

    We collect service activity and security information such as login and connection status, integration errors, audit and agent-action records, API request outcomes, device or browser data ordinarily included in web requests, and pseudonymous identifiers used for rate limits and booking-page visitor counts. We do not use advertising cookies or sell personal information.

    2. How We Use Information

    • Provide booking pages, availability, meeting creation, calendar sync, team and group scheduling, and booking management.
    • Operate mailbox and browser-extension scheduling assistance, including drafts, approvals, negotiation, and permitted automated actions.
    • Authenticate users, process payments, send service communications, provide support, and maintain user preferences.
    • Secure the Service, enforce limits and host rules, prevent abuse, troubleshoot failures, and maintain audit records.
    • Improve reliability and understand aggregate product use without using personal data for targeted advertising.

    We do not sell your personal information.

    3. Calendar Integrations

    3.1 Google and Microsoft connections

    Hosts may connect Google Calendar or Microsoft Outlook Calendar. Depending on the features selected, Breaker1 requests identity, offline access, calendar free/busy, calendar read/write, event-management, online-meeting, and related permissions. We store encrypted authorization tokens, provider email addresses, selected calendars, connection status, and sync state so the connection can continue to work.

    For ordinary availability checks, we use free/busy information and do not need to show event titles or descriptions to guests. When a booking is confirmed, we create or update the required event, attendees, and Google Meet, Microsoft Teams, Zoom, or other configured meeting details.

    3.2 Guest calendar access

    A guest may optionally connect a Google or Microsoft calendar to compare mutual availability. Guest authorization is limited to the booking or group-scheduling flow and may be held temporarily in the browser or processed by our servers, depending on the flow. We do not display the guest's private event details to the host or other participants.

    3.3 Calendar sync and replication

    Calendar Sync is separate from ordinary free/busy scheduling. In two-way mode, Breaker1 reads and replicates events among selected calendars in both directions. In one-way mode, events are copied from the primary calendar to selected calendars. This can include event title, description or notes, location, start and end times, all-day status, updates, and deletions. Read-only mode copies no events and uses selected calendars only to block availability.

    To prevent duplicate copies and apply later changes, we store provider event IDs, sync markers, change tokens, checksums, and replica mappings. Event content is read and transmitted to the connected calendar providers as needed for replication.

    3.4 Disconnecting a calendar

    You can disconnect calendars in the Service or revoke access in your Google or Microsoft account. Disconnecting removes the applicable authorization token and cleans up associated sync state and memberships. Copies already created in an external calendar may remain there until removed from that provider.

    4. Mailbox Scheduling Agent and AI

    4.1 Mailbox permissions

    If you enable the mailbox agent, you separately authorize Gmail or Microsoft Outlook access. Available modes may include Gmail compose-only access, Gmail inbox read and send access, and Microsoft mailbox read/write access for reading messages and creating drafts. The permissions shown during connection control what Breaker1 can do. Calendar and mailbox grants are stored separately.

    4.2 What the agent processes and stores

    The agent may scan recent mailbox history and new messages for scheduling requests. For classification and reply interpretation, Breaker1 sends the message subject and context, sender and recipient addresses, and a message excerpt of up to 2,000 characters to Google Gemini through the Lovable AI Gateway. Submitted content is used to provide the feature and is not permitted to be used to train the models.

    Message bodies and excerpts are processed in transit and are not stored by Breaker1. We may store encrypted mailbox tokens, provider and mailbox identifiers, thread references, short subject hints, participant addresses, proposed times, scheduling decisions, timing preferences, known-contact summaries, safety results, and action logs. Disconnecting a mailbox removes the connection and stored thread history. Some security, communication-suppression, or legal records may be retained as described in Section 10.

    4.3 Drafts, sends, and controls

    Depending on the connection and autonomy level you choose, the agent may suggest a response, create a draft for review, send a Gmail reply, negotiate scheduling, or book, reschedule, or cancel a meeting. Host rules, recipient limits, sensitive-topic checks, approval settings, activity records, and the pause control govern these actions. You can change these settings or disconnect the mailbox at any time.

    5. Browser Extension and Invitations

    • Manual lookup: When you highlight a name or email and choose the lookup action, only that selected text is sent to Breaker1 to find a matching user and calculate availability. We do not receive the page URL, the rest of the page, or browsing history.
    • Gmail auto-detect: If enabled with in-extension consent, the extension inspects only the Gmail thread currently open. It first checks for scheduling language locally. On a match, up to 2,000 characters and thread addresses are sent for the AI processing described above. Attachments are not sent.
    • Participant invitations: When you choose to invite someone, we process the recipient email and a short context hint, check delivery suppression and duplicate limits, and send the invitation. A limited invitation record is retained to enforce those limits.
    • Control: You may disable auto-detect or remove the extension. Removing it clears its local data. The extension itself cannot send replies from your mailbox.

    6. Outside Assistants, MCP, and API Keys

    You may authorize outside assistants and applications, including ChatGPT, Claude, or other MCP/API clients, to check availability and request bookings, reschedules, or cancellations. Host rules and granted key scopes limit these actions. We store hashed API keys and request logs that may include the tool used, result, outside agent identifier, target user, error details, metadata, and a rotating pseudonymous IP hash for security and rate limiting. Plaintext API keys are shown only when created and can be revoked by the account owner.

    7. Payments

    Square processes payment-card information for Pro subscriptions. Breaker1 receives customer and subscription identifiers, billing cycle, payment status, trial and renewal dates, and limited card details such as brand and last digits when provided by Square. Breaker1 does not receive or store your full card number or card security code.

    8. Communications

    We send account verification, password recovery, booking, agent-decision, approval, team invitation, billing, service, and support emails. If SMS alerts are enabled, our delivery provider receives the verified phone number and booking-alert content, which can include guest name, email, date, time, and duration. You can disable SMS alerts and remove the number in the Service. We retain delivery, bounce, unsubscribe, and suppression information as needed to honor communication choices and protect deliverability.

    9. Service Providers and Disclosures

    We disclose information only as needed to operate the Service: to hosting, authentication, database, storage, and email infrastructure providers; Google and Microsoft for identity, calendars, mailboxes, and video meetings; Square for payments; Google Gemini through the Lovable AI Gateway for the AI features described above; Brevo and other delivery providers for transactional email or SMS; and Zoom or other video providers you select. Their handling of information is also governed by their terms and privacy policies.

    We may disclose information when required by law, to protect rights and safety, to investigate abuse, or in connection with a merger, financing, acquisition, or sale of assets. We do not disclose personal information for cross-context behavioral advertising.

    Breaker1's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    10. Storage, Security, and Retention

    We use access controls, encryption in transit, and encryption at rest for sensitive credentials. No system is completely secure, and we cannot guarantee absolute security. We retain account and scheduling information while needed to provide the Service. Connection data is removed when the relevant integration is disconnected; account data is deleted when the account is deleted, subject to records we must keep for payment, tax, fraud prevention, security, legal, suppression, dispute, backup, or service-integrity purposes. Those records are kept only as long as reasonably necessary for the applicable purpose.

    11. Cookies and Measurement

    We use essential cookies and local or session storage for authentication, preferences, and temporary booking state. We also use a pseudonymous visitor identifier to count unique visits to a host's booking page and rotating pseudonymous IP hashes to secure and rate-limit agent requests. We do not use advertising cookies or third-party behavioral advertising trackers.

    12. Your Choices and Rights

    Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your information. Account Settings lets you update profile information, export core account, profile, meeting-type, and booking data, disconnect calendars or mailboxes, pause the agent, revoke API keys, remove a phone number, and delete your account. You may also revoke provider access directly with Google or Microsoft. To make another privacy request, email privacy@breaker1.ai. We may need to verify your identity before completing a request.

    13. Children's Privacy

    The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided such information, contact us so we can address it.

    14. Changes to This Policy

    We may update this policy as the Service changes. We will post the revised date and, when appropriate, provide additional notice by email or through the Service.

    15. Contact

    For privacy questions, contact Shastia, LLC at privacy@breaker1.ai. For general support, email support@breaker1.ai.