Next Meeting

Privacy policy

Effective date: October 11, 2026 · Contact: hello@sunday.engineering

What the plugin accesses

With your permission, Next Meeting reads your Google account identifier and email address, your calendar list, and events from calendars you select. Event responses may include titles, times, attendance information, calendar event links, and video meeting links. The plugin uses these responses to select and display the next eligible timed meeting, merge duplicate invitations, and open Google Meet or the calendar event when you press a key. It does not create, edit, or delete calendar events.

Where data is stored

OAuth access and refresh tokens, connected account information, and calendar selections are stored locally in macOS Keychain. Events are held in memory while the plugin runs. After a failed sync, cached events are used for at most fifteen minutes before the next refresh discards them. Key appearance settings are stored by Stream Deck and can be included when you export a profile. Account tokens are not stored in exported profiles.

Who receives data

The release candidate uses a Sunday Engineering OAuth service hosted on Cloudflare for Google sign-in and token refresh. This service transiently handles authorization codes and OAuth tokens over HTTPS. It stores encrypted sign-in sessions and authorization codes for up to ten minutes, then they expire; it does not persist access or refresh tokens. The plugin reads calendars directly from Google. Displayed meeting information is sent locally to Stream Deck. Opening a meeting sends its URL to your default browser. Calendar contents are not sent to the OAuth service. Account tokens remain in macOS Keychain, and pass through the service when sign-in or refresh is needed. Request contents are not intentionally logged. Cloudflare processes network/request metadata to operate and secure the service. We do not sell calendar data, use it for advertising, or use it to train AI models. The plugin contains no analytics or advertising SDK.

Google API data

Next Meeting’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Disconnecting and deletion

Choose Disconnect beside an account to remove its tokens and account data from the plugin’s Keychain record. Calendar data for that account is cleared from the plugin’s cache on the resulting refresh. Disconnecting does not revoke Google’s authorization grant. To revoke permission, remove Next Meeting in your Google Account connections. Uninstalling the plugin alone may leave its Keychain record behind; disconnect your accounts first.

Support and this website

If you email support, we receive the information you choose to send. Do not include passwords, OAuth JSON files, tokens, or private meeting links. We use support messages to respond to your request. This static website does not add analytics or tracking cookies. Its hosting provider processes ordinary request information, such as IP addresses, to deliver and secure the website.

Changes and questions

We update this page when the plugin’s data practices change. Contact hello@sunday.engineering about this policy or a data request.