Privacy Policy

Effective May 17, 2026

OverDue is a task scheduler that builds your week around your work, the recordings you connect, and the calendars you connect. This page explains what we collect, how we use it, and what control you have. Plain language, not legalese.

What we collect

  • Account. Your email address and a password hash. Optionally a display name.
  • Your tasks and settings. Tasks you create, categories, time windows, and busy blocks you add.
  • Recording connectors. When you connect a provider like Fathom, Fireflies, or Grain, OverDue stores an encrypted API key and pulls transcripts and action items from that provider on your behalf. You can disconnect at any time.
  • Google Calendar. If you connect Google Calendar, OverDue reads your events (their title and time) within the visible window to draw them on your week view, and reads your free/busy times so the scheduler can place tasks around your real meetings. We do not read attendee lists or send, create, edit, or delete anything on your calendar. Calendar data is fetched fresh each time you open the dashboard and is never stored on our servers.
  • Cookies. A session cookie to keep you signed in. No advertising or third-party tracking cookies.

How we use it

Only to run the service: store your tasks, fetch transcripts from connectors you authorize, schedule your week around your real availability, and send you account emails (signup confirmation, password reset). We do not sell your data, share it with advertisers, or use it to train models.

Google user data

OverDue’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we request only the calendar.readonly scope, which is read-only; we read your event titles and times to display your calendar on your week view, and your free/busy times to schedule tasks around your real availability; we do not read attendee lists, and we never write to, modify, or delete anything on your calendar; we do not store your calendar data on our servers (it is fetched fresh per dashboard view); and we never sell it, transfer it to third parties, use it for advertising, or use it (or data derived from it) to train generalized or personalized AI or ML models.

Where it lives

  • Database and auth. Supabase, in the US East region.
  • Web hosting. Vercel.
  • Transactional email. Resend, used only to send you account emails.
  • Recording providers and Google. When you connect a provider, OverDue communicates with their API on your behalf. Their terms and privacy policies cover what they do with your data on their side.

Your rights

You can export your tasks, disconnect any provider, change or delete your data, and delete your account at any time. To request an account deletion or a copy of your data, email us at the address below. We respond within seven days.

Children

OverDue is not intended for anyone under 13. We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.

Changes

If we materially change how OverDue handles your data, we will update this page and email everyone with an active account before the change takes effect.

Contact

Questions, requests, or concerns: smrichardson2507@gmail.com.