Privacy Policy
Last updated: 7 July 2026
WhenWeFree ("we", "our", or "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
Who we are
WhenWeFree is a group availability app built to help people find when everyone is free. We are operated by WhenWeFree, based in the United Kingdom. Contact us at hello@whenwefree.app.
What data we collect
We collect only what is necessary to provide the service:
- Display name - the name you enter when you first open the app. This is visible to members of your groups.
- Availability dates - the dates you mark as free. These are shared with members of your groups to calculate overlap.
- Anonymous user ID - a randomly generated ID created automatically when you use the app. No email address or password is required for free tier use.
- Group data - group names, invite codes, and event details you create.
- Google account information - if you choose to upgrade to Premium, we collect your Google account email address and a unique Google ID via Google Sign-In. This is used solely to link your Premium subscription to your account.
- Subscription status - whether you hold an active Premium subscription, managed via Google Play Billing. We do not store payment card details. All payment processing is handled by Google Play.
- Push notification token - a device token generated by Firebase Cloud Messaging (FCM) used to deliver notifications about group updates and events. This token is not linked to your identity and is not shared with third parties.
- Google Calendar data - if you choose to use the Google Calendar sync features, we request read access to import your calendar events as busy days, and write access to export confirmed events to your calendar. We do not store your calendar data on our servers. Calendar data is accessed in real time and used only to perform the action you request.
What we do not collect
- We do not collect your phone number
- We do not collect your precise location
- We do not collect payment card information
- We do not sell your data to third parties
- We do not use your data for advertising profiling
How we use your data
- To show your availability to members of groups you have joined
- To calculate shared free days within your group
- To display your name to other group members
- To allow you to create and view events
- To link your Premium subscription to your account via Google Sign-In
- To process and verify your Premium subscription via Google Play Billing
- To send push notifications about group activity and confirmed events
- To sync your Google Calendar when you choose to use this feature
Data sharing and disclosure
We do not sell your personal data to any third party. We do not share your data with advertisers or use it for any purpose unrelated to providing the WhenWeFree service.
We share or transfer user data only in the following limited circumstances, solely to provide the functionality of the app:
- Google Firebase (Firestore and Authentication) - your display name, availability dates, group data, anonymous user ID, and Google account information are stored in Google Firebase Firestore, hosted in the European Union. Firebase Authentication is used to manage your account session. Google acts as a data processor on our behalf.
- Google Play Billing - your subscription purchase data is processed by Google Play. We receive confirmation of your subscription status from Google Play in order to unlock Premium features. We do not receive or store your payment card details.
- Google Calendar API - if you choose to use the Calendar sync feature, your calendar event data is transmitted to and from the Google Calendar API in real time to perform the action you request. This data is not stored on our servers and is not shared with any other party.
- Firebase Cloud Messaging - your device notification token is shared with Firebase Cloud Messaging solely to deliver push notifications to your device.
No other third parties receive, access, or process your personal data. We do not transfer your data outside of the above named services.
Data protection mechanisms
We take the security of your data seriously and implement the following technical and organisational measures to protect it:
- Encryption in transit - all data transmitted between the app and our servers is encrypted using HTTPS/TLS. This includes all communication with Firebase, the Google Calendar API, and Google Play Billing.
- Encryption at rest - all data stored in Google Firebase Firestore is encrypted at rest by Google using AES-256 encryption.
- Firebase Security Rules - access to your data in Firestore is controlled by Firebase Security Rules, which ensure that users can only read or write data they are authorised to access. Group data is only accessible to verified members of that group.
- Google OAuth 2.0 - Google account authentication is handled entirely by Google via OAuth 2.0. We never receive, handle, or store your Google password. OAuth tokens are managed securely by the Google Sign-In SDK and are not stored on our servers.
- Calendar data not stored - Google Calendar data accessed via the Calendar API is used ephemerally and in real time only. It is never written to or stored on our servers or in our database.
- Minimal scope access - we request only the minimum OAuth scopes necessary to provide the features you use. Calendar access is only requested when you explicitly choose to use the Calendar sync feature.
- Anonymous authentication - the core app functionality does not require you to provide any personally identifiable information. Anonymous accounts are used by default to minimise data exposure.
- Access controls - access to production systems and user data is restricted to authorised personnel only.
Google API Services User Data Policy
WhenWeFree's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve the features that are visible to the user in WhenWeFree
- We do not use Google user data for serving advertisements
- We do not allow humans to read Google user data unless we have your affirmative agreement, it is necessary for security purposes, or we are required to do so by law
- We do not transfer Google user data to third parties except as necessary to provide or improve the app's features, comply with applicable law, or as part of a merger or acquisition
Google Sign-In
If you upgrade to Premium, you will be asked to sign in with your Google account. This allows us to securely link your subscription to your WhenWeFree account. We use Google Sign-In via Firebase Authentication. Your Google credentials are handled entirely by Google and are never stored on our servers. You can read Google's privacy policy at policies.google.com/privacy.
Google Play Billing
Premium subscriptions are processed entirely by Google Play. We do not handle, store, or have access to your payment card details. When a purchase is verified by Google Play, we update your account status in our database to reflect your Premium subscription. You can manage or cancel your subscription at any time via the Google Play Store. We use Google Play's Real-time Developer Notifications to automatically keep your subscription status up to date, including reflecting cancellations, renewals, or expirations.
Push notifications
We use Firebase Cloud Messaging (FCM) to send push notifications. A device token is generated automatically to enable this. You can disable push notifications at any time via your device settings. Notification tokens are not linked to your identity and are not shared with third parties.
Google Calendar access
The Google Calendar sync features require access to your Google Calendar. We request:
- Read access - to identify your busy days and automatically mark your availability in WhenWeFree
- Write access - to add confirmed group events to your Google Calendar (Premium only)
We do not store your calendar data. All calendar access is performed in real time at your request. You can revoke calendar access at any time via your Google account settings at myaccount.google.com.
Our use of Google Calendar data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Data storage
Your data is stored securely using Google Firebase (Firestore), hosted in the European Union. Google Firebase complies with GDPR. You can read Google's privacy policy at policies.google.com/privacy.
Data retention
Your data is retained for as long as you use the app. You can request deletion of your data at any time by contacting us at hello@whenwefree.app and we will delete it within 30 days. If you hold a Premium subscription, cancelling your subscription does not automatically delete your account data.
Your rights (GDPR)
If you are based in the UK or European Union you have the following rights:
- Right to access - you can request a copy of your data
- Right to erasure - you can request deletion of your data
- Right to rectification - you can request correction of your data
- Right to portability - you can request your data in a portable format
To exercise any of these rights contact us at hello@whenwefree.app.
Third party services
WhenWeFree uses the following third party services which have their own privacy policies:
Children
WhenWeFree is not directed at children under the age of 16. We do not knowingly collect data from anyone under the age of 16.
Changes to this policy
We may update this privacy policy from time to time. We will notify users of significant changes by updating the date at the top of this page.
Contact
If you have any questions about this privacy policy please contact us at hello@whenwefree.app.