Skip to content
Neos Meet is in public beta.3 months of any paid plan free for every beta user — and permanent perks for the first 100.See the beta terms

Privacy Policy

Last updated July 13, 2026

This Privacy Policy explains how RSpond Inc("RSpond", "we", "us"), a Delaware corporation and the provider of Neos Meet, collects, uses, stores, and shares information when you use our scheduling service at meet.neos.network (the "Service"). RSpond Inc is the data controller for that information. By using the Service you agree to this policy.

Who this applies to

The Service has two kinds of users: hosts, who sign in with Google to create booking links and connect a calendar, and invitees, who book time with a host through a public booking page without signing in.

Information we collect

  • Host account data (from Google): your name, email address, and profile picture, obtained when you sign in with Google.
  • Google Calendar data: with your permission, we read your calendar free/busy information to determine when you are available, and we create, update, and cancel calendar events for the bookings you receive — only on calendars you own. The free/busy permission we request is technically incapable of returning event titles, attendees, or contents. The events permission is a broader write scope covering events you organize, because Google offers none narrower; we do not request access to calendars merely shared with you, and we do not list or read events other than the ones Neos Meet itself created.
  • Scheduling configuration: event types, availability hours, timezone, and booking links that you create.
  • Invitee booking data: the name, email address, timezone, and any notes an invitee provides when booking a meeting.
  • Product analytics: pages viewed, the features you use, and the marketing source that first brought you to the site. See the section below for exactly what this does and does not include.

Product analytics

We use PostHog (PostHog, Inc., United States) to understand how the Service is used — which pages people visit, which features hosts use, and how many visitors from a given marketing campaign go on to create an account. PostHog processes this data on our behalf as a sub-processor.

  • We do not send your email address to our analytics provider. Hosts are identified only by an anonymous identifier or a one-way cryptographic hash, so analytics answers questions about counts and cohorts rather than about individuals.
  • We never send Google Calendar data — not event titles, attendees, contents, or free/busy times — to our analytics provider.
  • We never send invitee booking details— an invitee's name, email address, or notes are not included in analytics. Public booking pages record only that a page for a given booking link was viewed.
  • No session recording on public booking pages. Invitees are not recorded. Where session replay is used at all, it is limited to signed-in host screens and all form inputs are masked before anything leaves the browser.
  • Marketing attribution: if you arrive with campaign parameters in the URL (for example utm_source), we store those plus the referring site and the page you landed on in a first-party cookie, and record them with your account if you sign up. This is how we measure which channels work. Clearing your cookies clears it.

Analytics is loaded only where it is configured; the Service functions normally with it disabled, and browser "Do Not Track" and tracker-blocking settings are not circumvented.

Transactional email

Booking confirmations, reminders, cancellations, and account notices are sent through Resend. We do not enable open-tracking pixels or click/link rewriting on these messages, so they are not instrumented to report whether you opened them or which links you clicked. Some emails link to our own site with a campaign tag (for example utm_source) — that tag names the channel the message came from, not you, and it is the only link tracking of any kind we use.

The setup assistant

If you use the optional in-product setup assistant — the chat that helps you configure event types and availability — your side of that conversation is processed on our behalf by Amazon Web Services (Bedrock), which runs the Anthropic Claude model. We send it Your side of the assistant conversation (what you type); The titles and descriptions of the event types it helps you edit; Any location detail on those event types — your own meeting URL, phone number, or address. We never send it Any Google Calendar data — your free/busy times, your events, or any connected-calendar contents; Invitee names, emails, or anything an invitee entered; Your bookings. Amazon Bedrock does not use your inputs or outputs to train any model, and does not share them with model providers. No Google account data is sent to it, and nothing you send it is used to train or improve any AI model. It runs only when you open it, plays no part in booking, and sees nothing about your invitees or your calendar. It is listed on our sub-processor page whenever it is enabled.

How we use Google user data

We use Google account and Google Calendar data solely to provide the scheduling features you request: to authenticate you, to show times you are free, to place confirmed bookings on your calendar, and to generate Google Meet video links for those bookings. We do not use Google user data for advertising, and we do not use it to train generalized artificial intelligence or machine-learning models.

Limited Use disclosure

Neos Meet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the calendar scopes necessary to operate scheduling, and we do not sell Google user data or transfer it to third parties except as needed to provide the Service or as required by law.

How we share information

We do not sell your data. We share information only as necessary to run the Service: a confirmed booking is shared between the host and the invitee (including the calendar event and video link), and we rely on sub-processors who process data on our behalf under their own terms. Our sub-processor list is the authoritative, maintained version — it names each provider, what it processes, and where. If you need a signed processing agreement, our data processing addendum is published in full.

Data retention and deletion

We retain your scheduling configuration and bookings for as long as your account is active. You may disconnect a calendar at any time from your settings, which always deletes the stored calendar credentials. What happens to the grant depends on the provider, and the difference is worth stating rather than glossing:

  • Google — we ask Google to revoke the grant. If Google does not confirm the revocation we tell you so and point you at your Google Account permissions page, rather than reporting a revocation we cannot vouch for.
  • Outlook / Microsoft 365we cannot revoke it for you. Microsoft publishes no way for an application to revoke its own delegated consent; the only mechanisms available would either require your administrator or would sign you out of every application you have ever authorised, which is not ours to do. So disconnecting deletes our copy of the credential — after which we hold nothing that can reach your calendar — but the grant remains listed under your account until you remove it at myapps.microsoft.com → Enterprise applications. We say so in the product at the moment you disconnect, not only here.

Both export and erasure are self-serve, from Settings → Data & privacy. Export downloads a machine-readable copy of your profile, event types, availability, bookings and their invitees, team links, calendar connections, and a billing summary. Deleting your account is immediate and irreversible: it cancels your upcoming meetings and notifies the invitees, revokes our access to your Google account with Google, (for Microsoft connections, see the limitation above — we delete the credential but cannot revoke the grant) cancels any active subscription, and deletes your payment profile at Stripe.

A few small records survive deletion, and we would rather say so plainly than let you discover it later. Paid invoices and receipts are retained — tax and accounting law requires us to keep them, and that obligation overrides an erasure request for those records specifically. Database backups are not edited; they age out on their normal retention cycle, after which the data is gone from them too. A deleted-account marker is kept — a one-way hash of your email address, not the address itself, so a released booking handle is not silently reassigned during its quarantine window and the account cannot be re-created behind your back. And if you had unsubscribed or an email to you had bounced, that email-suppression record stays on our do-not-contact list: deleting your account does not license us to start emailing that address again. Both keep the minimum needed to honor a promise to you, and nothing more.

You can also revoke access directly from your Google Account permissions page, or from myapps.microsoft.com for a Microsoft account, which cuts our access immediately regardless of anything on our end. For the full list of who else processes your data, see our sub-processors.

Security

Calendar access credentials are stored server-side and used only to make requests to Google on your behalf. Access to the Service is transmitted over HTTPS.

Contact

Questions about this policy? Email support@neos.network.

The data controller is RSpond Inc, a Delaware corporation, registered office 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Email reaches us faster than post.