Privacy Policy
Last updated: August 13, 2026
intelliLesson (“we”, “our”, “the platform”) is a lesson booking and management platform for instructors and their clients. This policy explains what data we collect, how we use it, and your rights.
1. Information we collect
From instructors (account holders)
- Account information: name, email address, business name.
- Calendar data: when you connect Google Calendar, we access your calendar events and free/busy information to sync lesson bookings and prevent scheduling conflicts.
- Google email sending: when you authorize Gmail Send, we use that permission to send transactional lesson messages from your connected mailbox. We do not read your inbox, messages, replies, labels, contacts, or drafts.
- Booking data: lesson schedules, client bookings, lesson notes, availability settings, location information.
From clients (people booking lessons)
- Contact information: name, email address, phone number — provided during booking or by the instructor.
- Booking history: lesson dates, times, types, and status.
Automatically collected
- Usage data: pages visited and features used.
- Device information: browser type and operating system, for compatibility.
2. How we use your data
- Booking management: schedule, confirm, reschedule, and cancel lesson bookings.
- Calendar synchronization: sync bookings with your Google Calendar so lesson appointments appear alongside personal events, and detect scheduling conflicts via free/busy data.
- Notifications: send booking confirmations, approvals, rejections, cancellations, reminders, client-access links, and status updates through configured channels — including the connected instructor's mailbox when authorized.
- Account management: authenticate users, manage instructor profiles, process onboarding.
3. Google API data (Limited Use disclosure)
intelliLesson's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We access Google Calendar data only to synchronize lesson bookings and check free/busy availability.
- We use Gmail Send only to send transactional lesson messages initiated by defined intelliLesson workflows or an instructor action.
- We do not request permission to read Gmail messages, inspect replies, manage drafts, apply labels, or access Google Contacts.
- We do not use Google API data for advertising, sell it, or use it to build advertising profiles.
- We do not use Google Workspace APIs, or any data obtained through them, to develop, improve, or train generalized or non-personalized AI and/or ML models. Note suggestions are drawn only from your own previously written notes, ranked by how often you have used them.
- We do not allow humans to read Google API data except where necessary to provide support you requested, protect security, or comply with applicable law.
- We store calendar sync tokens and event IDs for incremental synchronization; we do not store the full content of personal calendar events.
- We may store transactional-message delivery intent and provider outcome for operational reliability and audit history, but we do not retrieve or store the instructor's Gmail inbox.
4. Data sharing
We do not sell, rent, or trade your personal data. We share data only with:
- Supabase — database hosting and authentication.
- Vercel — application hosting.
- Google — Calendar synchronization and transactional Gmail sending, only when you connect and authorize your Google account.
- Nylas — a planned integration processor for the authorized Google Calendar and Gmail Send connection. Nylas does not receive broader production permissions than intelliLesson requests.
- Twilio — SMS notifications, when enabled by the instructor.
5. Data retention
- Active accounts: data is retained as long as your account is active.
- Deleted accounts: upon account deletion we remove your personal data within 30 days, except where retention is required by law.
- Google connection tokens and calendar sync state: removed when you disconnect the Google integration.
- Transactional delivery records: retained with the related business record as needed for reliability, support, security, and audit history.
6. Your rights
You have the right to:
- Access your personal data.
- Correct inaccurate data.
- Delete your account and associated data.
- Disconnect the Google integration at any time from your account settings.
- Export your booking data.
To exercise these rights, contact us at the email below.
7. Security
We use industry-standard security measures including:
- Encrypted connections (HTTPS/TLS).
- Row-level security on all database tables.
- OAuth 2.0 for Google authentication — we never see your Google password.
- Encrypted token storage for Google connections.
8. Children's privacy
intelliLesson is not directed at children under 13. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this policy from time to time. We will notify account holders of material changes by email or in-app notification.
10. Contact
For privacy questions or data requests, email privacy@intellilesson.com.
