Last updated: 16 September 2026
Turnabee collects only what it needs to put a task on someone else's calendar. We do not sell data, we do not run ads, we do not track you, and we do not analyse the contents of your calendar.
This shapes everything below, so it comes first:
When you sign in with Google we ask Google for three things and nothing else
(the scope is openid email profile):
| Your Google account ID | A stable number Google gives each account. We use it to recognise you when you come back. |
|---|---|
| Your email | To identify your account. |
| Your name | Shown in the app, and in the emails recipients get (“scheduled by …”). |
We never see your Google password. Sign-in happens entirely on Google's own pages.
iOS/26.0 dataaccessd).That last one exists to answer one question: did it actually connect? Without it the creator is guessing, and “thinking someone will be reminded when they won't” is the worst way this product can fail. We cannot see anything in their calendar, and we cannot see whether they turned notifications on.
What you type in: title, notes, category, dates and times, who it is for, who can see it, whether it appears on the shared calendar, and who ticked it off on what day.
This content is delivered as written to the recipients you choose — that is the whole point of the product. So please remember: what you type, they will read.
Three, all of them needed for the site to work, none of them for tracking:
sid | Remembers that you are signed in. |
|---|---|
gid | Remembers which group you are looking at. |
lang | Remembers the language you chose. |
There is no Google Analytics, no advertising pixel, and no third-party cookie.
Turnabee runs on Cloudflare and stores its data in Cloudflare D1. Beyond the three companies below, nobody else receives it:
| Cloudflare | Hosting and database. All data lives here. |
|---|---|
| Sign-in. Also used if you choose to connect Google Calendar (see below). | |
| Resend | Sends the digest email. Only the email addresses of recipients who provided one, and the contents of that email, pass through it. |
Today Turnabee uses Google only for sign-in.
We are adding an option for recipients to connect Turnabee to their own Google Calendar, so tasks appear directly on their calendar instead of depending on how often an external subscription URL is refreshed. If you choose to do that:
calendar.app.created, which means we can
only manage the one calendar Turnabee creates.
Your existing events and other calendars are neither readable nor writable by us.myaccount.google.com/permissions. After that we can no longer write anything, and you
can delete the calendar itself in Google Calendar.Limited Use: Turnabee's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Everything is served over HTTPS. Calendar subscription URLs are long random strings that cannot be guessed, and can be regenerated at any time, which immediately invalidates the old one. Note though: anyone holding that URL can see what is on it, so treat it like a password.
Turnabee is not a service for children and we do not knowingly collect children's data. A parent can of course add a child's name as a recipient in order to schedule things — that is just a name.
Changes update the date at the top. If a change materially affects how your data is used, we will say so on the site.
For any privacy question, or to request a copy of your data or its deletion, write to hello@turnabee.com.