Privacy Policy for Just Team
Last updated: September 29, 2026
1. Overview
Just Team ("we", "our", or "us") provides schedule management and educational meeting synchronization services. This Privacy Policy explains how we collect, use, and protect your information when you use our platform and connect your Google Account via Google OAuth.
2. Google User Data We Access and Collect
When you connect your Google Account via Google OAuth, Just Team requests access only to the following Google user data:
Google Calendar events (Google Calendar API scope:
https://www.googleapis.com/auth/calendar.events)
- Access type: read, create, update, and delete events in your primary Google Calendar only.
- Data we read: for the week you are viewing in Just Team, the event ID, title, start and end time, the link to the event in Google Calendar, and the Google Meet link, if present. All-day events are skipped.
- Data we create and update: events for sessions you schedule in Just Team, with the session title, start and end time, and a Google Meet conference.
- Data we store: only the ID and Google Meet link of events created by Just Team. Events read from your calendar are not stored.
- Deletion: we delete events created by Just Team when the session is cancelled, and any other event of yours only when you explicitly click delete on it.
OAuth tokens: the access and refresh tokens Google issues for this scope, stored encrypted (see section 6).
Data exclusion: we do NOT use, display, or store event descriptions, locations, attendees, or attachments, and we do NOT access your Google profile, email address, contacts, Gmail, Google Drive, calendars other than your primary calendar, or any other Google data. Signing in to Just Team is done via Slack, not via Google.
3. How We Use Google Calendar Data
Our application interacts with your Google Calendar for the following specific functionality:
- Creating Events & Links: when you schedule an educational session in Just Team, we create the event with a Google Meet link directly in your calendar, and update or delete it when the session is rescheduled or cancelled.
- Calendar Synchronization: we display your existing events inside your personal portal on Just Team so you can plan sessions around your schedule. These events are fetched on demand and are not stored in our database.
- Public vs. Private Event Handling:
- Events created via Just Team link to our public educational topics (e.g., training sessions), which are stored in our system and managed according to platform roles (e.g., cancellations by authorized administrators).
- Personal events created outside of Just Team are strictly private. They are never published, shared with other users, or accessible to administrators or third parties. Only you can see your personal schedule inside your account interface.
4. Data Sharing and Third-Party Transfer
We share Google user data only as needed to provide the session scheduling feature:
- Google Meet link of an event created by Just Team is shown in Just Team to users who can view that session, and is sent to the participants in session announcements and reminders in your organization's Slack workspace.
Events read from your calendar are shown only to you and are never shared. We do not sell, trade, or rent Google user data, and we do not transfer it to third parties except as described above or when required by law.
5. Google API Services User Data Policy Compliance
Just Team's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google user data is used only to provide the user-facing features described in this policy. We do not use or transfer it for advertising (including retargeting and personalized or interest-based ads), do not sell it to data brokers or information resellers, do not use it to determine creditworthiness or for lending, and do not use it to train generalized AI or machine learning models. Our staff do not read your Google user data unless you explicitly ask us to (for example, for support), it is necessary for security purposes, or it is required by law.
6. Data Security and Protection of Sensitive Data
We treat Google OAuth tokens and Google Calendar data as sensitive data and protect them with the following technical and organizational measures:
- Encryption at rest: Google OAuth access and refresh tokens are stored in our database only in encrypted form, using authenticated symmetric encryption (Fernet: AES-128 in CBC mode with HMAC-SHA256). The encryption key is kept in the server's protected configuration, separately from the database, so a copy of the database alone does not reveal the tokens.
- Encryption in transit: all traffic between your browser and Just Team, and between Just Team and Google APIs, is encrypted with HTTPS (TLS). Plain HTTP requests are redirected to HTTPS, HTTP Strict Transport Security (HSTS) is enabled, and session and CSRF cookies are marked Secure and HttpOnly.
- Data minimization: we request only the narrowest scope our features
need (
calendar.events). Events from your calendar are fetched on demand to display them to you and are not stored in our database. - Access control: access to Just Team requires authentication via your organization's Slack workspace. Your Google tokens are bound to your account and are used only to access your own calendar on your behalf; they are never used to access another user's calendar and are never shown to other users or administrators in the interface.
- Infrastructure security: the application and database run on a dedicated server. Administrative access to the server is restricted to authorized maintainers and requires SSH key authentication; application secrets (including the encryption key and Google OAuth client credentials) are stored outside the source code repository.
- Revocation: when you disconnect Google Calendar, we revoke the token at Google and delete it from our database immediately. If Google reports a token as revoked or invalid, we delete it as well.
- Incident response: if we become aware of a security incident affecting your data, we will revoke the affected tokens and notify affected users without undue delay via a direct message in Slack, and publish a notice on Just Team.
7. Data Retention and Deletion
Google Calendar access tokens are stored encrypted and retained only for as long as your Google Account stays connected to Just Team. You can remove this data at any time in either of two ways:
- In Just Team: open Meetings → Calendar («Зустрічі → Календар») and click Disconnect («Відключити») next to "Google Calendar connected" («Google Calendar підключено»). We revoke Just Team's access at Google and delete your tokens from our database immediately.
- In your Google Account: remove Just Team in your Google Account Permissions settings. Your tokens are deleted from our database the next time Just Team attempts to use them.
The event ID and Google Meet link of events created by Just Team are kept as part of the session record for as long as the record exists, to preserve session history.
Events already created in your calendar remain there as your own data; you can edit or delete them in Google Calendar at any time. To request deletion of any other Google-related data we hold about you, contact us at the address below.
8. Changes to This Policy
If we change how Just Team accesses, uses, stores, or shares Google user data, we will update this policy and the "Last updated" date, notify users via Slack before the change takes effect, and ask for your consent again where required.
9. Contact Us
If you have any questions or concerns regarding this Privacy Policy or your data, please contact us at: vasilenkorobota@gmail.com