PRODUCT GUIDE

Meetin.gs security and privacy overview

Learn how calendar data, access, sessions, and integrations are protected.

Short answer: Learn how calendar data, access, sessions, and integrations are protected. Begin with “Classify the calendar, participant, and free-text data in the workflow.” and verify the result through the public participant path.

Organizer access is protected by verified Google identity, sessions are secure, and email delivery is logged. What is stored and for how long is on the security page and in the privacy policy. Guests never need an account, and private event titles never appear on a public page.

Before you start

  • The data in your workflow: calendar, participant, free text.
  • Who needs access, and the minimum they need.
  • How you would report a scheduling-data incident.

How to complete this task

  1. Classify the calendar, participant, and free-text data in the workflow.
  2. Restrict access and integration permissions to the minimum required.
  3. Set secure session, transport, backup, logging, and retention controls.
  4. Practice reporting and responding to a scheduling-data incident.

Finish by opening the public link in a signed-out browser: a saved setting is not proof that the guest path works.

Troubleshooting

The problems people report most often with this task, and the cause behind each one.

What participant data does a booking hold?

Name, email address, chosen time, and any answers you requested. Free-text answers are the highest-risk field, so ask for them only when necessary.

Who can see a private booking page?

Anyone with the URL. These links are unguessable and unindexed, but they are not access-controlled — treat them as shareable secrets.

How should a scheduling incident be handled?

Decide in advance who is notified, who revokes integration access, and how affected participants are told. Practise it before you need it.

Related Meetin.gs help

Return to the Meetin.gs Help Center for the adjacent configuration guide, or send the exact event code and expected result when the documented checks do not explain the behavior.

RELATED CAPABILITY

Administration and governance

Manage users, groups, roles, event standards, domain policy, integrations, and activity from one place. This page explains administration and governance requirements. Confirm production availability before depending on this capability.

Review scope

Frequently asked questions

Short answers to what organizers ask most about this task.

Is a booking page private?

It is unindexed and its URL is unguessable, but anyone holding the link can open it. Treat these links as shareable secrets rather than access-controlled pages.

What participant data does a meeting hold?

Name, email address, chosen time, and any answers you requested. Free-text answers carry the most risk, so ask for them only when they change your preparation.

How is scheduling data protected in transit?

Traffic is served over HTTPS with strict transport security, a content security policy, and same-origin framing controls. Session cookies are HTTP-only and marked secure in production.

What should an incident plan cover?

Who is notified, who revokes integration access, how affected participants are told, and what evidence is preserved. Decide it before you need it.