privacy
The short version: Blocky is built so that the private thing is never sent to it in the first place.
What Blocky asks Google for
Exactly one calendar permission: “See the availability on your calendars” (the Google scope calendar.freebusy), plus your name, email and profile picture so your friends know which blocks are yours.
What Google sends back
A list of start and end timestamps for the times you are busy over the next five weeks. That is the entire payload. Event titles, descriptions, guests, locations, attachments, conference links and organizers are not included — the permission Blocky holds cannot return them, so they never reach this app and there is nothing here to leak, subpoena, or breach.
What Blocky stores
Your name, email, profile picture URL, those busy start/end timestamps, and an encrypted Google refresh token so the page can stay up to date without asking you to log in again. Refresh tokens are encrypted with AES-256-GCM before they touch the database.
Who can see it
Anyone holding the link to your group can see that you are busy at a given hour — never what you are doing. Do not share the link outside the group.
Deleting it
Tap the ✕ on your own chip in a group. Your busy blocks and your stored token are deleted immediately. You can also revoke Blocky at myaccount.google.com/permissions at any time.
What Blocky never does
No ads, no selling or sharing data with third parties, no analytics profiles, no writing to your calendar, and no use of your data to train any model. Blocky's use of information from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
terms · roshan.amurthur@gmail.com · Last updated 25 August 2026