Privacy Policy

Effective July 13, 2026

topcal is operated by Top of Funnel, LLC (“topcal,” “we,” “us,” or “our”). topcal provides agent-native scheduling software that lets people and their AI agents connect a calendar, publish availability, and book meetings. This Privacy Policy explains what we collect, how we use it, and the choices you have. By using topcal (including app.topcal.ai and related APIs), you agree to this policy.

The marketing site at topcal.ai is covered by the same substance. The canonical product policy for OAuth and in-app use is topcal.ai/privacy.

Information we collect

  • Account & workspace data: name, email address, profile/booking identity fields, passkeys, workspace name and slug, team membership and roles, and the API keys you create for agents.
  • Calendar data (Google / Microsoft): when you connect a calendar, we access free/busy information and create, read, update, and cancel calendar events (including conference links such as Google Meet or Microsoft Teams) using the OAuth scopes you grant. Access and refresh tokens are stored encrypted at rest.
  • Booking data: event types, availability rules, bookings made with you — including invitee name, email, time zone, OTP verification for public or agent-assisted booking, and answers to intake form fields you configure.
  • Agent & API data: API key metadata, short-lived booking-intent tokens, MCP/REST request context needed to authorize actions, and audit logs of agent activity in your workspace.
  • Enrichment data (when enabled): prospect or invitee signals and credit usage used to generate prep briefs for your team. Enrichment is for your sales/meeting prep — we do not sell enrichment data as marketing lists.
  • Billing data: subscription status, plan, seat quantity, and limited payment descriptors surfaced by Stripe (for example card brand and last four digits). We do not store full card numbers; payments are handled by Stripe.
  • Usage & technical data: log data, IP address, and basic device or client information used to operate, secure, and debug the service.

How we use information

  • To authenticate you and operate your workspace.
  • To compute real availability and prevent double-booking against connected calendars.
  • To create and manage calendar events when a booking is made by a human or an authorized agent acting for a verified invitee.
  • To send transactional email (magic links, OTP codes, booking confirmations, invitations).
  • To operate billing, support, security, the agent API/MCP surface, and (when you enable it) enrichment prep features.
  • To prevent abuse and improve deliverability — for example, limiting OTP spam and detecting abusive booking patterns. Booking activity may be used for these protection purposes; it is not used for third-party advertising or sold as a marketing list.

Google user data & Limited Use

topcal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request only the Google scopes needed to sign you in (when you choose Google sign-in) and/or to read free/busy and create and manage events on calendars you connect.
  • We use Google user data only to provide and improve the scheduling features you request — never for advertising.
  • We do not sell Google user data, and we do not transfer it to third parties except as needed to provide the service (sub-processors below), for security, or to comply with law.
  • We do not allow humans to read Google user data unless you give explicit consent for a specific support request, it is necessary for security or to comply with law, or the data has been aggregated and anonymized.

Microsoft user data

When you sign in with Microsoft or connect a Microsoft calendar, we use Microsoft Graph with the permissions you grant (identity and calendar/meeting scopes as shown on the consent screen). We use that data only to provide scheduling features you request — not for advertising — and we do not sell it. You can disconnect a Microsoft calendar in topcal and revoke access in your Microsoft account permissions (for example via myapps.microsoft.com).

Calendar access in practice

  • Why we need access: to show accurate open slots and to write confirmed meetings (with optional Meet/Teams links) to the host calendar.
  • What we write: events for bookings you or your invitees/agents create through topcal; cancellations/updates for those same bookings.
  • How to disconnect: remove the connection under workspace Calendars in topcal, which deletes stored OAuth tokens for that connection. You may also revoke the app in Google or Microsoft account settings.

Sub-processors

We share data only with vendors that help us run topcal, under appropriate contractual terms:

  • Google and Microsoft — sign-in and/or calendar access you authorize.
  • Stripe — subscription billing and payments.
  • Supabase — authentication and application database.
  • Resend — transactional email.
  • Vercel — application hosting.

Retention & deletion

We keep your data for as long as your account or workspace is active, and for a limited period afterward as needed for backups, dispute resolution, security, and legal compliance (for example billing records). You can disconnect a calendar at any time from your dashboard, which revokes our access and deletes stored OAuth tokens for that connection. You may request deletion of your account and associated personal data by emailing support@topcal.ai or hello@topcal.ai; we will delete or anonymize personal data within 30 days except where retention is required by law. You can revoke Google access at Google Account permissions.

Security

Calendar OAuth tokens are encrypted at rest. Access to production systems is restricted and logged. No method of transmission or storage is perfectly secure, but we use industry-standard safeguards appropriate to the service.

International transfers

We may process data in the United States and other countries where we or our sub-processors operate. Where required, we use appropriate safeguards for cross-border transfers.

Children

topcal is not directed to children under 16, and we do not knowingly collect personal information from children.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights. We will not discriminate against you for exercising privacy rights available under applicable law.

Changes

We may update this policy from time to time. We will post the updated version here and revise the effective date above. Material changes will be communicated by email or in-product notice when appropriate.

Contact

Top of Funnel, LLC — privacy questions: hello@topcal.ai or support@topcal.ai.