Gyst← Back to home

Privacy Policy

Last updated: July 19, 2026

Gyst (“Gyst,” “we,” “us”) is a scheduling assistant that works on top of Google Calendar through a Chrome extension, an iOS app, and this website. This policy explains what we collect, why, and the choices you have. In short: we use your data only to run Gyst for you, and for nothing else.

Limited Use of Google user data

Gyst’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and to the Chrome Web Store User Data Policy. Concretely, this means we use Google user data only to provide and improve the user-facing features of Gyst — reading your calendar and creating or updating the events you approve. We do not use or transfer Google user data for advertising, we do not sell it, we do not use it for any purpose unrelated to Gyst’s scheduling features, and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. We process it only to run Gyst for you.

Information we collect

  • Account identity. When you sign in with Google we receive your name, email address, and profile image to create and identify your account.
  • Google Calendar data. With your permission we read your calendar events and create or update events you approve, so Gyst can suggest and place scheduling proposals.
  • Scheduling preferences. Work hours, timezone, and any preferences you provide, used to tailor suggestions.
  • Your AI provider key. If you supply your own model API key, we store it encrypted at rest and use it only to generate your scheduling proposals.

How we use information

We use your data solely to operate Gyst for you: syncing your calendar, generating and placing the scheduling proposals you approve, and remembering your preferences across the extension, iOS app, and web. We do not use it for advertising or profiling, we do not use it to train artificial-intelligence or machine-learning models, and we do not use it for any purpose beyond running Gyst. We share it only with the infrastructure providers below, which process it on our behalf and solely to provide their part of the service.

How Gyst generates proposals (AI processing)

To turn a request into calendar proposals, Gyst sends the minimum context it needs — the text of your request and the relevant details of your schedule — to an AI model provider (Google’s Gemini API), using the API key you provide. This processing happens only to generate the proposals you preview and approve, and nothing is added to your calendar until you approve it. We do not use your Google data, and do not use this AI processing of it, to build, improve, or train generalized AI or machine-learning models, to advertise, or for any purpose other than operating Gyst for you. If you remove your API key, this processing stops.

Because you bring your own Gemini API key, the tier of that key is under your control. On Gemini’s free tier, Google’s Gemini API terms allow Google to use prompts and responses to improve Google’s products, including with human review of de-identified samples. If you do not want that, enable billing on your key (the paid tier is excluded from that use). Gyst surfaces this same notice inside the extension before your first request.

The Chrome extension, specifically

  • Sign-in detection. The extension reads Gyst’s own session cookie on our domain to know whether you are signed in, and reads the account label on calendar.google.com only to avoid showing Gyst on the wrong Google profile. It never reads other sites’ cookies and never holds your Google password or OAuth tokens.
  • What leaves your device. When you submit a request, the extension sends your typed or dictated request text (and your timezone) over HTTPS to Gyst’s service, which processes it with your Gemini key as described above. Your Gemini key is transmitted once when you save it, then stored encrypted. The extension asks for your explicit agreement, in the extension UI, before the first request is ever sent.
  • Voice stays on your device. Dictation is transcribed locally by an on-device model; your audio is never uploaded to Gyst or anyone else. To do this, the extension downloads the speech-recognition model weights (about 200 MB, one time) from huggingface.co after you agree to the in-extension notice; only the final text transcript is used, and only if you send it.

Service providers

We rely on a small set of processors to run the service, each engaged to process data only to provide its part of Gyst: Google (calendar and sign-in), Google’s Gemini API (to generate the scheduling proposals you approve, using the API key you provide, as described above), and our hosting, database, and background-job providers. We do not sell your data, we do not use it for advertising, and we do not use it to train AI or machine-learning models.

Data retention & deletion

We keep your data while your account is active. You can request access to, or deletion of, your account and associated data at any time by emailing trygyst@gmail.com. You can also revoke Gyst’s access to your Google account at any time from your Google Account permissions.

Security

Data is transmitted over HTTPS and stored with access controls. Sensitive credentials, such as your AI provider key, are encrypted at rest. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your information.

Contact

Questions about this policy? Email trygyst@gmail.com.