Privacy Policy
Last updated: 2026-07-22
overlap ("the app") is a static, backend-free world clock and meeting-scheduling tool. There is no server that overlap's developer operates or controls, and no account system. This page explains what data the app touches and where it goes.
What the app collects
Nothing is collected or stored by the developer. The app runs entirely in your browser:
-
Your clock configuration (which cities you've added, their colors, working
hours, and any scheduled meetings) is stored only in your browser's
localStorage, on your own device. -
When you use the "Share" button, that same configuration is encoded into the
URL itself (after the
#) so the link works for whoever you send it to — it is never uploaded anywhere. - No analytics, tracking scripts, or cookies are used.
Google Calendar access
If you choose to schedule a meeting, overlap asks you to sign in with Google and
requests the calendar.events scope.
Data Access
overlap never reads or lists your existing Google Calendar events. The only Google user data it accesses is the event it creates on your behalf — the title, start time, and end time you chose in the app — and, if you remove that meeting, the ID of that same event so it can be deleted.
Data Use
The calendar.events scope is used only to:
-
Create an event on your primary Google Calendar at the time you selected, via a
direct call from your browser to Google's Calendar API
(
POST /calendars/primary/events). -
Delete that event later, if you remove the meeting from the app
(
DELETE /calendars/primary/events/{eventId}).
No other use is made of this scope or of any Google user data.
Data Protection
Google classifies calendar.events as a sensitive scope, so here is
specifically how that data and the access token are protected. This entire flow
is client-side: your browser talks directly to Google over HTTPS/TLS-encrypted
connections — both to Google Identity Services (accounts.google.com)
for sign-in and to the Calendar API (www.googleapis.com) for
creating and deleting events — so the access token and any calendar data are
encrypted in transit at every step. overlap's developer never receives, sees, or
stores your Google access token, your calendar data, or any event you create —
there is no backend in the request path, and no developer-controlled server ever
sees this traffic. The access token itself is held only in an in-memory
JavaScript variable in your browser tab for the duration of the request: it is
never written to localStorage, cookies, or disk, is confined by the
browser's same-origin sandboxing to overlap's own page, and is discarded once the
request completes — each further action (or removing a meeting) requests a fresh,
short-lived token from Google rather than reusing a stored one. (A separate,
non-sensitive flag is saved to localStorage noting only that you've
connected before, so the app knows to show your existing meetings on this device
— this flag contains no token, event data, or other personal information.)
Data Transfer
The only third-party service the app talks to is Google (Google Identity Services for sign-in, and the Google Calendar API), and only when you explicitly choose to schedule or remove a meeting. No Google user data is sold, shared, or transferred to any other party, service, or server — there is nowhere else for it to go, since the app has no backend of its own.
Data Retention & Deletion
Since nothing is stored outside your own browser, you can remove all app data at any time by clearing your browser's site data for this domain, or by using the app's own remove-location / remove-meeting controls. Calendar events created via the app live in your Google Calendar and are governed by your Google account — remove them there, or via the app's delete action, at any time.
Contact
overlap is developed and maintained by Yaniv Aharon. Questions about this policy or the app's use of your data: ayaniv@gmail.com.