Last updated 7 August 2026
This policy explains what Apointo collects, why, and what we do with it — including exactly what we do with your Google Calendar data if you choose to connect it.
Apointo is an appointment scheduling app operated by NxtGenAiDev. It connects hosts (such as consultants, doctors or coaches) with their visitors so appointments can be booked against the host's real availability.
We keep the minimum needed to run scheduling. Specifically:
Identity: your name, and the phone number or email address you sign in with. Sign-in is handled by the NxtGenAiDev authentication service, which verifies your phone or email with a one-time code. Apointo never sees or stores a password.
Preferences: your time zone, and — if you act as a host — your working hours, appointment length, buffer and minimum notice.
Visitor entries: if you are a host, the name and phone number or email address you save for each visitor, so they can be connected to you when they join.
Appointments: who booked with whom, the date and time, whether it is a video or voice appointment, its status, and any cancellation reason or rating and comment you leave.
Device tokens: a push notification token for each device you sign in on, so we can notify you about your appointments.
Delivery records: a log of which notifications we sent you and whether they were delivered, so we can tell whether a reminder reached you.
Connecting Google Calendar is optional. A host who connects it grants exactly two Calendar permissions, and we use them only for the purposes below:
See when you are busy (calendar.freebusy) — read only your busy time intervals so visitors are never offered a slot when you already have something booked. We do not read the titles, guests, descriptions or locations of your other events.
Manage appointment events (calendar.events) — create a calendar event when an appointment is confirmed, add a Google Meet link for video appointments, and delete that event if the appointment is cancelled. We only touch events Apointo itself created.
Apointo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google Calendar data for advertising. We do not sell it. We do not transfer it to anyone except as needed to provide the scheduling feature you asked for, or where required by law. We do not allow humans to read it, except with your explicit permission, for security purposes such as investigating abuse, or where required by law.
Your Google access and refresh tokens are encrypted before being stored on our servers. You can disconnect Google at any time from the Profile screen in the app, or by removing access at myaccount.google.com/permissions — either revokes our access and deletes the stored tokens.
We do not sell your personal information. It is shared only in these ways:
Between the two parties to an appointment: a host and their visitor see each other's name. For a voice appointment the host also sees the visitor's phone number, because the host places the call.
Google — only if you connect Google Calendar, as described above.
WhatsApp (Meta Platforms) — we send appointment notifications and reminders to your phone number through the WhatsApp Business Platform.
Expo — push notification tokens and message content are handled by the Expo push notification service to deliver notifications to your device.
The NxtGenAiDev authentication service — which verifies your phone or email and issues your sign-in token.
We send notifications about your own appointments: booking requests, confirmations, declines, proposed new times, cancellations, and reminders 24 hours and 1 hour before an appointment starts. These are transactional messages tied to appointments you are part of.
You can turn off push notifications in your device settings. To stop WhatsApp messages, reply to the message thread asking to opt out, or contact us.
Account and appointment records are kept while your account exists, because both parties need an accurate history of their appointments. Google tokens are deleted as soon as you disconnect Google. Notification delivery logs are kept only as long as needed to diagnose delivery problems.
You can ask us to delete your account and personal data at any time by contacting support@nxtgenaidev.com. We will delete or anonymise it, except where we are required to keep records by law.
Traffic between the app and our servers is encrypted in transit. Google tokens are additionally encrypted at rest using AES-256-GCM. Access to production systems is limited to people who need it to operate the service.
No system is perfectly secure, and we cannot guarantee absolute security — but if a breach affects your personal data we will notify you as required by applicable law.
Apointo is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
If we change this policy we will update the date at the top of this page, and — for changes that materially affect how we use your information — tell you in the app before the change takes effect.
Questions about this policy or your data: support@nxtgenaidev.com.