Hughesboro

Privacy Policy — Hughesboro

Last updated: August 31, 2026

Hughesboro is a private family organization tool built and operated by Terry Hughes ("I," "we"). It is used by a single household to coordinate calendars, lists, contacts, files, and shared logistics. This policy describes what information Hughesboro collects, how it is used, and how it is protected — including information obtained through Google APIs.

If you have questions about this policy, contact terry@hughesboro.com.


1. Who this applies to

Hughesboro is not a public product. Accounts are created only for members of the operating household. This policy describes our practices for those users.

2. Information we collect

Account information. When an account is created, we store an email address and authentication credentials managed by our authentication provider (Supabase). We do not store passwords in readable form.

Information you enter. Lists, tasks, deadlines, events, contacts, and related notes that you create in Hughesboro are stored in our database so the application can display them to you and to the household members you share them with.

Files you add to Hughesboro. You may attach files to events, list items, and other things in Hughesboro. These are stored by us, in our own storage, and are not sent to Google. They are visible only to the people who can already see the thing you attached them to.

Google account information, if you connect your Google account. Connecting is optional and initiated by you. If you connect, we receive and store:

Technical information. Our hosting providers generate ordinary server logs (timestamps, request paths, error conditions). We keep a limited operational log of synchronization outcomes — what synced and whether it succeeded — which records identifiers and counts, never event contents, contact details, file contents, or credentials.

3. How we use information

We use this information solely to operate Hughesboro for its users:

We do not use your information for advertising, profiling, or marketing. We do not sell, rent, or trade it. We do not transfer it to third parties except the infrastructure providers listed in §5, who process it only to provide their services to us.

4. Google API Services — Limited Use disclosure

Hughesboro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

What we ask for, and why each is the narrowest permission that works:

PermissionWhy
Google CalendarHughesboro reads and writes events, and reads and updates which calendars you are subscribed to and how they appear. This is the smallest single permission Google offers that covers all of it — asking for narrower ones in combination would grant the same access across more separate permissions.
Google ContactsContacts sync is two-way: a change you make in Hughesboro is written back to Google. That requires write access. Read-only would make Hughesboro's contacts a dead-end copy that silently diverges from yours.
Specific Drive filesThis grants access only to the individual files you pick through Google's own file chooser, and to files Hughesboro creates. It does not grant access to your Drive as a whole. We deliberately do not ask for the broader Drive permissions, which would let this application read every file you own.
Basic profile and emailTo identify you when you sign in and to label which Google account a connection belongs to.

5. Where information is stored and who processes it

Hughesboro runs on third-party infrastructure. Each provider processes data only to deliver its service to us:

ProviderRole
SupabaseDatabase, authentication, file storage
RailwayApplication server for synchronization and Google API access
VercelWeb application hosting
GoogleCalendar, Contacts, and Drive data source, when you connect your account

6. How information is protected

7. Your choices and how to revoke access

One thing disconnecting cannot undo. If you attach a Google Drive file to an event and give a guest access to it, that access is granted in Google Drive and belongs to Drive, not to Hughesboro. It is permanent until you change it yourself. Deleting the event, removing the guest, disconnecting Google, and deleting your Hughesboro account will none of them take it back. Hughesboro says so at the moment you grant it, and shows you where to change it. You can review and remove file access at any time in Google Drive.

8. Data retention

Calendar and contact data mirrored from Google is retained while the connection is active. When you disconnect, or when a calendar is removed, that data is marked deleted and stops being shown immediately.

Deleted items remain recoverable before being permanently removed: 30 days for information you created in Hughesboro, and 35 days for data mirrored from Google. The longer window for mirrored data exists so that an item you restore in Google is not permanently discarded here first. Operational synchronization logs are retained for 30 days.

Files you add to Hughesboro are kept while the thing they are attached to exists, and are removed with it on the same 30-day recovery window. We do not keep copies of Google Drive files — a Drive attachment is a link to a file that stays in Drive, and removing the attachment does not delete the file.

9. Children

Hughesboro is used within a single household and includes accounts for the operators' minor children, created and administered by their parents. Where a child connects a Google account, their calendar and contact data is mirrored in the same way and under the same protections described above — including that their contacts are visible only to them and not to other household members. We do not offer the service to the public and do not knowingly collect information from children outside this household.

10. Changes to this policy

If we change this policy we will update the date above. For material changes — including any change to what Google data we access — Hughesboro shows a notice inside the application to every user, which stays visible until dismissed.

11. Contact

Terry Hughesterry@hughesboro.com

Hughesboro is operated by an individual, not a company.