Privacy policy
Last updated: October 11, 2026
Midore is a free, open-source scheduling service. People connect their Google Calendar, publish booking links, and others use those links to book meetings with them. Hosts can also keep their tasks in Midore, have them planned around their calendar, and, if they choose, talk to Dori, an optional assistant. This policy explains what data Midore collects, how it is used and shared, how it is protected, and how you can delete it. It applies to the service at midore.app, which was called DoorCal until October 2026. Midore works with Google Calendar and with Microsoft (Outlook, Microsoft 365). Copies of the open-source code run by other people are separate services with their own policies.
In this policy, a host is someone who signs in with Google and shares booking links, and an invitee is someone who books a meeting through a host's link.
1. Information we collect
From hosts, through Google or Microsoft sign-in
- Your name, email address, profile picture (Google only) and the provider's account ID.
- An OAuth refresh token that lets Midore reach your calendar while you are not on the site, for example when someone books you. It is stored encrypted. You can connect several Google and Microsoft accounts; each has its own token.
From hosts, through Google Calendar
Midore asks for three Google Calendar permissions and uses each one only as described here:
- See your free/busy information (
calendar.freebusy). When someone opens your booking page or books a time, we check which times you are busy across the calendars you chose, so nobody can book you when you are not free. We only receive busy time ranges, not event details, and we don't store them. - See the list of your calendars (
calendar.calendarlist.readonly). On the Settings page we list your calendars so you can choose which ones count for conflicts and which one new bookings go to. We store only the IDs of the calendars you select. - View and edit events on your calendars (
calendar.events). We use this to show your events in your Midore dashboard, to create the calendar event (with a Google Meet link for online meetings) when someone books you or when you create a meeting in Midore, to update it when a booking is rescheduled, and to delete it or remove an attendee when a booking is cancelled. We store the ID and Google Meet link of events Midore creates for bookings. We don't store the contents of your other events; they are fetched when you view your dashboard and not kept.
From hosts, through Microsoft
For Microsoft accounts we ask for the Calendars.ReadWrite permission (plus basic profile and sign-in permissions) and use it in the same three ways: to find your busy times, to list your calendars, and to show, create, update and delete events for the meetings booked with you, with a Microsoft Teams link for work and school accounts. Outlook sends the invitations.
Event categories and AI categorisation (optional)
You can sort your calendar into categories with your own rules. Midore then stores a category and priority per event together with a scrambled fingerprint of its title, never the title itself.
If you switch on AI categorisation in Settings (it is off until you do), Midore sends a minimal description of events that no rule covers to OpenRouter (which passes it to the model provider, OpenAI) so that a model can suggest a category: the event title, its length, whether it repeats, how many attendees it has (not who they are), whether it has a video link, and the calendar's name. Descriptions, attendee names and addresses, free/busy data and booking details are never sent, and requests are subject to daily limits per user and for the whole service. The model currently used is openai/gpt-6-luna-pro. The provider processes this only to answer the request and does not use it to train or improve AI models: under OpenAI's API terms, data sent to the API is not used for training and is retained for at most 30 days for abuse monitoring; OpenRouter is instructed, on every request, to route only to OpenAI or to Microsoft's Azure OpenAI Service (which hosts the same models under the same no-training terms) and only to providers that do not store or train on data. In our OpenRouter account, zero data retention is enforced for OpenAI models, so requests are served only by endpoints that do not store them; routing to providers that may train on data is disabled; and prompt logging is switched off. Midore itself keeps only the resulting category label. You can switch this off at any time, which also deletes the AI-suggested labels.
Tasks and planning
If you use Tasks, Midore stores what you enter: your areas, projects and tasks, with their notes, due dates, estimates, priorities, links between tasks, and the names of people you type in. Midore then plans your open tasks into free time around your calendar. The planning is done by Midore's own code, not by an AI model; it uses the busy times from the calendars you chose for conflicts, and stores only the resulting planned times and which task each belongs to, not the details of your events.
To keep the plan current, Midore asks Google and Microsoft to notify it when events change on those calendars. A notification says only that something changed, not what; Midore then reads your busy times again and moves planned work if needed. Planned work stays in Midore and is never written to your calendar unless you add it yourself.
Dori, the assistant (optional)
Dori is off until you turn her on. When you message her, Midore sends OpenRouter (which passes it to the model provider, OpenAI) what she needs to answer: your message and your recent conversation with her; your areas, projects and tasks (titles, notes, dates, estimates, priorities and the names of people you typed); notes she keeps for you, such as “not in the mood for writing today”; your working hours and planned work; and, from your calendars for the coming week (or a range you ask about), each event's title, start and end time, calendar name and number of attendees. Attendee names and email addresses, event descriptions and locations are never sent. The model currently used is openai/gpt-6-luna. The same no-training and zero-data-retention setup described above for AI categorisation applies, and requests are subject to daily limits per user and for the whole service.
Dori can add, change, complete and remove your tasks and projects, and every change she makes can be undone. She never moves or deletes calendar events. She can offer to add an event to your calendar, which happens only when you press Add to calendar, and she can prepare emails, which open in your own mail app with the recipients filled in by Midore in your browser; Midore never sends them. Your conversation with Dori is stored in Midore until you clear it or turn Dori off, which also deletes the notes she kept.
If you talk to Dori with the microphone, your recording is sent through OpenRouter to ElevenLabs to be turned into text; only the text is kept, as your message. If you have Dori read an answer aloud, the text of that answer is sent the same way to be turned into speech. Both requests are restricted to endpoints that keep no data (zero data retention) and do not use it for training, and Midore stores neither recordings nor audio.
Settings hosts create
Your username, display name, headline, welcome message, time zone, availability schedules and event types, including any questions you ask invitees.
From invitees
When you book a meeting we collect the details you enter: your name, email address, any guest email addresses, a phone number if the meeting is a phone call, your answers to the host's questions, your notes, and your time zone. Invitees don't need an account and we don't access invitees' calendars.
Technical information
- Cookies: a session cookie that keeps hosts signed in (30 days) and a short-lived cookie used during Google sign-in (10 minutes). We don't use analytics, advertising or tracking cookies.
- IP addresses, used to limit abuse of booking pages. We store only a one-way hash of your IP address in short-lived request counters, never the address itself.
- Standard request logs kept by our hosting provider for operating and securing the service.
2. How we use information
- To provide scheduling: show availability, take bookings, and create, update and cancel calendar events.
- To show hosts their calendar, bookings and settings in the dashboard.
- To keep hosts' tasks, plan them around their calendar, and, if they turn it on, let Dori answer and act on their requests.
- To let invitees view, reschedule or cancel their own booking.
- To keep the service secure and working, including preventing spam and abuse.
We don't use your data for advertising, we don't sell it, and we don't build profiles of you.
3. Google user data and Limited Use
Midore's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve the scheduling features you use.
- We don't transfer it to others except as needed to provide the service, to comply with law, or as part of a merger or acquisition with notice to you.
- We don't use it for advertising, including retargeting, personalized or interest-based ads.
- We don't sell it, and we don't use it to train or improve generalized AI or machine-learning models.
- No person reads your Google data unless you ask us to (for example for support), it is needed for security or to investigate abuse, or the law requires it.
4. How information is shared
- Between host and invitee. When an invitee books, the host sees the details the invitee entered, and both see the meeting details. These details are written into the host's Google Calendar event, and Google sends the invitation and any updates to the invitee and their guests.
- Service providers that run Midore for us and may process data only on our instructions: Vercel (hosting) and Neon (database). Data may be processed in the United States and other countries where these providers operate.
- Google and Microsoft, to read and update your calendars as described above.
- The AI provider (OpenRouter (which passes it to the model provider, OpenAI)), only if you turn on AI categorisation or Dori, and only what is described above. It may not use the data to train or improve AI models.
- ElevenLabs, through OpenRouter, only for Dori's voice: recordings you make with her microphone and answers you ask her to read aloud, on zero-data-retention endpoints.
- When required by law, or to protect the rights, safety and security of users and the service.
We don't sell or rent personal information to anyone.
5. How information is protected
- All traffic to Midore is encrypted with HTTPS.
- Refresh tokens are encrypted at rest with AES-256-GCM. Access tokens are kept only in memory, briefly.
- A host's dashboard, calendar and bookings are available only to that host after signing in. A host's public profile and event types are visible to anyone with the link, by design. Invitees can reach only their own booking, through its private link.
- Our database provider encrypts stored data, and access to production systems is limited to the operator.
No system is perfectly secure, but we work to protect your data and will notify affected users of a breach as required by law.
6. How long we keep data, and how to delete it
- Hosts: your data is kept while your account exists. You can delete your account at any time in Settings → Delete account. This immediately deletes your profile, settings, event types, schedules, tasks, plan, conversation with Dori and booking history from our database and revokes Midore's access to your Google accounts. Calendar events already on your calendars stay there, under your control.
- Removing a connected account (Settings → Connected calendars → Remove) deletes its stored token and, for Google, revokes Midore's access. Microsoft doesn't let apps revoke their own access, so also remove Midore at account.microsoft.com/privacy/app-access (personal accounts) or myapps.microsoft.com (work and school accounts). Google access can also be revoked at myaccount.google.com/permissions.
- Invitees: booking details are kept as part of the host's booking history until the host deletes their account, or until you ask us to delete them.
- Tasks and Dori: tasks and projects are kept until you delete them. Your conversation with Dori is kept until you clear it or turn Dori off. The plan is recomputed and overwritten as things change.
- Deleted data may remain in our database provider's backups for a short period (up to about 30 days) before it is overwritten.
7. Your choices and rights
You can see and change your data in the dashboard, and delete it as described above. You can also ask us to access, correct, export or delete your personal information, including booking details you entered as an invitee, by contacting us. Depending on where you live, you may have further rights under privacy laws such as PIPEDA, the GDPR or US state laws, and you may complain to your data protection authority.
8. Children
Midore is not directed to children under 13 and we don't knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.
9. Changes to this policy
We will post any changes on this page and update the date above. If a change materially affects how we use Google user data or other personal information, we will tell hosts by email before it takes effect.
10. Contact
Email hadi.fariborzi@gmail.com. We aim to reply within 7 days.
See also the terms of service.