Privacy policy
How Attenda handles account information, attendance, identified feedback, and optional Google Calendar access.
Effective date:
Who operates Attenda
Attenda is operated by Asociația CNMK Studio for its educational activities and projects. The association is responsible for personal information processed in Attenda. This policy covers the public website, accounts, temporary check-in identities, participation records, feedback, and optional integrations.
Information collected
- Account details: name and display name, email, profile image when supplied, sign-in provider and provider identifier, role, access status, and account timestamps. Email/password accounts have a password hash, not a readable password; verification and password-reset records support account recovery. If you add a passkey, Attenda stores its public key, credential identifier, label, creation date, authenticator model identifier when supplied, device/backup information, supported transports, and signature counter. Private keys, device PINs, fingerprints, and facial data are not received or stored by Attenda; your device or chosen passkey provider handles them.
- Participation details: the event and project, attendee identity, check-in time and method, attendance-session reference, and administrative corrections, reasons, and audit records.
- Feedback details: answers to event questions, the responding identity, the related event and form, and submission timestamps. Feedback is identified, not anonymous, including for temporary identities. Administrators can view summaries and individual responses.
- Technical and security details: session cookies and identifiers, IP address, browser information, request paths, timestamps, rate-limit records, and operational logs. OAuth grants and encrypted tokens are kept when you authorize a connection.
- Optional push notifications: if you enable them, Attenda stores your browser's push endpoint and encryption keys, your login-session reference and language, project/event choices, selected reminder times, and delivery attempts. It does not use a device location or contact list for notifications.
Temporary identities
A valid event check-in link lets you use a temporary identity with a display name and a session cookie, without supplying an email or password. Temporary means there is no permanent sign-in method; it does not mean anonymous feedback or automatic deletion. Attendance and feedback remain associated with that identity. Linking or merging into a permanent account preserves participation history and may move compatible sign-in methods.
How information is used
We use information to authenticate users, manage access, organize events, record voluntary attendance, collect feedback, produce participation reports and requested exports, support account recovery, maintain an audit trail, and protect and troubleshoot the service. A participant sees their own participation; administrators manage the organization's records.
Google access
Optional Google sign-in
If you choose Google sign-in, Google supplies your account identifier, name, email, and profile image when available. Attenda uses these to authenticate and link your account. You can instead use email/password or, at a valid check-in, a temporary identity.
Better Auth manages the Google account link, granted permissions, and encrypted access and refresh tokens. Attenda uses them for the Google action you request; tokens are not shown to participants or supplied to MCP clients.
Connected Google Calendar copies
Calendar access is requested separately from sign-in. A Google-linked permanent account can authorize event access to add an Attenda event to its primary Google calendar. Attenda sends the event title, description, project name, location, start/end times, an Attenda link, and private identifiers that associate the copy with the event and account. When you press Resync, it reads and updates that tracked copy, preserving your Google reminders and personal settings. Nothing updates automatically.
An administrator can additionally authorize read access to their calendar list to choose a calendar they can write to. Attenda reads calendar identifiers, names, and access roles, then stores the selected identifier and name. Administrators explicitly publish, update, or remove Attenda event copies in that destination. Who can see those copies depends on the destination calendar's Google sharing settings; Attenda does not invite participants or share calendars.
Google's event permission allows viewing and editing calendar events more broadly than the copies Attenda uses. Attenda does not browse unrelated events or use the permission to manage them; its requests concern tracked Attenda copies. Calendar-list permission is used for administrator destination selection, not ordinary personal copies.
Attenda retains the Google event identifier and link, sync time, and a fingerprint of the Attenda fields to detect changes. It does not store a copy of your unrelated Google calendar or the full Google event response.
One-time links and calendar files
A one-time Google add link opens Google Calendar with event details filled in for you to review and save. An .ics download provides the event details to the calendar application you choose. Neither option grants Attenda Calendar access. Attenda cannot track or resync these copies, and using multiple methods may create duplicates.
Limited Use
Attenda's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google API data is not sold, used for advertising, or used by Attenda to train generalized AI or machine-learning models. Human access is limited to support you explicitly authorize for specific data, necessary security work, or applicable legal requirements. Read: Google API Services User Data Policy
Optional notifications
You can follow a project or event and choose individual reminders. Event creation alerts are sent for newly scheduled events to project followers; cancellation and start-time or location changes are sent to event and project followers. A project reminder choice applies to every scheduled event in that project. When both choices match, Attenda sends one notification per enabled device. The browser's notification permission is requested only when you enable push on that device. Delivery is best effort and reminders may arrive late or not at all.
You can stop following a project or event in Notifications, remove a device there, or revoke permission in your browser. A device registration is tied to its login session and is removed after session expiry or deletion. Delivery metadata is normally removed after 30 days; exhausted failures are removed after seven days. Push-service operators receive the encrypted message and delivery metadata needed to route it; the browser may display the event title on a lock screen.
Turnstile and abuse protection
Cloudflare Turnstile protects credential and temporary check-in flows against automated abuse. It processes technical signals such as IP address, browser headers, connection fingerprints, and the site origin to distinguish users from bots and improve its protection. Details: Cloudflare Turnstile Privacy Addendum
Storage and security
Application records are stored in Cloudflare D1; operational logs are handled by the hosting and logging services. The public deployment uses HTTPS, role-based access checks, protected sessions, password hashing, and encrypted Google OAuth tokens. Providers may process information across their service locations. These safeguards reduce risk but do not guarantee absolute security.
Retention
Account, temporary identity, attendance, feedback, audit, and Google connection records are retained until reviewed and deleted by the organizer. Apart from the push metadata cleanup described above, there is currently no automatic purge. Session and QR-link expiry stop access or check-in; they do not delete participation records. Removing or suspending access also does not automatically erase records. Retention is reviewed when a deletion request is received, including any applicable project, audit, security, or legal requirements.
Google Calendar copies, calendar files, and exported reports remain with their recipients until removed there. Provider-managed logs and database recovery copies follow the provider's retention and recovery arrangements; deletion from the live application does not promise immediate removal from every recovery copy.
Deletion and Google revocation
Contact the association at the address below to request deletion of an account, temporary identity, participation record, feedback, or stored Google connection. This is a reviewed request, not a self-service automatic deletion feature. We may need to verify the requester's identity and explain which records can be removed or must be retained.
You can revoke Attenda's Google authorization in your Google Account to stop future use of that grant. Manage it here: Google Account connections
Revoking Google access does not delete Attenda records, stored connection records, or calendar copies already created. Ask the association to remove eligible stored account and token data, and delete calendar copies in Google or your calendar app. Clearing an administrator's Calendar destination in Attenda is not the same as revoking Google access.
Your choices and requests
You can review your own attendance, edit your display name, choose whether to connect Google Calendar, and contact the association for access, correction, export, restriction, objection, or deletion requests where applicable. You may also raise a concern with the relevant data-protection authority. Avoid including sensitive personal information in feedback unless it is necessary and you are authorized to provide it.
Policy changes
The effective date identifies this version. We update the policy when data handling changes and seek additional authorization before using Google data for a new purpose requiring it.
Contact
For privacy, deletion, account, or service questions, contact Asociația CNMK Studio using the email below. Identify the relevant account or event, but do not send passwords, login links, or Google tokens.
privacy@cnmkstudio.ro