Your calendar data is sensitive. We treat it that way.
We believe security isn't just a feature—it's a foundation. Every decision we make considers the privacy and protection of your data first.
All your calendar data is encrypted when stored. Even if someone gained access to our databases, your information would be unreadable.
All connections to Tilly use TLS 1.3 encryption. Your data is protected every step of the way between your device and our servers.
We only collect what's necessary to provide our service. We don't sell your data, and we never will.
We use OAuth 2.0 for calendar connections. We never see or store your calendar provider passwords.
We regularly review our security practices and update our systems to address new threats and vulnerabilities.
Your data belongs to you. You can export or delete your data at any time from your account settings.
Tilly is built on modern, secure infrastructure:
We value the security research community. If you discover a security vulnerability, please report it responsibly to security@trytilly.com. We commit to:
If you have any questions about our security practices, please reach out to us at security@trytilly.com.