Connected data

Use the minimum data needed for a visible athlete feature.

Review state: DRAFT — OWNER AND PROFESSIONAL PRIVACY/LEGAL REVIEW REQUIRED BEFORE OAUTH SUBMISSION

GFD does not currently connect to Google Calendar or a fitness provider. The production-readiness design below explains the proposed boundary before any real connection is activated.

Google Calendar

Where an authorised future user chooses to connect Google Calendar, GFD intends to request the narrowest permission that supports the selected feature. Availability-only mode should use free/busy intervals and avoid event titles or descriptions. A separate selected-details mode may be considered only when the athlete chooses it and the product genuinely provides that feature.

Purpose and control

Authorised calendar information would be used to provide visible availability and planning context inside GFD. The athlete chooses relevant calendars and confirms classifications such as work/roster, personal availability, external sport, travel or ignore. Suggestions never silently become coaching authority.

Storage and sharing

Reusable provider tokens must remain encrypted and server-side, never in browser storage, logs or exports. GFD does not use Google user data for advertising, sell it, or permit connection to authorise global learning. Any use and transfer of Google user data must comply with the Google API Services User Data Policy, including its Limited Use requirements.

Disconnect and deletion

The intended design supports disconnect/revocation, stops future processing after consent withdrawal, and applies the documented export, retention and deletion authority. Provider connection remains separate from PlanAuthority.