Security
To ask for access to your calendar, your clients, and your payments, we first have to earn your trust. This page describes what we actually do — no badges, no slogans.
Payments
Payments are processed by Stripe, through a Stripe account that belongs to you, the professional — your clients' money goes directly into your account, not through ours.
Card numbers never touch our servers: Stripe collects and stores them. Our database keeps only identifiers, such as the Stripe customer ID — never card data.
Encryption
All traffic between your browser and our servers runs over TLS.
The sensitive credentials we store — Google access tokens and payment gateway keys — are encrypted at rest with AES-256-GCM.
Passwords are never stored in plain text: we keep only a bcrypt hash (cost factor 12).
Account access
Two-factor authentication (TOTP) with backup codes, available to every user — and enforceable across the whole organization by its administrator.
Sessions have an absolute expiration: even active ones end after the defined period and require signing in again.
Sensitive endpoints are rate-limited, to slow down automated attacks.
Access control
Inside an organization, every member has a role — owner, manager, or professional — and sees only what that role allows.
Private session notes are visible exclusively to the assigned professional. Not the account owner, not managers — by design, not by configuration.
Backups
The database is backed up daily, with a seven-day retention window.
Your data and your rights
The rights under the GDPR (European Union) and the LGPD (Brazil) — access, correction, deletion, portability — are exercised by direct contact: write to [email protected] and we take it from there.
The details of what data we process, why, and for how long live in our privacy policy.
Who we are
Appointments is operated by Glie Lda., a company incorporated in Portugal. There is a concrete legal entity responsible for this service — and an email address where it answers.