Privacy
Last updated 15 September 2026
BrainTime is an internal scheduling tool for a university research laboratory. It coordinates when research staff are available and books the shared EEG room. It is used by lab members, not by research participants, and it holds no participant or research data of any kind.
What it stores
If you enter availability without signing in: the name you type and the half-hour blocks you mark, for the weeks you mark them. A random token is kept in your browser so you can edit your own entry later, and, if you choose to set one, a hashed PIN so you can edit from another device. The token and the PIN are never readable by anybody else.
If you sign in with Google: additionally your Google account identifier, email address, name and profile picture, so that calendar invitations can reach you and so your training status stays attached to you rather than to a spelling of your name.
If you are a team lead who connects Google Calendar: a Google refresh token, encrypted at rest with AES-256-GCM. It is held only on the server, is never sent to any browser, and is used solely to create and cancel events on the EEG room calendar on your behalf. You can revoke it at any time from the Settings page, or from your Google account permissions.
Who can see it
Names and marked availability are visible to anyone who opens the site, in the same way a shared When2Meet poll is. That is the point of the tool: the lab needs to see when it can run sessions.
Email addresses, browser edit tokens, PIN hashes, Google refresh tokens and calendar invitation lists are not visible to any browser. Database permissions withhold those columns from the public and signed-in roles alike, so they cannot be read even by someone querying the database directly from the page.
How Google data is used
Signing in requests only your email address and basic profile. Team leads are separately asked for permission to manage calendar events; ordinary users are never asked for this.
Calendar access is used for one thing: creating an event on the lab’s EEG room calendar when a lead confirms a session, inviting the researchers who marked themselves available for it, and removing that event if the session is released. BrainTime does not read your personal calendar.
BrainTime’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who it is shared with
Nobody. The data is not sold, not used for advertising, and not shared with third parties. It is processed only by the services that run the application: Supabase, which hosts the database in Montreal, Canada; Vercel, which hosts the site; and Google Calendar, when a lead confirms a session.
There is no analytics, no advertising and no third-party tracking on this site.
How long it is kept
Past weeks are kept indefinitely, because they are the lab’s record of when the room was used and by whom. Availability you enter for a future week can be cleared by you at any time from the weekly page.
Removing your data
Clear your own availability for a week from that week’s page. To have your entries, your roster listing or your account removed entirely, ask your team lead, or write to dyanitsk@ualberta.ca. Disconnecting Google Calendar deletes the stored refresh token immediately.
Contact
Questions about this notice or about data held in BrainTime go to dyanitsk@ualberta.ca.