How this scheduling service uses information
This service uses only the information needed to create polls, collect availability, manage organizer accounts and send scheduling notifications. It does not use advertising, behavioural tracking or third-party analytics cookies.
Essential cookies and local storage
| Name | Purpose | Typical duration |
|---|---|---|
__Host-meetpoll_secure_session | Keeps forms secure, maintains organizer sign-in and remembers access to protected polls. | Until the browser session ends. |
meet_musalab_response_<poll> | Lets a participant return to the same poll and update an existing response from the same browser. | Up to 180 days. |
meet_musalab_cookie_notice_v1 (local storage) | Remembers that the essential-cookie notice has been acknowledged. | Until browser storage is cleared. |
These technologies are strictly necessary for the requested service. There are no optional marketing or analytics cookies to accept or reject.
Information collected
Organizers provide their name, email address and account credentials and may optionally save an organisation and profile photo. New organizer accounts may be activated through a short-lived, single-use invitation link, and active accounts may request a short-lived password-reset link by email. Poll participants may provide a name, email address, availability, comments, suggested meeting times and their device time zone. When an organizer account is already signed in, its saved name and email are used for that person’s participant response and the response is linked to that account. The application also keeps security and audit records, including a one-way protected representation of the requesting IP address.
Email notifications
Participant email addresses are used only for notifications connected with the relevant poll, such as requests to review newly added times and confirmation of the selected meeting time. Organizer email addresses are used for account invitations, poll-creation and response notifications. Email delivery records are retained to diagnose delivery failures and prevent duplicate confirmation messages.
Connected calendars
Organizers may choose to connect Microsoft 365/Exchange Online or subscribe to a public HTTPS ICS calendar feed. Connections are used only to show the signed-in user’s appointments privately while proposed meeting times are selected or while that user responds to another organizer’s poll. Calendar events are requested when the weekly planner is opened; event data is not copied into polls or shown to other participants.
Microsoft authorization credentials and ICS subscription URLs are encrypted before database storage. Organizers can remove either connection at any time from Calendar settings. Public ICS subscription links should be treated as confidential because anyone who obtains the original link may be able to read that calendar.
Participants who do not have a connected account calendar may optionally choose a local .ics file to compare with the proposed times. The file is sent to this server only for immediate parsing, is not written to disk or stored in the database, and event subjects are not returned to the browser. Only sanitized free/busy time windows are used for the current page.
Images
Administrators may upload organisation logos and browser icons. Account holders may optionally upload a profile photo. Uploaded images are checked by file type, decoded and re-created as PNG files; original upload metadata and active image formats are not retained. Profile photos are stored privately and are available only to the signed-in account holder.
Managing your information
Participants can update their response from the browser used to submit it. When new times are added, participants who supplied an email address may receive a short-lived, single-use link that re-establishes access to their own response. The poll organizer can remove participant responses, comments or the entire poll. Deleting a poll also removes its associated responses and votes; delivery records may retain the destination address and delivery status for operational accountability.
Contact
Questions about privacy or removal requests can be sent to m.chaniotakis@ucl.ac.uk.