CoreFusionOS

Privacy

Privacy at CoreFusionOS.

CoreFusionOS is an operating system for chambers of commerce and small organizations. It runs the organization's member records, events, bookings, invoices, and website in one place. This page says what we do with information, in plain words. It covers the platform itself and, in its own section, the optional connection to Google Workspace.

Buzzfish Media runs CoreFusionOS. Write to support@buzzfishmedia.com about anything on this page.

Last changed 2026-09-18.

01

One database per organization

Every organization on CoreFusionOS has its own database. There is no shared table with a column that says which organization a row belongs to; your records are in a database that holds only your records. Nothing on the platform reports across organizations, and we do not sell, rent, or trade the information in any organization's database.

02

The Google Workspace connection

An organization can connect CoreFusionOS to Google Workspace. Its Google Workspace administrator can install the app for everyone in the organization, or a staff member can connect their own Google account from their Staff page. Either way, this is what the connection does and does not do.

What it reads from Google

  • Your name and email address, to sign you in and to match you to your staff record.
  • The events on your Google Calendar, to show your day on your home screen beside the organization's own items, and to know when you are busy.
  • The names of the calendars you can see, so you can choose which shared calendar the organization's records are mirrored onto.

What it writes to Google

  • Calendar entries for records the organization owns in CoreFusionOS — events, bookings, renewal dates, invoice due dates — on your calendar and on shared calendars you have chosen. Each entry says in its description that it was placed by CoreFusionOS. When the record changes, the entry changes; if you edit the entry in Google, the next change to the record overwrites your edit. The app never changes, moves, or deletes an entry it did not create.

What it never reads

  • Your email. The app has no access to Gmail and does not ask for it.
  • Your files. The app has no access to Google Drive and does not ask for it.
  • Your Google Contacts. The Contacts integration is deferred; the app does not request Contacts permission or read or write Google contacts.

What we keep, and how

We keep the token Google gives us for your connection, encrypted. We mark the calendar entries we place in Google with a key for the CoreFusionOS record they mirror, so we can find them again. We do not keep a copy of your calendar: your day is read when your home screen is shown and is not stored.

Who can see it

You, on your Staff page, where the connection is listed. Your organization's administrators can see that a connection exists and can remove it. The platform operator can see that an organization is connected and can sever the connection for the whole organization; the operator cannot read your calendar.

Who receives Google user data

Buzzfish Media processes Google user data to operate the connection. Our application hosting and database provider, Render, processes the data handled or stored by its services on our behalf. Cloudflare R2 stores our database backups, which include stored Google connection records and encrypted tokens. Google receives the API requests needed to sign you in, read your calendar, and create, update, or remove the calendar entries the app mirrors.

Your calendar entries are shown to you in CoreFusionOS. Connection status is visible to the administrators described above. Records sent to a shared Google calendar are visible to people who have access to that calendar under Google's sharing settings.

We do not sell or rent Google user data or share it with advertisers, data brokers, or information resellers. Transfers of Google user data are limited to providing the features you authorize, security purposes, compliance with applicable law, or a merger, acquisition, or sale of assets with your explicit prior consent, consistent with Google's Limited Use requirements.

How we protect Google user data

The public application and requests to Google's APIs use HTTPS to protect data in transit. Stored Google refresh tokens are encrypted with AES-256-GCM; the encryption key is held in the server environment, separately from the database. Tokens are used on the server to make authorized requests to Google.

Organization records are isolated in separate tenant databases. Access to the connection is checked against the staff account and its permissions. A removed or disabled staff seat cannot be used for new Google API calls through that connection. Removing the connection stops further access as described below.

Turning it off

Remove the connection from your Staff page at any time, or ask your Google Workspace administrator to uninstall the app. When a connection is removed, we discard the stored token and stop every call to Google for that account. Entries and contacts we placed in your Google account stay where they are; they are yours, and you can delete them in Google. You can also revoke our access at any time from your Google Account's permissions page, which has the same effect on our side the next time we try to call.

If you previously used the Contacts export, those contacts remain in your Google account; deferring the feature does not delete them. An earlier Google authorization may still list Contacts permission. You can revoke the earlier authorization in your Google Account and reconnect to authorize only the current Calendar connection.

What Google asks us to say

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

We do not use information from Google Workspace to develop, improve, or train non-personalized artificial intelligence or machine learning models.

03

Email we send

Every email the platform sends passes through one place and is counted against a cap set when the organization was created. If an organization goes over its cap, its sending stops and someone is told; it does not queue and send later.

04

Changes to this page

When what we do changes, this page changes first, and the date at the top changes with it.