Privacy · Penciled.software

Discuss a provisional appointment without sending a private one.

The marketing site explains an unbuilt hold lifecycle. It has no product account or booking form, and a drawn slot is not a stored appointment. This page explains the information useful for a conversation and the questions that remain to be answered before a future deployment. It is not a claim of certification or a negotiated data-processing agreement.

Separate reading, emailing and reserving

Reading these pages does not create a provisional claim on a time. There is no Penciled hold service behind the illustration, no expiry clock running on the page and no confirmation action. The email link opens your mail application. If you send a message, its content becomes correspondence that a person can use to reply. That is a different activity from entering data into a product booking form, which this site does not offer.

The existing site posture is that the marketing renderer sets no cookie, uses no third-party advertising or tracking scripts and builds no behavioral profile; basic short-lived operational logs may record page requests. Do not turn that statement into an assumption that sending email leaves no record. Keep introductory correspondence limited to what the discussion needs. This guide does not assign an exact log lifetime or promise a deletion mechanism that has not been described for a deployed product.

A fictional time is enough to explain the mechanism

Use a fictional appointment and neutral adult labels when describing a soft-hold problem. State the time being considered, the length of the decision window and the reason that immediate confirmation is difficult in general terms. For example, another adult may need to agree before the booking can be settled. That is enough to discuss a provisional state. The person's name, contact details and private circumstances are not necessary to understand the decision.

Do not send customer lists, medical information, payment details or records about children to illustrate the proposed lifecycle. The marketing discussion needs a rule and an expected outcome, not the underlying personal file. If an eventual implementation requires sensitive or child-related handling, that needs a separately reviewed product workflow. Nothing in the soft-hold drawing supplies that workflow, and this page introduces no new consent or family-access mechanism.

A useful status does not require a public identity list

The design says that a holder and relevant staff should understand the provisional status and expiry. It does not establish a public directory of who is considering an appointment. When discussing your intended use, identify who needs to know that capacity is held and who needs to know the person's identity. Those are separate questions. A useful availability view can explain that a slot is unavailable without turning every scheduling note into a story about the person behind it.

This is a review question rather than a claim that specific permissions, redaction or sharing controls have been built for Penciled. The hold lifecycle itself remains planned. Before any operational use, ask to see the actual views for each role and the handling of a completed or expired decision. A promise about the meaning of held should be accompanied by a clear answer about who can see that meaning in the intended deployment.

Ask what remains after a hold ends

In the proposed booking behavior, expiry releases capacity. That does not by itself say which records are retained, which can be corrected or how a support investigation would work. Treat availability and data lifecycle as separate questions. Likewise, confirmation would settle a booking choice but would not establish consent for unrelated uses of the person's information. Those details need explicit product and operational decisions; they cannot be inferred from the name of a state.

Before relying on a future deployment, ask who administers access, how incorrect appointment information is corrected, what the record-retention terms are and how an appropriate deletion request is handled. Bring the requirements of your organization to that discussion. This page makes no FERPA, COPPA, SOC2 or VPAT certification claim. It also makes no AI-generated or autonomous-assist claim. Planned pricing and branding do not change those limits or substitute for the required review.

The pencil has not become a working reservation yet

The distinction runs through the whole site. The fixed-slot capacity floor has existing sibling-source grounding. The hold state is a separate design: it would count provisionally, carry an expiry and resolve into confirmation or release. None of those hold actions is running on Penciled.software. A route that displays this explanation does not supply the missing state transition. The small board on the home page is a static illustration, and no timer runs inside it.

That is why the next action is a conversation rather than a booking button. No date shown in an example is being offered to you, and no click can confirm a slot. Smart reschedule is also planned: applying a ranked proposal pattern to a lapsed hold has not been wired here. The useful question is whether the proposed behavior fits your work, followed by what evidence you would need to see before relying on it.