Sandy sends and receive messages without any kind of encryption. Therefore, third parties could be aware of the apointments. It might be a good idea for sandy to use PGP/GPG. She only needs to create a pair of keys and give away the public key, then the user would use his public key to sandy. This method is far from perfect, because, as it is not possible to verify the keys pesronally, there could be a man in the middle attack, but at least is better than nothing. Isn't it?