Privacy Policy
Last updated: 19 September 2026
FlexCal is a Chrome extension and a companion server that schedule your tasks and habits into your Google Calendar. This policy explains what data FlexCal handles, why, and how you can delete it. It is written to be read, not skimmed: there are no hidden clauses.
The short version
- FlexCal stores the tasks, habits and settings you enter so it can plan your week.
- It reads your Google Calendar to find free time and writes only the events it creates (prefixed
[AI]). - Your data is never sold, never used for advertising, and never shared with third parties except the Google APIs needed to do the job.
- You can delete everything by emailing 100extensions@gmail.com.
What we collect and why
| Data | Why | Where |
|---|---|---|
| Google account ID and email | To identify your account and show who is signed in. | FlexCal server |
| Google OAuth refresh token | To read your calendar and write scheduled blocks on your behalf without asking you to sign in every time. Stored encrypted at rest. | FlexCal server |
| Tasks, habits, projects, labels, notes | They are the input to the scheduler. | FlexCal server |
| Timezone, working hours, personal hours, buffer | To plan inside the hours you choose. | FlexCal server |
| Calendar events: start, end, title, busy/free status, your attendee response | To know when you are busy. Titles are kept so the popup can show what a block is next to. Refreshed every 15 minutes; replaced on each sync. | FlexCal server |
| Scheduled blocks and the IDs of events FlexCal created | To move or remove its own events later and to avoid duplicates. | FlexCal server and your Google Calendar |
| Session token, theme, cached email, rating status | To keep you signed in and remember preferences. | Your browser (extension storage) only |
Google user data
FlexCal requests the following Google scopes: calendar.events (read your events and create, update or delete events), userinfo.email and userinfo.profile (your email address and basic profile), and openid. It does not request access to Drive, Gmail, Contacts or any other Google service.
FlexCal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide the scheduling features you see in the extension. It is not used for advertising, not sold, not used to train models, and not read by humans except with your explicit permission for support, or as required by law.
What we do not do
- No advertising, no trackers, no analytics on your schedule or task contents.
- No selling or renting of data, ever.
- No modification of calendar events FlexCal did not create.
- No access to pages you browse. The extension has no content scripts and requests no host permissions other than its own API server.
Chrome permissions
identity | Runs the Google sign-in flow. |
storage | Keeps your session and preferences in the browser. |
alarms | Schedules the morning digest and deadline checks. |
notifications | Shows the morning digest and deadline warnings. |
| Host permission for the FlexCal API | Lets the extension talk to the FlexCal server. |
Third parties
Data is sent only to Google (Calendar and sign-in APIs) and to the FlexCal server. If you rate the extension, the Chrome Web Store or a feedback form opens in a new tab; anything you type there is governed by that site's policy. The uninstall feedback form receives the extension's ID, name and your browser language so responses can be attributed to the right extension. It receives no account data.
Retention and deletion
- Sign out in the extension removes the session from your browser. Server-side data is kept so you can sign back in.
- Delete your account by emailing 100extensions@gmail.com from the Google address you signed in with. All server-side data, including the encrypted refresh token, is deleted within 30 days. Events FlexCal created remain in your calendar unless you ask for them to be removed as well.
- Revoke access at any time at myaccount.google.com/permissions. FlexCal then loses the ability to read or write your calendar immediately.
- Cached calendar events are replaced on every sync and cover only a rolling window of about two weeks.
Security
All traffic between the extension, the server and Google uses HTTPS. Refresh tokens are encrypted at rest with a key that is never stored alongside the database. Sessions are signed tokens that expire and can be invalidated by signing out.
Children
FlexCal is not directed at children under 13 and does not knowingly collect data from them.
Changes
If this policy changes in a way that matters, the "last updated" date above changes and the extension's store listing links to the new version. Continued use after that means you accept the updated policy.
Contact
Questions, access requests or deletion requests: 100extensions@gmail.com.