A clear boundary
between browser and cloud.
Effective: 2026-08-10 · Last updated: 2026-08-24
The 30-second version
- manyCalendars access is currently full. The public website offers product information, a waitlist, and a free Calendar Converter. Browser extension and web app access is limited to approved members.
- Your schedule stays on your device when you use the Calendar Converter. We receive limited usage-status events, but not the file, screenshot, text, calendar events, or generated calendar file.
- Your passwords, authentication cookies, and corporate browser sessions stay in your connected browser profile. manyCalendars does not upload or store them.
- Web app access is an optional cloud feature. If you turn on Cloud Sync, the extension uploads a copy of only the calendars you choose so your private web calendar can display them.
- Busy only is the default. Full details require a separate choice for each source.
- We do not sell waitlist data. Our policy is not to sell calendar or account data or use calendar content for advertising or AI training.
1. Information we receive now
1.1 Waitlist data
When you join the waitlist, we receive your email address and the signup label associated with the form. We also store a salted, one-way hash of the requesting IP address for short-term abuse prevention; the raw IP address is not written to the waitlist table by our application.
1.2 Support and website metadata
We do not automatically receive the contents of your browser console or screenshots. If you contact support, we receive what you choose to send. Our hosting and security providers may process standard request metadata such as IP address, user agent, timestamp, and response status while delivering the site and API.
1.3 Calendar Converter usage data
The Calendar Converter processes the schedule you provide and creates its draft events and calendar file in your browser. The usage endpoint is designed not to receive the source file, screenshot, OCR text, event names, dates, times, locations, descriptions, generated ICS contents, email address, or a persistent user or device identifier.
On compatible devices, a difficult picture may use an optional AI reader that runs inside your browser. The first use downloads the reading model and supporting files from Hugging Face. The picture, recognized words, and draft events are not sent with those download requests and are not used for model training. Hugging Face may receive ordinary network request information, such as an IP address and browser details, while serving the model files.
To understand whether the converter works, we may receive a limited status event when the converter is viewed, a conversion starts, succeeds, or fails, a manual event is added, review is confirmed, or a calendar file is downloaded or shared. That event can include a coarse input category such as image, PDF, spreadsheet, CSV, text, or manual entry; an allowlisted failure category; and a public application-version label. The application payload does not include an IP address or user agent, although Cloudflare may process ordinary request metadata while delivering the endpoint.
2. Information used by member accounts
A member account uses an email address, authentication records, and entitlement information. If paid checkout is offered, Stripe will process payment-card details; manyCalendars is not designed to receive a full card number.
When personal-calendar sync is enabled for a source, the service receives its generated source identifier, display name, color, bridge label, detail setting, last-updated time, and an event snapshot.
Busy only is the default. The uploaded event record is limited to the timing and minimal state required to draw a busy block. Full details is optional per source and may include title, location, meeting link, and description when available. The extension redacts the record before upload, and the sync endpoint applies an allowlist again before storage.
3. What stays in your connected browser
The Firefox, Chrome, and Edge extensions read supported calendar pages inside a browser profile where you are already signed in. The extraction order is page structure and accessibility information first, guided page interaction when needed, and a separately reviewed Screen Sync fallback only where supported.
- manyCalendars does not receive your Outlook, Google, or client password.
- Authentication cookies and browser profile or Firefox Container cookie jars are not included in sync payloads.
- Raw page markup, screenshots, and general browsing history are not uploaded by the normal structured and guided adapters.
- The source URL and connected browser/profile identity remain local so the bridge can return to the correct signed-in context. In Firefox, that identity can include a Multi-Account Container.
Calendar providers see normal requests from your browser when a page is opened or refreshed. Your employer's or client's browser-extension and data-handling policies still apply.
4. Local and cloud storage
The extensions store source configuration, recent extraction results, health state, and preferences in browser storage. Clearing extension storage or uninstalling the extension removes that local copy.
When Cloud Sync is enabled, the latest selected snapshot is stored in a Supabase-backed account service and made available to the signed-in personal calendar over HTTPS. Cloud Sync is not end-to-end encrypted, so data enabled for Cloud Sync is technically processable by manyCalendars and its infrastructure provider. Do not enable Full details for a source unless you are allowed to copy that information into manyCalendars.
5. Your controls
You can unsubscribe from waitlist emails using the link in a message or contact us to request deletion of your waitlist record. Member controls let you:
- Choose Busy only or Full details independently for each synced source.
- Pause or remove a source from the extension.
- Turn off sync for a source to remove its server snapshot.
- Delete the manyCalendars account to remove its calendar snapshots, feed token, sync counters, and authentication user.
- Contact us to access, correct, export, or delete other account information where applicable.
If paid checkout is offered, transaction and anti-abuse records may need to be retained for tax, fraud prevention, dispute handling, or legal obligations. Uninstalling an extension does not by itself delete an account or server snapshots; use the account deletion control or contact support.
6. Service providers
- Supabase provides database storage, server functions, authentication, and calendar snapshot services. Supabase privacy policy.
- Cloudflare delivers and protects the website, may process standard request metadata, and may provide privacy-limited aggregate usage measurement for the Calendar Converter. Cloudflare privacy policy.
- Hugging Face serves the optional on-device picture-reading model. Your browser requests model files only when that fallback is needed; the converter does not send the schedule image or extracted calendar details in that request. Hugging Face privacy policy.
- Stripe may process payments if paid checkout is offered. Stripe privacy policy.
- Resend may deliver waitlist, account, or license email. Resend privacy policy.
We do not sell waitlist data. Our product policy is not to use calendar content for behavioral advertising, sell it to data brokers, or provide it to AI-model training systems.
7. Retention and security
Waitlist records are retained only as needed to provide access updates, prevent abuse, comply with legal obligations, and honor deletion or unsubscribe requests. Calendar Converter usage records may be retained in Cloudflare Analytics Engine for up to three months under Cloudflare's current service limits. Account, licensing, transaction, and calendar snapshot records follow the retention periods presented to members. Snapshots are retained while a source remains enabled or until the user removes the source or deletes the account.
No system is risk-free. The waitlist uses HTTPS and server-side abuse controls. The member service uses authenticated API calls, per-user access checks, row-level database controls, payload limits, and client- and server-side field allowlists. See Trust & Security for the architecture and its limitations.
8. Changes and contact
We will update this policy before broadening access to accounts, extensions, personal calendars, or paid checkout, and before materially expanding the information we collect or changing how it is used. Questions and privacy requests: privacy@manycalendars.com. General questions: support@manycalendars.com.