manyCalendars
  • How it works
  • Plans
  • Blog
  • FAQ
Join the waitlist
TRUST & SECURITY

Local session access.
Explicit cloud boundaries.

Limited access product · Updated 2026-08-24

The important boundary

  • manyCalendars is currently at capacity. Access is limited to approved members while Free and paid spots are full. New members can join the waitlist for the next opening.
  • The bridge operates inside the connected browser/profile you control. It reads an already signed-in session instead of asking Microsoft or Google for an OAuth grant.
  • Firefox Container identity is part of every Firefox source. If the correct Container cannot be reopened, the bridge stops instead of silently using the default cookie jar.
  • Credentials stay local; selected event data may not. Cross-device viewing requires an allowlisted snapshot, with Busy only as the default.
  • V1 is read-only. The bridge does not create, move, or delete events in a corporate calendar.

1. Data flow

StepWhere it runsData involved
Waitlist (now)manyCalendars website serviceEmail, signup label, and abuse-prevention data.
Read a calendarYour connected Firefox, Chrome, or Edge browser/profileThe extension reads supported page and accessibility data from a calendar you can already open.
Guided refreshYour connected browser/profileThe bridge may navigate dates or expand overflow in a background calendar page. It is not designed to submit a password.
Local cacheExtension storageSource configuration, recent events, health state, and preferences.
Personal calendar syncmanyCalendars account serviceAn authenticated, allowlisted event snapshot. Busy only by default; Full details only after per-source opt-in.

The Cloud Sync architecture is not end-to-end encrypted. If you enable Cloud Sync, treat that snapshot as data processed by manyCalendars and its infrastructure provider. See the Privacy Policy for the fields and controls.

2. Firefox Container safety

Two client accounts can use the same Outlook hostname and path while living in different Firefox Multi-Account Containers. URL-only matching is therefore unsafe.

The Firefox source includes the cookieStoreId. The bridge preserves it when the source is added and whenever it reopens the page. A failed Container recreation produces a visible reconnect error instead of silently retrying in another account.

The Firefox extension needs Container and cookie-related permissions to create a tab in the correct cookie store. That permission is not used to upload cookie values. Session cookies and passwords are excluded from sync payloads.

3. Extraction and refresh

  1. Structured and accessibility extraction: semantic roles, accessible labels, event relationships, and provider-aware parsing.
  2. Guided interaction: move through date ranges, expand overflow, and open details when a supported layout requires it.
  3. Screen Sync fallback: a limited recovery adapter, clearly labeled and separately reviewed. It is not the normal extraction path.

The target refresh cadence is 15 minutes. Browser scheduling, sleep, connectivity, authentication expiry, and page changes can delay it. The interface shows the last successful refresh and a degraded state rather than claiming an empty calendar is current.

4. Permissions in plain language

  • Tabs and scripting: identify selected calendar tabs and run the extraction adapter on sites the user grants.
  • Storage: keep source configuration, bridge status, and local event cache.
  • Alarms: wake the bridge for periodic refresh.
  • Contextual identities and cookies (Firefox): target the correct Multi-Account Container when recreating a source tab. The bridge is not designed to upload cookie values.
  • Optional site access: the user grants access for the calendar origins they connect. Broad browsing history and bookmark permissions are not required.

The extension package has no remotely hosted executable code. Reviewers can inspect the bridge code supplied with each release. Permission disclosures are updated whenever these permissions or data flows change.

5. Questions to ask before using manyCalendars

Does this bypass company policy?

No. The bridge avoids an OAuth/admin-consent integration, but an employer or client may still restrict browser extensions, automation, or copying calendar information to another service. Obtain any approval your agreement or policy requires before using manyCalendars.

What would a backend breach expose?

If you enable Cloud Sync, a backend breach could potentially expose account information and the event snapshots you selected. Busy-only defaults and field allowlists reduce that exposure; they do not make it zero. Source passwords and browser session cookies are not part of those snapshots.

Is it SOC 2, HIPAA, FedRAMP, or CMMC certified?

No. manyCalendars has not completed those certifications or assessments, and no BAA is offered. The website offers a member waitlist and the free Calendar Converter; manyCalendars access is currently limited to approved members. Do not use manyCalendars for regulated or contract-restricted data unless your organization has reviewed and approved the actual data flow.

Does AI train on events?

No. V1 sync and the calendar viewer do not send event content to an AI model or use it for model training. On compatible devices, the Calendar Converter can use an AI picture reader that runs locally in the browser. It downloads model files, but it does not upload the schedule image or extracted events to that model provider.

6. Responsible disclosure

Report vulnerabilities to security@manycalendars.com with reproduction steps and the affected version. Privacy questions: privacy@manycalendars.com. General support: support@manycalendars.com.

manyCalendars

A read-only view for the calendars your browser can already access.

Product

How it works Plans Join the waitlist Security

Resources

Blog Security Privacy FAQ

Company

About V1 Join the waitlist Contact

Legal

Privacy Policy Website Terms DPA / GDPR Legal contact

© 2026 manyCalendars. Built by contractors, for contractors.