FlowDeck provides browser extensions, including FlowDeck for Gmail, FlowDeck for GitHub, FlowDeck for Docs, and FlowDeck for Calendar. Each product processes only the information needed for its visible, user-requested workflow features.
FlowDeck uses information only to provide those features. It does not sell user data, use it for advertising or credit decisions, transfer it to data brokers, or make it available for routine human review.
DATA PROCESSED AND STORED
FlowDeck for Gmail may store Inbox Guard and Reply View preferences; trusted and protected sender rules; Copy Rules settings; and configured CC or BCC recipient addresses. While Gmail is open, it temporarily observes the interface state needed for enabled features, including message-row movement, displayed sender and subject details used in confirmation prompts, compose recipient fields, and the presence of trimmed reply content. It does not store Gmail message body text.
FlowDeck for GitHub may store whether Timeline Loader and Latest Comment scrolling are enabled, the stalled-load retry delay, the automatic expansion limit, the manual batch size, and the order, button labels, and comment text of user-configured Quick Replies. It may also store whether optional Unicode attachment filename preservation is enabled; that setting stays local because it is tied to a browser permission.
After a matching user action, an attachment URL and its displayed filename are eligible for matching for one minute in Chrome session storage so a download or Save Link As action can retain the visible name across a service-worker restart. Expired entries are ignored and removed on the next service-worker read or wake, and Chrome clears this session storage when the browser session ends.
While GitHub is open, FlowDeck observes the current page path, the main issue or pull request comment field, GitHub's own timeline pagination controls, and visible-text GitHub attachment links needed for enabled features. It does not store GitHub page content.
FlowDeck for Docs temporarily processes the active or explicitly selected Google document ID and tab, a short-lived cursor anchor, Zotero-compatible active-field metadata, exact Zotero library and item keys, citation options, citation metadata needed for the requested operation, and a short-lived Google OAuth token managed by Chrome.
The FlowDeck for Docs macOS companion stores only local operational records: operation type and time; a one-way hash of the Google document ID; exact Zotero item keys used for the operation; success or failure status; an idempotency-key hash; and a non-content audit identifier. Its audit and diagnostic records exclude manuscript prose, rendered citations, titles, authors, document URLs, OAuth tokens, Zotero library contents, and personal identities. The local bridge capability is stored in the macOS Keychain.
FlowDeck for Calendar reads upcoming events from the user's primary Google Calendar. It processes event identifiers, titles, start and end times, response states, locations, conference links, descriptions, and the minimum attendee and organizer state needed to show Today Deck, identify Meeting Guard warnings, and determine whether a supported Zoom meeting is eligible to open. It does not request or cache Calendar attachment links.
FlowDeck for Calendar may store settings in Chrome sync storage. Chrome local storage may contain a short-lived normalized event cache, scheduled launch records, skipped or opened meeting identifiers, short-lived launch claims, simultaneous-meeting choices, and sanitized diagnostics. Diagnostics exclude event titles, attendees, descriptions, and meeting URLs, and are exported only through an explicit user action.
DATA HANDLING AND TRANSFERS
FlowDeck for Gmail and FlowDeck for GitHub do not send Gmail content, GitHub content, recipient data, rule data, account information, repository details, browsing history, settings, download metadata, or usage telemetry to the developer or any developer-operated service. Chrome may sync extension settings between the user's signed-in Chrome browsers when chrome.storage.sync is available. That browser-managed synchronization is controlled by Chrome; FlowDeck does not receive the synchronized data.
A Quick Reply changes only the local comment draft; FlowDeck never clicks GitHub's submit button.
When the user enables attachment filename preservation, Chrome asks for the optional downloads permission. Chrome then exposes browser-wide download metadata. FlowDeck checks only the original URL locally and immediately ignores anything other than an exact https://github.com/user-attachments/files/... URL with a pending filename from a user-activated GitHub link. It never reads downloaded file contents. Disabling the feature removes the optional permission and clears pending filename suggestions.
Exporting Gmail Copy Rules creates a local JSON file through the browser. Importing reads only the local JSON file selected by the user.
When the user chooses Copy diagnostic information in FlowDeck for Gmail, FlowDeck creates a local support report containing the extension version, UI locale, enabled-module states, and aggregated runtime health. The report excludes email addresses, message content, subjects, tab URLs, and rule values. It is shown and copied only at the user's request and is never sent automatically.
For FlowDeck for Docs, Google Docs API and Google Picker requests go directly to Google under the user's authorization. The extension opens a static FlowDeck Picker page on Firebase Hosting. OAuth tokens and callback values stay in the URL fragment, are removed before Picker loads, and are not included in the hosting request. Zotero requests go directly to Zotero Desktop on the same computer. Extension-to-companion traffic stays on the local computer through Chrome Native Messaging and a user-private local socket. No manuscript text or Zotero library data is sent to FlowDeck-operated infrastructure.
For FlowDeck for Calendar, Google Calendar API requests go directly from Chrome to Google under the user's authorization. Calendar data is not sent to FlowDeck-operated infrastructure. Opening a meeting link sends the link and the browser's ordinary request data to the meeting provider in the same way as opening that link manually.
FlowDeck has no telemetry, analytics, advertising, or developer-operated data server.
GOOGLE ACCESS AND LIMITED USE
FlowDeck for Docs requests the per-file drive.file scope. It can create a new document or work with an existing Google Doc the user explicitly selects in Google Picker. It does not request access to every Google Drive file.
FlowDeck for Calendar requests only the calendar.events.readonly scope. It reads events from the primary calendar and re-checks an eligible event immediately before opening a meeting link. It cannot create, change, or delete Google Calendar events.
FlowDeck's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Chrome Web Store User Data Policy, including their Limited Use requirements.
SITE ACCESS
FlowDeck for Gmail runs only on https://mail.google.com/mail/*.
FlowDeck for GitHub runs only on https://github.com/*. Timeline Loader and Quick Replies activate only on issue and pull request conversation paths. Attachment filename preservation can activate on a GitHub page only for a visible-text user-attachments/files link whose name plausibly matches its URL.
FlowDeck for Docs runs its cursor adapter only on editable Google Docs document pages. Its Google API permission is limited to files the user creates with or explicitly selects for FlowDeck. It does not request Chrome's broad tabs permission.
FlowDeck for Calendar does not inject code into Google Calendar pages. It reads events from https://www.googleapis.com/* and opens only recognized Zoom meeting URLs when the configured launch rules allow it.
RETENTION, CONTROL, AND REMOVAL
Remove the relevant FlowDeck extension from chrome://extensions to stop it. Chrome controls deletion or synchronization of extension settings.
For FlowDeck for GitHub, disabling attachment filename preservation removes the optional downloads permission and clears pending filename suggestions. Removing the extension clears its Chrome storage according to Chrome's controls.
For FlowDeck for Docs, running the companion's Uninstall command removes its Native Messaging registration, LaunchAgent, local audit and idempotency records, socket, bundled runtime, and Keychain capability. Removing FlowDeck does not delete Google Docs or Zotero items; those remain under the user's Google and Zotero controls.
Audit records are rotated when the current log reaches 5 MiB, and only the current and immediately previous logs are retained. Completed idempotency records are removed after 30 days and limited to the 5,000 most recent entries. Pending records are retained because deleting an unresolved outcome could allow a duplicate document write.
For FlowDeck for Calendar, normalized events, scheduled launch records, launch claims, and opened or skipped meeting identifiers are removed no later than 24 hours after the last successful Calendar refresh. A simultaneous-meeting choice expires after at most two hours. Sanitized diagnostic entries are retained for at most 30 days and are limited to the latest 100 entries.
For FlowDeck for Calendar, disconnecting Google removes the cached OAuth grant from Chrome and clears local calendar state. Removing the extension removes its Chrome storage. Disconnecting or removing FlowDeck does not delete or modify Google Calendar events.
CONTACT
Questions about this policy may be sent to flowdeck.support@gmail.com.
Last updated: August 25, 2026.