FlowDeck provides browser extensions, including FlowDeck for Gmail, FlowDeck for GitHub, FlowDeck for Docs, and FlowDeck for Calendar. Each product processes only the information needed for its visible, user-requested workflow features.
FlowDeck uses information only to provide those features. It does not sell user data, use it for advertising or credit decisions, transfer it to data brokers, or make it available for routine human review.
DATA PROCESSED AND STORED
FlowDeck for Gmail may store Inbox Guard and Reply View preferences; trusted and protected sender rules; Copy Rules settings; and configured CC or BCC recipient addresses. While Gmail is open, it temporarily observes the interface state needed for enabled features, including message-row movement, displayed sender and subject details used in confirmation prompts, compose recipient fields, and the presence of trimmed reply content. It does not store Gmail message body text.
FlowDeck for GitHub may store whether Timeline Loader and Latest Comment scrolling are enabled, the stalled-load retry delay, the automatic expansion limit, and the manual batch size. While GitHub is open, it observes the current page path, GitHub's own timeline pagination controls, and comment positions needed for optional scrolling. It does not store GitHub page content.
FlowDeck for Docs temporarily processes the active or explicitly selected Google document ID and tab, a short-lived cursor anchor, Zotero-compatible active-field metadata, exact Zotero library and item keys, citation options, citation metadata needed for the requested operation, and a short-lived Google OAuth token managed by Chrome.
The FlowDeck for Docs macOS companion stores only local operational records: operation type and time; a one-way hash of the Google document ID; exact Zotero item keys used for the operation; success or failure status; an idempotency-key hash; and a non-content audit identifier. Its audit and diagnostic records exclude manuscript prose, rendered citations, titles, authors, document URLs, OAuth tokens, Zotero library contents, and personal identities. The local bridge capability is stored in the macOS Keychain.
FlowDeck for Calendar reads upcoming events from the user's primary Google Calendar. It processes event identifiers, titles, start and end times, response states, locations, conference links, descriptions, and attachment links needed to show Today Deck, identify Meeting Guard warnings, and determine whether a supported Zoom meeting is eligible to open.
FlowDeck for Calendar may store settings in Chrome sync storage. Chrome local storage may contain a short-lived normalized event cache, scheduled launch records, skipped or opened meeting identifiers, and sanitized diagnostics. Diagnostics exclude event titles, attendees, descriptions, and meeting URLs, and are exported only through an explicit user action.
DATA HANDLING AND TRANSFERS
FlowDeck for Gmail and FlowDeck for GitHub do not send Gmail content, GitHub content, recipient data, rule data, account information, repository details, browsing history, settings, or usage telemetry to the developer or any developer-operated service. Chrome may sync extension settings between the user's signed-in Chrome browsers when chrome.storage.sync is available. That browser-managed synchronization is controlled by Chrome; FlowDeck does not receive the synchronized data.
Exporting Gmail Copy Rules creates a local JSON file through the browser. Importing reads only the local JSON file selected by the user.
For FlowDeck for Docs, Google Docs API and Google Picker requests go directly to Google under the user's authorization. Zotero requests go directly to Zotero Desktop on the same computer. Extension-to-companion traffic stays on the local computer through Chrome Native Messaging and a user-private local socket. No manuscript text or Zotero library data is sent to FlowDeck-operated infrastructure.
For FlowDeck for Calendar, Google Calendar API requests go directly from Chrome to Google under the user's authorization. Calendar data is not sent to FlowDeck-operated infrastructure. Opening a meeting link sends the link and the browser's ordinary request data to the meeting provider in the same way as opening that link manually.
FlowDeck has no telemetry, analytics, advertising, or developer-operated data server.
GOOGLE ACCESS AND LIMITED USE
FlowDeck for Docs requests the per-file drive.file scope. It can create a new document or work with an existing Google Doc the user explicitly selects in Google Picker. It does not request access to every Google Drive file.
FlowDeck for Calendar requests only the calendar.events.readonly scope. It reads events from the primary calendar and re-checks an eligible event immediately before opening a meeting link. It cannot create, change, or delete Google Calendar events.
FlowDeck's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Chrome Web Store User Data Policy, including their Limited Use requirements.
SITE ACCESS
FlowDeck for Gmail runs only on https://mail.google.com/mail/*.
FlowDeck for GitHub runs only on https://github.com/*. Its current features activate only on issue and pull request conversation pages.
FlowDeck for Docs runs its cursor adapter only on editable Google Docs document pages. Its Google API permission is limited to files the user creates with or explicitly selects for FlowDeck.
FlowDeck for Calendar does not inject code into Google Calendar pages. It reads events from https://www.googleapis.com/* and opens only recognized Zoom meeting URLs when the configured launch rules allow it.
RETENTION, CONTROL, AND REMOVAL
Remove the relevant FlowDeck extension from chrome://extensions to stop it. Chrome controls deletion or synchronization of extension settings.
For FlowDeck for Docs, running the companion's Uninstall command removes its Native Messaging registration, LaunchAgent, local audit and idempotency records, socket, bundled runtime, and Keychain capability. Removing FlowDeck does not delete Google Docs or Zotero items; those remain under the user's Google and Zotero controls.
For FlowDeck for Calendar, disconnecting Google removes the cached OAuth grant from Chrome and clears local calendar state. Removing the extension removes its Chrome storage. Disconnecting or removing FlowDeck does not delete or modify Google Calendar events.
CONTACT
Questions about this policy may be sent to flowdeck.support@gmail.com.
Last updated: July 30, 2026.