Privacy Policy
Draft last updated 2026-08-21
This policy covers Plot It's website and Chrome extension. Plot It is built around a simple idea: it changes how Google Calendar looks, and that's it. This page explains exactly what that means in practice.
Why does Plot It need permission?
What the free extension accesses today
The Plot It Chrome extension declares five permissions in its manifest:
- Access to calendar.google.com — needed to inject the CSS that applies your chosen theme. Plot It cannot see or act on any other website.
- Local browser storage — needed to remember which style you've picked, on your device, between visits.
- Access to plotitapp.com — Plot It's own content-hosting server. Needed so the extension can retrieve a paid bundle's theme files (CSS, fonts, and illustrations) once a license code you've entered has been verified.
- Alarms — needed to periodically re-check purchased licenses in the background, so a refunded or disabled code loses access automatically, without you needing to do anything.
- Access to api.lemonsqueezy.com — needed to verify license codes directly against Lemon Squeezy when you redeem a purchase, and again whenever the periodic re-check above runs.
Beyond that: the extension injects CSS to change colors, fonts, and background imagery — it does not read, collect, store, or transmit your calendar events, contacts, or any other content from the page. There is no account to create and no calendar data ever leaves your browser.
When you redeem a purchased code
Paid bundles work differently, because the files for a bundle you haven't purchased aren't shipped inside the extension at all. Redeeming a license code involves two additional, narrowly-scoped connections:
- Lemon Squeezy — the extension sends the code you enter to Lemon Squeezy's license activation/validation service, to confirm it's a real, unrefunded purchase. No calendar data is included in this request.
- Plot It's content-hosting server — once a code is confirmed, the extension fetches that bundle's CSS, font, and illustration files from a small server we operate, which independently re-checks the license with Lemon Squeezy before releasing any file.
Content-hosting server: built and livePopup redemption: not yet available to users
The content-hosting server described above isn't hypothetical — it's real, running code, live in production today, and it already independently re-validates every request the way this section describes. The popup screen for entering a code is built too, but the extension itself hasn't been published anywhere yet, so no real customer has gone through this flow. This section will be re-confirmed once the extension actually ships.
Payment processing
All payments are handled by Lemon Squeezy, our Merchant of Record. Lemon Squeezy collects and processes your payment details, calculates and remits applicable sales tax/VAT, and emails you a receipt and license code directly. Plot It never sees or stores your full card number.
What we don't collect
- No user accounts or passwords — Plot It doesn't have a login system anywhere.
- No calendar event content, contacts, or any other Google Calendar data.
- No sale or sharing of personal information to third parties for their own marketing.
Information collected on this website
The website itself collects only:
- Order lookup / resend-code requests — the email (and optionally order reference) you enter on the Support page, used only to look up your order with Lemon Squeezy and send your code back to the email on file.
- Basic product analytics — which bundles/styles get previewed and purchased, so we know what to build next. Events never include calendar content or other personal information. Not yet connected to an analytics provider
Cookies
The Plot It website does not currently set tracking or advertising cookies. If that changes (for example, once analytics is connected), this section will be updated first.
Children's privacy
Standard boilerplate — confirm before launch
Plot It is not directed at children under 13, and we do not knowingly collect personal information from children.
Your choices
To ask what data we hold about you or to request it be deleted, contact plotit@plotitapp.com.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page.
Governing law
Pending — jurisdiction not yet set
The governing law and venue for this policy haven't been decided yet — this depends on where the business is formally registered (see docs/roadmap.md's business-entity item), which hasn't happened yet. Do not assume a jurisdiction until this is filled in.
Contact
Questions about this policy: plotit@plotitapp.com. No formal business entity has been registered yet — this line will name it once that's done.
This page is a draft, pending legal and business review — not yet reviewed by a lawyer, not yet in effect, and no effective date has been set.