Privacy
Last updated 16 September 2026
There is no analytics, no telemetry, and no usage tracking of any kind in this extension. Nothing is sent anywhere except the calls described below, and the content you're extracting from is only sent when you press the button.
Extraction runs on included credits, through this extension's own server. Using it means signing in with Google, because the credits need an account to belong to — and that same sign-in is what lets approved events be written to your calendar.
What leaves your browser
When you press Create events, the content you supplied — pasted text, and any PDF or image you attached — is sent so the event details can be extracted from it. The request also includes your current date and time zone, which is what lets phrases like "next Tuesday" resolve correctly.
That content goes to this extension's server (quickaddcal.com), which
passes it to the Anthropic API and returns the result. The server
handles your content in memory only: it is never stored, logged, or used for anything
except that one extraction call. What the server does keep is described under "What our
server stores" below.
Anthropic handles the content under Anthropic's privacy policy, on the terms of this extension's API account.
Only submit content you're comfortable sending to a third-party API. A screenshot often contains more than the event you care about.
What our server stores
For each signed-in user the server keeps: your Google account id and email address, your credit balance, and a ledger of credit events — when credits were granted, bought, or spent, with token counts and cost. Never the content: no text, files, or extracted events are stored, and none of it appears in logs.
Referrals add three things, and only for people who use them: your share code, created the first time you open the Share screen; a count of how many times that code has been used; and, if you enter a friend's code, a note that your account has used one. Who referred whom is never recorded — a code is matched to its owner at the moment it's entered, both accounts are credited, and the pair isn't written down.
Feedback is the one exception, and only because you typed it on purpose: if you send a thumbs up or down from Settings → Account, the message, the rating, and the extension's version number are stored and emailed to us. Nothing is attached that says who sent it — not your email address, not your account — so it also means nobody can reply to it.
Buying credits happens on Stripe's own checkout pages under Stripe's privacy policy; your card details go to Stripe and are never seen by this extension or its server. The server records only that a purchase happened and how many credits it granted.
You can delete the account from the extension's Settings, under Account. That clears your email address, your balance, your share code and its count, and the whole ledger of what you extracted and bought. What's kept is the minimum that stops a one-time offer being claimed twice: a marker that this Google account has already had its free credits, and, if it has, that it has already used a referral code. Signing in again gives you the same account back, empty.
What stays on your device
- Your sign-in session token and last known credit balance
- Your acknowledgement of this notice
- For each Google account you connect: its email address and the OAuth tokens that authorise calendar access, plus the names of its calendars
- A record of the events this extension added (title, time, and the Google event id), so they can be removed again from Settings → History
These live in your browser profile's local extension storage. They are deliberately not put in Chrome's sync storage, which would copy them to Google's servers. They never leave the device, and uninstalling the extension deletes them.
Don't take our word for it
Every claim above is one you can check yourself, because the browser enforces the important part rather than us.
-
Open
chrome://extensions, press Details on Quick Add Calendar, and read Site access. It names the three hosts listed under Permissions below and nothing else. Chrome blocks any request this extension might make to anywhere else — that is a rule the browser applies, not a promise we make. - On the same page, click the extension's service worker link to open DevTools, then watch the Network tab while you use it. Every request it makes is listed there.
- The extension is a zip file you can unpack and read, and the source is public — including the server's extraction endpoint, so what the server does with your content can be read too. What is published can be compared against it.
Google Calendar
Signing in is what gives you credits, and the same account is where approved events are written. If no calendar destination is available — you have not granted calendar access, or the grant has been revoked — events instead open a Google Calendar page with the fields pre-filled, which you then save yourself.
Signing in grants the extension permission to create and manage the events it writes and to read the list of your calendars, so you can pick where events land. It cannot read your existing events. You can connect more than one account, and disconnecting an account revokes the grant at Google and deletes its tokens from your device. Sign-in happens on Google's own pages; the extension never sees your Google password.
The credentials Google issues stay in your browser profile's local extension storage,
like everything else above. One step of sign-in — exchanging Google's one-time code for
tokens — passes through a small relay at quickaddcal.com, because Google
requires a secret that cannot be embedded in a public extension. The relay forwards
that one request to Google and returns the answer; it stores nothing, sets no cookies,
and keeps no copy of your tokens. Its source ships in the same public repository.
The extension's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: calendar data is used only to provide the features described here, and is never sold, transferred for advertising, or used to train models.
Permissions
The extension requests storage, to keep the settings above;
identity, which opens Google's own sign-in window when you choose to
connect an account; contextMenus, which adds a right-click menu item so
text you highlight can be sent to the extension — handled exactly like text you paste,
and only when you choose that menu item; and network access to exactly three hosts —
quickaddcal.com for extraction and for the sign-in
relay, www.googleapis.com for calendar writes, and
oauth2.googleapis.com for revoking access when you disconnect. It cannot
read your browsing history or your tabs, and it receives page content only when you
highlight text and pick the right-click menu item yourself. Its network access
is additionally restricted by a content security policy so it cannot contact any other
host.
It also requests activeTab and scripting, which together let
it act on the one page you are already on at the moment you use the extension, and on
no other. Two things use them. The right-click item reads back the exact text you
highlighted, because the copy Chrome hands over has had its line breaks flattened. And
after you have added events a few times, the extension draws a card on that page asking
whether you would leave a review — it is drawn, not read: nothing about the page is
looked at or sent anywhere, and dismissing it or answering it stops it for good.
Changes
If this notice changes in a way that affects what is sent or stored for everyone who uses the extension, the extension will ask you to acknowledge it again rather than changing quietly. A feature that stores something only when you choose to use it says so at the point where you use it — referrals do, on the Share screen and beside the code box.