PRIVACY POLICY
A personal desktop should stay personal.
This policy explains how the Deskpot Chrome extension and website handle information. It reflects the current public version of Deskpot and will be updated whenever its data practices change.
Last updated: August 18, 2026What Deskpot stores on your device
Deskpot uses Chrome's local extension storage to remember the desktop you create. This can include shortcut names and website addresses, folders, dock order, wallpaper choices or a custom wallpaper, plant status, countdown names and dates, weather location and cached forecast data, calendar visibility, a limited cache of Google Calendar event titles and times for the visible month, preferences, and onboarding status.
Folder passcodes are not stored as readable passcodes. Deskpot stores a locally generated salt and cryptographic hash on your device. Folder locks are a local convenience feature, not encrypted storage. Google Calendar events and connection status are excluded from all Deskpot JSON backups. Free users can create a local backup by choosing Export. Pro users can also choose to connect automatic Google Drive backup.
If you activate Deskpot Pro, the extension stores a randomly generated device identifier, your Freemius license key, the Freemius installation identifier, license status, and the last successful verification time in Chrome's local extension storage. License information is kept separate from Deskpot backups and is never included in an exported or Google Drive backup.
Information used for specific features
Adding the current website
When you press Deskpot's toolbar button, Chrome gives Deskpot temporary access to the active tab so its title and address can be saved as a shortcut. Deskpot does not continuously monitor browsing activity.
Chrome bookmarks
Chrome bookmark access is optional and is requested only when you enable Saved from this site from a website shortcut's right-click menu. If granted, Deskpot reads bookmark titles, addresses, folders, and available bookmark dates directly from Chrome to find pages belonging to that shortcut's hostname and subdomains. It shows up to 5 matches in the menu, lets you view additional matches, and hides the bookmark section when the site has no matches.
Deskpot does not create, edit, move, delete, upload, or copy Chrome bookmarks into Deskpot storage. Matches are read live when you use the feature. You can remove bookmark permission from Chrome's extension settings.
Search
When you submit a non-URL search, Deskpot hands the query to Chrome's search API. Chrome sends it to the search provider you selected in your browser. Deskpot does not save the query.
While you type at least two characters, Deskpot may request live suggestions from Google's suggestion service after a short delay. The typed query and browser language are sent to Google for that request. Deskpot omits credentials and does not store the suggestion query.
Weather
When you choose a city, Deskpot sends the city name to Open-Meteo's geocoding service and uses the resulting approximate coordinates to request weather information. The result is cached locally for up to 30 minutes. Deskpot does not request precise device location.
Currency converter
When you use the currency converter, Deskpot sends the selected source and destination currency codes to Frankfurter to request the current exchange rate. The amount you enter stays on your device and is not sent with the request. Exchange rates are cached locally for up to 15 minutes.
Google Calendar
Google Calendar access is optional and begins only when you choose Connect Google Calendar and grant consent. Deskpot requests the read-only calendar-events scope and retrieves event titles, start and end times, all-day status, and Google Calendar links from the connected account's primary calendar for the visible month. Deskpot does not create, edit, or delete calendar information. Chrome manages the OAuth access token. Deskpot caches the limited event list locally so the panel can remain useful between refreshes.
You can disconnect inside Deskpot at any time. Disconnecting clears Deskpot's cached Calendar authorization, connection status, and locally cached calendar events without disconnecting a separately enabled Drive backup.
Google Drive backup
Automatic Google Drive backup is an optional Deskpot Pro feature and begins only when you choose Connect Google Drive. Deskpot requests the narrow drive.appdata scope and creates a private JSON backup for that device inside Google Drive's hidden application-data folder. This permission lets Deskpot access only configuration data it created for Deskpot. It cannot browse or read your other Drive files.
Each connected device uses a separate backup file with a user-editable device name. This prevents automatic changes from one computer from overwriting another computer's desktop. During restore, Deskpot lists the available device backups so you can choose the layout you want.
The Drive backup can contain shortcuts, folders, layout, wallpaper data, plant state, countdowns, sticky notes, weather preferences, and widget settings. It never contains Google Calendar events, OAuth tokens, or Freemius license details. Deskpot updates the private backup automatically after changes. You can disconnect automatic backup at any time; disconnecting stops future uploads and keeps the existing backup available if you reconnect later.
Deskpot Pro checkout and licensing
Purchases are completed on Freemius, Deskpot's payment and licensing provider. Freemius collects the checkout information needed to process the purchase, issue a license, provide receipts, handle taxes, and support refunds under the displayed purchase terms. Deskpot and Heapps Labs do not receive or store your full payment-card details.
When you activate, validate, or deactivate Pro, Deskpot sends your license key, random 32-character device identifier, device title, and Freemius installation identifier through the Heapps Labs license service to Freemius. The service uses this information only to perform the action you requested, enforce the three-personal-device activation limit, and return a limited status result. It does not return Freemius secrets or payment information to the extension.
Google API user data
Data accessed and how it is used
Deskpot accesses Google user data only after you deliberately connect an optional Google feature and approve its requested permission. For Calendar, Deskpot reads event titles, start and end times, all-day status, and event links from the connected account's primary calendar for the visible month, solely to display those events inside the Deskpot calendar widget. For Drive backup, Deskpot creates, lists, reads, updates, and restores only Deskpot configuration files that Deskpot created inside the connected account's hidden Google Drive application-data folder, solely to provide the backup and restore feature you requested.
Deskpot does not create aggregated or anonymized datasets from Google Calendar or Google Drive user data. It does not use Google user data for advertising, profiling, creditworthiness, lending, or developing, improving, or training generalized AI or machine-learning models.
Data sharing and transfer
Deskpot does not sell Google user data or share it with advertisers, data brokers, or other third parties. Calendar data travels directly between Google's APIs and the Deskpot extension and is not sent to Heapps Labs, Freemius, or another external service. Drive backup data travels directly between the Deskpot extension and the user's own Google Drive app-data folder. Heapps Labs does not receive or keep a server-side copy of Calendar events or Drive backups.
Data protection
Requests to Google APIs use encrypted HTTPS connections. OAuth access tokens are managed by Chrome's Identity API, are not included in Deskpot backups, and are not transmitted to Heapps Labs. The limited Calendar cache is kept in Chrome's extension storage within the user's browser profile. Google user data is processed only for the connected feature and is not exposed to website scripts or advertising systems.
Retention, deletion, and access removal
Locally cached Calendar events remain only until they are replaced by a later Calendar request, or until you disconnect Calendar, reset Deskpot, clear extension storage, or uninstall Deskpot. Disconnecting Calendar clears its local connection state and cached events. You may also remove Deskpot's authorization from your Google Account's third-party access settings.
A Drive backup remains in the user's hidden Google Drive app-data folder until the user permanently removes that app data through Google account controls. Disconnecting Drive stops future backup access and uploads but does not silently delete the existing backup. Resetting or uninstalling Deskpot does not delete data stored in the user's Google Drive account.
Google API Services User Data Policy
Deskpot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What the website handles
The Deskpot website uses Cloudflare Web Analytics to understand aggregate page visits, referrers, countries, browsers, and website performance. Cloudflare states that Web Analytics does not collect or use visitors' personal data, does not fingerprint visitors, and does not use cookies for this service. Heapps Labs uses these aggregate measurements only to improve the website and understand which public pages help people discover Deskpot.
The website does not use advertising trackers, account registration, or marketing cookies. Hosting infrastructure may process standard network information, such as an IP address, browser type, and request logs, to deliver and secure the website. License API responses are marked not to be cached, and Deskpot does not intentionally log license keys. Deskpot itself does not contain marketing analytics or behavioral telemetry.
How information is shared
Deskpot does not sell personal information and does not share information for advertising. Information leaves the device only when necessary for a feature you choose, such as requesting calendar events from Google, storing a private Pro backup in your own Google Drive app-data folder, requesting typed search suggestions from Google, sending a submitted search to your browser's selected search provider, sending a city and approximate coordinates to Open-Meteo, sending selected currency codes to Frankfurter, or asking Freemius to process a purchase or license action.
Retention and deletion
Locally stored Deskpot information remains until you change it, reset Deskpot, clear the extension's storage, or uninstall the extension. Cached weather data is refreshed periodically. Cached Google Calendar events are replaced when you refresh or change the visible month and are deleted when you disconnect or reset Deskpot. You can export a backup before resetting or uninstalling, but the export does not contain Google Calendar events, authorization, or license information.
Disconnecting automatic Drive backup stops future uploads but does not delete the existing private backup. You can reconnect to restore or update it. To permanently remove it, delete Deskpot's hidden app data through your Google Drive account controls or contact support for guidance.
Deactivating Pro releases the Freemius device activation and removes the license key from Deskpot's active local license record. Purchase and license records retained by Freemius are governed by Freemius's legal obligations and policies. Contact support if you need help with license or purchase records.
Chrome Web Store Limited Use
Deskpot's use of information received through Chrome extension APIs also complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Children's privacy
Deskpot is a general-audience productivity extension and is not directed to children under 13. Deskpot does not knowingly collect personal information from children.
Operator and contact
Deskpot is operated under the Heapps Labs name. For privacy questions, support requests, or data concerns, contact support@heappslabs.com or review the Deskpot Support page.
Changes
Material changes will be reflected on this page and, when required, disclosed inside the extension before new information is handled.