Privacy
Last updated 1 August 2026
Cords runs on your own computer. There is no Cords server, no account and no analytics, so nothing you write in it is sent to us — there is nowhere to send it.
Where your data lives
In a SQLite database on your own machine: tasks, notes, time blocks, settings, and a mirror of any calendar events synced in. The credential for a connected Google account is encrypted by your operating system's key store; if it cannot be, Cords refuses to connect the account rather than store it unprotected.
Google Calendar
Optional, and off until you connect an account. Signing in happens in your own browser, and the resulting credentials stay on your machine. Cords asks for your email address, so it can label the account, and for two calendar permissions:
- Read your calendars and events. Events are copied into the local database so the app can show your day without asking Google each time. That copy stays on your computer.
- Add and change events, used only if you turn on write-back by choosing a calendar to write to. Until you do, nothing is written to Google.
With write-back on, Cords writes only blocks you created in Cords, and only their title and times. Events synced from Google are never written back — they belong to the calendar they came from. Your notes are never sent.
Your calendar data is not sold, shared, used for advertising, used to train any model, or read by anyone here; there is no mechanism by which it could reach us. Disconnecting an account deletes its calendars and synced events from your machine and revokes Cords' access at Google.
Cords' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Agents
Cords can be driven by an agent running on the same machine, such as Claude Code. An agent you connect can read and change the same things you can. That is the point of it, but it stays your decision: each agent needs a token you create in the app, its changes are attributed to that token, and revoking it ends access at once. What the agent does with what it read is governed by whoever runs it.
Everything else
No telemetry, analytics or crash reporting. An installed copy checks GitHub for a newer version, which you can switch off. A watch contacts the source you pointed it at and nothing else. This site sets no cookies and carries no trackers.
Deleting, changes, contact
Disconnect a Google account to remove its token, calendars and synced events; uninstalling Cords and deleting its data folder removes the rest. If this policy changes, the date at the top changes with it. Cords is not directed at children under 13. Questions: support@a5n.co.