Small sloth.
Small data footprint.
Privacy policy · Effective September 6, 2026
Shoulder Sloth is a personal desk-companion project operated by Katherine Champagne. It uses calendar availability to suggest short movement breaks. This policy covers the website, calendar connection service, and device.
What we access and why
When you authorize Google Calendar access, Shoulder Sloth requests the calendar.events.freebusy permission. It reads busy time intervals from your connected calendar to calculate whether you are free and how much time is available. It does not request event titles, descriptions, locations, attendees, or permission to create, change, or delete events.
What we store
- The calendar service stores a Google OAuth refresh token in Cloudflare Workers KV so it can continue checking availability without asking you to sign in each time. Short-lived access tokens and calendar intervals are processed to answer availability requests; the application does not maintain a calendar-history database.
- Temporary authorization state is stored for up to ten minutes to secure sign-in. The connection flow also uses short-lived security cookies.
- The device stores its Wi-Fi configuration, connection credentials, and movement statistics such as completed routines, skips, feedback, and streaks locally. The application does not upload these movement statistics to the calendar service.
Sharing and protection
Google supplies the calendar availability, and Cloudflare hosts the website and processes and stores data for the calendar connection service. The device receives a simplified availability response through an authenticated HTTPS endpoint. Hosting providers may process technical request information, such as IP addresses and security logs, to operate and protect their services.
We do not sell Google user data, use it for advertising, or use it to train AI models. Access is used only to provide and secure the calendar-aware movement reminders. Shoulder Sloth’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Your choices and deletion
You can revoke Shoulder Sloth’s access at any time in your Google Account connections. This stops future calendar access. The stored refresh token remains until replaced or manually deleted; contact [email protected] to request deletion from the connection service. Temporary authorization state expires automatically. Device movement statistics remain until you reset them on the device; clearing those statistics does not revoke Google access or erase Wi-Fi credentials.
This website
This static website has no advertising, analytics scripts, sign-up forms, or application-set cookies. Its font and artwork are hosted here rather than fetched from third-party font or image services. The separate calendar connection flow uses the security cookies described above.
Questions or changes
For privacy questions or deletion requests, contact Katherine Champagne at [email protected]. Material changes to these practices will be reflected here with an updated effective date.