🔒 Official Legal & Compliance Hub

Privacy Policy

Effective Date: October 4, 2026
Last Updated: October 4, 2026
✓ Google Limited Use Certified

This Privacy Policy explains how Yearly (yearly.click), originally developed as Auto-Gifter, collects, protects, and handles data across the Google Workspace Add-on, Chrome Extension, and official web services.

1. Introduction & Dual-Branding Harmonization

Yearly (formerly developed and referred to in technical source manifests as Auto-Gifter, “we”, “our”, or “us”) provides an intelligent celebration assistant and Google Workspace Calendar Add-on available at yearly.click. We respect your privacy and are committed to maintaining the highest standards of data security and transparency.

This Privacy Policy explains what information we collect, how we process and protect it, and your rights under global privacy laws including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and the Google API Services User Data Policy.

G

2. Google API Services User Data Policy Compliance (Limited Use Disclosure)

Yearly's (formerly Auto-Gifter, “we”, “our”, or “us”) use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Limited Access: We only access Google Calendar data strictly necessary to identify upcoming celebrations (such as birthdays, anniversaries, and milestones).
  • No Transfer or Sale: We do not transfer, sell, or disclose your Google Calendar data to third parties, except as strictly necessary to provide the user-facing functionality of the Service or comply with applicable law.
  • No Advertising: We do not use Google user data for serving advertisements, including personalized, re-targeted, or interest-based advertising.
  • No Human Access: We do not allow humans to read your Google Calendar data unless we have obtained your affirmative agreement for specific messages (e.g., technical support), it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for the Service's internal operations where the data has been aggregated and anonymized.
  • Prohibition on AI/ML Model Training: Google user data and Google Calendar metadata received via Google APIs are never used to develop, train, retrain, improve, or fine-tune generalized or foundation artificial intelligence (AI) and/or machine learning (ML) models.

3. Google OAuth Scopes & Justification Table

Yearly adheres strictly to the principle of least privilege. The table below discloses every Google OAuth permission requested by the Google Workspace Add-on as configured in our manifest (gas/appsscript.json):

OAuth Scope URI Access Level Justification & Usage
https://www.googleapis.com/auth/calendar.addons.current.event.read Narrow / Read Required to inspect the event title, start time, and notes of the currently opened event to detect if it is a birthday, anniversary, or celebration.
https://www.googleapis.com/auth/calendar.addons.current.event.write Narrow / Write Enables 1-click event enrichment when requested by the user, updating description notes with floral links or reminder alarms.
https://www.googleapis.com/auth/calendar.addons.execute Structural Required by Google Workspace to render contextual cards inside the right sidebar of Google Calendar.
https://www.googleapis.com/auth/calendar.events Events Access Used solely during time-driven daily background trigger to inspect upcoming celebrations across the next 14 calendar days.
https://www.googleapis.com/auth/calendar Service API Used by Google Apps Script runtime to instantiate Calendar service objects for milestone event scanning.
https://www.googleapis.com/auth/spreadsheets Drive / Sheets Allows appending milestone audit rows to a private spreadsheet (CelebrationLog) stored exclusively in the user's personal Google Drive.
https://www.googleapis.com/auth/script.external_request Network Used for real-time FloristOne catalog lookups and optional Gemini AI greeting generation.
https://www.googleapis.com/auth/script.scriptapp Execution Required to manage the automated daily trigger that performs celebration reminder scans.

4. Information We Process vs. What We Do NOT Collect

✓ Information Processed Locally

  • Calendar Event Metadata: Event titles (e.g. “Sarah's Birthday”), dates, and timestamps to extract celebrant names and milestone categories.
  • Private Celebration Log: Records logged into your private Google Sheet (CelebrationLog) in your own Google Drive.
  • Local UI Preferences: Budget tiers, brand selections, and dismissal flags stored in your browser session.

✗ Information We Do NOT Collect

  • We do not collect passwords, credit card numbers, or banking credentials.
  • We do not operate centralized surveillance databases tracking personal calendar schedules.
  • We do not harvest contact address books or private meeting notes.

5. How We Use Information

We process information solely to deliver the user-facing functionality of Yearly:

  1. Detect celebration milestones (birthdays, anniversaries) in your schedule and display curated FloristOne bouquets and gift card recommendations.
  2. Construct 1-tap WhatsApp deep links (https://api.whatsapp.com/send?text=...) with warm greetings for you to review and send.
  3. Maintain your private gift history audit log in your own Google Sheet (CelebrationLog).
  4. Optionally generate AI greetings using the Google Gemini API without storing personal prompt snippets for public model training.

6. Local Storage & Zero-Centralized-Database Architecture

Yearly is engineered with a strict Zero-Centralized-Database architecture. We do not operate external application databases that harvest, ingest, or store your private calendar events.

Local Browser Storage

Preferences (e.g. default floral budget tier, UI dismissals, demo mode) are stored locally in your browser session via localStorage or chrome.storage.sync. You can purge this data at any time by clearing your browser storage.

User-Owned Google Drive Log

Any celebration reminder logs or gift history reside exclusively within a private Google Sheet (CelebrationLog) in your own Google Drive account. Yearly never maintains a copy of this data on external servers.

7. Third-Party Integrations & Service Providers

We interact with third-party service providers solely to perform requested features:

  • Google Workspace & Google Cloud: Executes Google Apps Script code in Google's secure cloud container to inspect calendar items and write to your personal sheet.
  • FloristOne: When you tap 1-click cart links, you are directed to FloristOne's secure checkout gateway. FloristOne handles payment processing, fulfillment, and delivery across local florist networks.
  • Meta / WhatsApp: When you click the WhatsApp share button, a client-side link opens WhatsApp with pre-composed greeting text for your manual review and approval.
$

8. FTC 16 CFR Part 255 Affiliate Disclosure

In compliance with the FTC 16 CFR Part 255 guidelines regarding the use of endorsements and testimonials in advertising:

Yearly participates in affiliate marketing programs. When you click on certain merchant links provided within the Service (including, but not limited to, FloristOne floral arrangements, Amazon, DoorDash, Starbucks, Target, and associated gift card platforms) and complete a transaction, Yearly may receive an affiliate commission or referral fee at no extra cost to you.

All flower arrangements are fulfilled by FloristOne and independent local florists. Pricing is set directly by merchant partners and is never marked up for Yearly users.

9. Data Retention and Storage

Because Yearly does not operate a centralized user database, all calendar metadata processed by the add-on or extension stays in your local browser session or is synchronized across your signed-in Google Chrome profile via chrome.storage.sync.

All audit trails reside within your personal Google Account ecosystem. You can view, modify, or permanently delete your CelebrationLog Google Sheet in your Google Drive at any time.

§

10. Your Privacy Rights (GDPR & CCPA/CPRA)

Whether you reside in the European Economic Area (EEA), United Kingdom, California, or other jurisdictions with comprehensive privacy frameworks, Yearly respects your statutory data rights:

• Right to Access & Portability (GDPR Art. 15/20, CCPA): You may inspect and export your data directly from your local browser storage or your personal Google Drive sheet.
• Right to Erasure / “Right to be Forgotten” (GDPR Art. 17, CCPA): You can wipe all local application data by clearing browser storage and delete your Google Drive celebration log.
• Right to Revoke Access: You may instantly revoke Yearly’s Google Workspace permissions at any time via Google Account Security Settings.
• Do Not Sell or Share Personal Information (CCPA/CPRA): We do not sell, rent, or trade your personal information, nor do we share it with third parties for cross-context behavioral advertising.
• Non-Discrimination: We will never discriminate against you, deny services, or alter pricing for exercising any of your privacy rights.
• Privacy Inquiries & DSR Submission: To submit a verified Data Subject Request, contact our Data Privacy team at support@yearly.click.

11. Technical & Operational Security Controls

We enforce modern security best practices:

  • All communication between your client and external services occurs over TLS 1.3 encrypted HTTPS.
  • Execution logic runs within sandboxed browser content scripts and Google Apps Script V8 runtimes.
  • No hardcoded administrative tokens or third-party tracking pixels exist within our client extensions or web pages.

12. Contact Information & Data Protection Officer

If you have questions, privacy concerns, or requests regarding this Privacy Policy, our legal team is available to assist:

Direct Inquiries support@yearly.click
Official Web Domain https://yearly.click