Your data, without the fog.

Moonfold is local-first. Google Calendar is an optional connection, not the place where your Moonfold workspace lives.

At a glance

Your Moonfold workspace is stored on your Mac. There is no Moonfold cloud account or cross-device sync today. Connecting Google Calendar is optional and does not move your projects, tasks, or notebooks into a Moonfold cloud service.

Current beta data boundaries
DataWhere it livesWhen it leaves your Mac
Tasks, projects, notebooksMoonfold's local application dataNot sent to a Moonfold cloud service
Notebook images and PDFsLocal Moonfold workspace and local backupsOnly when you choose another app or service to share them
Google OAuth tokensEncrypted local storage protected by macOS KeychainExchanged directly with Google to authorize or refresh access
Google Calendar eventsGoogle, plus a local cache while connectedRead from or written to Google only for enabled features

What Moonfold keeps locally

Moonfold stores the content needed to run your workspace: tasks, project context, notebooks, resource attachments, preferences, local history, and backup data you create. The desktop app uses a per-user workspace in macOS application storage.

Local-first does not mean risk-free. Anyone with access to your unlocked Mac or an unprotected backup may be able to access local content. macOS account security and a current backup remain important.

No Moonfold account

The beta does not create a Moonfold identity, upload your workspace to Moonfold servers, or synchronize it between devices. Moonfold cannot recover a workspace that exists only on a lost or damaged Mac.

How Google connection works

  1. You choose to connect from Moonfold settings.
  2. Moonfold opens Google's consent page in your system browser.
  3. Google shows the requested permissions before you approve them.
  4. The desktop app receives an authorization result through a local loopback connection protected with PKCE.
  5. Moonfold stores the resulting token locally using operating-system protected encryption.

Moonfold never asks for or receives your Google password. You can keep using Moonfold without connecting Google Calendar.

Permissions are separated by purpose

Calendar list, read-only
Lets Moonfold discover the calendars selected in your Google Calendar account and read basic calendar metadata.
Events, read-only
Shows calendar events in Agenda and keeps a local cache available while Moonfold is open.
Events, read and write
Optional, separate access used only after you enable event creation for timed Moonfold tasks.

Read-only access is the default. Moonfold asks for event write access only after a separate choice. External Google events remain read-only inside Moonfold; event writing is limited to events linked from eligible Moonfold tasks.

What “sync” means in this beta

While Moonfold is open, Agenda reads the local event cache first and refreshes it after launch, when the app regains focus or connectivity, and periodically when the cache is old. Failed background refreshes retry without interrupting normal use.

  • Moonfold can show events from Google Calendar alongside dated local tasks.
  • A pending Moonfold task needs a date and start time before it is eligible to create a Google event.
  • Already-linked Moonfold events can be updated after write access is enabled.
  • External Google events stay read-only, but you may save one as a separate Moonfold pending item.
  • There is no closed-app real-time sync and no cross-device Moonfold sync.

Disconnecting and deleting data

Disconnect Google Calendar

Disconnecting asks Google to revoke Moonfold's OAuth token, then removes the local token, temporary authorization state, and cached Google events. If Google cannot confirm revocation, Moonfold still removes local access and tells you what happened.

Disconnecting does not delete Google events that already exist and does not delete your local Moonfold tasks, projects, or notebooks. You can also review and revoke access from your Google Account's third-party connections page.

Delete Moonfold data

Because Moonfold has no cloud account, deletion is performed on your Mac. Remove the Moonfold workspace and any backups you created after you have saved anything you need. Moonfold cannot perform this local deletion remotely.

Google Calendar release status

The local OAuth, cache, incremental refresh, disconnection, and task-linked event flows have been built and tested with local simulations. Production Google OAuth approval and broad real-account access are still external release gates. Event creation should be treated as pre-release until that review is complete.

This page will be updated if Moonfold's data model, permissions, or hosting change.

For the wider policy, read the privacy draft.

Read privacy