Privacy policy

Privacy that doesn't read between the lines.

Effective March 28, 2024 · Last reviewed October 1, 2026

1. Scope and data controller

This policy governs information collected, stored, or otherwise processed by the Video Notes browser extension for Chrome and Firefox. The extension operates primarily within your browser to augment youtube.com/watch pages. Optional encrypted Backup & Sync, Share, flashcards, and Ask your notes rely on external services, the saved-notes library loads thumbnail images from YouTube, and its Product updates popup requests public release notes from DuckPost (see Section 5). Free note-taking remains local and account-free. For the purpose of applicable privacy regulations, the data controller is Pramesh Bajracharya (prameshbajra.github.io).

Contact
Privacy inquiries can be sent to pe.messh@gmail.com.

2. Information processed by the extension

Video Notes is designed to function locally without an account. The extension processes the information required to save and surface your notes:

  • The free-form text you enter into the Video Notes workspace.
  • Timestamps associated with the active YouTube video in order to place markers on the timeline.
  • The YouTube video identifier, title, and locally calculated note counts to organize entries.
  • Drawing annotations, including editable scene data, a rendered PNG preview, and image and viewport dimensions.

If you affirmatively connect the optional paid Backup & Sync service, Video Notes additionally processes your email address, account and device identifiers, device name, session and entitlement records, encrypted payload sizes, opaque entity identifiers, mutation and revision metadata, and operational timestamps. Note text, video titles and identifiers, tags, and drawings are encrypted on the device before upload. The service receives ciphertext and cannot decrypt it. Payment details are collected by Paddle as Merchant of Record and are not received by Video Notes; Video Notes receives billing customer, transaction, subscription, entitlement, and status identifiers needed to provide access.

When you use the optional Share feature, the extension transmits the following to the share API at api.videonotes.dev (older releases use share-api.video-notes.workers.dev, which points at the same service and remains available). A read-only page is then generated at share.videonotes.dev:

  • The YouTube video identifier and title.
  • Every note associated with that video, including timestamps and text.
  • For notes with drawings, the rendered PNG image and image and viewport metadata. Editable drawing scene data is not sent.

No note text or drawing data is transmitted unless you explicitly click the Share button or enable one of the optional AI features, flashcards or Ask your notes (see section 5). Opening the saved-notes library requests thumbnail images from YouTube using the saved video identifiers; it does not include your notes or drawings. Opening Product updates requests the latest public Video Notes releases from DuckPost; it does not include your notes, drawings, saved video identifiers, or settings. Outside an optional Backup & Sync account, the extension does not request or infer usernames or email addresses. It does not collect general browsing history or analytics identifiers.

3. Storage location and retention

Your notes, drawing data, video metadata, and settings are stored on the device using the browser's local extension storage under videoNotes:* keys. This storage is not browser-sync storage.

Local data persists until you delete it through the extension, clear the extension's browser storage, or uninstall the extension. When you use Share, a copy of the video identifier, title, timestamped note text, and any rendered drawing images and metadata is stored in Cloudflare Workers KV for 90 days, then expires automatically. Video Notes does not intentionally log note or drawing contents; Cloudflare may process routine request metadata and diagnostics needed to operate the service.

For paid Backup & Sync, encrypted current data and revisions are stored in Cloudflare R2 and per-account Durable Objects. Revisions expire after 30 days. After subscription access ends, encrypted cloud data is read-only for up to 30 days and is then scheduled for deletion, unless you delete it sooner. Account, device, authentication, webhook, entitlement, and deletion records are stored in Cloudflare D1 for service operation, security, billing reconciliation, and legal obligations. Expired email challenges and sessions are routinely removed. The account master key and recovery key stay in local extension storage and are never uploaded or stored in browser sync storage.

4. Browser permissions and their purpose

Video Notes requests the minimum set of permissions needed to operate:

  • storage — allows the extension to store the notes, drawings, settings, and API key you choose to save in local extension storage.
  • unlimitedStorage — prevents the browser's small default extension-storage quota from blocking larger local note and drawing collections.
  • tabs — opens a saved video's timestamp in a tab and supports the optional new-tab flashcards page.
  • alarms — schedules periodic encrypted sync and resumes a device-connection poll. No sync alarm is created until you connect and enable Backup & Sync.
  • host_permissions for api.videonotes.dev — allows the extension to send note and rendered drawing data to the share API when you explicitly click the Share button. No requests are made to this host unless you initiate a share action. (Releases before 2.4.0 request share-api.video-notes.workers.dev, the same service on its legacy address.)
  • optional_host_permissions for sync.videonotes.dev — allows account, entitlement, and encrypted backup requests only after you start connecting optional Backup & Sync and grant access. Free users make no requests to this host.
  • host_permissions for generativelanguage.googleapis.com — allows the optional flashcards and Ask your notes features to send your note text, note timestamps, internal note identifiers, and the titles, YouTube video IDs and tags of the videos those notes belong to, to Google's Gemini API, using an API key you provide. Drawings are never sent. No requests are made to this host unless you enable one of those features and add your own key.
  • content_scripts on youtube.com — injects the inline workspace that renders the note editor, timeline, and controls on youtube.com/watch pages.

The annotation editor is packaged with the extension and exposed to YouTube pages so it can be loaded on demand; no executable code is downloaded remotely. Video Notes does not use its permissions to read page content on non-YouTube sites or collect browsing history.

5. Network access, disclosures, and third parties

The extension initiates outbound requests only for optional Backup & Sync, Share, flashcards and Ask your notes features, YouTube thumbnail images, and public DuckPost release notes in the saved-notes library, as described below. No analytics or advertising SDKs are bundled with the codebase. Video Notes does not sell or trade your information.

Backup & Sync. This paid feature is off by default. Connecting an account sends authentication and device information to sync.videonotes.dev, hosted on Cloudflare. After subscription activation and recovery-key confirmation, the extension sends encrypted entity payloads plus opaque identifiers, hashes, logical versions, sizes, device IDs, and revision cursors. The service does not receive plaintext note text, titles, YouTube video identifiers, tags, drawings, the master key, or recovery key. Cloudflare processes service data and routine connection metadata and its Email Service delivers authentication messages. Paddle processes checkout, payment, invoice, tax, and customer-portal data under Paddle's privacy terms and sends signed subscription-status webhooks to Video Notes. The legal bases are performance of the requested service, account security and fraud prevention, compliance with legal obligations, and your affirmative choice to enable upload.

Library thumbnails. When you open the full-page saved-notes library, the extension requests thumbnail images from i.ytimg.com using the YouTube video identifiers already stored with your notes. These image requests do not contain note text, drawings, or your Gemini API key. Google or YouTube may receive routine connection metadata, such as your IP address and browser user agent, under its own privacy policy.

Product updates. When you open Product updates in the full-page library, the extension requests public release titles, summaries, content, tags, dates, and optional cover images from duckpost.app and cdn.duckpost.app. The request uses a shared, non-unique client label and contains no note text, drawings, saved video identifiers, settings, or unique analytics identifier. DuckPost and its infrastructure may receive routine connection metadata, such as your IP address and browser user agent, under its own privacy policy. No request is made until you open the popup.

Share feature. When you click the Share button, the extension sends a request to api.videonotes.dev (older releases use share-api.video-notes.workers.dev, the same service on its legacy address), a Cloudflare Workers endpoint maintained by the developer. The request contains the video identifier, video title, all timestamped note text for that video, and any rendered drawing PNGs and image and viewport metadata. The API stores this data in Cloudflare Workers KV for 90 days to generate a unique, read-only shareable link. Anyone with the link can view the shared data until it expires. Browsing history, cookies, device identifiers, and editable drawing scene data are not included in the request. This feature is entirely opt-in — no network requests are made unless you explicitly initiate a share action.

Flashcards feature. Flashcards are off by default. If you enable them and provide your own Google Gemini API key, the extension sends a sample of your notes directly from your browser to Google's Gemini API (generativelanguage.googleapis.com) to generate quiz questions. Each sampled note is sent with its text, its timestamp, its internal note identifier, and the title and YouTube video ID of the video it belongs to. Drawings are never sent. Your API key is stored only in local extension storage on your device and is never sent to the developer. This data is processed by Google under Google's own terms and privacy policy; note data is not sent to the developer's servers. No requests are made unless you have enabled flashcards and added a key.

Ask your notes. Ask your notes is off by default. If you enable it and provide your own Google Gemini API key, then each time you ask a question the extension sends the following directly from your browser to Google's Gemini API (generativelanguage.googleapis.com): the question you typed; and, for every note in the scope you selected, the note's text, its timestamp, its internal note identifier, and the title, YouTube video ID and any tags of the video it belongs to. In a multi-turn conversation your earlier questions and the earlier answers are sent again with each follow-up, so the model can follow the thread.

This is a broader flow than flashcards: the default scope is your entire note library, so unless you narrow it to a single video or a single tag, every note you have is included in each request. If your library is too large to send in full, only the notes most relevant to your question are sent, and the answer tells you when that has happened. Drawings are never sent to Gemini — only note text is used, so a drawing-only note is excluded entirely. Answers are not limited to your notes: by default Gemini may also draw on its own general knowledge to explain or expand on what your notes cover, and the answer tells you when it has done so. Turning on "Only my notes" in the panel restricts answers to what you wrote. This setting changes what Gemini may say, not what is sent — the same note data is sent either way. Your API key is stored only in local extension storage on this device and is never sent to the developer. This data is processed by Google under Google's own terms and privacy policy; note data is not sent to the developer's servers. No requests are made unless you have enabled Ask your notes, added a key, and asked a question.

6. Security measures

Outside optional Backup & Sync, Share, flashcards and Ask your notes features, note text and drawing data never leave your browser. Backup & Sync encrypts that content before it leaves the browser. Library thumbnail requests contain only saved YouTube video identifiers. Security focuses on minimizing attack surface:

  • The extension injects only the scripts needed to provide the Video Notes workspace on YouTube watch pages.
  • All executable code, including the annotation editor loaded locally on demand, is bundled with the extension. No executable code is downloaded from or evaluated on remote servers.
  • Cloud backup payloads use AES-GCM with a fresh nonce and authenticated metadata; opaque server entity identifiers are derived with HMAC.
  • Access tokens are short-lived, refresh tokens rotate, device sessions can be revoked, and server-side secrets and verification codes are stored only as hashes.
  • Patches are distributed through the Chrome Web Store and Firefox Add-ons update channels to ensure authenticity.

Users remain responsible for protecting their own devices with appropriate operating-system level safeguards.

Video Notes' use of information received through browser APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Such information is used only to provide or improve the extension's disclosed user-facing features, service security, and legally required operations; it is not sold, used for advertising or credit decisions, or made available for human review except with specific consent, for security, or where law requires it.

7. User controls and data subject rights

You are fully in control of the content stored by Video Notes. Available controls include:

  • Using the export option in the popup dashboard to download a JSON backup of all notes.
  • Importing a trusted backup file to restore data on a different profile or machine.
  • Deleting individual notes or clearing all data through the browser's extension controls or by uninstalling the extension.
  • Viewing and revoking Backup & Sync devices, downloading the local recovery key, deleting encrypted cloud backup, signing out every device, or deleting the account.

For notes that have not been shared or uploaded through optional Backup & Sync, the data resides solely with you and no note-content server record exists. Shared note data expires automatically after 90 days. Anyone with the link can view it until expiry, and the current extension does not provide an in-app revoke control. To request earlier deletion of shared data, email pe.messh@gmail.com with the share link you want removed.

Backup & Sync account holders may request access, correction, portability, restriction, objection, or deletion by using the in-product controls or emailing the privacy contact. A manual JSON export contains local notes and metadata but intentionally excludes authentication tokens, encryption keys, recovery material, and internal sync state. Deleting encrypted cloud data does not delete local notes. You may also complain to a competent data-protection authority.

8. Children's privacy

Video Notes is intended for general productivity use and is not directed at children under 13. The extension does not knowingly collect personal data from children, and it stores only what the user themselves choose to enter.

9. Changes to this policy

Any updates to this Privacy Policy will be posted on this page with a new effective date. Material updates will also be noted in the project README and Chrome Web Store or Firefox Add-ons listing where applicable. Continued use of the extension after an update constitutes acceptance of the revised terms.

Questions about this document can be sent to the contact email noted above.