Anchored Notes — Privacy Policy

Last updated: 26 July 2026

Anchored Notes is a browser extension that lets you attach sticky notes to web pages, sites, and tabs. This policy explains what data the extension handles, why, where it is stored, and how to have it deleted. The data controller is Anchored Notes.

What we collect

DataPurpose
Your Google account email Identifying your account so notes sync to you and only you. Collected via Google OAuth sign-in when you choose to sign in.
Note content The text you type into your notes, stored so it can sync across your devices. Content is encrypted on your device (AES-256-GCM) before upload; our servers store only the encrypted form. See “Encryption” below.
Note metadata The page URL, site, or tab a note is anchored to, plus timestamps, so each note reappears in the right place.
Product usage events Anonymous event names (for example note created, sign-in, feature used) plus optional non-identifying context such as plan tier, note count, and UI source. Used only to understand which features are used and improve the product. See “Product analytics” below.
Anonymous install identifier A random UUID generated in the extension and stored locally (anonymousIdentifier). It lets us count unique installs in aggregate analytics without using your email or other account identifiers.

We do not collect browsing history, advertising identifiers, or any data from pages you visit beyond the notes you explicitly create and the product usage events described above. Note content and the URLs of pages you browse are never included in analytics events. If you never sign in, your notes stay in your browser's local storage and are never sent to our sync servers (analytics events may still be sent as described below).

Product analytics

The extension measures feature usage with a privacy-friendly analytics stack we operate ourselves (Umami, self-hosted under puhulab.com). Events are sent directly from the extension via HTTPS to our collect endpoint — there is no third-party analytics vendor, no advertising SDK, and no third-party cookies. Analytics data stays on infrastructure we control.

Each event may include the anonymous install identifier, a timestamp, plan tier (anon / free / pro), note count, and similar product context. It does not include your email, note text, or browsing URLs.

Encryption

Note content never leaves your device in readable form: it is encrypted in the extension with AES-256-GCM before syncing, and decrypted only on your devices. The encryption key is derived (PBKDF2) on your device and is never sent to our servers.

By default the key is derived automatically from your account identifier, so encryption works without any setup. For stronger protection you can set a personal encryption password in the extension's options: your notes then become end-to-end encrypted — we have no way to read them. This also means we cannot recover your synced notes if you forget that password.

Note metadata (the anchored page URL or site, position, color, and timestamps) is not encrypted, because the sync service needs it to deliver each note to the right place.

Where your data is stored

Authentication and note records are stored in our PocketBase instance and mediated by the anchored-notes-backend service, both hosted under puhulab.com. Product analytics events are stored on our self-hosted Umami instance under the same domain family. All of this data is transmitted over HTTPS and remains on infrastructure we control.

How we use it

Account and note data are used to provide authentication and sync: authenticating you and storing/retrieving your own notes. Product usage events are used only to understand how the extension is used and to improve it. We do not sell your data, share it with third-party analytics or advertising companies, or use it for advertising.

Retention and deletion

Notes and account data are retained until you delete them. You can delete individual notes at any time from the extension. To delete your entire account and all associated notes, email [email protected] from the address tied to your account, or use the in-app account-deletion action where available. We will action verified deletion requests promptly.

The anonymous install identifier lives in your browser's extension storage and is cleared if you remove the extension or clear that storage. Aggregated analytics events already received may remain on our Umami instance; they are not linked to your email or account. Contact [email protected] if you have questions about analytics retention.

Permissions

The extension requests the identity permission for Google sign-in, storage for notes and the anonymous install identifier, and host access to place notes on the pages you visit and to send sync and analytics requests to our puhulab.com services. These permissions are used only to deliver the features described above.

Contact

Questions about this policy or your data: [email protected].