Privacy Policy
Notate is built privacy-first. Your annotations live on your own device, and nothing leaves it unless you choose to export it to a tool you've connected.
Last updated: July 15, 2026
The short version
- Your pins, comments, screenshots, and any screen recordings are stored locally in your browser — not on our servers.
- When you export feedback, it goes only to the tool you connected (Linear or Jira) and to no one else.
- Notate collects anonymous usage analytics by default — event names, workspace id, tracker type, and durations only, never your ticket content, screenshots, or recordings. You can turn it off in Settings → Workspace → Privacy.
- We use Sentry for crash and error reports, kept separate from usage analytics and off unless you opt in. It never receives your annotation content.
- If you upgrade to Pro, payment is handled by our processor, Dodo Payments — we don't see or store your full card details.
- We don't run ad trackers, sell your data, or build a profile on you.
- Uninstalling Notate removes the data it stored on your device.
1. Who we are
Notate ("Notate", "we", "us") is a browser extension for leaving pinned visual feedback on any web page and exporting it to your issue tracker. This policy explains what data Notate handles, where it goes, and the choices you have. It covers both the Notate browser extension and this website at notate.live.
2. Data stored on your device
Everything you create in Notate — the pins you drop, your comments and notes, captured screenshots, and your extension settings — is stored locally in your browser using the browser's extension storage. This data stays on your device.
We do not operate a backend that receives, syncs, or stores the feedback you create. We cannot see your annotations, the pages you visit, or your screenshots. Because this data is local, clearing your browser data or uninstalling the extension removes it.
3. Screen recording
Notate includes a screen recording feature (currently behind a feature flag, off by default). This section explains how it works before it is enabled for any users.
How a recording starts
Recording is always user-initiated — nothing records automatically or silently. You start a recording with an explicit record action, Notate shows an on-page countdown before capture begins, and a visible recording bar stays on screen for the entire duration so it's always clear when you're being recorded.
What is captured
When you start a recording, Notate uses the browser's chrome.tabCapture API to capture video of your current browser tab only. This is a browser-level permission — it does not inject a script into the pages you visit or access any other tab, window, or screen. You grant it in the moment you start a recording; it is not active in the background.
Where the recording goes
Recordings are held locally in your browser until you attach one to a ticket and explicitly push it to your project tracker (Jira or Linear), where it is uploaded as an attachment. We do not upload, store, or process your recordings on any Notate server. This is a deliberate exception to the cloud-workspace sync behaviour described in section 4: our sync layer explicitly blocks video from cloud sync, so even if you are using a shared workspace where comments and screenshots may sync, recordings are never auto-synced to any Notate backend. A clip only ever leaves your device when you choose to send it to your own connected tracker.
Recordings are cleared from your device when you close the Notate side panel or the browser session ends.
Audio
Microphone audio is optional and off by default. It is gated by two separate controls: you must explicitly turn on microphone or tab-audio capture in Notate's settings, and grant Chrome's own microphone permission prompt, which appears at the moment you turn the setting on — not at install time. You can revoke microphone access at any time from your browser's site permissions.
4. Tools you connect (Linear & Jira)
Notate lets you send feedback to a third-party issue tracker. We currently support Linear and Jira. These integrations are entirely optional and only do anything once you choose to connect an account and export an item.
When you export, Notate transmits the contents of that item — which may include the title and description you wrote, your comments, the captured screenshot, and the URL of the page you were annotating — directly to the service you connected, using the authorization you granted. The access token for that connection is stored locally on your device.
Once your data reaches Linear or Jira, it is handled under that provider's privacy policy and your organization's account settings:
You can disconnect a connected tool at any time from the extension, which removes its stored access token from your device.
5. Payment information (Pro plan)
If you upgrade to Notate Pro, your payment is handled by our payment processor, Dodo Payments, not by Notate directly. Dodo collects and processes the billing details needed to complete your purchase — such as your card information, billing email, and transaction history — under its own privacy policy and PCI-compliant infrastructure. Notate does not receive or store your full card number.
We retain the minimum account information needed to identify your subscription (such as your subscription status and billing email) so the extension can confirm your Pro access. You can view, manage, or cancel your subscription at any time from the extension's Settings → Billing.
6. Anonymous usage analytics
Notate collects anonymous usage events to help us understand how the product is used and where to improve it. As of July 10, 2026, this is on by default — you can turn it off, but it isn't opt-in.
The events we collect are limited to session_start, pin_created, tracker_push, and panel_time_spent. Each event carries metadata only — the event name, a workspace identifier, which tracker you're connected to, and durations. These events never include your ticket content, screenshots, recordings, or the content of the pages you visit.
You can turn this off at any time from Settings → Workspace → Privacy → "Share anonymous usage data." Turning it off stops future events from being sent.
This is separate from crash and error reporting (see the next section), which remains off unless you opt in.
Usage analytics data is processed by our sub-processors, Supabase (our backend database) and, if configured for your workspace, PostHog. Both process this data solely to help us operate and improve Notate.
7. Crash and error reporting (Sentry)
To find and fix bugs, Notate uses Sentry for crash and error reporting. When something goes wrong, Sentry may receive technical diagnostic data such as the error message and stack trace, the extension version, your browser and operating system type and version, and a timestamp. Sentry may also process your IP address transiently as a normal part of receiving the report.
We use this data only to diagnose and fix problems. We do not send your annotation content, screenshots, or the contents of the pages you visit to Sentry. For details on how Sentry processes data, see the Sentry Privacy Policy.
8. Browser permissions
To do its job, the extension requests the browser permissions needed to capture the current page, take screenshots of it, and store your feedback locally. These permissions are used solely to deliver Notate's features on the page you're actively working on. We do not use them to monitor your browsing or collect data in the background.
9. This website
This site is a static page hosted on GitHub Pages. It does not run analytics, advertising, or third-party tracking cookies.
As with any website, the hosting provider (GitHub) may automatically log standard technical request information, such as IP address and browser type, to serve and protect the site. That processing is governed by GitHub's privacy statement.
10. What we don't do
- We don't sell or rent your data to anyone.
- We don't use advertising trackers or build an advertising profile of you.
- We don't tie usage analytics to your identity, and we never include your ticket content, screenshots, or recordings in it.
- We don't access or store your annotations on our own servers.
- We don't store your full card or payment details — that's handled by Dodo Payments.
11. Data retention & your choices
Because your feedback is stored locally, you control it. You can delete individual items in the extension, clear it through your browser's site/extension data controls, or remove all of it by uninstalling Notate. Data you've already exported to Linear or Jira lives in those tools and is managed there.
Depending on where you live, you may have rights under laws such as the GDPR or CCPA — including the right to access, correct, or delete personal data, and to object to certain processing. Since Notate keeps your content on your own device, you can exercise most of these directly. For anything else, contact us using the details below.
12. Children
Notate is a productivity tool intended for a general, professional audience. It is not directed to children, and we do not knowingly collect personal information from children.
13. Changes to this policy
We may update this policy as Notate evolves. When we do, we'll revise the "Last updated" date at the top of this page. Significant changes will be reflected here before they take effect.
14. Contact us
Questions about this policy or your data? Email us at notate.developer@gmail.com and we'll get back to you.