Privacy policy
Last updated: 8 August 2026
Before publishing: replace [CONTROLLER] with the legal
entity or individual responsible for this service, [JURISDICTION] with where
you are established, and [CONTACT EMAIL] throughout. A privacy policy with no
identifiable controller does not satisfy GDPR Article 13, and Chrome Web Store review
checks that this page actually describes the extension.
LiveNotes is a browser extension that shows comments other people have written about web pages, and lets you write your own. This policy explains what that involves for your data. It is written to be read, not to be survived.
The short version
We do not receive your browsing history. This is not a promise about our intentions; it is how the extension works. It downloads a compact list of sites that have at least one comment and checks the site you are on against that list locally. If the site is not on it (the case for the overwhelming majority of the web), no request is made to us at all.
A page address reaches us only when you choose to post a comment on that page. For sites that are on the list, the page is identified by a SHA-256 hash of its address rather than the address itself.
You can verify this. The extension's settings page shows a live count of the network requests it has made. Browse sites nobody has commented on and it will not move.
Who is responsible
The data controller is [CONTROLLER], established in
[JURISDICTION]. Contact: [CONTACT EMAIL].
What we collect
| Data | When | Why | Kept |
|---|---|---|---|
| Email address | When you sign in with Google | Account identity and recovery | Until you delete your account |
| Name and profile picture | When you sign in with Google | Prefills your profile; both editable | Until you delete your account |
| Comments, likes, reports | When you write them | The service itself | Until deleted; unengaged comments are pruned after 180 days |
| Page address and title | Only when you comment on a page | So others find the conversation | While the page has comments |
| A hashed device signal | When you sign in | Detecting one person running many accounts | Until you delete your account |
| Highlight-accuracy counters | Batched, once per browsing session | Measuring whether highlights survive page changes | 90 days, aggregated, no identifiers |
| Stripe customer reference | If you subscribe to Pro | Billing | Until you delete your account |
We do not collect browsing history, page content, or any behavioural data for advertising. There is no advertising, there are no analytics vendors, and there are no data brokers.
The device signal, in full
This is the part most likely to surprise someone, so here it is in detail rather than buried in a clause.
What it is. A one-way hash of: a random identifier generated once when you install the extension, plus a few coarse, stable properties of your browser — platform, processor core count, memory size, timezone, primary language, and screen dimensions. It is hashed on your device, and hashed again with a secret on our servers before being stored.
What it is for. Exactly one thing: noticing when one person is running several accounts to evade a ban or manufacture the appearance of agreement.
What it is not.
- Not canvas, WebGL, audio or font fingerprinting. Those are the invasive, high-entropy techniques that make a tracker. They are also unstable across driver updates, so they produce false matches anyway.
- Not a block. Households, libraries, offices and shared laptops all legitimately produce matches. A match lowers an account's standing and flags it for a person to look at.
- Not reversible. Because of the server-side secret, someone who obtained the stored values could not work backwards to a device.
- Not permanent. The extension's settings page has a button that regenerates the identifier.
An honest limitation: anyone determined to defeat this can, with a fresh browser profile. It raises the cost of casual abuse; it does not stop a committed evader. We would rather say that than imply a guarantee we cannot make.
What other people can see
- Public comments are visible to anyone with the extension. They are public speech attached to a public page.
- Private notes (a Pro feature) are visible only to you. They are enforced by database access rules, not merely hidden in the interface. They are not encrypted at rest: a database administrator could read them. We would rather state that than let the word "private" imply otherwise.
- Blocking works in both directions: neither of you sees the other's comments or mentions. Only you can see your own block list.
Your rights
If you are in the EEA or UK, you have rights of access, rectification, erasure, restriction, portability and objection under GDPR. If you are in California, you have equivalent rights under the CCPA. Two of them are built into the extension:
- Export. Settings → Data. A JSON file with your profile, settings, every comment you wrote, your likes, friendships and notifications. It excludes other people's comments, even replies to yours: those are someone else's words.
- Deletion. Settings → Data. Scheduled rather than immediate: you have seven days to sign back in and cancel. After that your profile, comments, likes, friendships, notifications and device links are erased.
Moderation records retain a reference to a deleted account, because a moderation log that can be erased by the person it concerns is not a moderation log. Aggregate daily counts contain no personal data. Stripe retains transaction records independently, as tax law requires.
For anything else, write to [CONTACT EMAIL]. You may also complain to your
local data protection authority.
Legal basis for processing
- Contract. Your account, your comments, your subscription.
- Legitimate interests. The device signal, rate limits and moderation data, for keeping the service usable and safe. We have balanced this against your interests by keeping the signal coarse, hashed, disclosed and resettable.
- Legal obligation. Retaining billing records.
Who else receives data
| Who | What | Why |
|---|---|---|
| Supabase | All application data | They host the database and authentication |
| Stripe | Email, payment details | Billing. Card details never reach our servers. |
| That you signed in | Sign-in |
Children
This service is not directed at children under 13, or under 16 in the EEA. There is no age verification, which is an honest limitation rather than a claim of compliance. Accounts found to belong to children are removed on report.
Changes
If this policy changes materially, the extension will say so before the change takes effect rather than quietly updating the date at the top.