We use cookies to improve your experience on our site. By using our site, you consent to the use of cookies. Rejecting cookies will prevent non-essential cookies from loading.
Summary (the short version) - Your notes stay on your device. They are stored locally in Chrome and are never uploaded to us, transmitted to any server, or shared with any third party.
- We collect a small amount of account information at sign-in — your first name, email address, and approximate country (so we can recognise returning users and send occasional product updates).
- We do not sell your data, share it with advertisers, run analytics on your browsing, or read your notes. Ever.
The full detail follows below.
1. Introduction
NoteTab.app ("we", "us", "our") is provided by SharkDog Ltd (Company No. SC484465), registered at Compt Hall Sunnyside Road, Brightons, Falkirk, Stirlingshire, Scotland FK2 0RW.
This policy explains what personal data we collect when you use the NoteTab Chrome extension, why we collect it, and how we use and protect it.
2. Data We Collect
User profile (collected at sign-in):
- First name, via Google OAuth
- Email address, via Google OAuth
- Approximate country, derived from a one-time IP lookup
- An anonymous unique identifier (UID), generated locally on your device the first time you sign in
- The timestamp at which your sign-in record reaches our system
Notes & content:
- All notes, checklists, categories, themes, and settings are stored locally in your browser via Chrome's storage API. They are never transmitted to us or to any third party.
What we never collect:
- The contents of your notes
- Your IP address (it is used only at the moment of the country lookup and is not retained by us)
- Your browsing history or activity outside the extension
- Payment information (the extension is free).
3. How We Collect Data
- Google OAuth via chrome.identity.launchWebAuthFlow() retrieves your first name and email address.
- IP-based country lookup via freeipapi.com returns your approximate country (e.g. "United Kingdom"). The IP address itself is not stored by us.
- Chrome Storage API (chrome.storage.local) saves all your note content on your device. There is no cloud sync.
- A Google Apps Script endpoint (writing to a private Google Sheet that only we can access) receives your profile record (UID, first name, email, country) so that we can recognise returning users and send product updates.
4. Where We Store Your Data
- Notes and content live only in your browser, in Chrome's chrome.storage.local. They never leave your device.
- User profile data (UID, first name, email, country, receipt timestamp) is sent to our private Google Apps Script endpoint and stored in a Google Sheet that only the developer can access. It is used solely for product-update communications and to understand who is using the extension.
- We do not use Firebase, Firestore, or any third-party database. We do not collect or store your notes on any remote server.
5. Data Retention
We retain your profile data in our Google Sheet for as long as you have the extension installed, or until you request its deletion. Your note content is never sent to us and remains entirely in your browser; clearing your Chrome storage or uninstalling the extension deletes it.
6. Cookies & Analytics
We do not use Google Analytics, third-party tracking pixels, or any browsing analytics within the extension. The only data we collect is the profile record described in Section 2, sent once at sign-in. Chrome may place browser cookies as part of the standard Google OAuth flow; please consult Google's cookie policy for details.
7. Third-Party Services
- Chrome Identity API (chrome.identity.launchWebAuthFlow) — for Google OAuth
- Google OAuth2 "userinfo" API (www.googleapis.com) — to fetch first name and email
- freeipapi.com — for one-time approximate country lookup
- Google Apps Script endpoint (our own private Google Sheet) — for storing the minimal profile data described above
8. Your Rights
If you are in the UK or EU, you have the following rights under the UK GDPR / EU GDPR:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — ask us to delete your personal data
- Right to restrict processing
- Right to object to processing
- Right to data portability
- Right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk)
By installing the extension and signing in, you consent to receiving occasional product update emails and feedback requests at the email address associated with your Google account. We will only contact you when we have something genuinely useful to share. Every email includes an unsubscribe link, and we never sell, rent, or share your contact details with any third party.
10. Security Measures
All communication with our endpoints (Google OAuth, freeipapi.com, our Google Apps Script endpoint) takes place exclusively over HTTPS. We rely on Google's built-in authentication and access controls to secure the OAuth flow and the Google Sheet that holds profile records. The extension itself contains no remotely-loaded code: all JavaScript is bundled with the published extension and reviewed by the Chrome Web Store.
11. Governing Law
This policy is governed by the laws of Scotland. Any disputes must be brought in a Scottish court.