Privacy Policy
1. Local-First Data Storage
Your privacy and data sovereignty are our core design principles:
-
On-Device Storage: All notes, titles, body
content, web highlights, stationery selections, tags, comments,
and application settings are stored locally on your device using
Chrome's native
IndexedDBandchrome.storage.localAPIs. - No Account Required: You do not need to register, create an account, or provide an email address to use Notyx.
- Zero Telemetry & Analytics: Notyx contains no tracking scripts, no analytics SDKs, no telemetry tools, and no advertising code. We do not monitor what you write, which websites you visit, or how you use the extension.
2. Optional Bring-Your-Own-Key (BYOK) AI Features
Notyx offers dual-tier AI capabilities with full user control and transparency:
-
Chrome Built-In Prompt API (Gemini Nano):
When using Chrome's built-in Prompt API, all AI processing runs completely locally on your hardware. No data is sent over the internet for inference.
If the on-device model fails or is unavailable, Notyx never silently falls back to a cloud API. An explicit error message is displayed so you remain in control of whether to configure a cloud provider in Settings.
-
External Cloud Providers (Google Gemini & OpenAI):
If you configure an external AI provider, you supply your own API key. When you trigger an AI action (Summarize, Scrape JSON, tone polish, etc.), data is transmitted directly from your browser to the official API endpoint (
generativelanguage.googleapis.comorapi.openai.com) via HTTPS:- The prompt text and any note content you explicitly include.
- The web page text (up to ~9,000 characters), title, URL, and extracted tables when using Summarize or Scrape.
Your API keys are saved exclusively in
chrome.storage.localand are never transmitted to any third-party server controlled by Notyx.
3. Optional Google Drive Cloud Backup (BYOK)
Cloud backup is 100% optional and operates directly between your browser and Google Drive:
-
Direct Connection: When enabled, Notyx
authenticates using your personal Google OAuth Client ID via
chrome.identity.launchWebAuthFlow. This contacts Google's official endpoints (accounts.google.com,oauth2.googleapis.com, andwww.googleapis.com/drive/v3). -
Account Email Display: Your Google account email
address is retrieved from the Drive
/aboutendpoint using only thedrive.filescope. It is displayed in Settings and saved locally inchrome.storage.local. - Dedicated Folder: Backups are saved in a folder named "Notyx Backups" in your personal Google Drive.
- Metadata & Client-Side Encryption: Backup file names, timestamps, and note counts are visible in Google Drive. You can optionally set an AES-256-GCM passphrase (derived via PBKDF2) to encrypt note content client-side before uploading.
- Zero Access: We have no access to your Google credentials, Drive files, or backup tokens.
4. Fonts and External Resources
To provide an authentic handwriting and literary aesthetic, opening
the panel loads font files from Google Fonts (fonts.googleapis.com
/ fonts.gstatic.com):
- Shantell Sans (Modern Handwriting style)
- Caveat (Signature Pen style)
- Lora (Classic Editorial style)
- Inter (UI typography)
- Newsreader (Reading mode)
- JetBrains Mono (Code blocks)
These font requests are governed by Google's Privacy Policy.
5. Web Speech API (Voice Dictation)
When you activate voice dictation, Notyx uses the browser's built-in
SpeechRecognition API. Notyx does not record, retain,
or process your audio. Speech-to-text processing is performed by
Chrome according to your browser and operating system privacy
settings.
6. PIN Lock — Visual Mask Only
The PIN lock feature provides a visual mask in the UI to prevent casual shoulder-surfing during a browsing session. It is not cryptographic encryption. Locked note content remains saved in IndexedDB and in exports. For full encryption, enable the optional backup passphrase for Google Drive backups.
7. Chrome Permissions Justification
| Permission | Justification / Use Case |
|---|---|
sidePanel |
Hosts the primary note-taking notebook interface directly in Chrome's side panel. |
storage |
Persists notes, stationery settings, themes, and API keys in IndexedDB & chrome.storage.local. |
tabs & scripting |
Scopes notes to the active webpage/domain and extracts article text for user-initiated AI summaries. |
contextMenus |
Provides right-click options: "Append selection to Notyx - AI Note", "Open Notyx - AI Notes", and "Highlight selection on page". |
identity |
Enables the optional Google Drive backup OAuth flow via
chrome.identity.launchWebAuthFlow.
|
host_permissions |
Required for page context detection, web highlight insertion, tab screenshot capture, and direct HTTPS calls to official Gemini/OpenAI API endpoints. |
8. Contact Us
If you have any questions, feedback, or inquiries regarding this Privacy Policy or Notyx, please reach out to us:
- Email: findvishalsharma@gmail.com
- GitHub Repository: https://github.com/iamvishal345/noterr
- Hosted Privacy Policy: https://notyx.codeentity.dev/privacy