Privacy Policy

Last Updated: September 26, 2026 • Effective Date: September 26, 2026
🔒 Local-First Architecture Guarantee: Notyx: AI Notes is engineered from the ground up to protect your privacy. Your notes remain stored locally on your device unless you explicitly opt into external features.

1. Local-First Data Storage

Your privacy and data sovereignty are our core design principles:

  • On-Device Storage: All notes, titles, body content, web highlights, stationery selections, tags, comments, and application settings are stored locally on your device using Chrome's native IndexedDB and chrome.storage.local APIs.
  • No Account Required: You do not need to register, create an account, or provide an email address to use Notyx.
  • Zero Telemetry & Analytics: Notyx contains no tracking scripts, no analytics SDKs, no telemetry tools, and no advertising code. We do not monitor what you write, which websites you visit, or how you use the extension.

2. Optional Bring-Your-Own-Key (BYOK) AI Features

Notyx offers dual-tier AI capabilities with full user control and transparency:

  • Chrome Built-In Prompt API (Gemini Nano):

    When using Chrome's built-in Prompt API, all AI processing runs completely locally on your hardware. No data is sent over the internet for inference.

    If the on-device model fails or is unavailable, Notyx never silently falls back to a cloud API. An explicit error message is displayed so you remain in control of whether to configure a cloud provider in Settings.

  • External Cloud Providers (Google Gemini & OpenAI):

    If you configure an external AI provider, you supply your own API key. When you trigger an AI action (Summarize, Scrape JSON, tone polish, etc.), data is transmitted directly from your browser to the official API endpoint (generativelanguage.googleapis.com or api.openai.com) via HTTPS:

    • The prompt text and any note content you explicitly include.
    • The web page text (up to ~9,000 characters), title, URL, and extracted tables when using Summarize or Scrape.

    Your API keys are saved exclusively in chrome.storage.local and are never transmitted to any third-party server controlled by Notyx.

3. Optional Google Drive Cloud Backup (BYOK)

Cloud backup is 100% optional and operates directly between your browser and Google Drive:

  • Direct Connection: When enabled, Notyx authenticates using your personal Google OAuth Client ID via chrome.identity.launchWebAuthFlow. This contacts Google's official endpoints (accounts.google.com, oauth2.googleapis.com, and www.googleapis.com/drive/v3).
  • Account Email Display: Your Google account email address is retrieved from the Drive /about endpoint using only the drive.file scope. It is displayed in Settings and saved locally in chrome.storage.local.
  • Dedicated Folder: Backups are saved in a folder named "Notyx Backups" in your personal Google Drive.
  • Metadata & Client-Side Encryption: Backup file names, timestamps, and note counts are visible in Google Drive. You can optionally set an AES-256-GCM passphrase (derived via PBKDF2) to encrypt note content client-side before uploading.
  • Zero Access: We have no access to your Google credentials, Drive files, or backup tokens.

4. Fonts and External Resources

To provide an authentic handwriting and literary aesthetic, opening the panel loads font files from Google Fonts (fonts.googleapis.com / fonts.gstatic.com):

  • Shantell Sans (Modern Handwriting style)
  • Caveat (Signature Pen style)
  • Lora (Classic Editorial style)
  • Inter (UI typography)
  • Newsreader (Reading mode)
  • JetBrains Mono (Code blocks)

These font requests are governed by Google's Privacy Policy.

5. Web Speech API (Voice Dictation)

When you activate voice dictation, Notyx uses the browser's built-in SpeechRecognition API. Notyx does not record, retain, or process your audio. Speech-to-text processing is performed by Chrome according to your browser and operating system privacy settings.

6. PIN Lock — Visual Mask Only

The PIN lock feature provides a visual mask in the UI to prevent casual shoulder-surfing during a browsing session. It is not cryptographic encryption. Locked note content remains saved in IndexedDB and in exports. For full encryption, enable the optional backup passphrase for Google Drive backups.

7. Chrome Permissions Justification

Permission Justification / Use Case
sidePanel Hosts the primary note-taking notebook interface directly in Chrome's side panel.
storage Persists notes, stationery settings, themes, and API keys in IndexedDB & chrome.storage.local.
tabs & scripting Scopes notes to the active webpage/domain and extracts article text for user-initiated AI summaries.
contextMenus Provides right-click options: "Append selection to Notyx - AI Note", "Open Notyx - AI Notes", and "Highlight selection on page".
identity Enables the optional Google Drive backup OAuth flow via chrome.identity.launchWebAuthFlow.
host_permissions Required for page context detection, web highlight insertion, tab screenshot capture, and direct HTTPS calls to official Gemini/OpenAI API endpoints.

8. Contact Us

If you have any questions, feedback, or inquiries regarding this Privacy Policy or Notyx, please reach out to us: