Privacy Policy
Last updated: 2026-05-05
SideJot ("the extension") is a browser side-panel note-taking tool. We take your privacy seriously. This policy explains how the extension collects, uses, and stores your data.
1. Information We Collect
The extension only collects the minimum data necessary, and only when you actively use related features:
- Email address and password: Collected only when you voluntarily choose to register or sign in for cloud sync. Passwords are stored using industry-standard one-way hashing in a Supabase-hosted database; we cannot see your plaintext password.
- Notes you create: Including titles, content, source URLs, created/modified timestamps, and pinned state. Notes are always saved first to your browser's local IndexedDB.
- Selected text from web pages: When you explicitly invoke the right-click "Save to SideJot" context menu, the extension reads only the text content currently selected by you on the active web page. This is captured exclusively at the moment of your click, by injecting a single one-shot function via
chrome.scripting. We do NOT read or monitor any other content on the page, do NOT read pages you have not actively selected text on, and do NOT run any persistent content scripts.
- Source page URL and title: When you save a selection, the URL and title of the active tab are captured so the note can link back to the original source.
- Extension preferences: Such as interface language, panel height, and editor state. These are stored only in your browser's local storage.
We do NOT collect: your browsing history, the content of websites you visit (beyond your active selection), IP addresses, device fingerprints, click behavior, or any other data used for profiling or advertising.
2. How Your Data Is Used
- Offline mode: If you choose "use offline without sign-in", all notes are stored only in your browser locally and are never uploaded to any server.
- Cloud sync mode: If you sign in, your notes are uploaded over HTTPS to our Supabase-hosted database for synchronization across your devices. Supabase Row-Level Security (RLS) ensures each user can only access their own data.
We will never use your notes, email, or any other data for advertising, resale to third parties, or any purpose unrelated to the core functionality.
3. Where Data Is Stored
- Local data: Stored in your browser (IndexedDB and
chrome.storage.local). Only you can access it.
- Cloud data (signed-in users only): Stored with Supabase. See supabase.com/privacy.
4. Data Sharing
We do not share, sell, or rent your data to any third party. The only third party involved is Supabase, used purely as infrastructure for storing and syncing your notes.
5. Your Rights
- You can delete your notes at any time from within the extension.
- You can export all your notes using the extension's export feature.
- To delete your cloud sync account and all associated data, email tszxy0305@gmail.com. We will process requests within 7 business days.
- In offline mode, uninstalling the extension removes all local data.
6. Cookies and Tracking
The extension does not use cookies, does not inject tracking scripts, and does not integrate with any analytics platform (such as Google Analytics).
7. Children's Privacy
The extension is not directed to children under 13. If we discover that we have inadvertently collected personal information from a child, we will delete it immediately.
8. Policy Changes
If this policy changes materially, we will post a notice on the Chrome Web Store listing and on this page, and update the "Last updated" date above. Continued use of the extension after such changes constitutes acceptance of the updated policy.
9. Contact
For questions about this policy, contact: tszxy0305@gmail.com