Alt+Q Notes Privacy Policy

1. Scope

This policy explains how the Alt+Q Notes Chrome extension handles information when you create notes, attach images, save tabs, optionally sync with a cloud provider, and use features covered by usage analytics.

You can use the note-taking features without an account or a cloud connection. Notes are saved to your device first. Cloud sync is optional and runs only when you choose to connect a supported provider and start syncing. Google Drive is currently the supported sync provider. Builds with analytics enabled automatically send the usage events described below to PostHog, independently of cloud sync.

2. Information We Handle and Why

InformationPurposeStorage and transmission
Note content, formatting, colors, ordering, and creation, modification, and deletion timestampsCreating, displaying, organizing, and restoring notesLocal device storage; also your Google Drive when you start syncing
Images and screenshots you paste, including image dimensions and formatsAttaching and previewing imagesLocal device storage; also Google Drive when you start syncing
Open-tab titles and URLs read by tab-selection features, saved tabs, and note sourcesSelecting tabs, saving links to notes, and reopening themProcessed locally for selection; saved tabs and sources are stored with notes and sent to Google Drive when syncing
Note and image identifiers, device identifiers, change and deletion records, and sync statusSyncing across devices and preventing deleted notes from reappearingLocal device storage and Google Drive data needed for sync
Google connection status and authentication tokensAccessing the Drive app data you authorizeConnection status is stored locally; tokens are managed through Chrome Identity and used for Google API requests
Installation identifiers, usage events, and environment informationAnalyzing feature use, return use, and task success or failure, and improving the productSent to PostHog in builds with analytics enabled

The extension reads tab information in response to user actions needed for its note-taking features. It does not continuously collect your full browsing history. Image pasting is initiated by you; the extension does not continuously monitor your clipboard.

3. Local Storage

Notes and images are stored in the extension's IndexedDB database. Settings, installation identifiers, connection status, and similar information are kept in Chrome extension storage. Session information and some temporary data are kept in browser session storage or memory.

The extension does not send notes to a separate note server operated by us. If you start Google Drive sync, the information described in the next section is sent to Google. Usage analytics transmission is independent of whether Drive is connected.

4. Optional Cloud Sync

Connecting a cloud provider is not required to use local note-taking features. The provider-specific practices below apply only if you choose to connect that provider and start syncing.

Google Drive

Connecting Google Drive uses Chrome's Google authentication flow. The extension does not ask you to enter your Google password directly. The requested Drive permission covers this app's hidden app data folder (drive.appdata); the extension does not request access to all your regular Drive files.

When you start syncing, local notes, images, saved tabs, sources, ordering information, and Trash data are merged with the connected account's app data folder. Later changes and deletion records are also synced. Data is transferred directly between your device and Google APIs.

Logging out stops sync and does not delete existing data on your device or in Drive. Local notes are not separated by Google account. If you connect a different account, notes remaining on your device may be merged into that account.

Information received from Google APIs is used to provide the sync functionality you request. It is not used for advertising, usage analytics, or AI model training. The use and transfer to other apps of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google's own handling of information is governed by the Google Privacy Policy.

Additional Providers

We plan to support additional sync providers. Before making a new provider available, we will update this policy to identify the provider, the information shared, its purpose, and any provider-specific storage, access, and deletion practices. Adding support for a provider will not automatically connect your account or transfer your notes to it; you will need to choose to connect it and start syncing.

5. PostHog Usage Analytics

Builds with analytics enabled automatically send the following information to PostHog's EU ingestion endpoint (eu.i.posthog.com):

The installation identifier is used to recognize return use of the same installation and is not linked to your name or Google account. Because these identifiers distinguish repeated use, we do not describe this data as fully anonymous.

Analytics events do not include note content, images or screenshots, clipboard content, tab URLs or titles, Google account information, authentication tokens, or raw error messages. We also do not use automatic pageview collection, screen recording, or session replay.

PostHog may receive your source IP address as part of network communication. The extension sends a setting that disables geographic enrichment. Server-side handling, including whether IP addresses are stored, depends on the actual PostHog project settings.

The extension currently has no individual analytics opt-out setting or separate analytics consent screen. Disabling or uninstalling the extension stops future transmission. Builds with analytics disabled do not send events to PostHog.

For information about PostHog's own handling of data, see the PostHog Privacy Policy.

6. Sharing and Limits on Use

The extension currently uses Google for the Drive sync you choose to enable and PostHog for enabled usage analytics. The information sent to each service and the purposes of those transfers are described above.

We do not sell user data or use it for personalized advertising. Note content and Google Drive data are not provided to analytics services. User data handled through the extension is used to provide and improve note-taking and related user-facing features, in accordance with the Limited Use requirements of the Chrome Web Store User Data Policy.

7. Retention and Deletion

Notes and Images

Notes remain on your device until you delete them. Deleted notes move to Trash. Items that have been in Trash for 30 days are permanently deleted when the extension's cleanup process runs. You can also permanently delete notes from Trash yourself. Cleanup and synchronization may be delayed depending on whether the browser is running and the state of sync.

If you use sync, synchronization must complete for permanent deletion to be reflected in Google Drive. Minimal deletion records, such as note identifiers and deletion timestamps, may remain to prevent deleted notes from reappearing on other devices. These records do not contain the note body.

If you remove an image attachment from a synced note, the corresponding image file in Drive may remain until the note is permanently deleted so that changes from offline devices can still be processed.

Uninstalling and Disconnecting Google

Uninstalling the extension removes its stored data from that browser profile. Local migration backups created by earlier versions may remain in extension storage after individual notes are deleted.

Uninstalling or logging out does not also delete data stored in Google Drive, data on other devices, or analytics data already sent. You can revoke the app's access through your Google account. Drive app data must be deleted separately through Google Drive's app management features. Local data on other devices must also be deleted separately.

Usage Analytics

Analytics data already sent is subject to the retention and deletion practices in Section 5. The operator cannot directly access your device's note storage to delete notes for you.

8. Security

Communication with Google APIs and PostHog uses HTTPS. Authentication tokens are not included in notes or analytics events. The extension does not add its own encryption to local data or provide end-to-end encryption for Drive sync. You should also protect access to your device and browser profile.

9. Contact and Policy Changes

For questions about privacy or data deletion, contact ariadnelabs.contact@gmail.com. Do not include note content or authentication tokens in your inquiry.

When this policy changes, we will update its content and effective date. Material changes to data handling will be accompanied by any required notices and consent procedures.