Note Everything ("the extension", "we") is a Chrome extension for taking and linking
notes. This policy explains what data the extension handles and how.
English
Summary
- If you do not sign in, your notes are stored only on your device
(in the browser's local storage). We never see them.
- If you sign in with Google, your notes are synced to Google Firebase so you can
access them on other devices. We use your data only to provide this note‑taking and
sync feature. We never sell it, never use it for advertising, and never share it with third parties
other than the infrastructure provider (Google) used to run the service.
- The AI assistant is optional and off by default. It only works after you
add your own Google Gemini API key. When you use it, the relevant note content is sent
from your browser directly to Google's Gemini API using your own key — it never
passes through any server of ours. If you never add a key, no note content is ever sent to any AI
service. See "AI assistant" below.
What we collect and when
1. Guest mode (not signed in)
- Note content — titles, text, links, hierarchy, timestamps.
- Stored locally via
chrome.storage.local on your device only. Not transmitted anywhere,
unless you choose to use the AI assistant — see "AI assistant" below.
2. Signed in with Google (optional)
- Account information — the email address and basic profile associated with the Google
account you sign in with (via Google OAuth, scopes:
openid email profile). Used to identify
your account and to sync.
- Note content — titles, text, links, hierarchy, timestamps — stored in Google Firebase
(Cloud Firestore + Firebase Authentication) under your account so it can sync across your devices.
3. AI assistant (optional, off by default — "bring your own key")
The extension includes an optional chat assistant that can answer questions about your own notes and about
how the extension works. It is disabled until you add your own Google Gemini API key in
Settings › Connect AI. If you never add a key, this section does not apply to you and nothing described
here happens.
When the assistant is enabled and you send it a message:
- What is sent — your question, plus the content (titles and text) of notes from your own
collection, up to a size limit of about 80,000 characters per request. Which notes are included depends on
your question. Also sent: the text of the extension's own README, used to answer "how does this feature
work" questions.
- Where it is sent — directly from your browser to Google's Gemini API
(
generativelanguage.googleapis.com), authenticated with your own API key.
It does not pass through any server operated by us. We never see your questions, your
notes, or your key.
- This applies in guest mode too. Using the assistant sends note content to Google even
if you have not signed in.
- Your API key — stored on your device via
chrome.storage.local. It is
never synced to Firebase, never sent anywhere except to Google when making a request, and
never logged or displayed in error messages. You can delete it at any time in Settings, which fully
disables the assistant.
- Chat history — kept in
chrome.storage.session and automatically discarded
when you close the browser. It is not synced and not stored permanently.
- Google's handling of this data is governed by your own agreement with Google for the
Gemini API, not by us, because the request is made with your key. Please read Google's terms before
enabling the assistant — in particular, note that on the free tier of the Gemini API,
Google may use submitted content to improve its services.
Google's Gemini API terms: https://ai.google.dev/gemini-api/terms
· Google's Privacy Policy: https://policies.google.com/privacy
We do not collect analytics, browsing history, the content of web pages you visit, location,
or any data unrelated to your notes.
How we use your data
Your data is used solely to operate the extension's single purpose: creating, editing,
organizing, searching and syncing your notes. This use complies with the Chrome Web Store
Limited Use requirements:
- We do not sell or transfer your data to third parties.
- We do not use your data for advertising, ad targeting, or credit‑worthiness purposes.
- We do not allow humans to read your data, except: (a) with your consent, (b) for security purposes, or
(c) to comply with applicable law.
Where your data is stored
- Guest notes: locally on your device (browser storage).
- AI assistant: your API key stays on your device; note content you send to the assistant
goes to Google's Gemini API under your own key (see "AI assistant" above). Chat history is kept only for
the current browser session.
- Synced notes & account: Google Firebase (Cloud Firestore and Firebase Authentication).
Data is protected by Firestore security rules so that each account can only read and write its own notes.
Google's handling of this data is governed by Google's Privacy Policy:
https://policies.google.com/privacy
Data retention and deletion
- Guest notes stay until you delete them in the app or clear your browser data.
- Synced notes stay in Firebase until you delete them in the app.
- You can stop syncing at any time by signing out (your account data remains in Firebase unless deleted).
- To delete your synced data and account entirely, contact us at the email above and we will remove your
account and its notes.
- You can also export all your notes to a
.zip file at any time from the app (Export), and
re‑import it (Import).
Security
Network traffic to Google's services uses HTTPS. The extension is built on Manifest V3, bundles all code
locally, and does not execute remote code. Access to synced notes is restricted per account by Firestore
security rules.
Children
The extension is not directed to children under 13 and we do not knowingly collect data from them.
Changes to this policy
We may update this policy; the "Effective date" above will reflect the latest version.
Tiếng Việt
Tóm tắt
- Nếu bạn không đăng nhập, ghi chú chỉ được lưu trên máy của bạn
(trong bộ nhớ cục bộ của trình duyệt). Chúng tôi không nhìn thấy.
- Nếu bạn đăng nhập bằng Google, ghi chú được đồng bộ lên Google Firebase để dùng trên
nhiều thiết bị. Chúng tôi dùng dữ liệu chỉ để cung cấp tính năng ghi chú và đồng bộ.
Không bán, không dùng cho quảng cáo, không chia sẻ cho bên thứ ba ngoài nhà cung cấp hạ tầng (Google).
- Trợ lý AI là tùy chọn và mặc định TẮT. Nó chỉ hoạt động sau khi chính bạn
nhập API key Google Gemini của riêng bạn. Khi bạn dùng, nội dung ghi chú liên quan được gửi
thẳng từ trình duyệt của bạn tới Gemini API của Google bằng key của bạn — không đi qua
bất kỳ máy chủ nào của chúng tôi. Nếu bạn không bao giờ nhập key, không có nội dung ghi chú nào được
gửi tới dịch vụ AI nào cả. Xem mục "Trợ lý AI" bên dưới.
Thu thập gì và khi nào
1. Chế độ khách (chưa đăng nhập)
- Nội dung ghi chú — tiêu đề, văn bản, liên kết, cây phân cấp, thời gian.
- Lưu cục bộ bằng
chrome.storage.local ngay trên máy bạn. Không gửi đi đâu cả,
trừ khi bạn chủ động dùng trợ lý AI — xem mục "Trợ lý AI" bên dưới.
2. Đăng nhập bằng Google (tùy chọn)
- Thông tin tài khoản — địa chỉ email và hồ sơ cơ bản của tài khoản Google bạn dùng để
đăng nhập (qua Google OAuth, phạm vi:
openid email profile). Dùng để nhận diện tài khoản và
đồng bộ.
- Nội dung ghi chú — tiêu đề, văn bản, liên kết, cây phân cấp, thời gian — lưu trên Google
Firebase (Cloud Firestore + Firebase Authentication) dưới tài khoản của bạn để đồng bộ đa thiết bị.
3. Trợ lý AI (tùy chọn, mặc định tắt — "tự mang key của bạn")
Tiện ích có một trợ lý chat tùy chọn, trả lời câu hỏi về chính ghi chú của bạn và về cách dùng tiện ích.
Nó bị tắt cho tới khi bạn tự nhập API key Google Gemini của riêng mình trong
Cài đặt › Kết nối AI. Nếu bạn không bao giờ nhập key, mục này không áp dụng với bạn và không có điều gì
mô tả dưới đây xảy ra.
Khi trợ lý đã bật và bạn gửi một câu hỏi:
- Gửi đi những gì — câu hỏi của bạn, kèm nội dung (tiêu đề và văn bản) các ghi chú trong
kho của bạn, tối đa khoảng 80.000 ký tự mỗi lượt. Ghi chú nào được đưa vào phụ thuộc câu hỏi của bạn.
Ngoài ra còn gửi nội dung file README của tiện ích, để trả lời các câu hỏi dạng "tính năng này dùng thế
nào".
- Gửi đi đâu — thẳng từ trình duyệt của bạn tới Gemini API của Google
(
generativelanguage.googleapis.com), xác thực bằng API key của chính bạn.
Không đi qua bất kỳ máy chủ nào do chúng tôi vận hành. Chúng tôi không thấy câu hỏi,
ghi chú, hay key của bạn.
- Điều này áp dụng cả ở chế độ khách. Dùng trợ lý là có gửi nội dung ghi chú tới Google,
kể cả khi bạn chưa đăng nhập.
- API key của bạn — lưu trên máy bạn qua
chrome.storage.local.
Không bao giờ đồng bộ lên Firebase, không gửi đi đâu ngoài Google khi thực hiện yêu cầu,
và không bao giờ bị ghi log hay hiện ra trong thông báo lỗi. Bạn có thể xóa key bất cứ lúc nào trong
Cài đặt, khi đó trợ lý tắt hoàn toàn.
- Lịch sử trò chuyện — giữ trong
chrome.storage.session và tự động mất khi
bạn đóng trình duyệt. Không đồng bộ, không lưu vĩnh viễn.
- Việc Google xử lý dữ liệu này tuân theo thỏa thuận giữa CHÍNH BẠN với Google về Gemini
API, không phải với chúng tôi, vì yêu cầu được gửi bằng key của bạn. Hãy đọc điều khoản của Google trước
khi bật trợ lý — đặc biệt lưu ý: ở gói miễn phí của Gemini API, Google có thể dùng nội
dung gửi lên để cải thiện dịch vụ của họ.
Điều khoản Gemini API: https://ai.google.dev/gemini-api/terms
· Chính sách quyền riêng tư của Google: https://policies.google.com/privacy
Chúng tôi không thu thập dữ liệu phân tích, lịch sử duyệt web, nội dung trang web bạn truy
cập, vị trí, hay bất kỳ dữ liệu nào không liên quan đến ghi chú của bạn.
Cách sử dụng dữ liệu
Dữ liệu chỉ được dùng duy nhất cho mục đích của tiện ích: tạo, sửa, sắp xếp, tìm kiếm và
đồng bộ ghi chú của bạn. Việc này tuân thủ yêu cầu Limited Use của Chrome Web Store:
- Không bán hay chuyển dữ liệu cho bên thứ ba.
- Không dùng dữ liệu cho quảng cáo, nhắm quảng cáo hay đánh giá tín dụng.
- Không để con người đọc dữ liệu của bạn, trừ khi: (a) có sự đồng ý của bạn, (b) vì mục đích bảo mật, hoặc
(c) để tuân thủ pháp luật.
Nơi lưu dữ liệu
- Ghi chú khách: cục bộ trên máy bạn (bộ nhớ trình duyệt).
- Trợ lý AI: API key nằm trên máy bạn; nội dung ghi chú bạn gửi cho trợ lý đi tới Gemini
API của Google bằng key của chính bạn (xem mục "Trợ lý AI" phía trên). Lịch sử trò chuyện chỉ giữ trong
phiên trình duyệt hiện tại.
- Ghi chú đồng bộ & tài khoản: Google Firebase (Cloud Firestore và Firebase
Authentication). Dữ liệu được bảo vệ bằng Firestore security rules để mỗi tài khoản chỉ đọc/ghi được ghi
chú của chính mình. Việc Google xử lý dữ liệu tuân theo Chính sách quyền riêng tư của Google:
https://policies.google.com/privacy
Lưu giữ và xóa dữ liệu
- Ghi chú khách tồn tại đến khi bạn xóa trong app hoặc xóa dữ liệu trình duyệt.
- Ghi chú đồng bộ tồn tại trên Firebase đến khi bạn xóa trong app.
- Bạn có thể ngừng đồng bộ bất cứ lúc nào bằng cách đăng xuất (dữ liệu tài khoản vẫn còn trên Firebase cho
tới khi bị xóa).
- Để xóa toàn bộ dữ liệu đồng bộ và tài khoản, hãy liên hệ email phía trên, chúng tôi sẽ xóa tài khoản và
ghi chú của bạn.
- Bạn cũng có thể Export toàn bộ ghi chú ra file
.zip bất cứ lúc nào và Import lại.
Bảo mật
Lưu lượng tới dịch vụ Google dùng HTTPS. Tiện ích xây trên Manifest V3, đóng gói toàn bộ mã cục bộ, không
thực thi mã từ xa. Quyền truy cập ghi chú đồng bộ được giới hạn theo từng tài khoản bằng Firestore security
rules.
Trẻ em
Tiện ích không hướng tới trẻ dưới 13 tuổi và chúng tôi không cố ý thu thập dữ liệu của trẻ.
Thay đổi chính sách
Chúng tôi có thể cập nhật chính sách; "Ngày hiệu lực" phía trên phản ánh phiên bản mới nhất.