Privacy Policy
Last updated: September 27, 2026
This policy covers both the Annotated website and the Annotated Chrome extension. The extension is the main way people use Annotated: it opens in Chrome’s side panel and lets you clip and annotate what you are reading or watching.
Short version: what you read stays on the page until you clip it, and Annotated keeps what you chose to save. The one exception is spelled out below — with the panel open, a one-way hash of the page’s address is sent so the panel can tell you whether that page has context notes. No profile is built from it. There is no advertising and no analytics SDK in the extension or the site.
Your account
Accounts are created only through Google or X sign-in. From Google we receive your name, email address and profile image. From X we receive your name, username and profile image — X does not release an email address to Annotated, so accounts created that way have no email on file.
Signing in to the extension stores a session token in the extension’s local browser storage (chrome.storage.local), alongside your own name, email address and avatar URL so the panel can draw your account without asking us again each time. The token authenticates your API requests. Both are removed when you sign out of the panel.
Signing in on the website instead sets a session cookie in that browser, which is how the site knows it is you when you vote or reply there. It lasts seven days and renews while you keep using the site. Signing out of the panel does not end it: sign out on the website itself, from the button beside your name at the foot of the sidebar or from your own profile page. That removes the cookie, ends the session on our server, and clears any unsent reply you had typed on the site, which is kept in that browser’s local storage until you post it.
Each session we issue is recorded on our server with the IP address and browser user agent it was created from, which is how a session can be recognised and revoked. Those are attached to the session record and are deleted with it.
What the extension reads from pages you visit
While the side panel is open, Annotated reads the address and title of the tab in front, and whether the page shows a YouTube video (the addresses and titles of the YouTube players in it), and updates them when you switch tabs or navigate. This is what lets the panel name the page you are looking at, open its video, and offer to clip it. The address, title and video addresses themselves stay in your browser and are not sent to us unless you go on to capture that page.
One thing does leave your browser as you browse, and it is not the address. So the panel can tell you whether the page in front of you already has context notes on it, Annotated hashes the address locally — a one-way SHA-256 digest, shortened to sixteen characters — and asks our server about that digest alone. We never receive the address, and the digest cannot be turned back into one. It is still a stable identifier for that page arriving on our server while you read, and anyone holding it who guesses a URL could confirm the guess by hashing it; we tell you this rather than calling it anonymous. It happens whether or not you are signed in, because public context notes are readable signed out, and it stops the moment you close the panel.
When you capture — by highlighting a passage with the panel open, choosing “Clip with Annotated” from the right-click menu, or pressing “Use this episode” on a podcast page — Annotated reads the page more fully: the text you selected, plus the article body, title, author, site name, publication date and description. That capture is held in memory (chrome.storage.session, cleared when the tab closes) until you either publish it or discard it. On a post on X, pressing “Use this post” also renders that one post into a picture of the post, stored with your annotation when you publish it — so the annotation keeps showing what it annotated, with the poster’s name and a link to the original, even if the post is later deleted.
Annotated does place a small script on the web pages you open, so that the panel can show the passage you are highlighting while you are still highlighting it — a highlight is the gesture, so nothing can be injected after the fact to catch it. That script draws nothing on the page and adds nothing to it. It reports what you have selected to the side panel, and only while the panel is open and listening; with the panel closed it does nothing at all. It does not read, transmit or record page content otherwise.
Annotated does not build a profile of the sites you visit: the context-note lookup above is answered and not retained against your account, and nothing else about a page you did not clip is stored. The extension asks for access to all http and https sites because a highlight can happen on any page, and because Chrome excludes side panels from the permission model that would otherwise let it ask per-page — not because it reads them all.
What you create
We store the annotations, clips, comments, notes, ratings, follows, votes and topic suggestions you create, together with the source URL and attribution of the material you annotated. Anything you publish is public, including on pages viewable without an account.
Context notes are also published as a downloadable public dataset: three tab-separated files of notes, the ratings on them and each note’s status history. Today the ratings file carries no ratings. It stays empty while the admitted rater pool is in force: the early stage context notes are in now, while the community is small, in which Annotated can limit the ratings that decide a note to raters it admits by hand. When the file does carry ratings, each appears with the note it rates (and a note written on an annotation names that annotation), the time it was made to the millisecond and its rater’s pseudonym: a code that stays the same from one download to the next, never a name, handle or alias. Ratings made during the pool may be published that way after it ends; we will update this policy before that happens. Note authors appear as pseudonyms too, but a note’s text is also shown on the site under its author’s alias, so an author’s pseudonym can be matched to that alias. Copies of the ratings file downloaded before it was emptied carry each rating with its rater’s stable pseudonym, the time it was made to the millisecond and, where that annotation was public, the annotation it was made on. Copies already downloaded cannot be recalled.
If you record spoken or video commentary, the extension asks Chrome for microphone or camera access in a separate window, captures only during a recording you start and end, and uploads it as part of that annotation. Nothing is captured before you grant access, or outside a recording you started.
If you upload an audio or video file instead, the extension converts it on your computer into the same small format a recording uses, at most 90 seconds of it, without the file’s own title, date or other embedded details. Only that copy is uploaded, and only when you post.
Where it goes
Annotated runs on Railway with a Postgres database, and stores media clips and recordings in S3-compatible object storage so they can be played back. In addition:
- Transcription — audio and video clips, and recorded comments and replies, are sent to a speech-to-text provider to produce a transcript. This is the only processing by a third-party model: nothing you write, clip or search is sent to a language model, and apart from these transcripts the product generates nothing with a model. The sample accounts described below were made with AI tools outside the product, as the section on them explains.
- YouTube — when a clip’s source is a YouTube video, the panel embeds YouTube’s own player from
www.youtube.comwhile you trim it, so YouTube receives a request from your browser and applies its own privacy policy to it. This happens as soon as the video appears, before you press play. On a YouTube video page the video appears by itself when the panel is open on Capture, unless you have already started writing; otherwise, and on another page, when you choose Video. Unless you choose a 240p recording when you publish it (below), a YouTube clip plays in YouTube’s own player: we store the video’s address and the seconds you chose, not a copy of the video. It shows YouTube’s poster image fromi.ytimg.comwherever the post appears, in the panel and on the public page, and loads the player fromwww.youtube.comwhen you press play. The demo page (/demo) shows our launch film as our own picture with a play button: it loads nothing from YouTube until you press play, and then loads YouTube’s privacy-enhanced player fromwww.youtube-nocookie.comin its place. Once loaded, that player contacts YouTube and Google and keeps some data in your browser’s storage for that page. While you trim a YouTube video, the panel also asks YouTube for that video’s captions, when it has any, so it can show the words along the trimmer. It fetches them fromwww.youtube.comwithout your YouTube cookies. When you publish a clip that plays in YouTube’s player, the panel sends us the captions for the part you clipped, and we save them with your clip as its transcript. Otherwise they stay in the panel only while you trim. In the download from/install(the Chrome Web Store package does not record in the browser), publishing a YouTube clip asks whether it plays in YouTube’s player or as a 240p recording, and when you start clipping a YouTube video in the side panel — you choose it, play it, trim it, preview it, tag it, write about it or publish it — (and when a failed YouTube clip is shown there), the panel reads the video’s public YouTube page with your browser’s YouTube cookies, as if you opened it (YouTube may set its usual cookies in return), to check that the video is public and not age-restricted or members-only, whichever way you then post it. From then on it also looks through the addresses of your open tabs for one already playing that video, where a recording could be made; they stay in your browser. When you publish the clip as a 240p recording or make a clip again, the panel plays your part muted, at 2×, in YouTube’s privacy-enhanced player (www.youtube-nocookie.com), which takes the trimming player’s place on Capture (or appears at the top of the panel while you are elsewhere in it, or in a Chrome older than version 133), and records it. That player does not play as your YouTube account, and keeps a few player settings, such as a low playback quality, in your browser’s storage forwww.youtube-nocookie.com; like any YouTube player, it also loads a script from Google, and your browser sends your Google cookies with that request. When the panel’s player can’t make the clip — YouTube won’t play the video there, or the player fails — the panel records that part from your open YouTube tab instead: it says so first, in the panel and on the tab, with a Stop, keeps a notice on the tab while it records, and then puts the tab back. That tab plays as your YouTube session. The player that makes the clip in the panel does not. With no YouTube tab open it asks you first, then opens the video in a new tab, muted, and closes it afterwards. The recording is uploaded to our storage; we cut it to 240p and delete the recording. - Podcasts — when you clip a podcast episode, our server looks it up where it is published (Apple Podcasts, Spotify, the show’s feed or its episode page) to find the episode’s audio file. When the show publishes a transcript of the episode in its feed, our server also fetches that transcript so the panel can show the episode’s words along the trimmer; the words stay in the panel while you trim and are not saved with your clip. When you press Preview, the panel plays your part of the episode from the address the show publishes it at, so the podcast’s host receives a request from your browser, as it would if you played the episode there, and whatever is playing in the tab in front of you pauses.
- Email — Resend delivers claim notifications.
- Favicons — the site icon shown beside a source (a cited one, and in the side panel the page you have open) is the icon the site itself names, which it may serve from its own content network, or else its
/favicon.ico. Your browser requests it from there while the source is on screen — as it does when you open the page, and nothing more. No third-party icon service is involved.
We do not sell personal data, share it with data brokers, or use it for advertising. We do not use what you clip to train our own models.
Sample accounts
To show Annotated in use, we seeded the public feed with sample accounts. The people, their names and their bios are fictional; we run these accounts, and nobody named in them does. Their posts and replies were written with AI from real, published sources, and the quotes and sources are real. Any voice or video comment posted from a sample account is AI-generated. The film on the demo page is recorded on a mock news site whose stories, bylines and accounts are made up, and it has AI-generated narration, music and sound effects, and three short AI-generated transition shots. The side panel drawn on the demo page offers a built-in voice note and a short video in place of a file from your device; both are AI-generated.
Apart from transcripts, which a speech-to-text model makes from recorded audio as described above, Annotated generates nothing with a model: the sample content was made with AI tools outside the product. The website and the side panel say so once, in an “About this feed” note shown the first time you open the feed, a profile, a post, a source page or search on the website, and the first time you open the side panel (version 1.3.1 or later). Individual posts and recordings are not marked, but a sample account’s profile, and the card that opens when you hover over its name, say “Sample Account”.
Rights claims
Anyone may file a claim on a public annotation page. A claim includes the name, email and statement you enter, so that we can review it and reply. Claims are retained as a record of the decision.
Deletion
You can take any annotation you have published back down from the side panel: open My clips and press Make private on it. That removes it from the feed and stops its public page resolving. It is not a deletion — the clip stays in your own list, as a draft, and you can publish it again.
To delete an annotation outright, or your account and everything attached to it, email privacy@annotatedbounty.dev from the address on your account, or with the handle you sign in under, and we will action it. Signing out removes the session token from your browser but does not delete anything held on the server.
Contact
Questions about this policy, or about data we hold: privacy@annotatedbounty.dev.