Quilldum Notes Privacy Policy
Quilldum Notes is a Chrome extension for creating visual annotations on web pages. This policy explains what data Quilldum Notes processes, why it is needed, and the choices available to you.
Data controller: Robin Alfredsson
Privacy contact: privacy@quilldum.se
Data processed
Free
When you use Quilldum Notes without signing in, settings, annotations, inserted images, web addresses, page titles, and a register of used web addresses are stored locally by Chrome on your device. This data is not sent to Quilldum Notes servers. Screenshots and exports are created only when you request them and are saved as local downloads.
Signed-in Free
When you sign in with Google, Quilldum Notes processes your Firebase user ID, name, email address, and profile picture. Private annotations, the web addresses and page titles they relate to, and inserted private images are synchronized with your account. An account register of up to ten unique normalized web addresses enforces the plan limit. A registered address remains in this counter even if the annotations on that page are deleted.
Pro
Pro processes the same account data and synchronized content as Signed-in Free, but without the ten-address limit. Pro includes up to 500 MB of private image storage. For subscriptions, Quilldum Notes also processes Stripe customer, subscription and price identifiers, subscription status, period end, and cancellation status. Card numbers and complete payment details are processed by Stripe and Link, not by Quilldum Notes servers.
Business
Business includes multiple user seats. To administer seats, Quilldum Notes processes the Firebase user ID, name, email address, role, assignment date, and associated Business account for the Business administrator and members. The administrator can see which accounts use seats and can assign or revoke them. Revoking a seat does not delete the user's private annotations or images.
Websites and page content
Quilldum Notes needs website access to display the correct annotations on the correct page. The extension uses the current web address, page title, and page view to position annotations and to create a screenshot when you explicitly select that function. Quilldum Notes does not build a general profile of your browsing history or send the contents of other visited pages to Quilldum Notes servers.
Sharing
Signed-in users can create and save shared folders. This stores the owner's user ID, folder name, web addresses, page titles, annotations, and images added by users. A sharing link is not private or access-controlled. Anyone with the link can view the shared folder and its content, even without signing in. Signing in is required to edit or save a share to an account. Do not put sensitive information in a shared folder.
How data is used
Data is used only to provide Quilldum Notes features: local storage, sign-in, synchronization, sharing, image storage, plan limits, payments, subscription management, troubleshooting, security, and abuse prevention. Quilldum Notes does not sell personal data, display advertising, or use data for targeted advertising, credit decisions, or purposes unrelated to the extension's functionality.
Chrome Web Store data disclosures
Depending on the features you choose to use, Quilldum Notes handles personally identifiable information such as your name and email address; authentication information such as Firebase account identifiers and authentication tokens; financial and payment information limited to subscription identifiers, plan, status, billing period, and cancellation status; personal communications contained in annotations you choose to share; web history limited to the addresses and titles of pages you annotate; user activity that you intentionally create as annotations, such as drawing coordinates, placements, and typed content; and website content that you explicitly select, annotate, capture, or upload. Quilldum Notes does not receive complete card details from Stripe or Link and does not collect health information or location data.
Service providers
Quilldum Notes uses Google Firebase and Google Cloud for sign-in, database services, and synchronization; STRATO for image storage and server functions; and Stripe and Link for payments and subscriptions. These providers process data on Quilldum Notes behalf or as independent controllers under their own terms. Data may be processed outside the EU/EEA under safeguards applied by the relevant provider.
Legal basis
Processing is necessary to provide the service and features you request. Some processing also relies on legitimate interests in protecting the service, preventing abuse, and resolving technical faults. Data that must be retained by law is processed to meet legal obligations.
Retention and deletion
Local data remains until you delete it, reset the extension's data, or uninstall the extension. Account data and synchronized content remain until the content is deleted or you ask us to delete the account and its data. Shared content remains until the owner deletes the shared folder. Payment and accounting records may need to be retained longer under law or by Stripe and Link.
You may request access, correction, deletion, restriction, or a copy of your data by contacting us. You may also object to certain processing and submit a complaint to the Swedish Authority for Privacy Protection, IMY.
Security
Communication with Firebase, STRATO, Stripe and Link uses HTTPS. Account access is verified using Firebase authentication and server-side checks. No internet-based storage can be guaranteed to be completely risk-free. Sharing links should be treated as public links.
Google API Services
Quilldum Notes' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Chrome Web Store User Data Policy, including the Limited Use requirements. Humans access Google user data only with your explicit consent, when required for security, to comply with law, or when the data has been aggregated and anonymized for internal operations.
Changes
This policy may be updated when Quilldum Notes features or providers change. The date at the top identifies the latest version.