Privacy Policy
Last updated: September 28, 2026
Sagitnote (the "Extension", "we") is a browser annotation extension developed and operated by the Sagitnote project. We know how important your personal information is to you, and we are committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have over it.
This Privacy Policy applies to the Sagitnote browser extension distributed through the Chrome Web Store and the Microsoft Edge Add-ons store, together with its accompanying backend services (website: https://www.webnoteshub.com). Information about the data controller for this service can be found in Section 14 "Contact Us".
1. Information We Collect
1.1 Information You Provide
Account information:
- Username (login ID)
- Email address
- Display name (optional)
- Password (stored in hashed form — we cannot see your plain-text password)
- When you sign in via Google or GitHub OAuth, we receive your third-party account identifier (e.g. Google's
subor GitHub's numeric user ID), email address, and display name
Content you create:
- Web annotations (text highlights, text notes, arrows, rectangles, freehand drawings, image annotations, etc.)
- Text context snippets of annotated passages (used to locate and restore annotations)
- Comments and tags attached to annotations
- Page snapshots (HTML content of pages you deliberately save, with scripts and extension markup stripped)
- Documents you create inside the extension (rich-text documents)
- Image attachments you deliberately add to annotations
Payment information (only when you purchase a paid subscription):
- Payments for paid subscriptions are processed by our payment processor, Waffo Pancake
- We do not collect or store your full card number, expiry date, or CVV security code — the card data you submit at the checkout goes directly to Waffo Pancake and never passes through, nor is stored on, our servers (see Section 6)
- We only receive and store the minimum information needed to activate your service: order identifier, transaction amount, payment status, and time
Feedback system information:
- When you use the built-in issue feedback feature, you enter our self-hosted open-source feedback system (Apache Answer) via single sign-on (SSO)
- The feedback system receives your user identifier (user ID), login name, display name, and email address in order to create and manage your feedback account
- Questions, suggestions, and comments you submit in the feedback system are stored in that system
Share-page visitor information (only when you open a share link that allows collaboration, or is protected by a password):
- An anonymous viewer identifier, stored in a functional cookie (
wpzl_sv) together with the display name you choose and permission/passcode flags. The cookie is valid for at most 35 days (default 7 days, renewed on activity, and never longer than the remaining validity of the share) - If you submit replies or collaborative annotations: the content you submit, stored together with your chosen display name and the anonymous viewer identifier
1.2 Technical Information Collected Automatically
Page metadata:
- The URL and page title of pages you have annotated
- Position information of annotations on the page (XPath, offsets, etc. — used solely to locate annotations)
Server-side automatic records:
- Sync operation logs (for troubleshooting data synchronization; they record user ID, operation type, and timestamp)
- Share-view rate-limit logs (temporarily cached IP addresses used to prevent brute-forcing of share passwords; automatically expiring)
- Payment callback notification logs (order identifier and payment status, used for reconciliation and service-tier activation; contain no card data)
1.3 Information We Do Not Collect
We explicitly do not collect:
- Your browsing history
- The list of all pages you visit (we only record pages you have actively annotated)
- Your search history
- Behavioural data about you on other websites
- Device fingerprints or unique identifiers (beyond the necessary account identifier)
- Any data used for advertising or user profiling
- Content of pages you have not actively annotated
- Your full payment card number, expiry date, or CVV (card data is handled exclusively by Waffo Pancake — see Section 6)
The Extension contains no third-party analytics/statistics SDKs (such as Google Analytics, Firebase, Facebook Pixel, or Hotjar), no advertising SDKs, and no tracking or user-behaviour beacon code.
2. How We Use Information
We use the information we collect only for the following purposes (with the legal basis for each):
| Purpose | Description | Legal basis |
|---|---|---|
| Provide the core annotation service | Render and manage your annotations, highlights, and notes on web pages | Performance of contract |
| Cross-device sync | Sync your annotations, pages, documents, folders, and snapshots across devices | Performance of contract |
| User authentication | Verify your identity to provide account services | Performance of contract |
| Billing & payment processing | Handle subscription purchases, refund approvals, and service-tier activation (card data is handled by Waffo Pancake) | Performance of contract |
| Sharing & collaboration | Let you share annotations with others for viewing or collaboration | Performance of contract |
| Transactional email | Send registration verification codes and password-reset codes (transactional only, never marketing) | Performance of contract |
| Product update emails | Send occasional product-update emails — only if you explicitly opted in at registration or in account settings. Product update emails are not currently being sent; if we begin sending them in the future, every such email will include an unsubscribe link | Consent (withdrawable at any time) |
| Service notifications | Billing, security alerts, policy updates, and other service-essential notices | Legitimate interests |
| User feedback & support | Collect and handle your feedback, feature suggestions, and problem reports through the integrated feedback system | Performance of contract / legitimate interests |
| Service improvement & troubleshooting | Analyze sync logs to fix technical problems | Legitimate interests |
| Legal compliance | Fulfil statutory tax and accounting obligations (e.g. statutory retention of transaction records) | Legal obligation |
Product update emails are sent strictly on an opt-in basis (off by default — see Section 11). Beyond that, we do not carry out any other consent-based marketing processing, and we will not use your information for:
- Advertising or personalized recommendations
- Building user profiles
- Selling, renting, or profit-driven sharing with third parties
- Automated decision-making (such as credit scoring or eligibility determination)
3. Data Storage and Transfer
3.1 Storage Locations
| Data type | Location | Notes |
|---|---|---|
| Account information | Germany (Hetzner Cloud, PostgreSQL database) | Server-side persistent storage |
| Annotation data | Germany (Hetzner Cloud, PostgreSQL database) | Server-side persistent storage |
| Page metadata | Germany (Hetzner Cloud, PostgreSQL database) | Server-side persistent storage |
| Documents / snapshot content | Germany (Hetzner Cloud, PostgreSQL database) | Server-side persistent storage |
| Transaction records (order no., amount, status) | Germany (Hetzner Cloud, PostgreSQL database) | Server-side persistent storage; contain no card data |
| Image attachments | Western Europe (Cloudflare R2 object storage) | Server-side persistent storage |
| All annotations / pages / documents / snapshots / images | Your device's browser IndexedDB | Local storage; enables offline use |
| Auth tokens / user preferences | Your device's chrome.storage.local | Browser-local storage |
| Feedback system data (questions / suggestions / comments) | Germany (Hetzner Cloud, feedback system's separate database) | Self-hosted Apache Answer instance |
3.2 Data Transfer
- All communication between the browser extension and our servers is encrypted via HTTPS
- Image uploads to Cloudflare R2 use HTTPS plus signed URLs
- Payments: the transfer of payment data between you and the Waffo Pancake checkout is handled under Waffo Pancake's own security standards and never passes through our servers
- Data in transit is protected by TLS encryption
- We do not transfer your data to servers outside the EU/European Economic Area (all server-side infrastructure is located in Europe). The exceptions to this are described in Section 12 (the Resend email service, and operational access from China)
3.3 Local Data
The Extension keeps a complete copy of your annotations, pages, documents, snapshots, and images in your browser's local storage (IndexedDB). This means:
- You can view and manage existing annotations while offline
- You can inspect and export this local data using your browser's developer tools
- Uninstalling the Extension erases this local data
4. Cookies and Tracking Technologies
| Type | Purpose | Can be disabled |
|---|---|---|
| Strictly necessary | Login session persistence, password verification for share viewing, anti-abuse rate limiting | No (the corresponding features cannot work without them) |
| Functional | Preferences such as interface language | Yes (clearable via browser settings) |
| Analytics | Not used | — |
| Marketing | Not used | — |
- Analytics tools used: none. The Extension and this website use no third-party analytics, statistics, or marketing tools, and set no analytics or marketing cookies.
- The Extension's local data (annotations, preferences, etc.) is stored in IndexedDB and
chrome.storage.local, not in cookies; it can be cleared via browser settings or by uninstalling the Extension.
5. Third-Party Services
| Third party | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| Waffo Pancake | Payment processing (subscription purchases and refunds) | Card data submitted at checkout (never via our servers), order information, billing email (controlling entity: Waffo.com Limited, Hong Kong) | Waffo Pancake Customer Help |
| Cloudflare (R2) | Image object storage (Western Europe region) | Image files uploaded to annotations | Cloudflare Privacy Policy |
| Resend | Registration verification and password-reset emails | Email address, verification code (note: Resend is a US company; email sending is configured in Resend's EU region, Ireland) | Resend Privacy Policy |
| OAuth third-party sign-in | Google account identifier, email, display name | Google Privacy Policy | |
| GitHub | OAuth third-party sign-in | GitHub account numeric ID, username, email, display name | GitHub Privacy Statement |
We only transfer the minimum amount of data necessary for each specific function, and we have data processing agreements with the third parties where applicable.
6. Data Sharing and Disclosure
We do not sell your personal information, including "sale" as defined by applicable law (such as the California CCPA). We will not sell, rent, or otherwise disclose your personal information except:
- Service providers: we use cloud hosting, payment, and email providers to operate the service; each is bound by confidentiality and data-processing agreements (see Section 5). Payment card data is processed exclusively by our PCI-DSS-compliant payment processor Waffo Pancake and is never stored on our servers. We only transmit to Pancake the order information necessary to complete payment (order identifier, amount, etc.); the card data you submit at the checkout goes directly to Pancake, not through us.
- Your explicit consent: when you use the sharing feature, the content you actively choose to share becomes visible to the people you share it with.
- Legal requirements: we may have to disclose your information under laws, regulations, legal process, or governmental requests.
- Protecting rights: to protect our or others' rights, property, or safety, or to detect, prevent, and resolve fraud, security, or technical issues.
Specifics of the sharing feature
- The annotation content you actively choose to share (including annotation positions, comments, tags, etc.) becomes visible to people who receive the share link
- Share links can be protected by a password (optional, set by you) and an expiry time (optional, set by you)
- You can revoke a share at any time
- Shared annotations never expose your account information (such as password or email) to viewers
7. Data Retention
- While your account exists: we retain your annotation data and account information for as long as your account exists.
- After account deletion: you can request account deletion by contacting us. After verifying your identity, we will delete your server-side data within a reasonable period (usually no more than 30 days). Note: deleted annotations, pages, folders, and image data are kept in "soft-deleted" form in the database for up to 90 days so that deletions propagate correctly across devices, after which they are physically purged.
- Transaction records: order numbers, transaction amounts, and payment statuses are retained, typically for 10 years, to fulfil statutory tax and accounting obligations, and are then deleted or anonymized. Transaction records never contain payment card data.
- Feedback system data: retained while your feedback account exists; deleted together with your account upon account deletion.
- Local data: you can delete all locally stored data at any time via your browser's clear-data feature or by uninstalling the Extension.
- Authentication tokens: refresh tokens are valid for 30 days and expire automatically. Logging out immediately deletes all refresh tokens.
- Rate-limit logs: cached IP addresses expire automatically within minutes.
- Sync / application logs: kept for troubleshooting on a rolling basis, for no longer than 12 months.
- Share-page viewer data: the
wpzl_svcookie expires at most 35 days after it is issued (or earlier when the share expires or is revoked). Replies and collaborative annotations submitted by viewers are stored under the share owner's account and are deleted together with that share or that account's data.
8. Your Rights
Under the EU General Data Protection Regulation (GDPR) and other applicable privacy laws, you have the following rights:
| Right | Description | How to exercise it |
|---|---|---|
| Information | Know what data we collect and use | Read this policy; contact us with any questions |
| Access | Obtain a copy of the personal data we hold about you | Export your annotation data via the extension's export feature (JSON/CSV/Markdown/HTML); or contact us for a full data export |
| Rectification | Correct inaccurate personal data | You can change your display name and similar details in the extension settings |
| Erasure | Have your personal data deleted ("right to be forgotten") | Contact us to request account deletion and data erasure |
| Restriction of processing | Restrict our processing of your data | Contact us with a restriction request |
| Data portability | Receive your data in a structured, machine-readable format | Use the export feature or contact us |
| Objection | Object to certain processing of your data | Contact us with your objection |
| Withdrawal of consent | Withdraw consent-based processing authorizations (e.g. OAuth sign-in) | Contact us, or revoke via your third-party account settings |
To exercise any of these rights, contact us:
- Email: service@webnoteshub.com
- Response time: we will reply within 30 days of receiving your request
Please note that we may need to verify your identity before responding to certain requests.
Your California privacy rights (CCPA/CPRA)
If you are a California resident, you have the following rights regarding your personal information, in addition to the rights listed above:
- Right to know / access: the categories and specific pieces of personal information we collect, and the purposes for which they are used (described in Sections 1 and 2)
- Right to delete: request deletion of your personal information
- Right to correct: request correction of inaccurate personal information
- Right to opt out of "sale" or "sharing": we do not sell or share your personal information as those terms are defined by the CCPA/CPRA (see Section 6), so no opt-out mechanism is needed
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights
To the extent the law treats account credentials as "sensitive personal information", we use them solely to provide the service you requested (authentication and account management), which the CCPA/CPRA permits without limitation. You can exercise the rights above via the contact channels listed in Section 14; we will respond within 30 days (or as otherwise required by law).
If the Personal Information Protection Law of the People's Republic of China (PIPL) applies to our processing of your personal information, we also honor the corresponding rights it grants (access, correction, and deletion) through the same contact channels.
9. Children's Privacy
The Extension is not directed at children under 16. We do not knowingly collect personal information from children under 16. If we discover that we have inadvertently collected such information, we will delete it immediately. The service is also not directed at children under 13, and we do not knowingly collect personal information from children under 13.
10. Security Measures
We take the following technical and organizational measures to protect your personal information:
- Encryption in transit: all data communication is encrypted via HTTPS/TLS
- Password protection: passwords are stored with one-way hashing algorithms such as bcrypt and cannot be reversed
- Payment data isolation: payment card data is processed exclusively by our PCI-DSS-compliant payment processor Waffo Pancake; it never passes through and is never stored on our servers
- Access control: annotation data is isolated per user account; each user can access only their own data (unless actively shared)
- Token security: short-lived JWT access tokens (1 hour) plus long-lived refresh tokens (30 days)
- Share security: share links support password protection and expiry times; share-view pages are rate-limited against brute-force attacks
- Least privilege: the browser extension requests only the permissions needed for its core functionality
If a security incident affects your personal data rights, we will notify you and the relevant supervisory authority within 72 hours of discovery, as required by law. Please keep your account credentials safe and do not share them with anyone.
However, no method of transmission over the internet or electronic storage is 100% secure. We make reasonable efforts to protect your information but cannot guarantee absolute security.
11. Product Update Emails and Unsubscribe
- The only emails we send today are service-essential transactional emails: registration verification codes and password-reset codes. They are triggered by your own actions and therefore contain no unsubscribe link. Payment-related communications are handled through the Waffo Pancake checkout (see Section 5).
- We offer an optional product update email preference: occasional news about new features and improvements. It is off by default; when you opt in (the checkbox at registration or the switch in the extension's account settings), we record the time of your consent and the version of this Privacy Policy then in effect. Product update emails are not currently being sent.
- If and when we begin sending product update emails, they will be sent only to opted-in users, and every such email will include an unsubscribe link. You may withdraw consent at any time in the extension's account settings or via the unsubscribe link in those emails. Withdrawal takes effect immediately for future product update emails and does not affect service-essential transactional emails.
- We send no other marketing emails or pushes, and we do not sell or share your email address for marketing purposes.
12. International Data Transfers
All of our server-side infrastructure is located within Europe (PostgreSQL database on Hetzner Cloud in Germany), and image object storage is in Western Europe (Cloudflare R2). Your data is not transferred outside the European Economic Area (EEA) except in the following situations:
- Email service: we use Resend to send registration verification and password-reset emails (and, if product update emails are introduced in the future, to send them to opted-in users). When you trigger these actions, your email address is submitted to Resend for processing. Email sending for our domain is configured in Resend's EU region (Ireland), so the email addresses used for sending are processed in that region. Please note that Resend is a US company; for how Resend handles data, see its privacy policy (Section 5). Resend is SOC 2 certified, and we have a data processing agreement with them.
- Payment processing: when you start a subscription purchase, your account email address is shared with Waffo Pancake to identify your order. Waffo Pancake's controlling entity, Waffo.com Limited, is located in Hong Kong, outside the European Economic Area; the data shared for this purpose is limited to what is needed to identify your order and is transmitted over encrypted connections. The processing and protection of that data is governed by Waffo Pancake's own privacy policy and security standards, including its cross-border transfer safeguards (see Section 5).
- Operations and support: we (the operator, see Section 14) are based in China. To operate, maintain, and support the service (such as server administration, troubleshooting, and handling support requests), we may remotely access data stored in Europe from China. This access constitutes a transfer of personal data to a country outside the EEA. It is limited to what is necessary for operating and supporting the service and is protected by access controls and encryption in transit.
For transfers outside the EEA described above, we apply appropriate safeguards as required by applicable law, taking into account the nature of the data and the risks involved, including: concluding data-processing agreements with recipients where applicable, transferring only the minimum data necessary for the specific purpose, and encrypting data in transit.
If you use the Extension from outside the EEA, your data will be transferred to Europe and processed there.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:
- Changelog entries accompanying extension updates
- Notices shown in the extension settings page or popup
Material changes will be announced at least 14 days before taking effect, and the "Last updated" date at the top of this page will be updated accordingly. Continued use of the Extension after that date constitutes acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions, comments, or complaints about this Privacy Policy, or wish to exercise any of the data rights listed in Section 8, contact us:
- Privacy contact email: service@webnoteshub.com
- Customer support email: service@webnoteshub.com
- Website: https://www.webnoteshub.com
- Data controller: Sagitnote
- Address: Jinan, Shandong, China
- Data Protection Officer (DPO): Not appointed
You also have the right to lodge a complaint with the data protection supervisory authority of your place of residence.
Additional notes
- This Extension is a general-purpose web annotation tool, not a content scraper or data collection tool. We have deliberately limited the scope of data collection in both design and implementation, collecting and storing only the annotations you actively create plus the minimal context needed to locate them.
- If you have concerns about any particular data collection, you can opt not to use that feature (such as cloud sync, sharing, or paid subscriptions); your annotation data will then remain only on your local device (an account is required to use the basic features of the Extension).
- This Privacy Policy does not apply to the content of third-party websites that you annotate. You are responsible for what you annotate on third-party websites; please comply with those websites' terms of service.
Sagitnote · https://www.webnoteshub.com