Data and security
Where your data lives, who can see it, and how to make it go away.
Last updated September 19, 2026. Written by the person who runs Fixnote, not a lawyer. The privacy policy is the formal version; this page is the plain one.
What Fixnote actually collects
Nothing until you send a report. Your notes and screenshots are stored inside your own browser (Chrome’s extension storage on your computer) while you work. You can take notes without an account. Removing the extension deletes all of it instantly.
When you create an account: your email address, your name if you sign in with Google, and which plan you are on. There are no passwords: sign-in is a Google login or a one-time link sent to your email.
When you send a report on the Free plan: only the title, project name, version number and note count, so your monthly count works. The Word file itself downloads to your computer and is not uploaded.
When you send a report on Pro: the same, plus the report file (Word, or Markdown with its screenshots) so you can download it again from any computer. That is what “report history” is.
Screenshots only ever contain the box you dragged or the element you pointed at, taken from the tab you were looking at. Fixnote never captures in the background and never captures a page you did not act on.
Usage: four events, and only four: someone reached the landing page, an account was created, the extension was detected, a first report was sent. Nothing about which pages you mark up. No advertising cookies, no third-party trackers.
Where it lives
- Database and report files: Supabase, in Amazon’s us-east-1 region (Virginia, USA). Report files sit in a private bucket that is not reachable by URL without your login.
- Website: Vercel.
- Payments: Polar, which is the merchant of record. Your card number never touches Fixnote; we get your email, what you bought and a customer id, nothing else.
- Sign-in with Google: Google tells us your email and name. Fixnote gets no access to your Google account, Drive or mail.
Who can see it
You. Each account can read only its own rows; that rule is enforced by the database itself (row-level security), not just by the website.
Mat, who runs Fixnote, has administrator access to the database and will use it only to fix a problem you have reported or to keep the service running. He does not open people’s reports out of curiosity, and nothing you create is used to train anything.
The companies above host the data on our behalf and are bound by their own terms. No one else. We do not sell, share or rent anything.
How long it stays
- Notes in your browser: until you send the report, clear it, or remove the extension.
- Account and report history: for as long as you keep the account.
- After deletion: gone from our database and storage immediately. Our hosting providers’ routine backups age out on their own schedule, at most 30 days later.
- Payment records: Polar keeps invoices for as long as tax law requires them to. That is theirs, not ours.
How to get it deleted
Email hello@fixnote.app from the address on the account and say “delete my account”. Everything, including report history, is deleted within 7 days and you get a reply confirming it. If you only want one report gone, say which one. There is no self-serve delete button yet; the email is the button.
How it is protected
- Everything travels over HTTPS.
- The extension talks only to fixnote.app and our Supabase project. Its broad permission to run on any page exists because it has to draw on any page; it sends nothing until you press Send.
- The database refuses any request that is not for the caller’s own rows.
- If something goes wrong on our side, affected accounts hear about it by email, plainly, as soon as we know.
Who to email
hello@fixnote.app. It reaches a person, and the person answers.