Last updated: September 27, 2026
Notestopin ("we", "our", or "us") is a local-first note tool for Pinterest. This Privacy Policy covers the Notestopin browser extension, mobile apps and capture pages, website, account, and synchronization service (together, the "Service"). You can use Notestopin without an account, and creating or signing in to an account does not upload your existing local note library. New notes are saved to your account only while Sync is enabled; otherwise they remain local. Existing local and account notes remain separate unless Sync is enabled and you explicitly confirm a merge or choose Cloud notes as an import destination.
Local data: The browser extension stores local notes, tags, Pin metadata, preferences, and account state with the Chrome Storage API. Mobile apps use private app storage. Existing local notes stay on the device when you sign in or out and are not uploaded merely because an account is present. Data can also leave your device when you explicitly export or share it, create a new note while Sync is enabled, confirm a merge into your account, or choose Cloud notes as an import destination.
Account data: When you create or sign in to an account, we process your email address, device label, platform, and activity timestamps. This alone does not upload existing local notes. New notes you create while Sync is enabled, local notes you explicitly merge after enabling Sync, and notes from a file you explicitly import into Cloud notes can include note text, tags, Pin identifiers and URLs, Pin titles, image or video URLs and media type, creation and update times, deletion records, previous note versions, language, theme, view and sidebar choices, and linked-note layout positions. Account notes are stored on our server and are not end-to-end encrypted.
Account notes on a device: Account notes are fetched for display while you are signed in and are not written to the device's note library. Signing out hides the account workspace without deleting its server copy or any local notes.
Sign-in and security data: Passwordless sign-in uses your email address. We temporarily process sign-in status and timestamps, a device label, platform, requested IP address, and hashed sign-in-code, polling, and device-token values. Sign-in codes expire after five minutes. We use this information to deliver access, prevent guessing and email abuse, and let you review signed-in devices.
Subscription data: Cloud features require an active paid plan, sold and processed by Paddle as merchant of record. We do not receive or store your full payment-card, bank-account, or payment-service credentials.
The free Cloud promotion ended on September 26, 2026. It did not create a paid subscription or an automatic charge.
We receive and retain Paddle customer, transaction, and subscription identifiers; the selected monthly or yearly price; subscription status; billing, failure, and cancellation timestamps; and limited operational payment events so we can grant cloud access, prevent fraud, provide support, and apply the retention period described below.
Paddle independently processes checkout details, payment methods, billing address, tax information, fraud signals, receipts, refunds, and payment recovery under its own privacy notice.
Product activity: The browser extension and Android app send a limited set of product events directly to Notestopin Cloud at cloud.notestopin.com. Extension events can include install, update, note-created, import, review-button, and aggregate note-count events. Android events are limited to the local-note safety prompt being shown or answered and can include the app version, prompt variant and trigger, reminder stage, aggregate local note count, answer, and method. Events can also include the platform, event time, and the area of the interface where an action occurred.
A random installation identifier distinguishes one browser or app installation from another. While you are signed out, its events remain installation-level. While you are signed in, new events may also be associated with your Notestopin account so we can understand account activation, reliability, and feature use across devices.
When an event reaches Notestopin Cloud, the server uses the request IP address in memory to derive an approximate country and continent for aggregate audience reporting, then discards the address instead of writing it to the product-analytics tables. Product activity does not retain city, region, postal code, coordinates, or precise location. Country results can be inaccurate, especially when a VPN, relay, mobile network, or corporate network is used.
We do not include note text, tag names, search terms, Pin URLs, Pin titles, Pin media, your Pinterest account, or your email address inside event properties. The uninstall page may send the same installation identifier, extension version, and aggregate note counts. We use this activity to operate, troubleshoot, secure, and improve the product; we do not use it for personalized advertising.
Website analytics: Pages on notestopin.com may use Google Tag Manager and Google Analytics to measure visits and site performance. This can process page and interaction data, approximate location, browser and device information, and first-party identifiers such as the _ga cookie. We do not send note content or account email to Google Analytics. You can block or delete these cookies using your browser controls. The Privacy Policy and Terms pages do not load our analytics tags.
Feedback and support: If you submit the feedback form, Web3Forms processes the name, email, and message you provide. If you email us, our email provider processes your address, message, and related delivery data. We use this information to respond, provide support, and maintain appropriate support records.
We do not sell personal information or note content, use it for personalized advertising, or use it to determine creditworthiness or eligibility for lending.
We use providers only for the functions described here:
We may also disclose information when required by law, to protect users or the Service, or as part of a merger, acquisition, financing, or sale of assets subject to appropriate notice and safeguards. We do not give providers permission to use note content for their own advertising.
Notestopin reads the Pinterest pages and Pin information needed to attach, display, search, and resolve the notes you request. We do not receive your Pinterest password or operate your Pinterest account. Pin information is not included in the product activity events described above. It remains local unless you create the note while Sync is enabled, explicitly merge it after enabling Sync, or import it into Cloud notes. The Pin identifiers, links, titles, and media URLs attached to those account records become part of your account copy.
When you share, open, or display a Pinterest Pin in Notestopin, the app can connect directly to Pinterest and its image or video hosts to resolve the Pin link and load the requested title or media. Those requests can reveal the requested Pin URL or identifier, the app's browser-style user agent, IP address, and ordinary network metadata to Pinterest, which processes the request under its own terms. Notestopin does not add your note text, tags, Notestopin account email, or product-analytics installation identifier to those Pinterest requests.
Android, iOS, or browser share features pass only the content you choose to share with Notestopin. Account notes, explicitly merged notes, and files explicitly imported into Cloud notes are sent to our service at cloud.notestopin.com and remain governed by this policy.
We use HTTPS encryption in transit, restricted server access, hashed access tokens, rate limits, firewalls, security updates, and protected backups. No system is completely secure. Synchronized notes are not end-to-end encrypted or encrypted with a key that only you control, so authorized server administrators can technically access them.
We restrict human access to user data to providing support you request, investigating security or abuse, maintaining the Service, complying with law, or working with aggregated or de-identified information as permitted by the Chrome Web Store User Data Policy. Do not use Notestopin to store passwords, authentication secrets, payment-card details, health records, or other information requiring a specialized regulated system.
Our restricted operational console can show authorized administrators an account email, account and device timestamps, authentication and billing status, retention state, and aggregate record counts needed to operate and secure the Service. The console is designed not to return note bodies, tag values, Pin URLs, Pin titles, or media addresses. Access to its overview, user list, and individual account dashboards is limited to explicitly allowlisted administrator accounts and recorded in an audit log.
Active account information remains while the account exists. While a paid Cloud plan is active, account content—including note version history and deletion records—also remains so multi-device access and recovery work. Signing out does not end Cloud access or delete the server copy. A deleted note can remain in version history while Cloud access is active.
When Paddle reports that a subscription is past due, cancelled, expired, or otherwise no longer active after its payment-recovery process, Cloud access and Sync are disabled. Cloud note content and its version history are then retained for 30 days so you can restore access by subscribing.
If there is still no active plan when the deadline arrives, we permanently delete that cloud note content and history from the live database. Restricted disaster-recovery backups rotate on a 14-day schedule, so an inaccessible residual backup copy can remain for up to 14 additional days and is not restored except for disaster recovery.
We retain the account identifier and limited subscription and transaction records longer when reasonably needed for security, accounting, disputes, support, and legal obligations. Local notes and exports are unaffected.
Raw product activity events, including their approximate country and continent, are retained for up to 400 days and are then deleted automatically. An installation-level operational summary, such as first and last activity time, version, event count, aggregate note counts, and most recently derived country and continent, remains while that installation is active and is deleted after 400 days without retained activity. Expired sign-in attempts and related security data are routinely removed when no longer needed for abuse prevention. Feedback and support records are kept only as long as reasonably needed for the conversation, security, and legal obligations.
When we complete an account-deletion request, we remove the active account and synchronized records. Residual copies may remain temporarily in restricted backups until their ordinary rotation; they are not returned to the active system except for disaster recovery. Local notes and exports on your devices are controlled by you and are not removed by deleting the server account.
We request the minimum permissions necessary for the extension to function:
storage: To save your notes locally.unlimitedStorage: To support large local note libraries and their safety snapshot.alarms: To schedule background maintenance, analytics delivery, and account refresh work.host_permissions (Pinterest): To inject the note editor into Pinterest pages.host_permissions (Web3Forms): To send feedback only when you submit the feedback form.host_permissions (Notestopin Cloud): To send the limited product activity described above. These events do not contain note content or Pin information.host_permissions (Notestopin account): To create or access an account and read or write new notes you create while Sync is enabled, local notes you explicitly merge after enabling Sync, and files you explicitly import into Cloud notes.Notestopin's use and transfer of information received from Chrome extension APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Our primary synchronization infrastructure is hosted in Europe. Some providers may process information in other countries under their own data-protection terms and lawful transfer safeguards.
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. A parent or guardian who believes a child provided information may contact us to request deletion.
We may update this Privacy Policy from time to time. If we make significant changes, we will notify users through the extension or this website.
If you have any questions about this Privacy Policy, please contact us at: support@notestopin.com