Privacy Policy
Last updated: October 7, 2026
This policy covers Annotated’s website and its Chrome extension, a side panel for annotating what you read, watch or hear. We don’t sell personal data, share it with data brokers or use it for ads. There’s no analytics SDK in either, and we don’t train models on what you annotate.
Our server counts sign-ups, posts, replies, views of a post’s page and presses on Add to Chrome, with the page or site a visit came from. No account, IP address or browser is stored with them, though a post’s or reply’s count names the post it belongs to.
Your account
You sign in with Google or X. From Google we get your name, email address and profile picture; from X, your name, username and profile picture, but no email. We also keep the sign-in tokens Google and X issue, and don’t use them after you sign in. Your name, picture and handle (your X username, or one made from your name) are public; context notes show an alias instead.
Your profile is public: a photo, cover photo and short bio you add, and the username of an X account you link if you choose to show it, appear on your profile and beside your posts. You can change or remove them at any time. Pictures you upload are stored with embedded details such as the camera and location removed, and one you replace or remove is deleted from our storage.
The extension keeps your session token and profile in chrome.storage.local until you sign out of it. The website’s session cookie lasts seven days and renews as you use the site; signing out of the panel doesn’t end it, so sign out on the website too. A reply you’ve typed on the website but not posted is kept, with the label you picked for it, in that browser until you post it or sign out. Our server records each session’s IP address and browser user agent, for security, until that session is signed out or your account is deleted.
What the extension reads
While the side panel is open, it reads the address and title of the tab in front, and of any YouTube players on it, so it can offer to annotate them. These stay in your browser unless you start annotating that page.
To show whether a page has context notes, the open panel sends us a 16-character SHA-256 hash of the page’s address, never the address itself, whether or not you’re signed in. The hash can’t be reversed, but anyone who guesses the address can confirm it, so it isn’t anonymous. We don’t keep it or build a profile of your browsing.
When you highlight text with the panel open, or annotate a page another way, the extension reads your selection and the page’s text, title, author, site name, date, description and picture, and keeps them in memory until you publish or discard them. It also sends us the page’s address and your passage, to show annotations already on that page. On X, “Use this post” adds a picture of the post, with its author’s name and a link, to your annotation; the picture stays even if the post is deleted.
A small script on each page tells the open side panel what you select, and does nothing else. The extension asks for access to all sites because you can annotate from any of them.
What you create
We store what you create (annotations, clips, comments and the label you put on a reply, notes, ratings, follows, votes, the posts you save, the topics you pick, and any questions you typed into the retired Ask search) with the source’s address and attribution. Anything you publish is public, even to people without an account. What you save is listed only to you; a post shows how many people saved it, never who. A post’s page also lists the people its author most often exchanges replies with, counted from public replies only. Your follows, votes and topics order your For You feed, and we keep daily counts of some features you use.
Context notes are also published as a public dataset of notes, ratings and status history, under pseudonyms. A note author’s pseudonym can be matched to the alias shown on the note. Ratings are scored to decide which notes are shown; your scores aren’t public. The ratings file is empty for now; ratings may be published later, and we’ll update this policy first. Copies downloaded earlier list each rating with its time, what it rated and the rater’s stable pseudonym, and can’t be recalled.
The microphone and camera are used only during a recording you start. A file you upload is converted on your computer to at most 90 seconds, without its embedded details, and only that copy is uploaded, when you post.
Services we use
Annotated runs on Railway, with a Postgres database and S3-compatible storage for clips and recordings.
- Transcription: a speech-to-text provider transcribes audio and video clips, recorded comments, and voice and video replies. No other model processes your data, and apart from transcripts Annotated generates nothing with a model.
- Podcasts: when you annotate an episode, our server finds its audio where it’s published and fetches the show’s own transcript, if it has one, to show while you trim, without saving it. Preview plays your part from the show’s audio host, which receives a request from your browser, and pauses audio in the tab in front.
- Email: Resend delivers claim notifications.
- Pictures: your browser loads a source’s picture and icon from that site (an X post’s picture from our storage), and profile photos from Google or X. No third-party image service is involved.
YouTube
When the panel shows a YouTube video (on a YouTube page it can do so by itself), it loads YouTube’s player from www.youtube.com, so YouTube receives a request from your browser, under its own privacy policy, before you press play. A YouTube clip plays in that player unless you choose a 240p recording: we store the video’s address and the seconds you chose, not a copy. Its poster loads from i.ytimg.com.
While you trim, the panel fetches the video’s captions from www.youtube.com without your YouTube cookies. For a clip that plays in YouTube’s player, we save the captions for your part as its transcript; otherwise they stay in the panel. It also shows the video’s frames along the trimmer: the preview pictures YouTube’s player shows over its seek bar, loaded from i.ytimg.com. They are not sent to us or saved.
The film on /demo loads YouTube’s privacy-enhanced player from www.youtube-nocookie.com only when you press play; it then contacts YouTube and Google and stores some data in your browser.
A copy installed from the download that /install used to offer (Annotated is now installed only from the Chrome Web Store) can also post a clip as a 240p recording, if you choose that at Publish. Once you start annotating a YouTube video there (even just playing or tagging it), or it shows you a failed one, the panel loads the video’s public page with your YouTube cookies (YouTube may set its usual cookies in return) to check that it’s public and not age-restricted or members-only, and looks through your open tabs’ addresses, which stay in your browser, for one playing it.
To record, the panel plays your part in YouTube’s privacy-enhanced player, which doesn’t play as your YouTube account but keeps a few settings in your browser and loads a Google script that receives your Google cookies. If that player can’t play the video, the panel says so and records from your YouTube tab instead, which plays as your account, with a notice and a Stop on the tab; with no such tab, it asks first, then opens one and closes it afterwards. We upload the recording, cut it to 240p and delete the original.
Sample accounts
We used AI agents to develop Annotated, testing and verifying each build, and the posts you see from sample accounts are samples of their output. To show Annotated in use, we seeded the feed with those sample accounts: fictional people, names and bios, run by us and not by anyone named in them. Their profile and cover photos are AI-generated. Their posts and replies were written with AI from real, published sources, with real quotes, and their voice and video comments are AI-generated. They also vote. The film on the demo page shows the side panel on made-up news and video pages, with AI-generated narration, music and sound effects, and the people in it have AI-generated profile and cover photos. The podcast episode you can annotate on the demo page is an AI-generated voice reading an AI-written script, and the voice note and video offered in its panel are AI-generated too. All of it was made with AI tools outside the product. The demo page’s silent video is drawn by our own code, not by AI.
Posts and replies aren’t marked, but a sample account’s profile, and the card that opens when you hover over its name, say “Sample Account”.
The web feed may leave sample posts out of Annotated and its topics. They stay readable on their profiles and their own pages, in Following and in the side panel’s feed. Where the web feed can show them, a line under its bar says so.
Rights claims
Anyone can file a claim on a public annotation page. We keep what you enter (your name, email and statement) to review it and reply, and as a record of the decision. The annotation’s author sees your statement, not your name or email.
Deletion and your data
Make private, in the side panel’s My Annotations, takes an annotation off the feed and its public page and keeps it in your list as a draft. Delete, on your post’s page or in the side panel (My Annotations, or the post itself), removes it for good, with its replies and the media only it used. A post with a rights claim on file can’t be deleted that way: email privacy@annotated.info. To delete your account and everything attached to it, email privacy@annotated.info from your account’s email address or with the handle you sign in with. You can also ask us there for a copy of your data or to correct it. Signing out ends that session but doesn’t delete your account or anything you’ve posted.
Contact
Questions about this policy or your data: privacy@annotated.info. If the policy changes, we’ll update this page and its date.