Privacy

Privacy policy

Effective date: 3 October 2026

In short: Anynotate runs entirely on your computer. The developer collects nothing: no accounts, no analytics, no telemetry, no third-party services. What you annotate goes from the extension to the bridge on your own machine, and from there to the AI agent session you chose.

This policy covers the Anynotate Chrome extension and the Anynotate bridge and command-line tool (together, "Anynotate"). Anynotate is an open-source project maintained by Kun Xu. You can check everything said here in the source code.

What Anynotate processes

Only when you annotate a page and send the notes, Anynotate handles:

  • the page's address and title;
  • the text you select and the notes you write;
  • the HTML of an element you pick;
  • the page's text, and a copy of the page's structure (its HTML);
  • a screenshot of the visible part of the page, and cropped images of the parts you annotated;
  • which agent session the notes are for.

Before a screenshot is taken, Anynotate covers password, one-time-code and payment-card fields (including text fields named for a password, code or card), and it blanks their values in the text and HTML it copies. This covers the page, its same-origin frames, frames from sites you have allowed (a frame that doesn't answer in time is blacked out whole), and card forms embedded from known payment providers (Stripe, Braintree, Adyen, PayPal, Square, Checkout.com, Authorize.net, Klarna, Shopify, Recurly, Chargebee, Paddle, Mollie, Razorpay, Spreedly, VGS, Cybersource). It is best-effort: fields a page doesn't mark, fields inside shadow DOM components and fields in embedded frames from sites you haven't allowed are not covered, so check what's on screen before you send. Anynotate does nothing on a page until you turn it on there.

Where it goes

  • The extension sends your notes only to the Anynotate bridge on your own computer, at 127.0.0.1. It makes no other network requests.
  • The bridge listens only on 127.0.0.1, so other computers cannot reach it. It saves each set of notes as a folder under ~/.anynotate in your home folder and hands it to the AI agent session you picked (for example Claude Code or Codex).
  • Your agent may send what it reads to its own model provider, as it does with anything else you give it. That is between you and the agent you chose; Anynotate does not control it.

The developer never receives any of this data. Anynotate has no server, no account system, no analytics, no telemetry, no crash reporting and no advertising, and it does not use any third-party service. Nothing is sold, shared or transferred to anyone. The only time the bridge contacts the internet is when you run anynotate update, which downloads the latest release from GitHub; it sends none of your notes.

How long it is kept

On your computer (bridge)

Sent notes, with their screenshots, stay under ~/.anynotate. By default each one is deleted 30 days after it was delivered to your agent (or after it was created, if it never was). You control this:

  • anynotate retention shows the setting; anynotate retention 7 sets 7 days, anynotate retention off turns automatic deletion off;
  • anynotate prune deletes everything past the retention period now;
  • anynotate uninstall --purge removes Anynotate and deletes ~/.anynotate entirely.

In your browser (extension)

Notes you have not sent yet, and their cropped images, are kept in the extension's storage in your browser until you send or delete them. Cropped images are capped at 200 MB in total. The extension's options page shows how much is stored and has a Clear all unsent notes button. Removing the extension deletes its storage.

Extension permissions and why

PermissionWhy it is needed
activeTabLets the extension work on the tab you are looking at, only after you click its icon or press its shortcut, and take the screenshot of that tab.
scriptingAdds the annotation tools to that tab when you turn Anynotate on.
storageKeeps your unsent notes and your settings in your browser.
nativeMessagingAsks the small helper that anynotate install set up on your computer for the bridge's access token, so you never have to copy it by hand.
http://127.0.0.1/*Sends your notes to the bridge on your own computer. The extension has no access to other sites in the background.
Optional: one site at a timeLets you annotate inside frames a page embeds from another site, such as an AI chat artifact or an embedded tool. The panel offers it for a page's frames from another site; Chrome asks you to approve the site only after you press Allow. One approval covers every claude.ai artifact, which each have their own address. Nothing is allowed when you install. Payment providers' frames are never entered. To take a site away, click Remove next to it under Frames from other sites in the extension's options.

Children

Anynotate is a developer tool and is not directed at children.

Changes

If this policy changes, the new version is published on this page with a new effective date, and the history is visible in the project's GitHub repository.

Contact

Questions about privacy: open an issue on GitHub. To report a security problem privately, follow SECURITY.md.