In short: Anynotate runs entirely on your computer. The developer collects nothing: no accounts, no analytics, no telemetry, no third-party services. What you annotate goes from the extension to the bridge on your own machine, and from there to the AI agent session you chose.
This policy covers the Anynotate Chrome extension and the Anynotate bridge and command-line tool (together, "Anynotate"). Anynotate is an open-source project maintained by Kun Xu. You can check everything said here in the source code.
What Anynotate processes
Only when you annotate a page and send the notes, Anynotate handles:
- the page's address and title;
- the text you select and the notes you write;
- the HTML of an element you pick;
- the page's text, and a copy of the page's structure (its HTML);
- a screenshot of the visible part of the page, and cropped images of the parts you annotated;
- which agent session the notes are for.
Before a screenshot is taken, Anynotate covers password, one-time-code and payment-card fields (including text fields named for a password, code or card), and it blanks their values in the text and HTML it copies. This covers the page, its same-origin frames, frames from sites you have allowed (a frame that doesn't answer in time is blacked out whole), and card forms embedded from known payment providers (Stripe, Braintree, Adyen, PayPal, Square, Checkout.com, Authorize.net, Klarna, Shopify, Recurly, Chargebee, Paddle, Mollie, Razorpay, Spreedly, VGS, Cybersource). It is best-effort: fields a page doesn't mark, fields inside shadow DOM components and fields in embedded frames from sites you haven't allowed are not covered, so check what's on screen before you send. Anynotate does nothing on a page until you turn it on there.
Where it goes
- The extension sends your notes only to the Anynotate bridge on your own computer, at
127.0.0.1. It makes no other network requests. - The bridge listens only on
127.0.0.1, so other computers cannot reach it. It saves each set of notes as a folder under~/.anynotatein your home folder and hands it to the AI agent session you picked (for example Claude Code or Codex). - Your agent may send what it reads to its own model provider, as it does with anything else you give it. That is between you and the agent you chose; Anynotate does not control it.
The developer never receives any of this data. Anynotate has no server, no account system, no analytics, no telemetry, no crash reporting and no advertising, and it does not use any third-party service. Nothing is sold, shared or transferred to anyone. The only time the bridge contacts the internet is when you run anynotate update, which downloads the latest release from GitHub; it sends none of your notes.
How long it is kept
On your computer (bridge)
Sent notes, with their screenshots, stay under ~/.anynotate. By default each one is deleted 30 days after it was delivered to your agent (or after it was created, if it never was). You control this:
anynotate retentionshows the setting;anynotate retention 7sets 7 days,anynotate retention offturns automatic deletion off;anynotate prunedeletes everything past the retention period now;anynotate uninstall --purgeremoves Anynotate and deletes~/.anynotateentirely.
In your browser (extension)
Notes you have not sent yet, and their cropped images, are kept in the extension's storage in your browser until you send or delete them. Cropped images are capped at 200 MB in total. The extension's options page shows how much is stored and has a Clear all unsent notes button. Removing the extension deletes its storage.
Extension permissions and why
| Permission | Why it is needed |
|---|---|
activeTab | Lets the extension work on the tab you are looking at, only after you click its icon or press its shortcut, and take the screenshot of that tab. |
scripting | Adds the annotation tools to that tab when you turn Anynotate on. |
storage | Keeps your unsent notes and your settings in your browser. |
nativeMessaging | Asks the small helper that anynotate install set up on your computer for the bridge's access token, so you never have to copy it by hand. |
http://127.0.0.1/* | Sends your notes to the bridge on your own computer. The extension has no access to other sites in the background. |
| Optional: one site at a time | Lets you annotate inside frames a page embeds from another site, such as an AI chat artifact or an embedded tool. The panel offers it for a page's frames from another site; Chrome asks you to approve the site only after you press Allow. One approval covers every claude.ai artifact, which each have their own address. Nothing is allowed when you install. Payment providers' frames are never entered. To take a site away, click Remove next to it under Frames from other sites in the extension's options. |
Children
Anynotate is a developer tool and is not directed at children.
Changes
If this policy changes, the new version is published on this page with a new effective date, and the history is visible in the project's GitHub repository.
Contact
Questions about privacy: open an issue on GitHub. To report a security problem privately, follow SECURITY.md.