Noterra

Privacy Policy

Last updated August 14, 2026

Noterra is a Chrome extension that shows notes, tags, and follow-up reminders for whoever's email thread you have open in Gmail. This page explains exactly what data the extension reads, what it stores, and how you can get it deleted.

What we read from Gmail

The extension's content script runs only on mail.google.com and reads two things directly out of the page you're already viewing:

We never read message bodies, subject lines, attachments, or any other Gmail content. Nothing is read from threads you don't have open.

What we store

For each contact you add a note to, we store:

This is stored in a Postgres database (hosted on Supabase), keyed to your Google account's email address. It is never sold, shared, or used for advertising.

Signing in

Sign-in uses Google OAuth and requests only two non-sensitive scopes: userinfo.email and userinfo.profile — enough to know who you are, nothing more (we cannot read or send email on your behalf). Your Google access token is verified against Google's own servers on every request; a refresh token is stored locally in your browser (not accessible to other extensions or websites) so you don't have to sign in repeatedly. You can revoke access at any time from your Google Account's connected-apps page, or by using "Sign out" in the extension.

Billing

Noterra is a paid extension ($3.99/month after a 7-day free trial). Payment is handled entirely by Polar, our merchant of record — we never see or store your card number. We store only your subscription status and Polar customer/subscription IDs, needed to know whether your account has access.

Data deletion

Signing out clears your session locally but does not delete your notes from our database (so they're there if you sign back in). To request deletion of all your data, email saku6445@colorado.edu from the Google account you used to sign in, and we'll delete it within 7 days.

Contact

Questions about this policy: saku6445@colorado.edu.