Privacy Policy for Marginalia
Last Updated: October 25, 2025
Overview
Marginalia ("we", "our", or "the extension") is a browser extension that provides context-aware note-taking with cloud synchronization. This privacy policy explains how we collect, use, and protect your information.
Information We Collect
Account Information
- Email address: Used for account creation, authentication, and password recovery
- User ID: A unique identifier generated by our authentication system
Note Content
- Your notes: All text content you create within the extension
- Timestamps: Creation and modification dates for your notes
- Context metadata: The URL scope (domain, subdomain, path) where notes are associated
Browsing Context
- Current tab URL: Used only to determine the appropriate note context (browser-wide, domain, subdomain, or page-specific)
- This information is processed locally and not stored on our servers
How We Use Your Information
We use the collected information solely to:
- Authenticate your account and maintain your session
- Store and sync your notes across your devices
- Organize notes by URL context for retrieval
- Provide password reset functionality via email
Data Storage and Security
Cloud Infrastructure
- Your data is stored using Google Firebase (Firestore Database and Firebase Authentication)
- All data transmission occurs over encrypted HTTPS connections
- Your notes are associated with your unique user ID and isolated from other users
Access Control
- Only you can access your notes through authentication
- We implement industry-standard security practices to protect your data
- Firebase security rules ensure users can only read/write their own data
Third-Party Services
Firebase (Google)
We use Firebase for:
- User authentication
- Cloud database storage
- Real-time synchronization
Firebase operates under Google's privacy policy. For more information, visit: https://firebase.google.com/support/privacy
No Other Third Parties
- We do not sell, trade, or share your data with any other third parties
- We do not use your data for advertising or marketing purposes
- We do not analyze your note content for any purpose other than displaying it to you
Your Rights
You have the right to:
- Access your data: All your notes are visible within the extension
- Delete your data: You can delete individual notes or all notes at any time
- Export your data: Contact us to request a complete export of your data
- Delete your account: Contact us to request account deletion and complete data removal
Data Retention
- Active accounts: Your data is retained as long as your account remains active
- Account deletion: Upon request, we will delete your account and all associated data within 30 days
- Inactive accounts: Accounts inactive for more than 2 years may be deleted with 60 days notice to the email on file
Offline Functionality
- The extension caches your notes locally for offline access
- Local data is stored using Chrome's extension storage API
- Local data is automatically synced to the cloud when you reconnect
Changes to Browsing Data
Marginalia accesses your current tab's URL to determine note context, but:
- We do not track your browsing history
- We do not store URLs on our servers
- We do not monitor which sites you visit
- URL information is used only for local organization of notes
Children's Privacy
Marginalia is not intended for use by children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with information, please contact us immediately.
Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes by:
- Updating the "Last Updated" date at the top of this policy
- Posting a notice in the extension (for material changes)
Contact Us
If you have questions about this privacy policy or wish to exercise your data rights, please contact us at:
Email: developer@marginalia-extension.com
We will respond to all requests within 30 days.
Legal Basis for Processing (GDPR)
For users in the European Economic Area, our legal basis for processing your data is:
- Contractual necessity: To provide the note-taking and sync service you've requested
- Legitimate interest: To maintain and improve the extension's functionality
- Consent: By using the extension, you consent to this privacy policy
Your California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect
- Request deletion of your personal information
- Opt-out of any sale of personal information (note: we do not sell personal information)
To exercise these rights, contact us at developer@marginalia-extension.com.
Marginalia is committed to protecting your privacy and being transparent about our data practices. This extension exists to serve you, and your notes remain private and under your control.