How SeeNote works
SeeNote asks you to install a browser extension and read securities filings through it. That deserves more than a promise, so this page shows the actual permissions, the actual click path, and how to check both yourself.
What permissions does SeeNote ask for?
These are the permission declarations from the extension's manifest.json, reproduced in full; only the line wrapping differs:
"content_scripts": [
{
"matches": [
"https://www.sec.gov/Archives/edgar/data/*",
"https://www.sec.gov/ix*",
"https://www.sec.gov/ixviewer*"
],
"all_frames": true,
"js": ["content-script.js"],
"run_at": "document_idle"
},
{
"matches": ["https://maya.tase.co.il/*"],
"js": ["maya-content.js"],
"run_at": "document_idle"
},
{
"matches": [
"https://mayafiles.tase.co.il/ixbrl/*",
"https://mayafiles.tase.co.il/translated_ixbrl/*"
],
"js": ["ixbrl-content.js"],
"run_at": "document_idle"
},
{
"matches": ["https://data.fca.org.uk/*"],
"js": ["nsm-content.js"],
"run_at": "document_idle"
}
],
"permissions": [
"storage",
"alarms",
"contextMenus",
"activeTab"
],
"host_permissions": [
"https://www.sec.gov/*",
"https://maya.tase.co.il/*",
"https://mayafiles.tase.co.il/*",
"https://data.fca.org.uk/*"
],
"optional_host_permissions": [
"http://*/*",
"https://*/*"
]
What each line means:
content_scripts.matches. The filing-reading code injects into four filing surfaces and nothing else: SEC filing pages and the inline XBRL viewer on sec.gov; the Tel Aviv Stock Exchange's Maya site; the two paths onmayafiles.tase.co.ilwhere Maya publishes filings rendered as iXBRL; and the FCA data site that serves the National Storage Mechanism. It runs on no other website: not onwww.tase.co.il, not onwww.fca.org.uk, not on the rest ofmayafiles.tase.co.il.storage. Keeps what SeeNote remembers on your own device: for example your settings, your marks, the resolution counters, the trial’s state and a license key once you activate it. If you use Chrome sync, Chrome also carries the trial’s start time, the version of its rules and its list of counted filings (short hashes of their public identifiers, or placeholders that stand for a count, never names) to your other computers, but never your install identifier or a license key. Version 1.1.0, the version on the Chrome Web Store until its next update reaches you, also keeps its review prompt’s state there; the privacy policy says what, and what else is different in 1.1.0.alarms. A once-a-day timer for SeeNote’s upkeep: it re-checks your license key if you hold one, including one set aside as not valid; reads your trial count back from our server if you hold no key, or only one set aside; tells our server if your trial count or state has changed; asks whether the founding price is still open; and sends the usage counts only if you turned them on. Each of those requests is listed below.contextMenus. Adds the "Open in SeeNote Reader" entry to the right-click menu for PDF links.activeTab. Lets the toolbar button read the current tab's URL, so a PDF you already have open can move into the Reader.host_permissions. Install-time access is the four filing sites and nothing else: sec.gov, the two Maya hosts, and the FCA data host. It exists so the Reader can fetch the PDF(s) of the one report you explicitly ask it to open. Usually that is one file. On Maya it is the report’s attachments, because a Tel Aviv periodic report is one submission split across several PDFs, and a reference in the directors’ chapter routinely points into the financial statements, so the Reader has to hold all of them; the fetch is capped at 20 and every one comes from the filing’s own host.mayafiles.tase.co.ilis granted host-wide here, unlike the two paths the filing-reading code injects into, because the attachments live at other paths on that host: fetching and injecting are different permissions, and this page shows both. It is never used to read pages in the background.optional_host_permissions. Any other site is asked for one origin at a time, at the moment you open a PDF from it in the Reader (the right-click entry or the toolbar popup), and only that origin. Chrome’s prompt names the one site; nothing is asked for at install, and a site you never open a PDF from is never asked about. Decline it and the Reader says so and offers drag-and-drop instead, which needs no site access at all.
Where does SeeNote work?
SeeNote reads three markets, and each one has its own way in.
- SEC EDGAR. Open a 10-K, 10-Q, 20-F or 40-F on sec.gov, in the classic HTML view or in the inline XBRL viewer. References become clickable on the page itself; there is nothing to press first. Current reports like 8-K and 6-K rarely carry note cross-references, so there is usually nothing to do in one.
- Tel Aviv Stock Exchange. On a Maya report page an "Open in SeeNote" button appears beside each filing document, and opens that report in the Reader: the clicked attachment together with the report’s others, because a Tel Aviv periodic report is one submission split across several PDFs and a reference in one chapter routinely points into another. Filings Maya has already rendered as iXBRL are read in place, the same way EDGAR pages are.
- United Kingdom. On the FCA's National Storage Mechanism the same button appears beside each document in the search results, and one button opens exactly one document. That is deliberate, and unlike Maya: an NSM results page is a search result whose consecutive rows are routinely different companies and different years under the identical heading "Annual Financial Report", so assembling a session from it could let a reference resolve into the wrong filer. A UK annual report is a designed document rather than a filled-in filing template, so its note headings vary far more than EDGAR's; where SeeNote cannot work out which note a reference means, it says so rather than guess.
- Any filing PDF. The Reader opens a PDF you point it at from the toolbar button, a right-click on a PDF link, or drag-and-drop, whatever site it came from. Text-layer PDFs only: a scanned one is detected and reported, never guessed at.
SeeNote does not read Companies House statutory accounts. Companies House re-renders those filings as page images with no text layer, so there is nothing on the page for SeeNote to find, and it does not pretend otherwise.
What happens when you click a reference?
You open a 10-K on sec.gov. The page is already fully downloaded by your browser; SeeNote waits until the document is idle, then parses it in place: it finds the notes to the financial statements, works out where each note begins and ends, and wraps every cross-reference like "see Note 12" in a clickable element. A Maya filing or a UK annual report open in the Reader takes the same path, run over a PDF's own text layer instead of a web page's DOM.
When you click one, SeeNote resolves the reference against the index it built and clones the note's content, the exact nodes already sitting in the page, into a popup next to the reference. The note itself is never fetched. The popup is not a fetched copy, an excerpt, or a rendering of our version of the note; it is the filing's own DOM, duplicated in place. In the Reader, where the document is a PDF, the popup is the printed page's own pixels instead: the exact region of the page, cropped, never re-typeset. Close it and you are exactly where you left off.
Because everything operates on the page you already loaded, popups open instantly and keep working with your network disconnected.
The toolbar icon's popup holds the two things that are not on a filing page: a button that opens the SeeNote Reader, and a link to My marks.
You don't need a reference to reach a note. Press S (or click the on-page button) to open the notes index: a keyboard-navigable list of every note in the filing, in document order. Choose one and it opens in the same popup, cloned from the page in place rather than fetched, and still verbatim.
Can you mark up a filing?
Reading is not only following references, so SeeNote also lets you keep what you found. Select a passage on an EDGAR page or a Tel Aviv iXBRL filing, or drag across a line in the Reader (a double-click takes one word, and a drag that crosses a page boundary marks each page it touches), and pick one of four colours; attach a note of your own if you want one. The mark is anchored to the filing's own text rather than to a pixel position, so it comes back where you left it the next time you open the document. Every mark collects in the sidebar's Highlights tab, where you can filter them, jump back to the page, or tick the ones you want and copy them out as a memo: a header naming the filer, form and period, then each quote with your note beneath it and a link back to the passage (a text-fragment link on an HTML page, a page link in the Reader). The memo is put on the clipboard in two flavours at once, so it pastes formatted into Word, Docs or Outlook and as plain text into Slack or a spreadsheet cell. Print the filing and your marks print with it, and none of SeeNote's own furniture does. My marks, reached from the toolbar popup, the sidebar's Highlights footer or the settings page, lists every filing you have marked, newest first, searchable across titles, quotes and notes; each entry reopens its filing on that passage, and a filing can be removed from the list, with a moment to undo. Marks are free on every filing, before and after the trial, and what they store (the quote, your note, the filing's title and address, and when you last changed it) is written to Chrome's local storage on that device and goes nowhere else.
What stays on your computer?
The privacy policy states this as policy; here it is as architecture:
- The filing never reaches our server. SeeNote never transmits filing text or page content, to us or to anyone else, under any setting. It does not send us which filings you opened either: the trial keeps a short hash of each counted filing’s public identifier, never its name, on your device and, if you use Chrome sync, in your own Google account. There is no account and nothing to log into.
- Statistics stay local unless you share them. The extension counts how many references it resolved or missed, and stores those counters in Chrome's local storage on your device. They leave it only if you turn on the setting below.
- Usage counts are off by default. One optional setting, disabled until you enable it, sends aggregate counters at most once a day, for example "42 references resolved on EDGAR web pages". No URLs, no tickers, no filing text, no personal data. Leave it off and no count of references resolved or missed ever leaves your device.
- PDFs are read, not uploaded. A PDF you open in the Reader is fetched by your browser and parsed locally. Which PDF you opened is never sent to us.
- Your marks stay put. Highlights and the notes you write on them are stored unencrypted in Chrome's local storage on the device you made them on. They are never synced to another computer, never transmitted, and they are removed with the extension; before that, a mark can be deleted from the sidebar and every mark at once from the settings page.
What does SeeNote send?
That is what stays. This is the other half: every request the extension makes to our server, api.seenote.co, with every field it carries. None of them is about the filing. The privacy policy has the same list, with what the server keeps from each.
POST /trial/startwithinstall_id,versionandruleset_version: at most once per install identifier, the first time a note opens in a filing that counts toward your trial.PUT /trial/syncwithinstall_id,trial_filings_usedandstate: when a new filing is counted, and when your trial or license state changes.GET /trial/statuswithinstall_id: once a day, while you hold no license key, or only one set aside as not valid.POST /license/validatewithlicense_key: when you activate a key, once a day while you hold one, when you press "Check again" in the settings, and once more just before a note would be refused to a reader who holds a key. Our server asks the payment processor and passes back yes or no.GET /founding/remaining, with nothing attached: when Chrome starts with SeeNote installed, when SeeNote is installed or updated, and once a day.POST /telemetrywithevents[].event,events[].market,events[].format,events[].outcome,events[].filingTypeandevents[].count: at most once a day, and only if you turned usage counts on.POST /subscribewithemailandintent: only if you type your address into the welcome screen's optional field and press Send.
Who built SeeNote?
SeeNote is built by Nir Dukas, a solo founder in Israel who read too many filings the hard way. That is the whole team. His name is on this page, under the quote on the homepage, in the byline of each guide, and in the structured data that tells search engines who founded SeeNote and wrote its guides. There is no biography, because SeeNote's privacy principle runs in both directions: the extension knows nothing about you, and this site tells you who made it and very little else. Everything else you might want to check, from the permissions and the code to the network tab, is below, and is worth more than a biography would be.
How can you check all this yourself?
- Check the permissions. After installing, open
chrome://extensions, find SeeNote, and click Details. The permission list Chrome shows you is the one above; Chrome enforces it regardless of what any website says. - Read the code. Enable Developer mode on
chrome://extensionsand every installed extension's files are plain JavaScript on your disk, open to inspection. - Watch the network. None of SeeNote’s requests to our server comes from the page you are reading, so that page’s own DevTools never show them. All but one come from its background service worker: on
chrome://extensions, with Developer mode on, find SeeNote and click service worker next to “Inspect views”, choose the Network tab in the window that opens, and read a filing. Everything the service worker sends goes toapi.seenote.coand is one of the requests listed above. The one it does not send is the email address you can give on the welcome screen, which that screen sends itself. (A PDF you open in the Reader is fetched by the Reader’s own tab, from the site it lives on, and shows in that tab’s DevTools.)
If you find behavior that contradicts anything on this page, tell us at hello@seenote.co. That report outranks every other inbox we have.
Questions
Does SeeNote send the filing anywhere?
No. SeeNote never transmits filing text or page content, to us or to anyone else, under any setting, and it does not send us which filings you opened. When you click a reference it clones nodes already in the page, so the note itself is never fetched. What it does send our server is about your trial and your subscription, never about the filing: for example the trial's count when a new filing is counted, and a daily check of your trial count or your license key. A check of whether the founding price is still open carries nothing at all, and anonymous usage counts and your email address are sent only if you choose to send them. Every request is listed on this page, field by field.
Which sites can SeeNote read?
Four filing sites at install and nothing else: sec.gov, the Tel Aviv Stock Exchange's Maya site, Maya's file host mayafiles.tase.co.il, and the FCA data site that serves the National Storage Mechanism. When you open a Maya report, the Reader fetches its PDFs from anywhere on mayafiles.tase.co.il, because a report's attachments live at several paths there; the filing-reading code runs only on the two paths where Maya publishes filings as iXBRL. Any other site is asked for one origin at a time.
How do I verify SeeNote's permissions myself?
Open chrome://extensions, find SeeNote and click Details: the list Chrome shows you is the one on this page, and Chrome enforces it regardless of what any website claims. Enable Developer mode to read the extension's files on your disk. To watch what it sends, click service worker next to Inspect views on SeeNote's card and open the Network tab in the window that appears: every request to our server is made there, except the email address you can send from the welcome screen, which that screen sends itself. The page you are reading never shows these requests, because it does not make them.