Privacy Policy

Last updated: October 1, 2026

This policy describes what data we collect, why, and what we do with it. The honest summary: almost nothing, on purpose.

In one paragraph: the SeeNote extension processes filings entirely inside your browser and never sends us what you read: not the filing, not its address, not the notes you open. Its free trial is counted on your own device. It does talk to our server about your trial and your subscription: a random install identifier, the versions of the extension and its trial rules, a count from 0 to 3, the trial or license state and, once you enter a license key, that key. We also use the trial numbers to count how many trials are running. Section 1 lists every request the extension makes, field by field. It has one optional setting, off by default, that shares anonymous aggregate counts (never URLs, tickers, or filing text). This website runs Cloudflare Web Analytics on every page, which uses no cookies. Apart from any email you send us, the only thing we keep that names you is the email address you give us if you sign up, which we use to email you about SeeNote; if you subscribe, our payment processor keeps what you give it at checkout, under its own privacy policy. Unsubscribe at any time, or email us and we delete you from the list.

1. What the extension reads, and what it sends us

The SeeNote Chrome extension runs entirely locally on your device. It reads the filing page you are viewing, on sec.gov or on one of the three other filing surfaces listed below, to make footnote cross-references clickable, and that processing never leaves your browser. Specifically, the extension:

Which filings you read is your business. By design, we cannot see it.

One optional setting, off by default. The extension's settings include a "Share anonymous usage counts" toggle. It stays off unless you turn it on, and what it sends when it is on is in the list below: aggregate counters with no URLs, no company or ticker identifiers, no filing text and no personal data. You can turn it off again at any time. The verbatim note you read in a popup is never transmitted, with the setting on or off.

The SeeNote Reader opens filing PDFs you choose (via the toolbar, a right-click, or drag-and-drop) and processes them entirely in your browser. The PDF is never uploaded. The same off-by-default anonymous usage-count setting applies, and which PDF you open is never sent to us.

Highlights and notes you write yourself. You can mark a passage in a filing and attach a note to it. What that stores is the passage you quoted, your note, the filing’s title and address, and the time you last changed it. All of it is written unencrypted into Chrome’s local storage on the device you marked it on, the same place the extension keeps its settings. It is never synced to another computer, never transmitted to us or to anyone else. The My marks page inside the extension reads that same local store and nothing else. You can delete a mark from the sidebar, delete every mark at once from the extension’s settings page, and all of it is deleted along with everything else the extension holds when you remove the extension. Anyone with access to your Chrome profile can read it, so treat a mark the way you would treat a note written in the margin of a printout.

The free trial. SeeNote’s trial covers your first three filings. Which three is worked out and remembered on your device: the extension stores a short hash of each filing’s public identifier (for an SEC filing, its accession number), not its name, in your browser’s own storage. No filing identity is ever sent to us, not even hashed, and neither is which notes you opened. We can see that somebody has used two of three filings, and roughly when their trial started (strictly, when our server first heard from that install); we cannot see which filings, which notes or which company. Those records are also how we count trials: a dashboard that only we can open shows how far trials have got and how many are now subscribed, how many started on each day and under which extension version, and the latest records, each listed by the first eight characters of its install identifier.

Everything the extension sends us

Our server is api.seenote.co, which runs on Cloudflare. These are the only requests the extension makes to it, each with every field it carries. None of them names a filing, a company, a note or an address you visited.

Cloudflare runs our server as well as this site, so each of these requests reaches Cloudflare with your IP address and your browser’s standard request headers, such as its user agent, attached, just as a visit to this site does (see section 2). Of those, our server’s code reads only the Origin header, so that your browser accepts its answer, and it stores none of them. If a request fails, SeeNote carries on: the trial count on your device is the one that decides what opens.

One more thing travels, through Chrome rather than to us. If you use Chrome sync, Chrome carries the trial’s start time, the version of its rules and its list of counted filings (short hashes of each filing’s public identifier, which anyone with a list of filings to compare them against could match back, or placeholders that stand for a count; never names) to your other computers through your own Google account, so a second computer continues the same trial rather than starting a new one, and so does this one if SeeNote’s storage is cleared. It never carries a license key, and it never carries your install identifier: each computer keeps its own. With Chrome sync off, clearing SeeNote’s storage starts a new trial, exactly as reinstalling does; the terms explain why we allow that.

If your SeeNote is version 1.1.0, the version on the Chrome Web Store until its next update reaches you, it makes fewer of the requests above (it has no “Check again”, no check just before a note would be refused and no question about the founding price), and two things above are different. With Chrome sync on, Chrome also carries the state of its review prompt, the card that asks for a store review: how many notes you have opened, short hashes of the filings you opened them in (the same kind as the trial’s), and your answer. It stops adding to them once you choose “Rate SeeNote” or “No thanks”. The next version moves them to this computer and then deletes them from sync; if it cannot read that copy, or the deletion fails, the old copy stays in sync, unused. And if Dodo answers that a key is not valid, 1.1.0 deletes the key from your device rather than setting it aside, so once the subscription is sorted out you enter the key again.

2. Data the website collects: page views, the requests your browser makes, and your email if you give it

If you ask us to email you about SeeNote, on seenote.co or from the optional field in the extension’s welcome screen, we collect the email address you enter and the intent sent with it (a label saying you asked for product updates and the occasional offer; both places send the same one). Our server keeps the address, the intent, whether you have unsubscribed, and when the entry was made and last changed. Giving your address is optional in both places, and nothing about SeeNote works differently if you skip it.

The homepage also asks our server, api.seenote.co, how many founding places are left, so it can show the count beside the price. That request carries no identifier, no cookie and nothing you have typed, and our server keeps nothing from it. Like the extension’s requests in section 1, it reaches Cloudflare with your IP address and your browser’s standard headers.

Besides the signup form, the one script on this site that collects data is Cloudflare Web Analytics, described next. We load no advertising pixels and no social media trackers, whatever you choose in the cookie banner: there are none on the site to load. Section 3 explains what the banner’s switches are for.

Cloudflare Web Analytics, on every page. Cloudflare, which hosts this site, adds its Web Analytics script to every page it serves, and the script runs for every visitor: the cookie banner’s choices do not turn it on or off. Cloudflare says it uses no cookies and no local storage. It records the path of the page you viewed, the page that referred you to it, and timings and other performance measurements of how the page loaded, and Cloudflare works out which browser, operating system, type of device and country each view comes from. Cloudflare processes this for us, as our hosting provider.

Cloudflare also says Web Analytics does not currently record the part of an address after the question mark. The page you land on after subscribing receives your license key and your email address there, with your subscription’s identifier and status, so it takes that whole part out of its own address before the script runs. It keeps only the key, in that browser tab’s session storage, so that reloading the page still shows it; the key lasts only as long as that tab’s session, and nothing on the page sends it anywhere.

Cloudflare, as our host, also receives every request your browser makes to this site, with your IP address, as any web host does. It may also ask your browser to send it a short report when a request to this site fails or is answered with an error (Cloudflare calls this Network Error Logging): the report gives the address that failed, the page that led to it and the error, and Cloudflare looks up the network, country and metro area of the IP address it came from, which it says it keeps only while it processes the report.

Subscribing is handled by our payment processor at its own checkout, under its own privacy policy. We never see or store your card details.

3. Cookies and your choices

This site sets no analytics or marketing cookies, and loads no script that would. The consent banner still offers three categories, and that is deliberate: the switches are the promise that anything added later starts switched off.

None of the switches reaches Cloudflare Web Analytics: it sets no cookies, and it runs whatever you choose.

Your choice is stored in your own browser, together with the list of third parties it was given for, which today is empty. If we ever add a tool that belongs under Analytics or Marketing, we will name it here first, and a choice you made before it existed will not count for it: the banner will ask you again. You can change your choice at any time with the "Cookie preferences" link in the footer.

4. What we use your email for

Every email we send includes an unsubscribe link. We will never sell, rent, or trade your email address to anyone.

5. Where your data lives

Signup data, and the trial records and usage counts described in section 1, are stored in a Cloudflare D1 database and processed by Cloudflare Workers (our infrastructure provider); emails are sent through Brevo (our email delivery provider). Both act as processors on our behalf and are bound by their own data processing agreements. Dodo Payments, which sells the subscription as merchant of record, keeps what you give it at checkout under its own privacy policy; when the extension checks a license key, our server sends Dodo that key and nothing else about you. We do not share your data with any other third party unless required by law or a court order.

6. Retention and deletion

A trial record holds only the fields listed in section 1, with the time it was made, and a usage-count record holds only the counts listed there, with the time they arrived. Neither names you or a filing: no name, no email address, no IP address. We keep both with no set date for deleting them.

We keep your email address until you ask us to delete it. Unsubscribing stops the list’s emails: it marks the entry as unsubscribed, and the list sends nothing to an address marked that way. Signing up again with that address, on this site or in the extension, puts it back on the list and sends it the welcome email again. Unsubscribing does not delete the entry; if you want it deleted from our database, email hello@seenote.co and we will delete it within 14 days and confirm.

7. Your rights

Under applicable data protection law, including the GDPR if you are in the EU/EEA or UK and the CCPA if you are a California resident, you have the right to access the personal data we hold about you, to correct it, and to have it deleted. Apart from any email you send us, the one record we keep that names you is your entry on the email list, and section 2 lists what it holds. Email hello@seenote.co and we will send you a copy of it, correct it, or delete it from our database within 14 days and confirm.

The trial records and usage counts described in section 1 name no person and no filing, so we cannot find yours from your name or your email address: neither holds a name or an email address, a usage-count record holds no identifier at all, and SeeNote never displays the install identifier a trial record is kept under. Section 6 says how long we keep them.

8. Security

All traffic to seenote.co and our API is encrypted (HTTPS/TLS). Access to the subscriber database is restricted by authenticated tokens held only by the operator. We hold no passwords and no payment data: there is no account system, and payments are handled by a dedicated payment processor that does not share card details with us.

9. Children

SeeNote is a professional tool for reading securities filings and is not directed at children under 18. We do not knowingly collect data from children.

10. Changes

If we change this policy, we will update the date at the top. If a change is material, for example if a future version of the extension sends anything section 1 does not list, we will say so prominently, and it will remain true that the filing you read, and the notes you open in it, never leave your browser.

11. Who we are, and how to reach us

The controller of the personal data this policy describes is SeeNote, except for what you give Dodo Payments at checkout, which Dodo keeps under its own privacy policy (section 5). You can reach us at hello@seenote.co, with questions about privacy and with any of the requests in section 7. We answer within a few business days.