Privacy Policy
Last updated: October 1, 2026
This policy describes what data we collect, why, and what we do with it. The honest summary: almost nothing, on purpose.
In one paragraph: the SeeNote extension processes filings entirely inside your browser and never sends us what you read: not the filing, not its address, not the notes you open. Its free trial is counted on your own device. It does talk to our server about your trial and your subscription: a random install identifier, the versions of the extension and its trial rules, a count from 0 to 3, the trial or license state and, once you enter a license key, that key. We also use the trial numbers to count how many trials are running. Section 1 lists every request the extension makes, field by field. It has one optional setting, off by default, that shares anonymous aggregate counts (never URLs, tickers, or filing text). This website runs Cloudflare Web Analytics on every page, which uses no cookies. Apart from any email you send us, the only thing we keep that names you is the email address you give us if you sign up, which we use to email you about SeeNote; if you subscribe, our payment processor keeps what you give it at checkout, under its own privacy policy. Unsubscribe at any time, or email us and we delete you from the list.
1. What the extension reads, and what it sends us
The SeeNote Chrome extension runs entirely locally on your device. It reads the filing page you are viewing, on sec.gov or on one of the three other filing surfaces listed below, to make footnote cross-references clickable, and that processing never leaves your browser. Specifically, the extension:
- sends no page content and no filing text to us or to anyone else, and never tells us which filings you read or which notes you open (what it does send us is listed below; if you use Chrome sync, the trial’s list of counted filings, as hashes, also travels to your own Google account, as described below);
- requires no account, and keeps what it stores (such as its settings, your marks, the trial’s state, and a license key once it is accepted) in your browser’s own storage;
- keeps resolution statistics (how many references resolved, missed, and so on) on your own device, and sends them only if you turn on the optional setting below;
- runs its filing-reading code on four filing surfaces and nothing else: SEC filing pages and the inline XBRL viewer on sec.gov; the Tel Aviv Stock Exchange's Maya site; the two paths on
mayafiles.tase.co.ilwhere Maya publishes filings rendered as iXBRL; and the FCA data site that serves the National Storage Mechanism. SeeNote injects nothing into any other website you visit: notwww.tase.co.il, notwww.fca.org.uk, not the rest ofmayafiles.tase.co.il. - is granted access at install to the four filing sites only (sec.gov, TASE/Maya, the FCA NSM); any other site is asked for one origin at a time, only when you open a PDF from it in the Reader, and never at install;
- can then fetch a PDF from that site, but only the PDF(s) of the one report you explicitly open (via the toolbar button, the right-click “Open in SeeNote Reader” entry, or the “Open in SeeNote” button beside a filing). A Tel Aviv Stock Exchange report is one submission split across several PDF attachments, so opening it fetches that report's own attachments, capped at 20 and all from the filing's own host. It has to: a reference in the directors' chapter resolves into the financial statements. A UK or SEC document is fetched on its own. Every one of them is read in your browser and never uploaded. This permission is what lets the Reader open a PDF you already have open in a tab; it is never used to read pages in the background or to track your browsing.
Which filings you read is your business. By design, we cannot see it.
One optional setting, off by default. The extension's settings include a "Share anonymous usage counts" toggle. It stays off unless you turn it on, and what it sends when it is on is in the list below: aggregate counters with no URLs, no company or ticker identifiers, no filing text and no personal data. You can turn it off again at any time. The verbatim note you read in a popup is never transmitted, with the setting on or off.
The SeeNote Reader opens filing PDFs you choose (via the toolbar, a right-click, or drag-and-drop) and processes them entirely in your browser. The PDF is never uploaded. The same off-by-default anonymous usage-count setting applies, and which PDF you open is never sent to us.
Highlights and notes you write yourself. You can mark a passage in a filing and attach a note to it. What that stores is the passage you quoted, your note, the filing’s title and address, and the time you last changed it. All of it is written unencrypted into Chrome’s local storage on the device you marked it on, the same place the extension keeps its settings. It is never synced to another computer, never transmitted to us or to anyone else. The My marks page inside the extension reads that same local store and nothing else. You can delete a mark from the sidebar, delete every mark at once from the extension’s settings page, and all of it is deleted along with everything else the extension holds when you remove the extension. Anyone with access to your Chrome profile can read it, so treat a mark the way you would treat a note written in the margin of a printout.
The free trial. SeeNote’s trial covers your first three filings. Which three is worked out and remembered on your device: the extension stores a short hash of each filing’s public identifier (for an SEC filing, its accession number), not its name, in your browser’s own storage. No filing identity is ever sent to us, not even hashed, and neither is which notes you opened. We can see that somebody has used two of three filings, and roughly when their trial started (strictly, when our server first heard from that install); we cannot see which filings, which notes or which company. Those records are also how we count trials: a dashboard that only we can open shows how far trials have got and how many are now subscribed, how many started on each day and under which extension version, and the latest records, each listed by the first eight characters of its install identifier.
Everything the extension sends us
Our server is api.seenote.co, which runs on Cloudflare. These are the only requests the extension makes to it, each with every field it carries. None of them names a filing, a company, a note or an address you visited.
POST /trial/start, carryinginstall_id(a random identifier your browser generates, tied to nothing about you),version(the extension’s version) andruleset_version(the version of the trial rules). Sent at most once for each install identifier, the first time a note opens in a filing that counts toward your trial. Our server keeps these in one row for your install, with the time that row was made: the one date we hold about your trial.PUT /trial/sync, carryinginstall_id,trial_filings_used(a whole number from 0 to 3) andstate(not started, trial, free mode, subscribed or grace). Sent only when the count or the state has changed since our server last accepted one, for example a new filing counted, a license key activated, removed or set aside, or a grace period beginning or running out. Our server keeps the highest count and the latest state in that same row, and makes the row, with the time, if this request gets there first.GET /trial/status, carryinginstall_id. Once a day while you hold no license key, or only one set aside as not valid. Our server answers with what it holds for that install and keeps nothing from the request; the extension uses only the count, and only when it is higher than its own, as a floor under a count this device may have lost, never to give a filing back.POST /license/validate, carryinglicense_key. When you activate a key, once a day while you hold one, when you press “Check again” in the settings, and once more just before a note would be refused to a reader who holds a key. Our server passes the key to Dodo Payments, our payment processor, which answers whether it is valid; we keep nothing from the exchange. If Dodo answers that a key you activated is not valid, the key is not deleted from your device: SeeNote sets it aside as lapsed and keeps asking about it once a day, so a subscription that gets sorted out comes back on its own.GET /founding/remaining, carrying nothing at all. When Chrome starts with SeeNote installed, when SeeNote is installed or updated, and once a day, so the extension stops offering the $99 founding price once the places are gone. Our server reads its count of places and keeps nothing.POST /telemetry, only if you turn on “Share anonymous usage counts” in the settings; it is off until you do. At most once a day, and only when a count has grown since the last send our server accepted, a list of counts, each withevents[].event(always “resolution”),events[].market(EDGAR, Tel Aviv or UK),events[].format(web page or PDF),events[].outcome(resolved, missed, ambiguous and so on),events[].filingType(sent as “unknown”: SeeNote does not report which kind of filing a count came from) andevents[].count. For example: 42 references resolved on EDGAR web pages. Your device keeps these counts whether or not the setting is on (the settings page shows them), so the first send after you turn it on includes the ones kept before. We store the counts with the time they arrived.POST /subscribe, carryingemailandintent(from the extension always the same value, meaning you asked to hear about product updates and the occasional offer). Only if you type your address into the optional field on the extension’s welcome screen and press Send. Our server keeps the address, the intent, whether you have unsubscribed, and when the entry was made and last changed; unsubscribing keeps the entry, marked as unsubscribed. Sections 4 to 6 cover what we send to it, where it is stored and how to have it deleted.
Cloudflare runs our server as well as this site, so each of these requests reaches Cloudflare with your IP address and your browser’s standard request headers, such as its user agent, attached, just as a visit to this site does (see section 2). Of those, our server’s code reads only the Origin header, so that your browser accepts its answer, and it stores none of them. If a request fails, SeeNote carries on: the trial count on your device is the one that decides what opens.
One more thing travels, through Chrome rather than to us. If you use Chrome sync, Chrome carries the trial’s start time, the version of its rules and its list of counted filings (short hashes of each filing’s public identifier, which anyone with a list of filings to compare them against could match back, or placeholders that stand for a count; never names) to your other computers through your own Google account, so a second computer continues the same trial rather than starting a new one, and so does this one if SeeNote’s storage is cleared. It never carries a license key, and it never carries your install identifier: each computer keeps its own. With Chrome sync off, clearing SeeNote’s storage starts a new trial, exactly as reinstalling does; the terms explain why we allow that.
If your SeeNote is version 1.1.0, the version on the Chrome Web Store until its next update reaches you, it makes fewer of the requests above (it has no “Check again”, no check just before a note would be refused and no question about the founding price), and two things above are different. With Chrome sync on, Chrome also carries the state of its review prompt, the card that asks for a store review: how many notes you have opened, short hashes of the filings you opened them in (the same kind as the trial’s), and your answer. It stops adding to them once you choose “Rate SeeNote” or “No thanks”. The next version moves them to this computer and then deletes them from sync; if it cannot read that copy, or the deletion fails, the old copy stays in sync, unused. And if Dodo answers that a key is not valid, 1.1.0 deletes the key from your device rather than setting it aside, so once the subscription is sorted out you enter the key again.
2. Data the website collects: page views, the requests your browser makes, and your email if you give it
If you ask us to email you about SeeNote, on seenote.co or from the optional field in the extension’s welcome screen, we collect the email address you enter and the intent sent with it (a label saying you asked for product updates and the occasional offer; both places send the same one). Our server keeps the address, the intent, whether you have unsubscribed, and when the entry was made and last changed. Giving your address is optional in both places, and nothing about SeeNote works differently if you skip it.
The homepage also asks our server, api.seenote.co, how many founding places are left, so it can show the count beside the price. That request carries no identifier, no cookie and nothing you have typed, and our server keeps nothing from it. Like the extension’s requests in section 1, it reaches Cloudflare with your IP address and your browser’s standard headers.
Besides the signup form, the one script on this site that collects data is Cloudflare Web Analytics, described next. We load no advertising pixels and no social media trackers, whatever you choose in the cookie banner: there are none on the site to load. Section 3 explains what the banner’s switches are for.
Cloudflare Web Analytics, on every page. Cloudflare, which hosts this site, adds its Web Analytics script to every page it serves, and the script runs for every visitor: the cookie banner’s choices do not turn it on or off. Cloudflare says it uses no cookies and no local storage. It records the path of the page you viewed, the page that referred you to it, and timings and other performance measurements of how the page loaded, and Cloudflare works out which browser, operating system, type of device and country each view comes from. Cloudflare processes this for us, as our hosting provider.
Cloudflare also says Web Analytics does not currently record the part of an address after the question mark. The page you land on after subscribing receives your license key and your email address there, with your subscription’s identifier and status, so it takes that whole part out of its own address before the script runs. It keeps only the key, in that browser tab’s session storage, so that reloading the page still shows it; the key lasts only as long as that tab’s session, and nothing on the page sends it anywhere.
Cloudflare, as our host, also receives every request your browser makes to this site, with your IP address, as any web host does. It may also ask your browser to send it a short report when a request to this site fails or is answered with an error (Cloudflare calls this Network Error Logging): the report gives the address that failed, the page that led to it and the error, and Cloudflare looks up the network, country and metro area of the IP address it came from, which it says it keeps only while it processes the report.
Subscribing is handled by our payment processor at its own checkout, under its own privacy policy. We never see or store your card details.
3. Cookies and your choices
This site sets no analytics or marketing cookies, and loads no script that would. The consent banner still offers three categories, and that is deliberate: the switches are the promise that anything added later starts switched off.
None of the switches reaches Cloudflare Web Analytics: it sets no cookies, and it runs whatever you choose.
- Essential. Always on. Covers the basic operation of the site and the signup form; sets no tracking cookies.
- Analytics. Off unless you switch it on. Nothing on the site uses it today.
- Marketing. Off unless you switch it on. Nothing on the site uses it today.
Your choice is stored in your own browser, together with the list of third parties it was given for, which today is empty. If we ever add a tool that belongs under Analytics or Marketing, we will name it here first, and a choice you made before it existed will not count for it: the banner will ask you again. You can change your choice at any time with the "Cookie preferences" link in the footer.
4. What we use your email for
- A welcome email confirming your signup.
- Product updates and the occasional offer, sent rarely: news such as a new market or a new kind of filing, or a price or offer worth knowing about. No drip campaigns.
Every email we send includes an unsubscribe link. We will never sell, rent, or trade your email address to anyone.
5. Where your data lives
Signup data, and the trial records and usage counts described in section 1, are stored in a Cloudflare D1 database and processed by Cloudflare Workers (our infrastructure provider); emails are sent through Brevo (our email delivery provider). Both act as processors on our behalf and are bound by their own data processing agreements. Dodo Payments, which sells the subscription as merchant of record, keeps what you give it at checkout under its own privacy policy; when the extension checks a license key, our server sends Dodo that key and nothing else about you. We do not share your data with any other third party unless required by law or a court order.
6. Retention and deletion
A trial record holds only the fields listed in section 1, with the time it was made, and a usage-count record holds only the counts listed there, with the time they arrived. Neither names you or a filing: no name, no email address, no IP address. We keep both with no set date for deleting them.
We keep your email address until you ask us to delete it. Unsubscribing stops the list’s emails: it marks the entry as unsubscribed, and the list sends nothing to an address marked that way. Signing up again with that address, on this site or in the extension, puts it back on the list and sends it the welcome email again. Unsubscribing does not delete the entry; if you want it deleted from our database, email hello@seenote.co and we will delete it within 14 days and confirm.
7. Your rights
Under applicable data protection law, including the GDPR if you are in the EU/EEA or UK and the CCPA if you are a California resident, you have the right to access the personal data we hold about you, to correct it, and to have it deleted. Apart from any email you send us, the one record we keep that names you is your entry on the email list, and section 2 lists what it holds. Email hello@seenote.co and we will send you a copy of it, correct it, or delete it from our database within 14 days and confirm.
The trial records and usage counts described in section 1 name no person and no filing, so we cannot find yours from your name or your email address: neither holds a name or an email address, a usage-count record holds no identifier at all, and SeeNote never displays the install identifier a trial record is kept under. Section 6 says how long we keep them.
8. Security
All traffic to seenote.co and our API is encrypted (HTTPS/TLS). Access to the subscriber database is restricted by authenticated tokens held only by the operator. We hold no passwords and no payment data: there is no account system, and payments are handled by a dedicated payment processor that does not share card details with us.
9. Children
SeeNote is a professional tool for reading securities filings and is not directed at children under 18. We do not knowingly collect data from children.
10. Changes
If we change this policy, we will update the date at the top. If a change is material, for example if a future version of the extension sends anything section 1 does not list, we will say so prominently, and it will remain true that the filing you read, and the notes you open in it, never leave your browser.
11. Who we are, and how to reach us
The controller of the personal data this policy describes is SeeNote, except for what you give Dodo Payments at checkout, which Dodo keeps under its own privacy policy (section 5). You can reach us at hello@seenote.co, with questions about privacy and with any of the requests in section 7. We answer within a few business days.