← Back to Home
Last Updated: April 13, 2026
Overview
NoteLayer for Gmail is a browser extension that allows users to add persistent notes to Gmail conversations. We are committed to protecting your privacy and being transparent about how our extension works.
We do not collect, store, or transmit any personal data to our servers.
Data Collection
What data is processed locally:
- Gmail thread IDs (to associate notes with conversations)
- Your notes content
- Google Drive file metadata (file IDs, folder structure)
- OAuth access tokens (stored temporarily in browser storage)
What data is stored in your Google Drive:
- Your notes content in JSON files within a "notelayer_notes" folder in your Google Drive
- File attachments you choose to upload with your notes
Data Storage
- Your data stays with you: All notes and attachments are stored exclusively in your personal Google Drive account
- No third-party servers: We do not use any external servers or databases to store your information
- Local browser storage: OAuth tokens and settings are stored locally in your browser using Chrome's storage API
Permissions Used
- storage: To save settings and temporarily cache Google Drive folder IDs locally
- Google Drive API access: To read and write note files in your Google Drive (requires your explicit authorization)
- Gmail domain access: To display the notes interface within Gmail (read-only access to page structure)
Third-Party Services
- Google APIs: We use Google Drive API to store your notes. This interaction is governed by Google's Privacy Policy
- OAuth Authentication: We use Google's OAuth 2.0 for secure authentication. No passwords are stored locally
Data Sharing
- We do not share your data with any third parties
- We do not sell your data
- We do not access your data - it remains in your Google Drive account under your control
Data Control
- You own your data: All notes remain in your Google Drive account
- Easy export: Your notes are stored as standard JSON files that you can access directly in Google Drive
- Complete removal: Uninstalling the extension does not delete your notes - they remain in your Drive unless you delete them manually
Security
- OAuth tokens are stored securely using Chrome's storage API
- All communications with Google APIs use HTTPS encryption
- No permanent storage of authentication credentials
Contact
For privacy-related questions or concerns, please contact: hello@notelayer.app
Changes to Privacy Policy
We will update this privacy policy as needed. The "Last Updated" date will reflect any changes.
Questions?
Contact us at: hello@notelayer.app
This extension is not affiliated with Google Inc. Gmail is a trademark of Google Inc.