Security & Trust Overview

Built so sensitive data never leaves your browser unprotected.

Annote captures the technical evidence behind a bug — console, network, and what the user did. That's exactly the kind of data that can contain secrets, so we built the product to protect it at the source.

Off by default

Capture is off until you start.

The extension stays inactive on the pages you visit. It captures only during a session you start, and stops the moment you end it. There is no always-on background recording.

Annote
Inactive · not capturing
Idle
you start a session
Capture session
Recording · 00:12
● Rec
Redaction at the source

Redaction happens in your browser, before anything is sent.

As data is captured, Annote replaces sensitive patterns — auth tokens, emails, card-like numbers, phone numbers, API keys, Authorization and Cookie headers — with placeholders, and strips sensitive headers, on your machine, before transmission. Password, hidden, and payment fields are never captured.

We call this fail-closed — if in doubt, it's redacted.
Outgoing capture redacted on-device
Authorization: Bearer sk-live-9f3a2b1c8e… Bearer [redacted]
email: jane.doe@acme.com [redacted]
card: 4242 4242 4242 4242 [redacted]
password field: never captured

We never read what users type.

Annote records which field was interacted with — never the characters entered into your page's fields.

Four browser permissions. Nothing more.

Annote requests only what it needs to show the capture tray and capture during a session. It does not request access to your browsing history or cookies, and does not use a webRequest interception permission.

No third-party tracking.

The product contains no advertising or product-analytics SDKs.

Two honest limits.

Said plainly

We'd rather tell you than have you discover them.

Limit 01

The screenshot is a picture of your visible tab.

Anything on screen at capture time is in the image — redaction protects the captured data, not the picture.

Limit 02

Privacy markers control action and console capture, not network data.

Network data is protected by automatic redaction instead.

Sub-processors

A small set of trusted providers.

O
OpenAI
AI structuring, diagnosis & voice transcription
F
Google Firebase
Auth and storage
S
Stripe
Billing
R
Resend
Email
V
Vercel
Hosting
Read more

Want the full detail?

For full detail on data handling, see our Privacy Policy. For enterprise security questions, reach out any time.

For enterprise security questions, contact help@annote.ai.