Last updated: September 5, 2026
Summary: Floating Notes is local-first. The free extension stores notes in your browser. Optional Pro sync stores synced notes in your own Google Drive folder; our servers do not store note contents in normal operation.
Floating Notes is operated by SHIFT LLC, 5, street 17, Argel, Nor Hachn, Kotayk region, 2404, RA. In this document, "we", "us" and "our" refer to SHIFT LLC.
For service, billing and personal data questions: Contact support.
Floating Notes has designed this policy to be consistent with the following principles:
The Floating Notes browser extension:
If you do not enable Pro sync, your notes remain local to your browser. If you enable Pro sync, your synced notes are written to a visible Floating Notes folder in your Google Drive.
The extension stores your notes, note positions, colors, collapse state, URL bindings, and local settings in your browser. This data is used only to provide the note-taking experience.
If you sign in, we process your Google account identifier, email address, profile name/avatar when provided by Google, session state, subscription status, and entitlement information. We use this to authenticate you, enable Pro features, and manage billing access.
If you enable Google Drive sync, Floating Notes requests Google Drive access only in that context. We use the Google Drive drive.file scope to create, read, update, and delete Floating Notes files that the app creates or that you explicitly open with the app. We use this access to sync your notes between your own browsers/devices.
Our backend stores encrypted Google refresh tokens so the extension can request short-lived access tokens. Sync traffic for note files goes directly from the extension to Google Drive. Note contents are not stored on Floating Notes servers during normal operation.
When you buy a subscription or Lifetime, our billing provider and payment processor handle your checkout email and order, payment, tax, subscription and refund details. The billing provider acts as the merchant of record. Payment details are entered on the provider’s checkout; we do not collect or store full card numbers or CVV.
We receive your checkout email, customer, order and plan identifiers, subscription and one-time purchase status, and payment/refund metadata. We use these to associate the purchase with your account, grant or withdraw Pro access, provide support and maintain billing records.
We collect anonymous counts of account actions and, after you enable sync, sync state changes. Account events are:
upgrade_click - the Upgrade button was pressedaccount_page_view - the "Account & plan" screen was openedsignin_start - sign-in was startedcheckout_start - a checkout link was issuedcheckout_abandoned - the payment tab was closed without a plan changeSync events are sync_enabled, sync_disabled, sync_paused_reauth, sync_paused_drive_full, sync_paused_folder_missing, sync_resumed, sync_conflict_copy, sync_trash_restore, sync_prev_restore and sync_initial_done. They describe transitions and recovery actions, not individual file transfers, and use the same opt-out setting.
Each event carries the event name and which surface it came from (note, floating window, notes page, or account page). Nothing else. No note content, no page addresses, no page titles, no note identifiers, no device identifiers, no account identifiers, and no IP address or browser user agent are stored with these events. They are counters, not records: once written, an event cannot be traced back to a person, a browser, or a session - not even by us.
If you never open the paid flow, the extension sends none of these events. You can also turn them off entirely: open Account & plan and tick "Do not send anonymous usage counts". The setting takes effect immediately and is stored in your browser.
Separately, our website pages count installs and uninstalls through a 1x1 pixel image, and the uninstall page offers an optional feedback form. Feedback you type there is stored as written - please do not include personal details in it.
When the extension shows account features and cannot tell whether our account service is reachable, it makes a short check: one GET request to our own /health address. If that request fails, it runs a fuller check - our readiness endpoint, our edge, our secondary domain floatingnotes.dimlight.online, and Apple's captive-portal address captive.apple.com - so it can tell "your internet is off" apart from "our servers are not reachable from this network". At most four requests, each with a four-second timeout.
These checks are sent without cookies or credentials and carry no data of yours: no email address, no note content, no page addresses, no identifiers, no analytics event. They fetch a fixed address and look only at whether a response came back. As with any network request, the receiving server sees that a connection was made and can log it under its own policy; for captive.apple.com that server is Apple's, and it is contacted only during the fuller check. We do not receive or store the result of these checks anywhere on our side - the verdict stays in your browser for the current session and is used to explain the account screen.
These checks do not run on a schedule and do not run in the background. Reading, writing and syncing notes never triggers them; neither does opening a page with a note on it. They happen when you open account features for the first time in a session, when a request you started fails, when you press "Check again", or when your browser reports that the network came back.
When you visit floatingnotes.app, our web server may log standard technical information such as IP address, timestamp, browser user agent, requested URL path, and error diagnostics. These logs are used for security, abuse prevention, and troubleshooting.
Floating Notes' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google user data only to provide or improve Floating Notes' disclosed single purpose: browser notes with optional account, billing, and Google Drive sync features. We do not transfer, sell, or use Google user data for personalized advertising, retargeting, data brokerage, credit-worthiness, or unrelated purposes. Humans do not read your Google Drive note files unless you explicitly ask for support with specific data, it is necessary for security, or we are required by law.
More detail is available on our Google Drive Sync and Data Controls page.
We do not use Floating Notes to collect or monetize:
We share data only when necessary to operate Floating Notes:
Subject to applicable law, you may request access, correction, deletion or portability of your personal data, restrict processing, or object to it. Contact us through Contact support to exercise these rights. Account and billing records may be retained as necessary to meet legal and tax obligations; your local notes and Google Drive files remain under your control.
We use HTTPS for network communication. Google refresh tokens stored by our backend are encrypted at rest. Account and billing records are retained while your account is active and for a reasonable period needed for security, accounting, dispute handling, and legal obligations. Server logs are retained for a limited period for security and troubleshooting.
Local browser data is controlled by your browser. Uninstalling the extension or clearing browser data may delete the local replica, including edits that have not reached Drive. Pausing sync or signing out keeps local notes. Synced files remain in your Google Drive.
Deleted synced notes enter Trash. Automatic cleanup starts after 30 days measured from the deletion reaching Drive. Permanent deletion first records an empty deletion marker, then removes note bodies when connected; offline copies cannot be erased immediately. Disconnecting Drive or deleting an account stops new token issuance. An encrypted revocation job can retain the refresh token for up to 24 hours while retrying Google revocation.
Floating Notes is intended for general audiences and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
We may update this Privacy Notice from time to time. We will post changes on this page and update the "Last Updated" date. If we materially change how we use Google user data, we will update this policy and request consent where required before using data in the new way.
If you have any questions about this Privacy Notice, you can contact us at: