Privacy Policy — Knowledge Book
Last updated: 30 August 2026
The short version: your notes live on your device. We run no servers, use no analytics,
and never see, sell or transfer your data. The only things that ever leave your browser are
(1) text you explicitly send to the AI provider you configured with your own API key, and
(2) your licence key, sent to our payment provider to activate a purchase.
What the extension stores — locally, on your device
- Your notes: text you choose to highlight and save, page snapshots you take, plus the page title, address and date, so a note can point back to its source.
- Your settings: theme, buddy character and preferences, notebooks, tags.
- Your AI API key (optional): if you add one, it is stored in your browser's local extension storage and used only to call the provider you selected.
- Your licence key (if you buy Buddy Pro): stored locally so your purchase stays unlocked.
All of this stays in your browser's local storage. If you use the backup feature, notes are also written as plain files to a folder you choose. We — the developer — can see none of it.
What leaves your browser, and when
- AI requests (optional, off by default): when you press an AI action (summarise, ✨ask), the relevant note text or highlighted text is sent directly from your browser to the AI provider you configured (OpenRouter, OpenAI, Anthropic or Google), authenticated with your own key. Their handling of that request is governed by their privacy policy. No AI request is ever made without your action.
- Licence activation: when you buy or activate Buddy Pro, your licence key is sent to our payment provider, Dodo Payments, to activate or validate it. Payment itself happens entirely on Dodo's own checkout pages — the extension never sees your card or billing details.
- Live note sharing (optional): if you start a share link, the notes you picked are end-to-end encrypted in your browser with a key derived from the pairing code you speak to your friend, and relayed via a public message broker that only ever carries encrypted bytes. Nobody without the code — including us and the broker — can read them.
What we do not do
- No analytics, tracking or telemetry of any kind.
- No developer servers — there is nowhere for your data to go.
- No selling or transferring user data to anyone.
- No reading of your browsing history; the extension only touches a page's content when you act on it.
- No ads.
Data removal
Uninstalling the extension deletes its local storage. Backup files you exported remain yours, in your folder, under your control.
Contact
Questions or concerns: please open an issue at github.com/deepthi-1673/knowledge-book/issues.
Changes
If this policy changes, the new version will be published at this address with an updated date.