HMDIA Note Privacy Policy

Effective date: August 20, 2026
Last updated: August 21, 2026

HMDIA Note is a browser extension developed and operated by HMDIA (“HMDIA,” “we,” “us,” or “our”), located in Ontario, Canada.

This Privacy Policy explains how HMDIA Note handles information when you use the Chrome, Chromium-based, or Firefox versions of the extension.

This Policy applies only to HMDIA Note. It does not cover the HMDIA business directory, other HMDIA plugins or products, or third-party websites and services.

1. Privacy summary

HMDIA Note is designed to keep your information under your control:

  • Notes are stored locally in your browser by default.

  • During ordinary use, HMDIA does not receive or store your note titles, note bodies, tags, reminders, note-associated website addresses, or exported backups.

  • Optional Google Drive synchronization stores encrypted HMDIA Note data in your own private Google Drive application-data folder.

  • Google Drive synchronization is optional and is not required to use HMDIA Note’s local features.

  • HMDIA’s servers are contacted only for Premium-license activation, validation, and deactivation.

  • HMDIA Note does not include advertising trackers, behavioural analytics, telemetry, data brokers, or third-party advertising.

  • We do not sell personal information or use it for personalized advertising, profiling, credit decisions, or training general-purpose artificial-intelligence models.

2. Information processed locally

HMDIA Note may store the following information in your browser’s extension storage:

  • Note titles, note bodies, rich-text formatting, checklists, and links;

  • Global, Domain, or Page note scope;

  • Website domains and page URLs associated with Domain and Page notes;

  • Tags, tag colours, sticky status, archive status, Trash contents, and deletion markers;

  • Creation, modification, archive, deletion, and reminder timestamps;

  • Reminder schedules, recurrence settings, time zone, snooze status, and notification status;

  • Extension settings, themes, colours, display preferences, filters, search preferences, and opening mode;

  • Autosaved drafts;

  • Protected-note encrypted content;

  • The most recently selected colour-picker value;

  • Premium-license information and installation identifiers; and

  • Google Drive connection status, connected-account display name and email address, file identifiers, synchronization status, and a locally stored unlocked synchronization key.

This information remains within your browser profile unless you:

  1. Enable Google Drive synchronization;

  2. Export a backup file;

  3. Activate, validate, or deactivate a Premium license; or

  4. Voluntarily provide information to HMDIA support.

Ordinary notes that are not password-protected are stored unencrypted in the browser’s restricted extension-storage context. Anyone who gains sufficient access to your device or browser profile may be able to access that information.

3. Website and browsing context

HMDIA Note uses website context to provide Global, Domain, and Page notes.

The extension may temporarily read URLs from open browser tabs to:

  • Determine which Domain or Page notes match a tab;

  • Display the correct notes when the extension opens;

  • Update the extension’s note-count badge; and

  • Follow the active tab when using the sidebar or movable-window interface.

HMDIA Note does not use the browser-history API, create a browsing-history profile, or transmit open-tab URLs to HMDIA.

A website domain or full page URL is stored only when you create or save a Domain or Page note. Page URLs may include paths, query parameters, document names, local file paths, or other identifiers. URL fragments are removed. You should avoid associating notes with URLs that contain passwords, access tokens, private access links, or other sensitive information.

The website context associated with a protected note remains visible in local extension storage even though its title, body, and tags are encrypted.

HMDIA Note does not run in Chrome Incognito or Firefox Private Browsing windows. Private tabs and windows are invisible to the extension, so their addresses and content cannot be added to shared extension storage.

4. Colour picker

In Chrome and compatible Chromium browsers, the colour picker uses the browser’s native eyedropper feature and retains only the selected hexadecimal colour value.

In Firefox, when you intentionally activate the colour picker, HMDIA Note may request website access, capture the visible portion of the active tab, and temporarily inject a colour-selection overlay into that page. The screenshot is processed locally for the colour-selection operation. It is not uploaded to HMDIA or Google and is not retained after the operation. Only the selected hexadecimal colour value may be stored locally and copied to your clipboard.

HMDIA Note does not continuously capture screens or webpage content.

5. Protected notes, drafts, and backups

Protected notes

When you password-protect a note, HMDIA Note encrypts its title, body, formatting, and tags locally using authenticated encryption based on AES-GCM and a key derived from your password using PBKDF2-SHA-256.

The extension does not save or transmit the protected-note password. HMDIA cannot recover a forgotten password or decrypt a protected note for you.

Note identifiers, scope, contextual URL or domain, timestamps, sticky status, archive status, and other metadata may remain unencrypted locally.

Autosaved drafts

Autosaved drafts are encrypted locally. The corresponding device key is stored in the same browser extension storage so drafts can be restored automatically. This protects draft contents from casual inspection but does not protect them against a person who has sufficient access to your browser profile or device.

Exported backups

You may export your note database as:

  • A readable JSON backup; or

  • A password-encrypted JSON backup.

Backups may include active notes, Trash contents, tags, and saved Domain or Page contexts. They do not include reminders, your Premium license, Google access token, or Google account connection details.

Exported files are controlled entirely by you after download. HMDIA does not receive them unless you voluntarily send a backup to HMDIA support. HMDIA cannot recover, replace, decrypt, or protect files that are lost, shared, corrupted, or stored insecurely.

6. Optional Google Drive synchronization

Google Drive synchronization is an optional Premium feature. It begins only after you select Connect Google Drive, review the in-extension disclosure, select the unchecked consent box, and authorize access through Google.

HMDIA Note requests only this Google OAuth scope:

https://www.googleapis.com/auth/drive.appdata

This permission allows the extension to manage only HMDIA Note’s own configuration data in Google Drive’s private application-data folder, including the technical ability to see, create, and delete its own app-data files. The current extension uses this access to create, read, and update its encrypted synchronization and key files. It does not permit HMDIA Note to access your ordinary visible Google Drive documents, folders, photos, or other files.

Google information processed

When you connect Google Drive, the extension may receive:

  • Your Google account display name;

  • Your Google account email address;

  • An OAuth access token; and

  • HMDIA Note file IDs, names, versions, and modification times.

Your display name and email address are stored locally to identify and bind the connected account in Settings. OAuth access tokens are held temporarily in browser-managed or extension session storage until they expire or are cleared.

Your Google account information and OAuth tokens are not sent to HMDIA’s licensing server.

Information synchronized

The encrypted synchronization payload can include:

  • Notes and note content;

  • Tags and the tag library;

  • Domain and Page context URLs;

  • Archived notes;

  • Notes currently in Trash;

  • Content-free deletion markers;

  • Reminders, reminder settings, and time-zone identifiers; and

  • Synchronization metadata.

HMDIA Note stores an encrypted synchronization file and a password-protected encryption-key descriptor in your private Google Drive application-data folder.

Encryption

When a new synchronization dataset is created, HMDIA Note:

  1. Generates a random 256-bit data-encryption key;

  2. Derives a wrapping key from your synchronization password using PBKDF2-SHA-256;

  3. Encrypts the data-encryption key using AES-256-GCM; and

  4. Uploads the protected key descriptor to Google Drive.

For each synchronization upload, HMDIA Note reuses that random data-encryption key to encrypt the current synchronization payload locally using AES-256-GCM, with a new encryption initialization vector, and uploads the encrypted payload to Google Drive.

Your synchronization password is not stored or transmitted to HMDIA or Google.

The unlocked synchronization key is stored locally in each connected browser so automatic synchronization can operate without repeatedly requesting the password. Anyone who compromises a connected browser profile may therefore be able to access synchronized information.

While connected, you may change the synchronization password by entering the current password. Changing the password re-encrypts the existing data-encryption key; it does not create a new synchronization account, replace your Google account, or enable HMDIA to recover a forgotten password.

HMDIA cannot recover a forgotten synchronization password. An already-connected browser that retains the unlocked key may be your only way to recover the synchronized information.

Google may see operational file and encryption-envelope metadata such as filenames, file IDs, sizes, versions, timestamps, encryption parameters, random write identifiers, and synchronization revisions. Note content and saved context URLs remain inside the encrypted payload.

7. Google API and Chrome Web Store Limited Use disclosures

HMDIA Note uses Google information only to provide the Google Drive synchronization feature requested by the user.

HMDIA Note’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

HMDIA Note’s use and transfer of extension user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Google API information and extension user data are not:

  • Sold or provided to data brokers;

  • Used for advertising, retargeting, or marketing profiles;

  • Used for credit, insurance, employment, housing, or eligibility decisions;

  • Used for surveillance;

  • Used to train or improve general-purpose artificial-intelligence or machine-learning models.

HMDIA does not receive your encrypted Google Drive files, OAuth token, note content, synchronization password, encryption key, or Google account information. Google Drive synchronization data is not made available for HMDIA personnel to read. Human access to that information can occur only if you intentionally provide specific information to HMDIA for support, or where access is required for security or legal compliance.

Authorized HMDIA personnel and service providers may access limited purchase, licensing, browser-installation, security, and support records when reasonably necessary for license administration, fraud and abuse prevention, support, security, accounting, or legal compliance. These records do not include your ordinary notes or encrypted Google Drive synchronization content unless you intentionally provide specific material to HMDIA support.

8. Premium licensing

When you activate, validate, or deactivate a Premium license, HMDIA Note communicates over HTTPS with HMDIA License Manager at hmdia.com.

Depending on the requested licensing action, the extension sends:

  • The license key you enter;

  • A license activation hash for later validation or deactivation, where applicable;

  • Fixed HMDIA Note product identifiers;

  • The requested activation, validation, or deactivation action;

  • A randomly generated browser-installation identifier; and

  • A synthetic HMDIA license URL representing that browser installation.

The synthetic license URL is only an installation identifier. HMDIA Note does not connect to that synthetic address.

The Chrome and Chromium versions also include the extension version and a general browser-and-platform label in the licensing payload. The Firefox version uses a generic HMDIA Note browser-extension label and does not add the Firefox browser/platform description or extension version to the licensing payload.

The licensing service may return license status, expiration, activation limits, active-installation counts, plan or product labels, and related validation information. This information may be stored locally so the extension can determine whether Premium features are available.

HMDIA License Manager and FluentCart may associate a request with existing purchase and license records, including a customer email address, product, plan, status, and browser-installation limit.

The requesting IP address is processed for secure delivery, abuse prevention, rate limiting, and protection of the licensing service. HMDIA’s hosting provider, WordPress security systems, and Cloudflare may also process ordinary request information such as IP address, request time, browser information, and security events. If country analytics is enabled, HMDIA License Manager may retain a two-letter country code supplied by Cloudflare; this feature does not intentionally store a full IP address in the license-activation record.

License requests never include your notes, reminders, tags, saved context URLs, Google account details, synchronization password, Google token, or Google Drive files.

9. Firefox data-collection choices

The current Firefox version requires Firefox 140 or later and declares no required data collection. Local note-taking and free features operate without granting an optional Firefox data-collection permission.

Firefox separately asks for the relevant optional permissions immediately before you deliberately start a feature that transmits information outside the browser:

  • Premium licensing: Firefox may request authenticationInfo, locationInfo, and personallyIdentifyingInfo, together with access only to https://hmdia.com. These categories cover the license credentials and stable browser-installation identifier sent to HMDIA, the connection IP address necessarily received by the service, and the two-letter country code that may be retained when Cloudflare country analytics is enabled.

  • Google Drive connection and synchronization: Firefox may request authenticationInfo, browsingActivity, locationInfo, personallyIdentifyingInfo, and websiteContent, together with access only to https://www.googleapis.com. These categories cover Google authorization information, the connected Google account display name and email address, saved contextual URLs, reminder time-zone identifiers, and encrypted note and reminder content sent directly to Google for the requested synchronization.

Accepting HMDIA Note’s own privacy notice does not pre-approve Firefox’s separate optional permission prompt. Declining an optional data or host-access request leaves the related remote feature disabled; local note-taking and free features remain available. You may be asked again only when you deliberately start that optional feature later.

The Firefox locationInfo category is a data-transmission disclosure. HMDIA Note does not request Firefox’s geolocation or GPS API permission and does not collect precise GPS coordinates.

10. Browser permissions

HMDIA Note uses browser permissions only for its disclosed functions:

  • Storage: Save notes, settings, reminders, encrypted drafts, and connection information locally.

  • Tabs: Read open-tab URLs locally to match Domain and Page notes and update badges.

  • Identity: Open Google’s authorization flow for optional Google Drive synchronization.

  • Alarms: Schedule reminders, synchronization checks, and license checks.

  • Notifications: Display note reminders through the browser or operating system.

  • Side panel or sidebar: Display the HMDIA Note interface.

  • Active tab and scripting on Firefox: Run the user-initiated colour picker on the visible webpage.

  • Optional website access on Firefox: Capture the visible active tab for the user-initiated colour picker.

  • Access to hmdia.com: Activate, validate, and deactivate Premium licenses.

  • Access to Google APIs: Perform optional Google Drive synchronization.

HMDIA Note does not request cookie, web-request, browser-history, advertising-identifier, microphone, camera, or geolocation/GPS API permissions.

11. How information is used

Information is processed only as necessary to:

  • Create, display, organize, search, protect, archive, restore, and delete notes;

  • Associate notes with websites or individual pages;

  • Schedule and display reminders;

  • Apply user-selected appearance and behaviour settings;

  • Export and import user-controlled backups;

  • Connect and synchronize encrypted information with Google Drive;

  • Activate, validate, and deactivate Premium licenses;

  • Enforce legitimate browser-installation limits;

  • Prevent fraud, abuse, and excessive automated requests;

  • Diagnose a problem when you request support;

  • Maintain the security and reliability of the extension and licensing service; and

  • Comply with applicable legal obligations.

HMDIA Note does not perform automated profiling or make decisions that produce legal or similarly significant effects. Automated license validation only determines whether Premium features are available.

Where applicable, HMDIA relies on performance of a contract, your consent or requested action, legitimate security and service-operation interests, and compliance with legal obligations as the basis for processing.

12. When information may be disclosed

HMDIA may disclose information under its control only:

  • To service providers that operate HMDIA’s website, hosting, security, ecommerce, or licensing systems and are required to process information for those purposes;

  • To Cloudflare or hosting and security providers for secure delivery, abuse prevention, and protection of the licensing service;

  • To FluentCart for purchase and software-license administration;

  • When reasonably necessary to investigate fraud, abuse, or a security incident;

  • When required by applicable law, court order, or lawful government request;

  • To protect the legal rights, safety, and security of HMDIA, users, or the public; or

  • In connection with a merger, acquisition, restructuring, or sale of HMDIA’s business, subject to applicable law and appropriate protections.

Because HMDIA does not receive your ordinary notes or Google Drive synchronization data, HMDIA generally cannot disclose that information in response to a request.

Google independently processes information sent directly to Google under the Google Privacy Policy. Chrome, Firefox, operating-system providers, extension stores, and websites you visit may process information independently under their own policies.

13. Data retention and deletion

Local browser data

Local extension information remains until you delete it, clear the extension’s storage, reset the browser profile, or uninstall the extension.

Deleting a note normally moves the complete note into Trash. Using Clear Notes also moves notes to Trash. Trash contents remain until restored or permanently deleted.

Permanent deletion removes the note content but may retain a content-free identifier and deletion timestamp as a synchronization marker. This marker prevents an older copy on another connected browser from restoring the deleted note.

Similar content-free deletion markers may remain for deleted tags and reminders.

Google Drive data

Disconnecting Google Drive:

  • Stops synchronization on that browser;

  • Clears the cached Google token, locally unlocked synchronization key, and most local connection information;

  • Does not revoke HMDIA Note’s authorization in your Google account;

  • Does not delete the encrypted HMDIA Note files already stored in Google Drive; and

  • Does not delete your local notes.

To remove Google authorization, visit your Google Account third-party connections and remove HMDIA Note.

To delete HMDIA Note’s hidden Google Drive data, open Google Drive settings, select Manage apps, locate HMDIA Note, and choose the option to delete its hidden application data where available.

Revoke access and delete hidden Drive data separately if you want both authorization and synchronized files removed.

Licensing information

Local license information remains until you deactivate the license, clear extension storage, or uninstall the extension.

Active server-side activation records are generally retained while the license remains active. After deactivation, activation history is ordinarily retained for the configured history period, which may range from 7 to 365 days, and is then eligible for deletion.

Purchase, transaction, accounting, fraud-prevention, backup, and legally required records may be retained longer where necessary.

Support information

If you voluntarily provide note content, screenshots, diagnostic information, or backup files to HMDIA support, that information will be used only to investigate and respond to your request. Remove unrelated or sensitive information before sending anything to support.

Support information is retained only as reasonably necessary to resolve the request, maintain appropriate service records, prevent abuse, and meet legal obligations.

14. Notifications

Reminder notifications may be visible on your screen, lock screen, notification centre, or to other people who can access your device.

Notification content is hidden by default. If you enable notification previews, an unprotected note’s title or part of its body may appear in a system notification. Notifications for protected notes remain generic.

You are responsible for deciding whether notification previews are appropriate for your device and environment.

15. Security

HMDIA uses reasonable technical and organizational safeguards appropriate to the information under its control. These measures include HTTPS transmission, authenticated encryption for protected notes and Google Drive synchronization, restricted browser-extension storage contexts, request validation, rate limiting, limited network endpoints, and explicit consent before optional remote features are activated.

No storage or transmission system is completely secure. Encryption cannot protect information if your device, browser profile, Google account, passwords, or unlocked local encryption key are compromised.

HMDIA cannot recover forgotten note, backup, or synchronization passwords and cannot restore local information lost through uninstallation, browser reset, storage clearing, device failure, corrupted profiles, or failure to maintain backups.

16. Your responsibilities and important limitations

HMDIA Note is a general-purpose note-taking utility. It is not designed to serve as a password manager, medical-record system, payment-card vault, legal-record repository, classified-information system, or sole backup service.

You are responsible for:

  • Deciding what information to place in a note;

  • Avoiding sensitive information in page URLs and URL query parameters;

  • Securing your device, browser profile, Google account, and passwords;

  • Choosing strong and unique encryption passwords;

  • Retaining passwords needed to decrypt protected notes or synchronized information;

  • Maintaining appropriate independent backups;

  • Permanently deleting Trash items when content should no longer be retained;

  • Revoking Google authorization and deleting hidden Google Drive data when desired;

  • Deactivating your Premium license before uninstalling if you want the activation slot released; and

  • Complying with laws and obligations that apply to information you store.

HMDIA cannot control and does not guarantee the security, availability, retention, or operation of your device, browser, operating system, Google account, Google Drive, Chrome Web Store, Firefox Add-ons, internet connection, or other third-party services.

Any liability limitations, warranty disclaimers, backup limitations, service-availability terms, indemnities, and governing-law provisions are addressed separately in the HMDIA Note Terms of Use and apply only to the maximum extent permitted by law. Nothing in this Privacy Policy limits rights or obligations that cannot legally be waived.

17. Your privacy rights

Depending on your location, you may have rights to:

  • Ask whether HMDIA holds personal information about you;

  • Request access to information under HMDIA’s control;

  • Request correction of inaccurate information;

  • Request deletion where legally applicable;

  • Withdraw consent for optional processing;

  • Object to or request restriction of certain processing;

  • Request a portable copy of qualifying information; and

  • Submit a privacy complaint.

HMDIA may need to verify your identity before responding. Some requests may be limited where retention is required for license administration, fraud prevention, accounting, legal claims, or compliance with law.

Because HMDIA does not possess your locally stored notes or encrypted Google Drive data, we cannot access, correct, export, decrypt, or delete that information for you. Use the extension and Google account controls described above.

18. International processing

HMDIA operates from Ontario, Canada. Service providers such as Google, Cloudflare, hosting providers, browser vendors, and extension stores may process information in Canada, the United States, or other countries.

Privacy laws and government-access rules may differ between jurisdictions. HMDIA uses appropriate safeguards where required for information transferred under its control.

19. Children’s privacy

HMDIA Note is a general-audience productivity tool and is not directed to children under 13 or a higher minimum age required by local law.

We do not knowingly collect personal information from children through the extension. A parent or guardian who believes a child has provided personal information to HMDIA may contact us to request appropriate action.

Google Drive synchronization is optional, and the extension’s local note-taking functions do not require a Google account.

20. No sale, advertising, or unrelated use

HMDIA does not sell or rent extension user information.

HMDIA does not “sell” or “share” extension user information for cross-context behavioural advertising as those terms are defined under applicable United States privacy laws.

Extension data is not used for:

  • Personalized advertising or retargeting;

  • Data-broker services;

  • Unrelated marketing;

  • Surveillance;

  • Credit, employment, insurance, housing, or eligibility decisions;

  • General user profiling; or

  • Training general-purpose artificial-intelligence models.

21. Changes to this Policy

We may update this Privacy Policy when HMDIA Note’s functionality, legal obligations, or privacy practices change.

The updated Policy will show a revised Last updated date. Material changes will be communicated through the extension, website, store listing, or another appropriate method where required.

If a change introduces a new use of Google user data or another materially different data practice, HMDIA will update the relevant disclosures and obtain new consent where required before beginning that use.

22. Contact and privacy complaints

For privacy questions, access or deletion requests, or complaints, contact:

Privacy Officer — HMDIA
Ontario, Canada
Email: [email protected]
Website: hmdia.com/hmdia-note/