The short version: almost everything the extension does happens entirely on your computer and is never transmitted anywhere. Two features send something off your machine — publishing a recording, and working on a page with other people — and neither starts until you act: you press Publish, or you mention someone. This policy is mostly about being precise about those two.
1What stays on your computer#
All of the following work with no network connection and send nothing to us or to anyone else:
- Drawing on a page — pen, highlighter, shapes, arrows, text labels, sticky notes, comment threads
- Everything you type into a note, a comment or a category name — except on a page you have shared with someone by mentioning them, which section 3c describes
- Marking up PDFs in the extension's built-in viewer, including PDFs on your own disk
- Your settings, keyboard shortcuts, colour categories and per-site rules
- Presenter mode (laser pointer, spotlight, ink)
- Taking a screenshot with your annotations drawn on it
- Recording an interactive demo — the screenshots, the page copies and everything captured with them are written to your browser's local storage and go nowhere else
- Copying a share link (
…#ap=…) — your annotations are compressed into the link itself, so the link is the transport; nothing is uploaded to make one - Exporting a recording as JSON or as Markdown
This data lives in your browser's own storage (chrome.storage.local and chrome.storage.session). Your annotations — and only your annotations, not recordings — are also written to chrome.storage.sync, which is Chrome's own profile sync. That means they travel between your own signed-in Chrome installations through Google's sync service, not through us. We never see them. You can turn this off in the extension's settings.
We do not collect analytics about your use of the extension. There is no telemetry, no crash reporting, no usage counter, no advertising or tracking SDK of any kind in this extension. We do not know that you installed it, how often you open it, or which pages you visit.
2The extension can see every page you visit. It does not send them anywhere.#
Replayink requests access to all websites, because you can ask it to draw on any page and it cannot know in advance which pages those will be. Access to a page is not the same as collecting it. Your annotations are stored locally against the address of the page you made them on, and page content is read only to place your marks back where you put them.
You can switch the extension off completely for individual sites, in Settings → Sites & URLs or with the per-site toggle in the extension's popup.
3What is uploaded: publishing a recording, and pages you share with someone#
The Share link and Publish buttons in the recording player upload a recording so that it becomes a web page anyone with the link can open. This only ever happens when you click one of those buttons. Nothing about a recording is uploaded before then, and deleting a recording you never published means it was never anywhere but your own computer.
The other thing that uploads is described in section 3c: a page you have shared with someone by mentioning them in a comment.
When you publish, these are uploaded and stored:
- The screenshot taken at each step
- The saved copy of each recorded page — its HTML, its form contents at that moment, and the stylesheets, images and fonts it referenced
- The web addresses of the pages in the recording, and the recording's title and step notes
- The account identifier described in section 5
3a. Please read this before publishing a recording of a site you are logged in to#
To make the saved copy of a page look the way it did when you recorded it, the extension fetches that page's stylesheets, images and fonts using your browser's cookies for that site — the same way the page itself loaded them.
The consequence is that a recording made inside a logged-in account can capture things only you were supposed to see: your name, your data, an image that is private to your account. If you then publish that recording, all of it becomes part of a page that anyone with the link can open. Anyone who has the link can see it; the links are not indexed by search engines, but they are not secret either.
Before you publish, look at what is actually in the recording. If it contains anything you would not put on a public web page, do not publish it. Keep it in your library, where nothing is uploaded.
Values you type into password fields, credit card fields and one-time-code fields are replaced with dots before they are ever stored, even locally. Settings → Interactive recording → Mask everything typed extends that to every field.
3b. What is deliberately kept out#
Addresses that are not http or https are never uploaded. A recording of a PDF on your own computer is published under the document's file name only — the path to it on your disk (file:///Users/yourname/…) is removed from the page, from the link preview and from the saved copy of the document.
3c. Working with other people: mentions, shared pages and captured copies#
Typing @ in a comment and choosing a person shares that page with them. This needs an account with your email address and a name on it (section 5); the extension asks for both the first time, right in the comment box, and nothing below happens before you have confirmed the share.
What is uploaded once a page is shared, and kept up to date while it is:
- Your marks on that page — including the words a highlight was made over, which the extension keeps so it can find the place again — and your comment threads on it, with your name on them
- The page's address (with tracking parameters removed) and its title, and the rule your settings use to tidy that address, so the other person's browser can recognise the same page
- The email addresses of the people you invite, whether or not they have an account yet
- Every later change you make on that page, sent shortly after you make it. Marks on pages you have not shared are never sent. Deleting a page's marks from your list takes yours off the shared page for everyone.
What is downloaded: the other people's marks and comments on that page, to your browser, and notices that someone mentioned you. To find those, the extension asks the project once a minute whether anything changed for the pages shared with you, and every ten seconds while a shared page is open in front of you. It asks by account, never by which pages you are looking at: which page a tab is on is matched against the shared pages on your own computer and never sent to find out.
Captured copies. When you mention someone on a page they may not be able to open — the extension guesses from the address and from one fetch of the page without your cookies, and shows you its guess before you send — it offers to attach a captured copy of the page. A copy contains the whole page as it is on your screen at that moment: all of its text, including what is scrolled out of view, its form contents, and the stylesheets, images and fonts it loads, fetched with your login as in section 3a, plus a screenshot. Values of hidden form fields and the request tokens frameworks keep in the page are removed first; password, card and one-time-code fields are masked as always. "This screen and what happens next" adds what you do on the page for a short while afterwards, as a recording. A copy is uploaded to private storage that only the people on that thread can open, through a link made for each of them; it expires after 30 days; and you can revoke it, which deletes the files. The first time you attach one, the extension explains this again and asks you to confirm.
Email. When you mention someone, they get an email saying who mentioned them on which page, with a link to the thread (and to the captured copy, if one went with it). The link is theirs: it signs their replies, so they can answer without installing anything. Someone with no account who has never replied is sent only the page's host name, not your message. Every mail carries a link to stop mail from you, or from Replayink altogether. No more than one mail per thread per person every fifteen minutes, and no marketing mail, ever.
Where it lives and who sees it. Shared pages, threads, captured copies and notices are stored in the project's database and file storage (section 7). Only the people a page is shared with can read it; a captured copy only through a link made for a person on its thread. Signing out of the account in Settings deletes everything shared with you from your computer.
4Hosted share pages, and people who open your links#
A published recording is served from a page at replayink.com (links made before 5 October 2026 are at annotate-share.surajp609.workers.dev, which is the same service). That page counts how it is used so you can see whether your demo worked, and it records, per viewer:
- A random identifier stored in that viewer's browser, so repeat visits are not counted twice. It is not linked to any account and identifies nobody.
- The referring page, if the browser sent one, truncated to 300 characters
- The browser's user-agent string, truncated to 200 characters
- Which step they reached, whether they finished, and how long the page was open
There are no advertising cookies and no third-party trackers on these pages. These statistics are readable only by the account that published the recording. If you send someone a link, the page they open will collect the above about their visit.
4a. This website#
The website at replayink.com (the pages that describe the extension, not the extension itself and not the share pages above) counts its visits with Cloudflare Web Analytics. It sets no cookies and keeps nothing in your browser. For a visit it records the page that was opened, the site that linked to it, the country, the kind of browser and device, and how quickly the page loaded. It is not tied to an account, and it is not used for advertising or to follow you to other sites.
5Accounts#
The first time you publish, the extension creates an anonymous account for that browser. It has no name, no email address and nothing you typed — it exists so your published recordings belong to you and so only you can read their statistics. The access token for it is stored in your browser.
You can optionally attach an email address (Settings → Cloud account) so that the same published recordings and statistics are available on another computer. Working with other people (section 3c) requires it, together with a name: the address is what someone types to reach you, and the name is what they see next to what you write. We store that email address and name; the address is used to sign you in with a one-time code and to send you the mail described in section 3c, and nothing else. We do not send marketing email. There is no password.
You can sign in with Google instead. Google then tells us your email address, your name and the address of your profile picture; we keep the address and the name, and nothing from Google beyond that. Signing in that way happens in a window Google draws, and the extension never sees your Google password.
Teams. On the sign-in page you can start a team and hand out its join code, or join one with a code. Everyone on a team sees every member's name and email address, and the code: that is what a team is for, so that mentioning a teammate needs only their name. Leaving a team removes you from that list. A team shares nothing else: a page is still shared only with the people mentioned on it.
6AI features are switched off in this build#
The extension contains an optional feature that can write step notes and record a voiceover using a language model. It is disabled in the version published on the Chrome Web Store: the buttons are not shown, and no text, screenshot or audio is sent to any AI provider by this build. If that changes, this policy will change with it before the feature ships.
7Who else handles this data#
- Supabase (supabase.com) — the database and sign-in: accounts, the published recordings' details, shared pages, threads and statistics
- Cloudflare (cloudflare.com) — file storage (R2) for the screenshots, voiceover and page copies of published recordings and captured copies; serves the published pages, their files and this website
- Resend (resend.com) — sends the sign-in codes and the mail described in section 3c
They process this data on our behalf in order to run the service. Beyond them, we do not share, sell, rent or transfer your data to anyone. We do not use it for advertising, for profiling, or for anything unrelated to showing you your own recordings and their statistics. We do not use it to train machine learning models.
We will disclose data if we are legally required to.
8Keeping and deleting your data#
- Anything not published is on your computer only. Uninstalling the extension removes it, and so does Settings → Sync & data → Clear. Once it is gone we cannot recover it, because we never had it.
- Unpublish in the player removes a published recording and its uploaded files. Its statistics are deleted with it. The link stops working.
- Published recordings are kept until you unpublish them or ask us to delete your account.
- On a shared page, deleting your marks removes them for everyone; a captured copy expires after 30 days or when you revoke it, and its files are deleted with it. Signing out deletes everything shared with you from your computer.
- To delete your account and everything published under it, email the address in section 11. We will action it within 30 days.
You may ask what we hold about you and ask for it to be corrected or deleted, at the same address.
9Children#
Replayink is not directed at children and we do not knowingly collect anything from anyone under 13.
10Changes to this policy#
If this policy changes, the date at the top changes with it. A change that widens what is collected will be announced in the extension's release notes on the Chrome Web Store, not made quietly.
11Contact#
Replayink is made by an individual developer, not a company.
Email: surajp609@gmail.com
Questions, deletion requests and privacy complaints all go to that address.