On this page
Content never touches Filed's servers
Captured content never passes through Filed. It goes directly from your browser to Notion. Every article, highlight, quote, note, screenshot, PDF, and audio transcript you save goes straight from your browser to the Notion API.
Optional Cross-device History can store the URL and title of your saves on Filed's servers. It's off by default. Turn it on in Settings (extension) or the app menu (mobile) if you want a save made on one device to show up in your history on another. With it off, nothing about your saves, not even the URL or title, reaches Filed's servers.
📸 [Image: What to show: a simple diagram showing browser → Notion API direct connection, with Filed server to the side handling OAuth token + plan tier always, and URL/title only when Cross-device History is on]
Audio never leaves your device
Audio memos use the browser's built-in Web Speech API. Speech recognition runs locally. Neither the audio recording nor interim transcription results are transmitted anywhere. Only the text transcript is saved, to Notion, directly from your browser.
Your Notion content stays in Notion
Filed cannot read your existing Notion pages or databases unless it needs to fetch a database schema to show you property options when you configure a workflow. It never reads the content of your existing pages.
OAuth tokens are stored locally
Your Notion access token is stored in chrome.storage.local, encrypted by Chrome's storage layer, never sent to Filed's servers.
The token grants Filed permission to create pages in your workspace on your behalf. It cannot be used to log into Notion, access other accounts, or read content outside of what Filed explicitly requests.
What Filed does collect
By default, Filed's backend receives:
- Your Notion OAuth token, for workspace connection
- Billing data (plan, subscription status), if you're on Pro
- Your country, derived from your IP address at save time for aggregate analytics. Your IP is discarded immediately and never stored.
- Anonymous usage counts (feature events, error rates)
- No page content, no article text, no highlight data, and no URLs or titles of pages you save
If you turn on the optional Cross-device History setting, the URL and title of each save are also sent to Filed's servers, so that save shows up in your history on your other devices. Everything else, article content, notes, tags, screenshots, is unaffected and still never reaches Filed's servers.
Filed's server never sees what you capture. Content and metadata are two different things, and only metadata (plan tier, usage counts, and optionally URL/title) ever reaches the backend.
Mobile app (Android)
The Android app follows the same privacy model. Your Notion token is stored on your device and never transmitted to Filed's servers except during the initial OAuth exchange. Content goes directly from your phone to the Notion API.
The mobile app sends a save count to Filed's backend by default (used for stats and badges): no content, no URLs, only the number. The same optional Cross-device History setting exists in the mobile app menu; turning it on sends the URL and title of saves made on mobile to Filed's servers as well, off by default.
Chrome permissions explained
| Permission | Why | What it cannot do |
|---|---|---|
| activeTab | Read the current tab's URL, title, and selection when you trigger a capture | Cannot read tabs you haven't triggered a capture from |
| storage | Store settings, workflows, history locally on your device | Stored data never leaves your device |
| alarms | Schedule background retries for queued captures | Not used for tracking or data collection |
| contextMenus | Add "Save quote" to the right-click menu | No access to right-click content itself |
| scripting | Inject the toast and selection toolbar into pages | Scripts are only injected when you actively use Filed |
| https://api.notion.com/* | Send captures to Notion | Access is limited to the Notion API only |