Skip to main content
Filed

Legal.

This page contains the Privacy Policy for Filed for Notion. See also: Terms of Service and Refund Policy.

Privacy Policy

The short version

Filed for Notion is built on one principle: your content is yours, and it never passes through our servers. Everything you save goes directly from your browser to the Notion API. Filed's backend handles authentication and billing, plus one optional feature described below: cross-device history sync, which is off by default.

What Filed collects

On Filed's servers (OVH VPS, EU, France):

DataPurposeRetention
Email addressAccount identification, billingUntil account deletion
Notion OAuth token (AES-256 encrypted)Authenticating API calls to your workspaceUntil account deletion or token revocation
Plan status (free / trial / pro)Feature access controlUntil account deletion
Account creation dateAccount managementUntil account deletion
Capture URL and title (only if you turn on Cross-device history)Showing your saves in history on your other devicesUntil you delete the entry, disable the setting and clear history, or delete your account

By default: nothing else. No captured URLs. No article text. No notes, tags, highlights, or screenshots. No browsing history. No Notion database content.

The one exception is Cross-device history sync, an optional setting (off by default, in both the extension and the mobile app) that lets a save made on one device show up in your history on another. Turning it on sends the URL and title of each save (not the page content, notes, tags, or screenshots) to Filed's servers so it can be displayed elsewhere. Every other save still never sends URL or title to Filed's servers when this setting is off, which remains the default for all users unless they explicitly enable it.

In your browser (chrome.storage.local, on your device only):

DataPurposeRetention
Workflow configurationsYour saved capture workflowsUntil you delete them
Extension settingsTheme, accent color, preferencesUntil extension uninstall
Capture history metadataWorkflow used, destination name, timestamp, status, Notion page URL30 days rolling
Session tokenShort-lived Notion API accessCleared on browser close

Local capture history always stores full metadata on-device, including the URL and title of what you saved, never the article body, notes, tags, or screenshots. This local copy exists regardless of whether Cross-device history sync is on. What changes with that setting is only whether the URL and title also leave your device and reach Filed's servers.

What Filed never does

  • Never reads your browsing history
  • Never runs code on pages you haven't explicitly opened Filed on
  • Never sends captured content (article text, notes, tags, highlights, screenshots) to its servers, under any setting
  • Never sends the URL or title of a save to its servers unless you have explicitly turned on Cross-device history sync
  • Never shares your data with third parties for advertising or analytics
  • Never uses your data for any purpose other than operating the service
  • Never injects code permanently into web pages (only on demand, via the activeTab permission)

How your captures flow

When you save something with Filed:

  1. The extension or mobile app reads the current page (title, URL, content) locally
  2. It sends that content directly to the Notion API (notion.com) on your behalf; Filed's servers are never involved in this transfer
  3. Separately, it logs the save's metadata (type, workflow used, timestamp) to Filed's servers for your account's stats and badges. If Cross-device history sync is on, the URL and title are included in that log so the save appears in your history on your other devices; if it is off, they are not

Any developer can verify this by inspecting the network requests made by the extension or app: one request goes to notion.com with your full capture, a separate request goes to Filed's backend with only the metadata described above.

Third-party services

ServicePurposeData shared
Notion API (notion.com)Sending your captures to your workspaceYour captured content, sent directly from your browser, not via Filed's servers
OVH (Paris, France)Backend infrastructureEncrypted OAuth tokens, account metadata
LemonSqueezyBilling and subscriptionsEmail address, payment data (never stored by Filed)
ResendTransactional emailsEmail address only

Filed does not sell, rent, or trade your personal data.

Security

  • OAuth tokens are AES-256 encrypted at rest
  • All communication with Filed's backend uses HTTPS
  • The extension content script is injected only on demand, not on every page by default
  • No sensitive data is stored in URL parameters or server logs
  • Backend logs contain no captured content and no user notes; they contain the URL and title of a save only if you have opted into Cross-device history sync

Your rights (GDPR)

If you are located in the EU or EEA, you have the right to:

  • Access: request a copy of all data Filed holds about you
  • Rectification: correct inaccurate data
  • Erasure: delete your account and all associated server-side data
  • Portability: receive your data in a machine-readable format
  • Objection: object to any processing of your personal data

To exercise any of these rights, contact hello@usefiled.app. Requests are handled within 30 days.

Data transfers

Filed's backend runs on OVH infrastructure in France (EU). No data is transferred outside the EU by Filed's infrastructure.

Captured content goes directly to Notion's API. Notion's own privacy policy governs how Notion handles that data.

Children

Filed is not directed at children under 13. If you believe a child has provided personal data, contact hello@usefiled.app and we will delete it promptly.

Changes

Any change to Filed's data practices will be reflected here with an updated date. Material changes will be communicated by email with reasonable notice.

2026-08-27: an internal audit found that Filed's servers were receiving the URL and title of every save, unconditionally, to power cross-device history, a discrepancy from what this policy stated. We've since added an explicit, off-by-default setting ("Cross-device history sync") that must be turned on before URL and title leave your device for this purpose, and rewritten this page to describe that behavior accurately. No other data practice changed.

Publisher

Virgile Gouala
Auto-entrepreneur
SIRET: 824 925 465 00034
Champigny-sur-Marne, 94500, France
hello@usefiled.app

Hosting

OVH SAS
2 rue Kellermann
59100 Roubaix, France
www.ovh.com