Legal.
Cette page est disponible en anglais uniquement. La version anglaise fait foi.
This page contains the Privacy Policy for Filed for Notion. See also: Terms of Service and Refund Policy.
Privacy Policy
The short version
Filed for Notion is built on one principle: your content is yours, and it never passes through our servers. Everything you save goes directly from your browser to the Notion API. Filed's backend handles authentication and billing only.
What Filed collects
On Filed's servers (OVH VPS, EU, France):
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account identification, billing | Until account deletion |
| Notion OAuth token (AES-256 encrypted) | Authenticating API calls to your workspace | Until account deletion or token revocation |
| Plan status (free / trial / pro) | Feature access control | Until account deletion |
| Account creation date | Account management | Until account deletion |
Nothing else. No captured URLs. No article text. No notes, tags, highlights, or screenshots. No browsing history. No Notion database content.
In your browser (chrome.storage.local, on your device only):
| Data | Purpose | Retention |
|---|---|---|
| Workflow configurations | Your saved capture workflows | Until you delete them |
| Extension settings | Theme, accent color, preferences | Until extension uninstall |
| Capture history metadata | Workflow used, destination name, timestamp, status, Notion page URL | 30 days rolling |
| Session token | Short-lived Notion API access | Cleared on browser close |
Local capture history stores only metadata, never the content of what you saved (no URLs, no selected text, no notes, no article body).
What Filed never does
- Never reads your browsing history
- Never runs code on pages you haven't explicitly opened Filed on
- Never sends captured content (URLs, text, notes, screenshots) to its servers
- Never shares your data with third parties for advertising or analytics
- Never uses your data for any purpose other than operating the service
- Never injects code permanently into web pages (only on demand, via the activeTab permission)
How your captures flow
When you save something with Filed:
- The extension reads the current page (title, URL, content) in your browser
- It sends that content directly to the Notion API (notion.com) on your behalf
- Filed's servers are not involved in this data transfer
Any developer can verify this by inspecting the network requests made by the extension.
Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| Notion API (notion.com) | Sending your captures to your workspace | Your captured content, sent directly from your browser, not via Filed's servers |
| OVH (Paris, France) | Backend infrastructure | Encrypted OAuth tokens, account metadata |
| LemonSqueezy | Billing and subscriptions | Email address, payment data (never stored by Filed) |
| Resend | Transactional emails | Email address only |
Filed does not sell, rent, or trade your personal data.
Security
- OAuth tokens are AES-256 encrypted at rest
- All communication with Filed's backend uses HTTPS
- The extension content script is injected only on demand, not on every page by default
- No sensitive data is stored in URL parameters or server logs
- Backend logs contain no captured content, no URLs, no user notes
Your rights (GDPR)
If you are located in the EU or EEA, you have the right to:
- Access: request a copy of all data Filed holds about you
- Rectification: correct inaccurate data
- Erasure: delete your account and all associated server-side data
- Portability: receive your data in a machine-readable format
- Objection: object to any processing of your personal data
To exercise any of these rights, contact hello@usefiled.app. Requests are handled within 30 days.
Data transfers
Filed's backend runs on OVH infrastructure in France (EU). No data is transferred outside the EU by Filed's infrastructure.
Captured content goes directly to Notion's API. Notion's own privacy policy governs how Notion handles that data.
Children
Filed is not directed at children under 13. If you believe a child has provided personal data, contact hello@usefiled.app and we will delete it promptly.
Changes
Any change to Filed's data practices will be reflected here with an updated date. Material changes will be communicated by email with reasonable notice.
Publisher
Virgile Gouala
Auto-entrepreneur
SIRET: 824 925 465 00034
Champigny-sur-Marne, 94500, France
hello@usefiled.app
Hosting
OVH SAS
2 rue Kellermann
59100 Roubaix, France
www.ovh.com