Privacy Policy
This policy explains how Palette for Notion processes information through its website and Chrome/Edge extension. Palette for Notion is an independent product and is not affiliated with or endorsed by Notion Labs, Inc.
- The extension reads and changes visible Notion page elements inside your browser to apply styles. Normal styling does not upload your Notion page content to Palette servers.
- Settings and presets stay in extension storage by default. Account presets are sent to Palette only when you choose Save to Account, and loaded only when you request it.
- Payment details are handled by Lemon Squeezy. Palette receives order, license, subscription, refund, and customer metadata needed to provide paid access.
- Feedback is sent only when you submit it. Guest reply emails are optional, unverified, and do not create or link an account.
1. Information We Collect
Account & Identity
Supabase processes your email address, authentication identifier, session data, email-verification status, and optional display name when you create or use an account. Security records can include sign-in activity, password or profile changes, administrative actions, and the request IP address and browser user agent where the relevant server route records them.
Payments, licenses, and devices
Lemon Squeezy processes checkout and tax information. Palette stores the related order, product or variant, license, subscription, status, price, refund, and customer email metadata needed for access and support. Activation also processes a generated extension device identifier, supplied device name, account or license association, activation status, and timestamps to enforce device limits.
Extension Usage Data
Theme, color, font, page-width, and related settings stay in Chrome or Edge storage until you clear them or remove the extension, subject to browser behavior. Account preset names and style values are sent only when you choose Save to Account; this is not continuous sync. Screenshot capture processes the visible tab after your action and downloads it to your device. It reaches Supabase only if you later attach it to authenticated feedback.
Support & Feedback
We store the message, optional diagnostic selector, submission time, replies, and images you intentionally attach. Member inquiries link to the signed-in account; guest inquiries do not. A guest reply email is optional, unverified, visible to authorized staff, and used only to answer the inquiry—not for marketing or account linking. Abuse controls use a keyed one-way IP digest, a hidden bot field, same-origin and size checks, and a temporary idempotency record; this endpoint does not store the raw guest IP. Pending customer text can enter a server-only support export without structural account identifiers, staff replies, selectors, or attachments. Personal data in free text must be redacted before a persistent AI queue or log, and no reply is sent automatically.
Website visits and marketing
The website loads Google tag services for advertising measurement. Google may receive standard web request data and use cookies or similar identifiers under its own policies. A dedicated Palette marketing redirect may store its path, referrer, UTM values, browser user agent, and a salted one-way IP hash. If you later sign up, the clean landing-path string can be copied from a signed attribution cookie to your profile, and UTM values present on the sign-up URL can also be stored with the profile. The raw IP and full referrer are not copied to the profile, and Palette does not create a browser fingerprint for this attribution.
2. Browser-side processing and external requests
Palette runs on its declared Notion web domains and processes page DOM and CSS inside your browser to apply the selected appearance; this differs from storing the document on Palette servers. Remote font or script providers can receive standard connection data such as IP address, browser user agent, and request time. Palette uses Google Fonts and selected font/CDN sources. If you choose a sharing action, your browser opens that third-party service; KakaoTalk sharing uses the Kakao SDK where configured.
3. Sharing & Third Parties
We do not sell personal information. Depending on the feature, recipients are Vercel for web hosting and server-request processing; Supabase for authentication, database and file storage; Lemon Squeezy for checkout, tax, orders, subscriptions, refunds and licenses; Amazon SES for transactional or support email; Discord for optional staff alerts that can contain feedback text and a reply email; Google tag services and Google Fonts for measurement and fonts; selected font or asset CDNs; and Kakao only when you choose KakaoTalk sharing. Each provider applies its own policy.
4. Data Retention & Deletion
Deleting an account removes the Supabase Auth user and data configured to cascade or be explicitly cleaned up, including active device links. Support, security, transaction, tax, and anti-abuse records may remain where needed or may be anonymized instead. Feedback remains available to authorized staff until deleted or no longer needed; guests must contact us because they have no verified owner session. A feedback rate bucket stops affecting requests after 10 minutes; stale rate rows older than one day and idempotency rows older than 30 days are pruned on later submissions, not necessarily immediately. External providers retain data under their own policies and legal duties.
5. Security
Palette uses HTTPS in transit, server-only credentials for privileged operations, database access controls, origin checks, input limits, and role-based administrative access. No online service can guarantee absolute security; contact us if you believe your account or data is at risk.
7. Your Rights
You can turn Palette off, reset styles, clear extension storage, or uninstall it to stop local styling. In the account area you can review or change available profile information, deactivate devices, open billing management, or delete the account. Contact us to request access, correction, export, objection, or deletion; some transaction or security records may need to remain under applicable law or legitimate operational requirements.
8. Children’s Privacy
Palette is not directed to children under 13, and we do not knowingly collect their personal information.
9. Changes to This Policy
We may update this policy when product behavior, providers, or legal requirements change. The current version and update date are posted on this page.
10. Contact Us
For privacy questions or requests, contact contact@mooil.dev.
