メインコンテンツへ移動

プライバシー

ドラフト — 法務レビュー待ち

ドラフト — 法務レビュー待ち

バージョン 2026-07-13 · 発効日 2026年7月13日

Notion Research Clipper

Your Notion token, Data Source ID, settings, monthly count, generated installation ID, and opaque ToolFlowy extension session are stored in Chrome local storage. ToolFlowy cannot read the Notion credentials. When you clip, the selected page, text, table/list cells, exact X post, YouTube research, summaries, tags, or enabled images go directly from the extension to Notion. Table/list capture is bounded to 100 rows, 20 cells per row, and 500 characters per cell.

Local processing

Pro summaries and tags are generated locally in the page. They are not sent to an AI provider or ToolFlowy.

Web tools

Image Compressor, Data Formatter, Text Diff, PDF Studio, Favicon Studio, Video Brief Studio, Asset Studio, and ordinary preview/export actions process working input in your browser. Their source files and text are not uploaded to ToolFlowy. One-time “Continue in” workflow payloads use browser storage, expire after ten minutes, and are removed when the destination consumes them. Data Formatter saves up to five input/output runs only after you click Save run locally. Invoice business profiles and PDF operation settings also stay in browser storage on that device.

Account presets

Signed-in users with an active Pro entitlement can explicitly save bounded settings to Postgres: Data Formatter mode, indentation, key sorting, and preferred next step; Snippet visual style; PDF operation settings and page-range expression; or Invoice currency, tax rate, and default due-day count. Presets never accept formatter input/output, source code, filenames, PDF bytes, invoice numbers, parties, addresses, emails, items, notes, totals, or logos. Dashboard exposes preset metadata and deletion even after entitlement ends; applying, creating, or updating cloud settings requires active Pro.

Explicit web transfers

Icon Studio generates its SVG variants locally. For signed-in users, Save to Dashboard can explicitly send the icon prompt, style settings, and locally rendered PNG to ToolFlowy Postgres. Other remaining account saves can send mockup artwork, SEO metadata, a color palette, link-page fields, or resume fields and photo. Snippet source and invoice fields are no longer accepted by this asset endpoint. Preview, local export, and download actions do not perform an account save.

Product usage measurement

For signed-in users, ToolFlowy records only the internal user ID, catalog product ID, a bounded action such as discovered, opened, started, completed, failed, handoff, saved, or Pro used, an optional destination product ID, a fixed safe failure code, optional extension session and installation identifiers, and a timestamp. It does not accept tool input, output, filenames, page URLs, invoice fields, PDF content, JSON, table cells, X-post text, or extension page content in these events. Cohort reporting calculates seven-day activation, week-four retention, cross-suite use, outcome rate, and failure-code distribution from this metadata.

Other ToolFlowy extensions

Smart Tab Manager reads tab titles, URLs, groups, and activity needed for actions you request. When you connect ToolFlowy, it sends saved workspace names, icons, open mode, and each saved HTTP(S) tab URL, title, and pinned state to the revisioned Browser Workspace record owned by your internal User ID. At most 50 workspaces and 200 tabs per workspace are accepted. Closed-tab history, current open-tab backup, current workspace selection, and favicons remain on the device. Concurrent device changes preserve both snapshots until you explicitly keep this device or restore the server copy. Prompt Genius stores your prompts and categories locally and inserts text into ChatGPT, Claude, or Gemini only when you request it. GitHub PR Reviewer reads the current PR title, metrics, and visible file changes for local checks; if you save your own Gemini or OpenAI API key, a bounded PR excerpt is sent directly to that provider when you request a review, and critical summaries go to Slack or Discord only when you enable a webhook. Dark Mode Tester reads current-page styles to preview dark mode, check contrast, and generate CSS. Figma to Code stores the token you enter in Chrome local storage and sends it only to api.figma.com to fetch the file or node you request; generated code stays local. Web Performance reads browser performance entries, image dimensions, and resource metadata after you click Run Analysis. Web Scraper reads only page elements you explicitly select and exports the result locally. Screen Recorder captures only the screen, window, tab, and optional audio you choose in Chrome’s native picker; WebM and GIF processing stays local. Color Palette reads computed page colors on demand. Font Downloader reads computed font-family values and opens Google Fonts pages for exact families or free alternatives. X Bookmarks reads the current X post only after you click Save and keeps saved posts, tags, and exports locally. Reading Highlighter reads only selected text. JSON Lens formats and copies current-tab JSON locally, can open an empty Data Formatter page after copying, and can sync formatter settings without sending JSON or the page URL. Download Organizer reads filenames and extensions but not file contents.

Accounts and billing

The website receives your Google name, email, profile image, and Google account identifier through Auth.js using only the openid, email, and profile scopes. Postgres stores the Auth.js account and session records. Polar processes checkout and license data. ToolFlowy stores Polar customer, subscription, masked license, and device activation references linked to your internal user ID.

Chrome extension sessions

“ToolFlowy로 로그인” opens the website login. After Auth.js completes Google sign-in, a one-time code is exchanged for short-lived, revocable extension access and refresh tokens. Google cookies, passwords, and Google OAuth tokens are never copied to an extension. ToolFlowy stores only token hashes and binds each session to your internal user ID, extension ID, installation ID, and device label. Dashboard shows connected devices and can revoke them. Current Pro status comes from Polar subscription and license records linked to the same internal user ID. The server checks the bound extension ID and allowlist before returning product-specific data: configured Notion Clipper IDs can use Capture Pro, and configured JSON Lens IDs can read or write Developer formatter presets. Other extension IDs cannot use these endpoints.

Chrome Web Store data categories

Depending on the extension you use, it can handle your ToolFlowy name, email, internal user ID, opaque device session, current page title and URL, selected page content, saved prompts, tab metadata, filenames, or user-selected screen and audio capture. Product content stays local or goes only to the destination you explicitly chose, such as Notion or an AI chat page, except for Smart Tab Manager workspace fields described above. ToolFlowy does not collect health data, personal communications, precise location, payment instruments, or checkout transaction details.

Sharing and retention

Notion clip content and credentials go only to the Notion API. Prompt text inserted by Prompt Genius is handled by the AI site already open in your tab under that site’s terms. Smart Tab Manager Browser Workspace data remains in ToolFlowy Postgres until you reset the cloud copy or delete the account; each reset creates a newer empty revision so an old device cannot silently restore removed tabs. Account presets remain until you delete them or delete the account. Screen recordings, scraped rows, performance results, page colors, font metadata, generated CSS, highlights, JSON, organized downloads, closed-tab history, and live-tab backups stay local; opening a Google Fonts link sends only the requested font-family path to Google. Polar receives billing information on its own checkout. Local extension and repeat-workflow data remains until you clear it or uninstall; server-side device sessions remain until expiry or revocation. Product usage events remain linked to the account until account deletion. You can clear local histories, delete presets, reset Browser Workspace, revoke devices from Dashboard, and request account deletion through support.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. ToolFlowy uses extension data only to provide or secure the user-requested extension function, account connection, and supported entitlement features. It does not sell user data, use it for personalized advertising or credit decisions, or allow human access except with explicit user consent for support, for security and abuse prevention, or where required by law.

Contact

Use the support page for privacy or deletion requests.

変更履歴

2026-07-13 — 現在のドラフト構成。法務承認はまだ保留中です。