Privacy

What PanNote handles, what it never sees, and where your notes actually live. Written to be read, not to be survived.

Last updated 21 August 2026

collected

What we collect

  • Account details — your name, email address and profile picture, from Google when you sign in. Used to identify your account and apply the weekly limit.
  • Usage records — one row per generation holding your user ID, the lecture's Panopto ID and a timestamp. This is what enforces the weekly limit and the per-lecture cooldown.
  • Lecture transcripts — sent to our server only while your notes are being generated, and forwarded to OpenAI to produce them. Transcripts are not stored.
  • Generated notes — cached on our server, keyed by lecture, so that when several students generate notes for the same lecture the work happens once. See below.
never

What we never collect

  • No browsing history. The extension can only run on Panopto pages.
  • No Panopto password or session cookie. Captions are read inside the page by the extension itself; your credentials never leave your browser.
  • No payment details. There is nothing to pay for.
  • No API key, if you bring your own. It is stored in your browser and sent only to OpenAI. We never receive it.
storage

Where your notes live

Your notes are stored in your browser, in IndexedDB. That copy is yours: uninstalling the extension deletes it, and nothing syncs anywhere by default.

Separately, generated notes are cached on our server keyed by the lecture's ID, so a second student opening the same lecture gets an instant result instead of paying to regenerate identical content. That cache holds notes derived from the lecture. It holds nothing about who generated them.

third parties

Who else is involved

  • OpenAI — receives lecture transcripts in order to generate notes. Under OpenAI's API policy, data sent through the API is not used to train their models.
  • Supabase — hosts authentication and the usage and cache database.
  • Wikimedia Commons — queried for openly licensed figures. These are ordinary public searches.
  • Google — handles sign-in.

We do not sell your data and we do not share it with anyone beyond the services listed above. PanNote is not affiliated with, endorsed by, or partnered with any of them, nor with any university.

your control

Deleting your data

Delete individual notes from the Library tab, or uninstall the extension to remove every local note at once. To delete your account and its usage records, email the address below; it will be done within 30 days.

Using your own API key avoids our server entirely: in that mode no usage record is created and nothing is cached.

contact

Questions

Anything unclear, or a data request: javinahuja18805@gmail.com.