tryhighlight.app
Privacy Policy
Highlight is designed to stay dormant until you act. This policy explains what the website and Chrome extension process when you choose to capture, discuss, or save something.
Effective date: July 10, 2026
Information we collect
Account and authentication information
We process your name, email address, password-derived authentication credentials, session tokens, and account status so you can create and secure an account. We do not store your plaintext password.
Content you intentionally capture
When you invoke Highlight, we may process the selected passage, nearby text used to re-anchor it, the page URL and title, readable page text captured at that moment, and the question or message you send. We store the resulting note, AI discussion, distilled takeaway, concepts, and graph relationships in your memory bank.
Optional research trails
Research-trail recording is off by default and must be enabled for a reading session. While enabled, Highlight records route-level browsing events, timestamps, and dwell time. Full URLs are retained only for pages that already contain your notes. You can turn recording off at any time.
Local extension data
The extension stores your session token, settings, disabled-site list, recording state, and a local index of URLs that contain notes. Temporary capture state is stored in Chrome session storage so the side panel can open the correct note.
Service and usage information
We process limited operational data such as request timing, error information, feature usage counts, and reading-session activity to secure, operate, and improve the service. We do not use advertising trackers or sell behavioral profiles.
When the extension accesses a webpage
Highlight's content script is available on webpages so your capture gesture works consistently and saved highlights can be repainted when you revisit a source. On an unnoted page, it checks local settings and the local noted-URL index. Page content is sent to our service only after an intentional capture, or when required to load notes for a page already present in your memory bank.
How we use information
- Provide anchored AI discussions, saved notes, search, and graph retrieval.
- Synchronize your memory across authorized Highlight and MCP clients.
- Authenticate users, enforce access controls, prevent abuse, and troubleshoot.
- Maintain optional research trails when you explicitly enable recording.
- Improve reliability and product behavior using aggregate operational metrics.
Service providers and AI processing
We use service providers solely to operate Highlight, including Vercel for hosting and AI routing, hosted model providers selected through Vercel AI Gateway, Neon for database infrastructure, and Resend for transactional email. If you connect Memory SDK, the memories and namespaces you authorize are processed according to that connection. Providers process data under their own security and privacy terms.
How we share information
We do not sell personal data, use it for targeted advertising, or transfer it to data brokers. We disclose information only to service providers needed to operate Highlight, when you direct an integration, to protect users and the service, or when legally required. Authorized personnel may access data only when necessary for support, security, or legal compliance.
Retention and deletion
Notes and discussions remain until you delete them or close your account. Deleting a note removes its local thread and graph contribution and schedules removal from connected projections. Some security, billing, backup, or legal records may be retained for a limited period. Contact us to request account deletion or a data copy.
Security
We use encrypted transport, scoped authentication, tenant isolation, encrypted integration credentials, and restricted operational access. No online service can guarantee absolute security, so please use a unique password and protect your device.
Your choices
- Capture only the passages you want Highlight to process.
- Disable Highlight on selected hostnames in extension options.
- Keep research-trail recording off or stop it at any time.
- Delete individual notes and disconnect linked memory providers.
- Request access, correction, export, or deletion by contacting us.
Children
Highlight is not directed to children under 13, and we do not knowingly collect their personal information.
Changes and contact
We may update this policy as Highlight changes. Material updates will be posted here with a revised effective date. Questions or privacy requests can be sent to zacharyvincentjohnson@gmail.com.