the fine print, in large print
Privacy policy
Effective September 28, 2026 · Chris Creates LLC
PopNotes is a note-taking app for Windows made by Chris Creates LLC ("we," "us"). This policy covers the PopNotes app and this website, popnotes.chris-creates.net. We wrote it to be read, not skimmed past.
The short version
- No account. No telemetry, analytics, ads or crash reports.
- Your notes live on your PC. We have no servers, so we never receive them.
- If you turn on sync for a stack, a copy goes to a PopNotes folder in your own Google Drive or OneDrive, straight from your PC.
- Vault notes are encrypted, and they only ever leave your PC encrypted.
- We don't sell data, share it, or use it for advertising. We don't have it to sell.
What PopNotes keeps, and where
Everything you put in PopNotes (notes, pictures, tags, stacks, settings and themes) is stored in a database in your Windows user profile on your PC. PopNotes also keeps its own backups there. None of it is sent to us.
Notes you put in the Vault are encrypted with AES-256-GCM under a key that is protected by your passphrase (through Argon2id). If you use Windows Hello to unlock the Vault, Windows keeps that key protected; your fingerprint, face or PIN never reaches PopNotes. If you forget your passphrase, nobody can recover your Vault notes, including us.
When PopNotes goes online
PopNotes works offline. It connects to the internet only in these cases, each of which you start:
- Sync, if you connect Google Drive or OneDrive and turn sync on for a stack. Details below.
- Link titles, if you turn them on in Settings (they're off until you do) and then click Fetch title on a note. PopNotes then requests that one web page and reads its title. The website you're asking about sees an ordinary request from your PC.
- The theme shelf, when you open Get more themes… in Settings > Appearance. PopNotes then reads the theme list and its pictures from this website, and downloads a theme only when you click Install. It talks to popnotes.chris-creates.net and nowhere else, and sends nothing about you or your notes; like any visit to this site, the host sees an ordinary request (see "This website" below). The shelf is on by default. Turn off "Theme shelf (network)" in Settings > Appearance and PopNotes never asks.
- Links you open. Opening a link in a note, or a Ko-fi button (in Settings, or in the "Enjoying PopNotes?" question it asks twice at most), opens your web browser. What happens there is between you, your browser and that website.
- Buttons that look something up. Some notes get a button that opens a website in your browser with part of the note in the address: Track with UPS, FedEx or USPS sends that carrier the tracking number, Maps sends Google Maps the address, and Search part sends Google the part number. Nothing is sent unless you click one.
PopNotes draws its window with Microsoft Edge WebView2, a part of Windows that Microsoft keeps up to date. Microsoft's own privacy statement covers that component. If your PC doesn't have WebView2, the PopNotes installer downloads it from Microsoft.
Sync with Google Drive or OneDrive
Sync is optional and off by default. You choose a drive, sign in with your own account in your browser, and choose which stacks to sync. PopNotes talks to your drive directly from your PC; nothing passes through us.
What PopNotes asks for
- Google Drive: the
drive.filepermission, which lets PopNotes see, edit, create and delete only the files it created itself. It cannot see anything else in your Drive. PopNotes also reads your Google account's email address, only to show you which account is connected. - OneDrive:
Files.ReadWrite.AppFolder, which limits PopNotes to its own folder (Apps > PopNotes) in your OneDrive;offline_access, so it can keep syncing without asking you to sign in again; andUser.Read, only to show you which account is connected.
What goes to your drive
For each stack you sync: its notes and their details (tags, paper color, pin, dates, order), the stack's name, color and settings, your tag colors and saved smart stacks, and each PC's name so your other PCs can say where a stack came from. Pictures and files travel too if "Sync attachments" is on.
Vault notes travel only if you turn on "Include Vault entries (sealed)," and then their text travels only encrypted, with what another PC needs to unlock them using your passphrase. A Vault note's kind, dates, tags, color and pin travel unencrypted beside it.
Where your sign-in is kept
PopNotes keeps the sign-in token for each drive, with the account's name, in Windows Credential Manager on your PC. It never writes that token into its database, a log, a backup or an export.
Stopping sync and deleting synced data
- Turn sync off for a stack, or click Disconnect in Settings > Sync to delete the stored sign-in from your PC.
- To withdraw PopNotes' access completely, remove it from your account: Google account connections, or Microsoft account app permissions.
- To delete what was synced, delete the PopNotes folder from your Google Drive, or Apps > PopNotes from your OneDrive.
Google API Services User Data Policy
PopNotes' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. PopNotes uses Google Drive only to sync the stacks you choose between your own devices. It does not use that data for advertising, does not sell it, and never sends it to us; no person at Chris Creates can read it. The one other place a synced note can go is Claude on your own PC, and only if you turn on the Claude connection and show Claude that note's stack (see below). Then the note reaches Claude only inside a conversation you're having with it.
The Claude connection
PopNotes can connect to Claude Desktop and Claude Code on your PC. It's off by default. When you turn it on, you choose which stacks Claude can see; every stack stays hidden until you show it, and the Vault is never shared, even when it's unlocked.
The connection runs only on your PC, between PopNotes and the Claude app, and only for your Windows user. PopNotes doesn't send anything to Anthropic itself. Notes reach Claude only when you ask Claude something that needs them in your conversation, and then Anthropic's terms and privacy policy apply to that conversation. Before Claude sees a note, PopNotes masks common shapes of passwords and keys as ••••. That masking is a safety net, not a guarantee, so keep real secrets in the Vault.
This website
This site has no cookies, no analytics, no ads and no third-party scripts, and it loads its fonts from itself. It remembers your light or dark choice in your own browser, and that never leaves your browser. The "pop something" demo runs entirely in the page; nothing you type into it is sent or saved.
The site is hosted by Vercel, which receives the standard information any web request carries (such as your IP address and browser type) in order to serve the page and protect the service. See Vercel's privacy policy. The Ko-fi links take you to ko-fi.com, where Ko-fi's privacy policy applies.
If you email support@chris-creates.net, we receive your email address and whatever you write, and we use it only to answer you. We don't add you to a mailing list.
Children
PopNotes isn't directed at children under 13, and we don't knowingly collect personal information from anyone. As described above, we don't collect it at all.
Your choices and rights
Because your notes stay on your PC and in your own drive, you control them directly: export them, delete them, or uninstall PopNotes whenever you like. To remove your notes from a PC for good, after uninstalling delete the PopNotes folder in %APPDATA%, the com.chriscreates.popnotes folder in %LOCALAPPDATA% (the app window's own storage, which can hold a draft), any backup mirror folder you chose in Settings > Backups, and the PopNotes entries in Windows Credential Manager. If you have a question or a request about your data, email us and we'll help.
Changes
If PopNotes starts handling data differently, we'll update this page and the date at the top before the change ships. We won't quietly add tracking. That's not a thing we do.
Contact
Chris Creates LLC · support@chris-creates.net