Privacy Policy
Product Scope
NoteFlow helps massage therapists generate and insert treatment notes into BookRelax. Its single purpose is to help massage therapists generate and insert treatment notes into BookRelax.
Independent Product Disclaimer
NoteFlow is an independent extension and is not affiliated with, endorsed by, or sponsored by BookRelax.
Data NoteFlow Accesses
When you use NoteFlow on a supported BookRelax page, the extension may read page content needed for treatment-note generation, including customer names shown on appointment cards, appointment/service details, treatment duration, body chart markers, complaint text, symptoms, treatment-note fields, and treatment plan controls.
Customer treatment information and health-related information may be processed locally in the browser to choose template content, body areas, muscles, and fields to insert into BookRelax.
Data You Provide
You may provide a NoteFlow account email address, one-time verification codes, template text, body map mappings, treatment-note field preferences, stop date settings, and treatment plan settings. Email verification is available without a membership purchase. You also provide consent status when you choose to use the extension.
Local Storage
NoteFlow stores extension settings, templates, body map mappings, membership status, usage counts, a public referral identifier, a private referral-owner token, active template slot, language choice, and privacy consent status in Chrome extension storage. The private token is never included in the shared referral link. This data remains until you delete it, reset Chrome extension data, uninstall the extension, or use the in-extension deletion control.
NoteFlow does not store generated treatment-note history as a separate history list. It stores only usage counts and the templates/settings required to operate the extension.
External Transmission
Email verification, membership checks, referral-owner registration, referral conversion records, and reward usage are sent by HTTPS to Google Apps Script endpoints on script.google.com or script.googleusercontent.com. Requests may include the verified email, one-time verification code, action, extension version, installation identifier, public referral code, private referral-owner token, and membership session token. The backend stores only a one-way hash of the private referral-owner token. Successful Gumroad purchase notifications may include buyer email, sale or subscription identifiers, product, payment status, and referral attribution needed to prevent duplicate or self-referral rewards.
Treatment-note text, body chart content, complaint text, symptoms, customer names, and appointment details are not sent to Google Apps Script by the current extension implementation.
AI Provider or Backend Processing
The current extension package does not send treatment information to an AI API. It uses local templates, local keyword matching, and local body-chart detection. The only external backend processing in the current implementation is Google Apps Script for membership and referral functions.
Use of Data
Data is used only to generate and insert treatment notes into BookRelax, verify membership access, track note usage, maintain user settings, and operate referrals.
Third-Party Processors
Google Apps Script is used for membership verification and referral registration. Chrome/Google browser storage is used to store extension settings through Chrome extension storage.
Data Sharing, Sale, Advertising, and Tracking
NoteFlow does not sell personal data. NoteFlow does not use customer treatment information for advertising. NoteFlow does not include analytics, advertising pixels, telemetry, or tracking services in the extension package.
Retention and Deletion
Local extension data remains until you delete it, reset the extension, or uninstall the extension. You can open NoteFlow settings and use "Delete locally stored extension data" to remove extension-owned local data. You can also withdraw consent, which disables sensitive processing until consent is granted again.
Security
External membership and referral requests are restricted to HTTPS Google Apps Script endpoints. NoteFlow blocks non-HTTPS external requests in the extension background service worker.
Permissions
NoteFlow uses Chrome storage to save settings and consent status, scripting to communicate with supported BookRelax pages, a BookRelax host permission to run only on supported BookRelax pages, and Google Apps Script host permissions for membership and referral processing.
User Controls
You can review this policy, view consent status, withdraw consent, and delete locally stored extension data from the NoteFlow settings tab.
Children's Privacy
NoteFlow is intended for professional use by massage therapists and is not directed to children.
Changes
If this policy changes materially, NoteFlow will update the policy version and require consent again before sensitive processing continues.
Contact
For privacy or support questions, contact supportnoteflow.app@gmail.com.