Terms and privacy
Public terms and privacy: https://aic.dzyha.com/terms
Українська · Open AIC Notes · Releases and installation
This page describes AIC's data handling and the limits of local storage. The software license shipped with each installed package governs its use; this page does not add a separate contractual agreement. The VS Code host's source license is available in AIC Notes.
Your files and devices
From the start screen, New workspace, Open files and Open folder create a local Markdown workspace without a password. Inside an open workspace, Open files and Open folder add files using its current local or encrypted storage mode. Save or Ctrl/Cmd+S stores a local workspace's notes, paths and labels as unencrypted data on this device. Local workspaces remain readable after restarting and do not auto-lock. Browser storage can be cleared or evicted; keep exported copies of important work.
The file list shows .md files, case-insensitively. New file and folder imports
include only those files and skip .git and node_modules folders. Opening a
folder imports a snapshot; editing and saving locally do not write changes back
to the original folder. Use Save plaintext copy or Export folder to write
readable files explicitly. Existing encrypted bundles retain other file types as
bytes even when the Markdown list hides them; folder export includes those
retained files.
Encrypt workspace creates a separate passphrase-protected copy. The original unencrypted workspace remains in device storage until you remove it with Remove local workspace. That action removes only the app's local copy; it does not delete original files, exported files or the encrypted copy. Creating an encrypted copy does not encrypt or erase an earlier plaintext copy.
The PWA, Chrome/Edge file-notes editor and VS Code encrypted-file editor open the
same .aicnotes files. Each encrypted entity has its own passphrase and can hold
notes, individual files or project folders. Optional names never determine a key;
local workspace labels are unencrypted, and encrypted entity labels are inside
the protected payload. Chrome/Edge's page-notes library and the VS Code encrypted
file host still require their encryption passphrase.
Protected files use the existing AIC envelope on the device: PBKDF2-HMAC-SHA256 with 600,000 iterations and a random salt, followed by authenticated AES-256-GCM. Passphrases are not saved. Unlocked content and keys exist in memory; locking or restarting ends the encrypted entity's unlocked session. Saved encrypted entities lock after five minutes without interaction; unsaved encrypted drafts remain unlocked until saved or closed. Encryption cannot protect a compromised device or an already unlocked editor. AIC is not an independently audited password manager.
For an encrypted entity, the selected .aicnotes file is the durable copy and
the browser cache contains ciphertext. AIC checks for observed external changes
before saving that connected file. It does not merge concurrent edits or guarantee
that an external writer cannot change the file during a save. Reopen a file after
your sync service updates it. Failed or conflicting changes remain in memory for
retry or export; they are not crash-safe backups. Closing can discard unsaved changes.
AIC provides no server storage, account recovery or synchronization service. You
can synchronize exported Markdown files or .aicnotes files through Google Drive
or another service you manage. A locally saved browser workspace is not a synced
folder. The service has its own privacy policy and conflict handling; AIC does
not authorize or control its access. Keep encrypted backups and their passphrases:
the developer cannot recover a forgotten passphrase.
Save plaintext copy, Export folder, Restore folder, Markdown exports and copy actions deliberately produce readable data, including secret values. Destination apps, clipboard history or synchronization, and services receiving files you share may access it. Folder export/restoration refuses observed existing files, but an interrupted operation can leave new files behind.
Offline use and connections
After its first successful online load and installation of the application cache, the PWA interface and local files work offline. The first visit and application updates need a connection to this website. Browser or operating-system services may handle extension updates, clipboard synchronization or your chosen file sync separately. AIC's offline storage does not control those services.
The website host receives ordinary requests for the application and documentation assets, including the connection's IP address. AIC's application does not send your notes, passphrases or encryption keys to that host.
Built-in AI
The Grammar and Improve actions use Chrome's on-device LanguageModel
Prompt API, as in the Core playground. The chosen note text is processed locally;
AIC has no cloud AI fallback, provider token or AI account connection. AI runs
only after you select an action. Review the proposed text before choosing
Apply; applied changes can be undone in the editor.
Chrome may download its model after your explicit AI action. This browser-managed download needs a connection. Once the model is available, supported devices can run AI offline. Availability depends on the browser API, device, storage and supported language. Browsers without it still edit notes offline. AI suggestions can change meaning or be incorrect; review them before saving or sharing. Chrome's Prompt API and requirements.
Chrome and Edge page-notes policy
The following policy covers the existing browser page-notes host, including its permissions, encrypted page library and Chrome Web Store Limited Use statement. Its network restrictions apply to that host. Opening a public documentation or source link uses ordinary browser navigation.
AIC page notes: local data handling
Public AIC terms and privacy: https://aic.dzyha.com/terms
This policy describes the encrypted page-notes panel of the experimental Chrome and Edge component. See README.md and VERIFICATION.md for release status and testing boundaries. The PWA's optional unencrypted local workspaces are described in Terms and privacy; the page-notes library described below remains encrypted.
In this version, AIC has no server, account, telemetry, analytics or synchronization. All runtime resources are bundled. Its extension content policy blocks outgoing connections and remote embedded resources. It reads page content only after you request an import; it does not edit, autofill or insert into source websites. Opening a source link is ordinary browser navigation.
Notes, domain AIC documents, the optional Global Shared record, titles, URLs, dates and the navigation index are encrypted together in local extension storage. Domain values are displayed only for the same exact scheme, host and port. Global Shared is one explicitly created record available across pages in this browser profile, including without an active page. Neither record is copied into page Markdown or inserted into websites. Your master passphrase is not persisted. The derived key remains only in trusted browser session memory after unlock; Lock, browser restart, extension reload or update removes it. There is no embedded key or disk fallback. Both local and session storage require explicit trusted-context access restrictions; local storage contains only encrypted data.
The panel maintains its bounded recent-pages list only while active and unlocked. It does not read the browser's history database or collect browsing in the background. Notes follow the active page in the panel's own window. Its ancestor chain contains only saved-note titles and source URLs for exact-origin path-segment ancestors; it does not expose ancestor Markdown or secret fields.
The manifest excludes Chrome Incognito and Edge InPrivate windows. AIC does not change browser privacy settings. Notes in normal windows persist locally until removed by the user or browser. Confirmed deletion removes the selected local note and its AIC recent-history entry while preserving other notes and exact-origin shared AIC data; restoration requires an earlier encrypted backup. Private browsing is not a way to clear notes.
Whole-library exports include Global Shared, are encrypted and need the backup's original passphrase. Backup merge preserves an existing local Global record and explicitly reports the skipped imported record; the original encrypted backup is unchanged. Markdown exports and Copy intentionally produce plaintext, including secret values. Copy section includes the selected section's masked and filter-hidden rows. Other software, clipboard history/synchronization and destination websites after you paste may access that plaintext. AIC network restrictions do not control those systems or the browser's normal update services.
Removing an extension removes its local data, but not downloaded backups. Keep an unpacked development installation at the same path and reload it instead of uninstalling it for updates. There is no server-side recovery. Keep backups and remember your passphrase. Failed or conflicting drafts remain in memory for retry/export, not crash-safe persistent storage.
Permissions
storage: encrypted local data and a session-only unlock key; nostorage.sync.tabs: identify the active page in the panel's window and open/activate saved source URLs. No history-database permission.sidePanel: display the notes panel in Chrome and Edge.scripting: deliberate, read-only page/selection capture after you grant access to the selected site.Optional HTTP(S) site access: requested for the selected origin on import, not granted to every site at installation. You can revoke site access in browser extension settings.
clipboardRead: an explicit Paste action on an empty typed field reads the latest clipboard text after the user's click. General editor paste stays native; there is no top-level clipboard-import button, monitoring, history collection or background read.clipboardWrite: deliberate copy actions, including hidden field values.
Encryption does not protect an unlocked extension or a compromised device/browser. Plaintext exists in memory while editing. Visible webpage text, titles and URLs can contain confidential information; excluding form values is not universal secret detection. This build is not an independently audited password manager.
Chrome Web Store Limited Use
AIC's handling of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Browser permissions support only the local notes, page import and navigation features described above. The developer does not receive or remotely access your notes or captured page content. AIC does not sell user data or use it for advertising, unrelated profiling, creditworthiness assessments or lending. Exports and clipboard copies happen only through your explicit actions, as described above.
Changes to this policy
The developer may update this policy with product releases. Accounts and synchronization between systems are not available in this version. Before such features become available, their data handling will be described separately, including what data is involved, where it is sent, who receives it and for what purpose.
Changes to data practices will be prominently disclosed. Where required, AIC will obtain your affirmative, informed consent before new collection, use or sharing begins. Updating this policy alone does not authorize new uses of previously stored data or constitute your advance consent to future data handling.