Safari Notes Clipper

Privacy policy

Updated 6 October 2026

Your clips stay under your control

Safari Notes Clipper has no developer-operated server, account system, advertising, analytics, or tracking. The developer does not receive your clipped pages, notes, or usage history. The app does not send page content to a cloud AI service.

What the extension reads

When you use the Safari toolbar button, a capture keyboard shortcut, or a capture contextual-menu action, the extension reads the current page or your selected passage, its source address, relevant metadata, and image references. It prepares the clip locally. It does not continuously record your browsing history or crawl linked pages. Safari controls which websites the extension can access.

If you enable optional toolbar indicators, Safari allows the extension to read tab addresses and check them against clips remembered on this Mac. These checks do not read page content or retain a log of visited addresses. Recognition after clicking works without this optional permission.

Local processing and recovery

The Mac app stores cleaned page content and selected temporary images in its local recovery queue. Unfinished drafts keep selected passages and any personal annotation locally until you save or discard the draft. Shortcuts saves only the URL and text supplied to its action; it does not read Safari pages in the background. Available AI processing uses Apple's on-device Foundation Models. If processing is interrupted or fails, recovery input stays on this Mac until you retry, accept the extracted result, or remove the recovery input.

After completion or acceptance, the app removes temporary source text and images. It retains a small receipt with a clip identifier, content fingerprint, Notes identifier, completion date, destination account/folder metadata, and content-free outcome details (content type, image and warning counts, passage count, and whether a personal annotation was included) to prevent duplicate transfers. Receipts contain no page text, title, source address, or image. Titles read from Notes and source domains from the current session stay in memory; they are not added to receipts or saved as a clip library. Removing recovery input does not delete an already saved note.

When page recognition is enabled, a separate local index links keyed hashes of normalized source addresses and selected-passage fingerprints to completion receipts. It does not keep readable source addresses, titles or passages. Known tracking parameters are omitted for matching; other parameters and application routes remain distinct. The key and index stay in this Mac's protected App Group storage and do not sync through iCloud. Hashing reduces retained readable data; someone with access to both the key and index could test guessed addresses. You can clear this history or turn recognition off in Settings. Turning it off clears the history. Pending captures retain their source addresses for recovery until they finish.

Apple Notes access

With your macOS Automation permission, the app reads Notes account and folder names, checks the chosen destination for an interrupted clip, and creates or updates clipped notes. When updating a clipped note, it reads its current content and temporarily exports existing images to preserve them. macOS grants permission for Notes as an application; it does not offer a permission limited to a single folder. You can revoke access in System Settings → Privacy & Security → Automation.

While the companion is active and idle, it reads current titles from notes linked to its twenty most recent completion receipts. This label lookup does not read note bodies, activate Notes or request new permission. If access is unavailable, the list identifies saved clips by their completion date instead.

If you choose Find older clips in Notes, the app reads source headers from notes linked to its existing completion receipts and adds their address hashes to local history. It does not search every note, modify notes, or retain their titles or bodies. A confirmed missing note removes that match from available results; a permission or temporary connection error does not.

Saved notes belong to your chosen Notes account. iCloud or another configured Notes provider may sync them according to that provider's settings and privacy practices.

Image requests

To create offline attachments, the app downloads selected image addresses from their hosting websites. Those servers receive normal network request information, including your IP address and the requested address. The app does not forward Safari cookies, authentication credentials, or page text. Images requiring authentication are left unavailable, with explanatory text in the note.

Your choices

You can choose captured text without AI, AI cleanup without summarization, or AI summaries, select another Notes destination, remove unfinished recovery input, revoke Notes access, or disable the Safari extension. Delete saved notes through Notes. The app stores your destination and content preferences locally and shares those choices with its Safari extension. Optional toolbar-permission reminders can be dismissed in the popup and managed in Extension Preferences. It does not require registration.

Contact

For questions about this policy or the app, contact Predrag Samardzic at predragsamardzic13@gmail.com. Please do not send private notes, passwords, or recovery files unless you have reviewed and deliberately chosen to share their contents.

Website delivery

This website is hosted by Cloudflare. Cloudflare processes normal request information, such as your IP address and requested page, to deliver and protect the site. This site has no forms, analytics, or tracking scripts. See Cloudflare’s privacy policy for its practices.