Tldraw Slide Board privacy policy
English privacy policy · 简体中文隐私政策 · English user guide · 中文使用指南
Effective date: 2026-08-19
Last updated: 2026-08-19
This Privacy Policy explains how the Tldraw Slide Board Chrome extension (“the extension”) handles user data. By using the extension, you acknowledge this policy. Google Drive sync is enabled only after you select Connect Google Drive and complete Google’s authorization flow.
1. Core principles
- The extension’s single purpose is to let users create, organize, store, and synchronize their own tldraw whiteboards in Chrome’s side panel.
- Local boards require no account and are not sent to a server operated by the developer.
- Google Drive sync is optional and uses only the user’s Google Drive application-data folder.
- The extension does not read browsing history, current website content, cookies, contacts, email, or ordinary Google Drive files.
- The extension does not sell user data, serve personalized advertising, or build advertising profiles.
2. Data handled by the extension
2.1 User-generated content
The extension handles content that you create or import, including:
- board titles, creation times, and update times;
- tldraw board records such as shapes, text, notes, pages, bindings, and resources that you add to a board; and
- board content contained in import and export backups.
This data is necessary to provide board editing, saving, import/export, and optional synchronization.
2.2 Synchronization metadata
After Drive sync is enabled, the extension also handles:
- a randomly generated installation/device identifier;
- record versions, vector clocks, update times, and pending-upload state;
- Drive file identifiers, change cursors, and synchronization status; and
- record-level conflict history created by concurrent edits.
The random device identifier distinguishes extension installations. It is not a Google account ID and is not used for cross-application tracking or advertising.
2.3 Authentication information
When you connect Drive, the extension obtains a short-lived OAuth access token through Chrome Identity and uses it only to call Google Drive API. Chrome manages and caches the token. The extension does not write the token to its board database, exported files, Drive board replicas, or project logs, and it does not collect your Google account password.
The only Google OAuth scope requested is:
https://www.googleapis.com/auth/drive.appdata
This scope allows the extension to read and write only its own Google Drive application-data folder. It does not allow the extension to read the user’s ordinary Drive file list.
3. Where data is stored
3.1 Local browser storage
Board metadata, tldraw snapshots, the synchronization queue, conflict history, and settings are stored in extension IndexedDB in the current Chrome profile. Local data normally remains until you delete boards, clear the relevant browser data, or uninstall the extension.
3.2 Google Drive application data
Only after sync is enabled, board content and synchronization metadata are sent over HTTPS to Google Drive API and stored in the selected Google account’s appDataFolder. This folder does not appear in the normal Google Drive file list and is accessible only to the application that created the data using the corresponding permission.
Drive data uses storage in that Google account and is subject to Google’s terms, privacy policy, retention practices, and security controls. The extension does not copy this data to a server operated by the developer.
Private application-data visibility is not the same as end-to-end encryption. The extension does not add a separate encryption layer whose key is held only by the user. Do not store content that you are not comfortable having processed by Google’s infrastructure.
3.3 Export files
When you export all boards, Chrome saves a JSON file to the location you choose or to the browser’s default download location. You are responsible for protecting that file. The extension cannot control access by other software, synchronization services, or people after download.
4. How data is used
The extension uses the data described above only to:
- display, edit, and save boards;
- organize and find boards by date;
- validate and perform imports and exports requested by the user;
- upload, download, merge, and restore boards across devices after the user enables sync;
- detect pending changes, errors, and concurrent edits; and
- provide user-requested recovery of conflict versions.
The extension does not use user data for advertising, marketing, credit assessment, data brokerage, user profiling, or analytics unrelated to its core feature.
5. Sharing and third parties
- Without sync, board data remains local unless you export it or another program on your device handles it.
- With sync, data is sent only to Google Drive to provide storage and synchronization in your Google account. Google processes this data as an independent service provider under its policies.
- The developer does not operate a backend that receives board content and does not permit employees or contractors to routinely read boards.
- The extension does not sell, rent, or transfer user data to advertising platforms, data brokers, or other information resellers.
Limited exceptions allowed by policy may apply where disclosure is legally required, necessary to protect users and the service, or based on your explicit consent for support involving specific content. Do not submit private boards or credentials in a public support ticket.
6. Google API Limited Use disclosure
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In particular, Google user data is used only to provide the disclosed board storage and synchronization feature. It is not used for personalized advertising, sold to third parties, or made available for human reading except with explicit consent for specific data, for security or legal needs, or for anonymized internal operations where policy permits.
7. Retention and deletion
Delete one local board
Select delete beside a board and confirm. If sync is enabled, the deletion is queued for synchronization to other installations.
Delete all cloud replicas
Select Delete cloud data in the sync panel and confirm. The extension attempts to delete every Tldraw Slide Board replica it has marked in that Google account’s appDataFolder, clears synchronization state on the current installation, and disconnects. Local boards are not deleted.
To prevent another connected installation from uploading the data again, disconnect the other devices before deleting cloud data.
Disconnect or revoke authorization
Disconnect stops synchronization on the current installation and clears Chrome’s cached authorization tokens, but does not delete local or Drive boards. You may also revoke access from Google Account third-party connections. Revoking authorization alone does not automatically delete data already stored.
Uninstall
Uninstalling removes the extension’s local data from the current Chrome profile, but does not automatically delete application data in Google Drive. Use Delete cloud data before uninstalling if you also want to remove Drive replicas.
8. Security
The extension uses Chrome Manifest V3, browser extension isolation, local IndexedDB, HTTPS Google API requests, and a minimal OAuth scope. The package does not execute remotely hosted code, and OAuth tokens are not stored with board content.
No storage or transmission method is guaranteed to be completely secure. Use a strong password and two-step verification for your Google account, export backups of important boards, and protect those export files.
9. Children’s privacy
The extension is not directed specifically to children under 13, and the developer does not knowingly collect personal information from children. Use in schools, families, or regulated environments should be decided by guardians or organization administrators under applicable law and Google Workspace administration policies.
10. Changes to this policy
If data handling, permissions, external services, or purposes change materially, the developer will update this policy and its effective date and will proactively disclose the change in the extension or another prominent location as required by Chrome Web Store policy. New consent will be requested before a material change where applicable.
11. Contact
- Privacy and data requests: pdai3892@gmail.com
- Public documentation: https://seachenjy.github.io/TldrawSlideBoard-legal/
- Issue reporting: https://github.com/seachenjy/TldrawSlideBoard-legal/issues
Do not post OAuth tokens, passwords, private boards, or complete export files in a public GitHub issue.