Tldraw Slide Board privacy policy

English privacy policy · 简体中文隐私政策 · English user guide · 中文使用指南

Effective date: 2026-08-19

Last updated: 2026-08-19

This Privacy Policy explains how the Tldraw Slide Board Chrome extension (“the extension”) handles user data. By using the extension, you acknowledge this policy. Google Drive sync is enabled only after you select Connect Google Drive and complete Google’s authorization flow.

1. Core principles

2. Data handled by the extension

2.1 User-generated content

The extension handles content that you create or import, including:

This data is necessary to provide board editing, saving, import/export, and optional synchronization.

2.2 Synchronization metadata

After Drive sync is enabled, the extension also handles:

The random device identifier distinguishes extension installations. It is not a Google account ID and is not used for cross-application tracking or advertising.

2.3 Authentication information

When you connect Drive, the extension obtains a short-lived OAuth access token through Chrome Identity and uses it only to call Google Drive API. Chrome manages and caches the token. The extension does not write the token to its board database, exported files, Drive board replicas, or project logs, and it does not collect your Google account password.

The only Google OAuth scope requested is:

https://www.googleapis.com/auth/drive.appdata

This scope allows the extension to read and write only its own Google Drive application-data folder. It does not allow the extension to read the user’s ordinary Drive file list.

3. Where data is stored

3.1 Local browser storage

Board metadata, tldraw snapshots, the synchronization queue, conflict history, and settings are stored in extension IndexedDB in the current Chrome profile. Local data normally remains until you delete boards, clear the relevant browser data, or uninstall the extension.

3.2 Google Drive application data

Only after sync is enabled, board content and synchronization metadata are sent over HTTPS to Google Drive API and stored in the selected Google account’s appDataFolder. This folder does not appear in the normal Google Drive file list and is accessible only to the application that created the data using the corresponding permission.

Drive data uses storage in that Google account and is subject to Google’s terms, privacy policy, retention practices, and security controls. The extension does not copy this data to a server operated by the developer.

Private application-data visibility is not the same as end-to-end encryption. The extension does not add a separate encryption layer whose key is held only by the user. Do not store content that you are not comfortable having processed by Google’s infrastructure.

3.3 Export files

When you export all boards, Chrome saves a JSON file to the location you choose or to the browser’s default download location. You are responsible for protecting that file. The extension cannot control access by other software, synchronization services, or people after download.

4. How data is used

The extension uses the data described above only to:

The extension does not use user data for advertising, marketing, credit assessment, data brokerage, user profiling, or analytics unrelated to its core feature.

5. Sharing and third parties

Limited exceptions allowed by policy may apply where disclosure is legally required, necessary to protect users and the service, or based on your explicit consent for support involving specific content. Do not submit private boards or credentials in a public support ticket.

6. Google API Limited Use disclosure

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

In particular, Google user data is used only to provide the disclosed board storage and synchronization feature. It is not used for personalized advertising, sold to third parties, or made available for human reading except with explicit consent for specific data, for security or legal needs, or for anonymized internal operations where policy permits.

7. Retention and deletion

Delete one local board

Select delete beside a board and confirm. If sync is enabled, the deletion is queued for synchronization to other installations.

Delete all cloud replicas

Select Delete cloud data in the sync panel and confirm. The extension attempts to delete every Tldraw Slide Board replica it has marked in that Google account’s appDataFolder, clears synchronization state on the current installation, and disconnects. Local boards are not deleted.

To prevent another connected installation from uploading the data again, disconnect the other devices before deleting cloud data.

Disconnect or revoke authorization

Disconnect stops synchronization on the current installation and clears Chrome’s cached authorization tokens, but does not delete local or Drive boards. You may also revoke access from Google Account third-party connections. Revoking authorization alone does not automatically delete data already stored.

Uninstall

Uninstalling removes the extension’s local data from the current Chrome profile, but does not automatically delete application data in Google Drive. Use Delete cloud data before uninstalling if you also want to remove Drive replicas.

8. Security

The extension uses Chrome Manifest V3, browser extension isolation, local IndexedDB, HTTPS Google API requests, and a minimal OAuth scope. The package does not execute remotely hosted code, and OAuth tokens are not stored with board content.

No storage or transmission method is guaranteed to be completely secure. Use a strong password and two-step verification for your Google account, export backups of important boards, and protect those export files.

9. Children’s privacy

The extension is not directed specifically to children under 13, and the developer does not knowingly collect personal information from children. Use in schools, families, or regulated environments should be decided by guardians or organization administrators under applicable law and Google Workspace administration policies.

10. Changes to this policy

If data handling, permissions, external services, or purposes change materially, the developer will update this policy and its effective date and will proactively disclose the change in the extension or another prominent location as required by Chrome Web Store policy. New consent will be requested before a material change where applicable.

11. Contact

Do not post OAuth tokens, passwords, private boards, or complete export files in a public GitHub issue.