KastorFlow Privacy Policy
Last updated: October 4, 2026
KastorFlow is a Chrome extension that works with Google NotebookLM. This policy explains what information KastorFlow handles, why, where it goes, and the choices you have. "We" and "us" mean Laxmipat Bhatera, trading as Tandem Labs, who makes KastorFlow.
Summary
- Your notebooks and the pages you capture go to NotebookLM in your own Google account. KastorFlow keeps a working copy in your browser so it can search and organize them.
- You can use KastorFlow without an account. If you sign in, we store your email address, your plan and your usage counts.
- If you buy a plan, Dodo Payments handles the payment. Your card details never reach us.
- AI features send the content you act on through our servers to Google's Gemini AI. Searches made by Build notebook go to Serper, a web search service.
- Podcast episodes you publish are public.
- Connected tools receive what you send them, or what an automation you set up sends.
- When you're signed in, we collect usage statistics. They never include your content.
- We don't sell your data, use it for advertising, or collect your browsing history.
1. What KastorFlow handles
1.1 Your NotebookLM notebooks
KastorFlow works with the Google account you're signed in to in Chrome. To list and change your notebooks, it uses the same session NotebookLM uses in your browser: it reads short-lived request details from the NotebookLM page, and the email address of the account NotebookLM shows, and keeps them in the extension's storage on your device. KastorFlow never sees your Google password and doesn't send these session details to us.
With that session, KastorFlow reads your notebooks, sources, notes and Studio artifacts so it can show, search, tag, organize, merge, export and report on them. It keeps a copy in your browser, including source text for search. When you add sources, KastorFlow sends them to NotebookLM in your account.
1.2 Pages, chats and videos you capture
Some KastorFlow scripts load on the websites you visit so its capture tools are ready: the save buttons in AI chats (ChatGPT, Claude, Gemini, Perplexity and Grok), on X and Reddit, and on YouTube; the right-click option that saves selected text; video frame capture; and Quick Capture, which stays off until you turn it on. These scripts read a page only when you use one of these tools, and only what that tool needs, such as the conversation you save, the text you selected, or the page's address and title.
What you capture goes to NotebookLM in your account. For YouTube videos, KastorFlow may also read the video's public page and captions to build the source. When you add links, open tabs or a CSV file of links, KastorFlow reads those addresses (and, for open tabs, their titles) and sends them to NotebookLM.
We do not collect your browsing history.
1.3 Your KastorFlow account (optional)
You don't need an account for KastorFlow's basic features. If you sign in, with Google or with a one-time code sent to your email, our provider Supabase stores: your email address; your name, if your sign-in provides it; how you signed in; your plan and its details, such as trial dates or a student offer; and the usage counts we use to apply plan limits.
1.4 AI features (only when you're signed in)
These features send the content each request needs to our server functions, which pass it to Google's Gemini API and return the result:
- AI tagging sends a source's title and up to its first 3,000 characters.
- Build notebook sends your topic, the search queries it generates and the text of the web pages it reads. It reads those pages in your browser. Its web searches go through our server to Serper.
- Notebook audit sends the notebook content it analyzes.
Some features, such as notebook audit, also ask NotebookLM's own chat about your notebook, in your account.
Our server functions don't save the content you send. If a request fails, our logs record the error, not your content. Google processes the content to return the result under the Gemini API terms for paid services, under which Google doesn't use it to improve its products.
1.5 Podcast publishing (only when you publish)
When you publish an Audio Overview as a podcast episode, KastorFlow uploads the audio, its title and notes, its picture, and the feed details you enter, including an owner email if you add one, to our storage (Cloudflare) and our database. It then lists the episode in an RSS feed. Anyone with the feed's address can access published episodes, including podcast apps and any directories you submit the feed to. The owner email, if you add one, appears in the public feed.
Unpublishing removes an episode from your feed. The audio file stays in our storage, and anyone who already has its direct link can still play it, until you delete it from your podcast library.
If you connect your own Cloudflare storage instead, the audio goes straight from your browser to your storage, not to ours.
If you use KastorFlow's podcast player, we save your listening position and favorites for your account.
1.6 Connected tools
You can connect Google Drive, Slack, Discord, Obsidian, Anki and Readwise.
- Google Drive uses Google's own sign-in in Chrome with the narrowest Drive permission (
drive.file), which covers only files KastorFlow creates or you open with it. Chrome holds the access token; it never reaches our servers. - Slack and Discord use the webhook address you paste in.
- Obsidian and Anki are apps on your computer. KastorFlow talks to them on your computer and nothing passes through our servers.
- Readwise uses the access token you paste in. KastorFlow reads your highlights from Readwise and adds them to NotebookLM.
These credentials stay in the extension's storage on your device. Content goes to a connected tool when you send it, or when an automation you set up runs. The first time you send something to a tool, yourself or through an automation, KastorFlow asks you to confirm, and an automation never sends to a tool you haven't confirmed. After content arrives, that tool's own privacy policy applies. You can pause all automations or disconnect a tool at any time.
1.7 Usage statistics (only when you're signed in)
When you're signed in, KastorFlow records which feature you used and when, your plan, whether it worked, and how long it took. For AI features it also records the AI model, the amount of text processed and the cost. It may add counts, such as how many items a run handled. These records are linked to your account ID.
They never include your content: no page or source text, titles, addresses, search queries or messages. KastorFlow keeps them in your browser and sends them to our database about once a day. When you're signed out, it records nothing.
1.8 Kept only on your device
Your settings, the working copy of your notebooks, tags, collections, favorites, jobs, activity log, saved clips, prompts, drafts and connected-tool credentials are stored in the extension's storage in your browser. We don't receive them.
1.9 Payments (when you buy a plan)
If you buy Pro or Pro+, you pay on the checkout page of our payment provider, Dodo Payments. Dodo Payments processes the payment and handles your card or other payment details; they never reach KastorFlow. Dodo Payments tells us your email address, the plan you bought and your subscription's status, and we store these with your account to turn your plan on and off.
2. What we don't do
- We don't sell or rent your data.
- We don't use your data for advertising, and we don't share it with advertising platforms, data brokers or information resellers.
- We don't collect your browsing history.
- We don't include your content in usage statistics.
- No one at KastorFlow reads your content unless you ask us to (for example, to help with a support request), or it's required for a security investigation or by law.
3. Who else handles your information
- Supabase hosts our accounts, database and server functions. Our database is in South Korea.
- Google runs the Gemini API used by AI features, and Google sign-in. Your NotebookLM data stays in your own Google account.
- Serper runs the web searches made by Build notebook.
- Cloudflare stores and delivers published podcast audio and pictures.
- Dodo Payments processes payments for Pro and Pro+.
- Tools you connect receive what you or your automations send them.
We may also share information when the law requires it, or to protect the safety and security of our users and service.
4. How long we keep it
- On your device: until you delete it, clear the extension's data, or uninstall KastorFlow.
- Account data and usage statistics: while your account exists. We delete them when you ask us to delete your account.
- Plan and purchase records: while your account exists, and longer where tax or accounting law requires.
- AI request content: our server functions don't save it.
- Published podcast episodes: until you unpublish them. The audio files stay until you delete them from your podcast library.
5. Your choices and rights
- Use KastorFlow without an account.
- Pause all automations, or disconnect any connected tool, at any time.
- Unpublish podcast episodes and delete their files from your podcast library.
- Delete the data on your device by clearing the extension's data or uninstalling it.
- Ask us for a copy of your account data, or ask us to correct or delete it, by emailing privacy@kastorflow.com. Depending on where you live, you may have further rights under local law.
6. Children
KastorFlow isn't meant for children under 13, and we don't knowingly collect their information.
7. Security
Information travels over encrypted connections (HTTPS). Our AI and storage keys stay on our servers and are never shipped in the extension. Only your own account can read its data on our servers.
8. Changes
When we change this policy, we update the date at the top. If a change is significant, KastorFlow will also tell you in the product.
9. Contact
Laxmipat Bhatera, trading as Tandem Labs · privacy@kastorflow.com · India
Limited Use
KastorFlow's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
KastorFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.