Last updated: 12 August 2026
MonkLayer works two ways, and they collect different things. Reading the right section matters more than reading both.
You can annotate a page and share a link without signing up. In that mode we do not ask for your name or email, and we do not have one. Your display name and cursor colour are generated in your browser and stored there.
When you share, we store the annotation itself and the address of the page it points at. Nothing else.
Anonymous pages are deleted automatically after their expiry — 30 days by default. Deletion is real, not a flag: the rows are removed.
Then we hold what an account needs:
Someone who opens a link you sent does not need an account. If they comment, we store the name they typed and a signed cookie that lets them edit their own comment. We record a hashed IP address and the browser user-agent string against the view, to make abuse of the link traceable and to enforce view limits. The raw IP is not stored.
To show annotations on top of a live page, our server fetches that page and strips the headers that would stop it being framed. We record which hosts failed to render, and how often, so we can fix them. We do not retain the fetched page.
The extension does not read, collect or transmit the content of pages you visit. It draws its own overlay on top. It sends a page address to our servers only when you share or save that page. If you connect it to a workspace, it stores a session token on that device — in local storage, not synced across your browsers.
Invitations, access requests and decisions, mentions, trial reminders, and payment failures. Mentions can be turned off in your settings; the rest are transactional and cannot, because they are the mechanism by which the product works. We do not send marketing email.
The marketing site uses PostHog for page views, session duration and session replays. IP addresses are anonymised. The extension collects no analytics, and neither does the signed-in application.
Only the providers we need to run the service. They are listed, by name and purpose, on the subprocessors page. We do not sell your data, and we do not share it for advertising.
You can export or delete your data. Deleting your account removes your profile and your authorship; where you were the only owner of a workspace, that workspace is handed to a colleague or deleted with you. Email hello@monklayer.app and we will action it — we are a small operation, so expect a person rather than a form.
If you are in the UK or EU, you have the rights the UK GDPR and GDPR give you: access, correction, erasure, portability, and objection. Those apply regardless of what this page says.
Privacy · Terms · Refunds · Subprocessors · MonkLayer