Is Milanote Web Clipper safe?

Clean risk

Milanote Web Clipper sends clipped selections and page, link, and image URLs to Milanote when you save web content.

Its content scripts run on most websites, but the saved data is built from user clipping actions such as selected text, page clips, links, and images. When you save a clip, it posts the selected text plus the page URL or the chosen link/image URL to Milanote API endpoints using the stored Milanote bearer token. Link metadata extraction also sends the chosen URL to Milanote's upload service.

Milanotev2.4.0Chrome Web Store
2Risk
Who publishes it

Milanote - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Milanote
Declared legal entity
Milanote
Registered address
Level 1/20-24 Guildford Ln, Melbourne, VIC 3000, AU
Registered contact
Ollie Campbell

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

app.milanote.com
Also called by 2 other listings, including Milanote Web Clipper
staging.milanote.com
Also called by 2 other listings, including Milanote Web Clipper
staging.test.milanote.com
Also called by 2 other listings, including Milanote Web Clipper

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.3.7. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2.4.0, which we have not unpacked yet.

  • Read and change your data on milanote.com

    https://*.milanote.com/

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Run its own code inside the pages you visit

    scripting

  • See the address and title of every tab you have open

    tabs

  • Act on the current tab, but only after you click the extension

    activeTab

  • Sign you in with your Google account

    identity

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

Where it sends data

Destinations our analysis observed Milanote contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • app.milanote.com

    Milanote sends data to app.milanote.com. One other extension we have analysed sends data here.

  • upload.milanote.com

    Milanote sends data to upload.milanote.com. No other extension we have analysed sends data here.

Updated 30 September 2026mipimgcmndeggldjcbjfeogcpoafomhl