Privacy Policy
How we collect, use, store, and protect your data — and the controls you have over it.
Last updated: July 9, 2026
This Privacy Policy explains how Noteary (“Noteary,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards your information when you use our web app, mobile apps, and related services (the “Service”). Noteary is a meeting and voice recorder that produces transcripts, summaries, and a searchable memory of what you record.
By using the Service you agree to this Policy. If you do not agree, please do not use the Service. Questions? Contact us at support@noteary.app.
1. Who we are
Noteary provides the Service and is the controller of the personal data described in this Policy. For privacy inquiries, data-subject requests, or to reach our data-protection contact, email support@noteary.app.
2. Information we collect
We collect the following categories of information:
- Account information. Your name, email address, password (stored only as a salted hash), authentication provider (Google, Apple, or email), email-verification status, and plan tier.
- Recordings and uploads. The audio you record or upload, along with any files you import from third-party sources you connect (for example, cloud drives).
- Transcripts and AI outputs. Text transcripts of your audio, AI-generated summaries, action items, highlights, chapters, and the searchable memory built from your content, plus questions you ask about it.
- Content metadata. Titles, recording type, timestamps, durations, language, custom vocabulary, folders, tags, comments, and sharing settings.
- Usage and device data. Log data such as IP address, browser and device type, pages viewed, feature usage, and diagnostic/error data used to keep the Service reliable and secure.
- Payment information. If you subscribe, our third-party payment processor collects your billing details. We receive limited data such as your subscription status, plan, and the last four digits of your card — we never store full card numbers.
3. How we use your information
- To provide the Service: transcribe your audio, generate summaries, and let you search, share, and manage your recordings.
- To create and secure your account, authenticate you, and prevent fraud and abuse.
- To process payments and manage subscriptions.
- To send transactional communications (e.g. summary emails, verification, security, and billing notices).
- To operate, maintain, debug, and improve the Service, and to enforce our Terms and usage limits.
- To comply with legal obligations and respond to lawful requests.
We do not sell your personal information, and we do not use your recordings, transcripts, or summaries to train AI models — ours or anyone else’s. AI providers process your content only to generate your results and are contractually restricted from training on it. We do not use your content for advertising.
4. Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you request); legitimate interests (to secure, maintain, and improve the Service, provided your rights do not override them); consent (for non-essential cookies/analytics and any optional features — you may withdraw it at any time); and legal obligation (to comply with applicable law).
5. Sub-processors we share data with
We share data only with service providers who help us run the Service, under contracts that require them to protect it and use it only on our instructions. Our current sub-processors are:
- Speech-to-text processing — a third-party provider transcribes your audio into text on our behalf.
- AI language processing — a third-party provider generates summaries, action items, and answers from your content. The active provider may change as our infrastructure evolves; each processes your content solely to return your results and does not train on it.
- Cloud storage — object storage for your audio files and derived media, accessed only through short-lived signed URLs.
- Payment processing — a third-party provider handles payment processing and subscription management; we never see or store full card numbers.
- Email delivery — a third-party provider delivers transactional and summary emails on our behalf.
- Sign-in providers — if you choose to authenticate with a third-party account, that provider confirms your identity to us.
- Product analytics — a privacy-friendly analytics provider, used only if you opt in via our consent banner.
- Error and performance monitoring — a monitoring provider helps us keep the Service reliable (diagnostic data only; recording content is not sent).
We may update this list as our infrastructure evolves and will keep this Policy current. We do not otherwise sell or rent your personal information.
6. Data retention & your controls
You control how long we keep your recordings. In Settings you can enable auto-delete after 30, 90, or 365 days, or choose to keep recordings indefinitely. When a retention window passes, the recording and its files are permanently removed. This applies to archived recordings as well — archiving takes a recording out of your library without deleting it, but it does not exempt it from the auto-delete window you chose.
You can also delete any individual recording at any time, which immediately removes its audio and its searchable memory. If you delete your account, we delete or de-identify your personal data, subject to limited retention required to comply with legal, accounting, or security obligations. Backups are purged on a rolling basis.
7. Your rights
Depending on where you live, you may have the right to access, correct, export (data portability), delete, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. Many of these are available directly in the app: you can export your data and delete recordings or your entire account at any time. To exercise any right, use the in-app controls or email support@noteary.app. We will respond within the time required by applicable law and will not discriminate against you for exercising your rights.
8. GDPR (EEA & UK)
If you are in the European Economic Area or the United Kingdom, you have the rights described in Section 7 under the GDPR/UK GDPR, and the right to lodge a complaint with your local supervisory authority. We process your data on the legal bases in Section 4 and honor your right to withdraw consent at any time without affecting prior processing.
9. California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to access and delete it, to correct inaccurate information, and to opt out of “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under the CPRA, and we do not use sensitive personal information for purposes beyond providing the Service. We will not discriminate against you for exercising these rights. To make a request, email support@noteary.app.
10. International data transfers
We and our sub-processors may process your data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), to ensure your data receives an adequate level of protection.
11. Security
We take reasonable and appropriate measures to protect your data, including:
- Encryption in transit using TLS/HTTPS for all connections to the Service.
- Encryption at rest. Recording audio is encrypted with AES-256-GCM before it’s written to storage, using a key we generate and control ourselves.
- Private-by-default storage. Files are never world-readable and are served only through short-lived, signed URLs to authenticated users.
- Access controls. Every recording requires authentication; one account can never access another’s content, and internal access to production systems is limited to what is necessary to operate the Service.
- Two-factor authentication. Password-based accounts can enable TOTP 2FA in Settings for additional login protection.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We do not currently hold formal certifications such as SOC 2, ISO 27001, or HIPAA — we will update this Policy if that changes. See our Security page for the current, detailed state of our technical measures. Do not record content you are not permitted to process.
12. Recording consent — your responsibility
Noteary records conversations that may include other people. You are solely responsible for obtaining consent from everyone you record. Recording laws differ by jurisdiction: some places require only one party’s consent, while others require the consent of all parties. You must comply with all applicable one-party- and two-party/all-party-consent laws, wiretap and eavesdropping laws, and workplace and privacy regulations that apply to you and the people you record.
Before recording, inform participants and get their agreement where required. You are responsible for how you use recordings and transcripts. See our recording-consent guidance for a practical overview (which is not legal advice).
13. AI accuracy
Transcripts and AI summaries can contain errors and are not a substitute for professional advice. For anything important — especially medical, legal, or financial details — review the transcript and confirm with the source.
15. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact support@noteary.app and we will delete it.
16. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
17. Contact us
For any privacy question or request, email support@noteary.app.
This Policy is written to be read alongside our Terms of Service and our recording-consent guidance. Recording laws vary by region and it is your responsibility to comply with them.