Privacy Policy

Privacy Policy for Notita

Last Updated: September 17, 2026

At Notita, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we handle your information when you use our AI-assisted note-taking application.

1. Information We Collect

  • Google Account Data: When you sign in via Google, we collect your email address and basic profile information to create and identify your account.
  • Google Calendar Data: If you enable the "Sync to Calendar" feature, we access your Google Calendar to view and edit events. Specifically, we collect event titles, dates, and times to link your notes to scheduled reminders.
  • Audio and Voice Recordings: When you use our voice recording feature, your audio is sent for transcription and then discarded. We do not store voice recordings. What we keep is the resulting text, saved as note content and encrypted as described in Section 4.
  • Note Content: We store the text, titles, and tags you create within the app so your data stays in sync across devices. Note text is encrypted before it is written to our database — see "Data Storage and Security" below.
  • Usage and Interaction Data: We collect basic technical information (IP address, browser and device type, and the page that referred you to us) and how you use the app (screens viewed, buttons tapped, features used) to ensure the security and performance of our service and to understand which features matter. Our analytics provider also records session replays of these interactions. All text shown on screen and everything you type — including note titles and content — is masked in your browser before a replay is sent, so replays show layout and movement, not your words.

2. How We Use Your Data

  • Service Delivery: We use your data to transcribe voice recordings and organize notes using AI.
  • Calendar Synchronization: We use the .../auth/calendar.events scope to automatically create, view, and update calendar events based on dates and times recognized within your notes.
  • Account Management: We use your email to manage your account and send important service updates.
  • AI Processing: We use third-party providers to transcribe and summarize notes. Your data is processed only to fulfill your requests and is not used to train public AI models without your explicit consent. The providers are named in Section 5.

3. Google API Limited Use Disclosure

Notita's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Storage and Security

  • Infrastructure: Your data is stored using Supabase (a managed PostgreSQL database and object storage).
  • In Transit: All traffic between your device and our servers is encrypted using SSL/TLS.
  • Note Encryption: The text of your notes — content, titles, checklist items, locations, and comments — is encrypted with AES-256-GCM before it is written to our database. Each account has its own encryption key, so one account's key cannot open another account's notes.
  • Separated Key Custody: The key that unlocks your account's encryption key is held by our application host, and is never stored in the database. This means our database provider, and anyone who obtained a copy of the database alone, cannot read the contents of your notes. It does not mean the two halves are held by parties who can never be compromised together: our application servers necessarily hold both the key and database credentials in order to show you your notes.
  • What This Does Not Mean: This is encryption at rest with separated key custody. It is not end-to-end encryption, and Notita is not a zero-knowledge service. Our servers can decrypt your note text, and do so to provide the features you ask for — AI titles and tags, reminder detection, and WhatsApp messages. We tell you this plainly rather than implying a stronger guarantee than we offer.
  • Voice Recordings: Recordings are not written to our storage at any point. Audio is held in memory only for as long as the transcription request takes, then discarded. This means there is no recording for us to lose, disclose, or be compelled to produce — but note that the audio does pass through our servers and our transcription provider in transit, so this is a retention guarantee, not a claim that we never see it.
  • Images: Image files are held in access-controlled storage and encrypted at rest by our storage provider. They are not covered by the per-account note key described above.
  • Administrative Access: Our automated systems decrypt note text only to deliver the features described above, and those accesses are written to an audit log. We do not read your notes for any other purpose. We will not claim this is technically impossible for us to do — it is not, and a policy that told you otherwise would be untrue.
  • No Selling: We do not sell, rent, or trade your personal data, note content, or calendar information to third parties for marketing or advertising purposes.

5. Service Providers and Data Transfers

We share data with the following providers only to operate the Service. Note text is decrypted before it reaches any provider that needs to read it.

  • Supabase — database, file storage, and authentication.
  • Vercel — application hosting; holds the encryption key described in Section 4.
  • Google — AI titles and tags (Gemini), sign-in, Calendar sync, and place lookup for note locations.
  • Deepgram — speech-to-text for voice notes. Audio is sent for transcription only; we opt out of their model-improvement programme, so it is retained no longer than the request itself.
  • Twilio — sending and receiving WhatsApp messages, where you enable that feature.
  • Resend — sending invitation and account emails.
  • PostHog and Sentry — product analytics, session replay and error monitoring. These receive usage and diagnostic data. On-screen text and input contents, including note content, are masked before a replay leaves your device, so neither provider receives note content.

Several of these providers operate in the United States, so using the Service involves transferring your data outside the European Economic Area.

Retention. Voice recordings are discarded as soon as they are transcribed and are never written to storage. Notes you delete are removed from your account immediately and purged from our database thereafter. Deleting your account removes your notes, tags, images, and profile. Providers listed above may retain data briefly under their own policies.

Legal requests. Because we are able to decrypt your note text, we may be compelled to disclose it in response to a valid legal order. We mention this explicitly because services that are genuinely end-to-end encrypted cannot be compelled in the same way, and we do not want our encryption described above to be mistaken for that protection.

6. Your Choices and Rights

  • Access and Deletion: You may view, edit, or delete your notes and synced reminders at any time.
  • Revoking Access: You can revoke Notita's access to your Google Calendar or your entire Google account at any time via your Google Account Security settings.
  • Account Removal: You can request the permanent deletion of your account and all associated data via our support channels.

7. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: