Skip to main content
NoteScribe

Privacy policy

Version 11.0 — July 19, 2026

Privacy Policy

Effective date: March 12, 2026

Thank you for using NoteScribe. This Privacy Policy explains what data we collect, how we use it, and your rights as a user. If you have questions, contact us at [email protected].


1. Who We Are

NoteScribe is an AI-powered post-meeting intelligence platform that transcribes audio, generates summaries, and helps you extract action items from conversations. We are the data controller for personal data processed through this service.


2. Data We Collect

Account information: Email address, name, and password (stored securely via Supabase Auth). If you sign in with Google, we receive your Google email and profile name.

Audio and transcript data: Audio files you upload or record, the resulting transcripts, AI-generated summaries, speaker labels you assign, alerts extracted by AI, and any edits you make to transcripts.

Usage data: Pages visited, features used, session duration, and interaction events — collected via Google Analytics 4 and Microsoft Clarity only if you give consent.

Technical data: IP address, browser type, device type, and error reports (via Sentry, anonymized).

Cookie and consent records: Your cookie consent choices, timestamp, and IP address are logged for compliance purposes.

Session data: When you log in, we record your device type, platform, and last active timestamp to enable session management features. This data is visible to you in Settings.

Push notification tokens: If you opt in to push notifications, we store your device push token (FCM registration token, APNs token, or Web Push subscription) to deliver notifications. Tokens are deleted immediately when you opt out.

Billing data: Subscription plan, payment status, invoice history, and discount code usage. Full payment credentials (e.g. credit card numbers) are processed and stored by our payment provider DoDo Payments and are never stored on NoteScribe servers.

Download analytics: When you download the desktop app, we record the platform (macOS/Windows) and timestamp for aggregate analytics purposes.


3. How We Use Your Data

  • Service delivery: Transcription, AI summarization, speaker diarization, alerts extraction, shared recording access, and search across your recordings.

  • Account management: Authentication, billing, session management, email changes, and support.

  • Notifications: Sending push notifications for events you have opted into (e.g. transcription completion).

  • Service improvement: Aggregate, anonymized analytics to understand feature usage and fix bugs. We never use your audio, transcripts, or summaries to train AI models.

  • Legal compliance: Retaining consent records and audit logs as required by applicable law.


4. Speaker Data & Diarization

When you upload audio with multiple speakers, NoteScribe uses AI to identify and separate different speakers (diarization). Speaker data is:

  • Used only within your session and stored only as part of your transcript

  • Not stored as biometric data or voice fingerprints

  • Not used to train any AI model

  • Deletable at any time by deleting the recording

You may rename speaker labels (e.g. "Speaker 1" to "Alice") within your account. These labels are private to you and are never shared.


5. Biometric Authentication

NoteScribe supports optional biometric login (Face ID, Touch ID, or fingerprint) on compatible devices. Biometric data is:

  • Processed entirely on your device by the operating system

  • Never transmitted to NoteScribe servers

  • Never stored in our database

We only receive a success/failure confirmation from your device''s biometric system. You can enable or disable biometric authentication at any time in Settings.


6. Push Notifications

Push notifications are entirely opt-in. When enabled:

  • A device-specific push token is stored on our servers to deliver notifications

  • Notifications are sent for events like transcription completion

  • You can manage notification preferences in Settings at any time

  • When you disable notifications, your push token is immediately deleted from our servers

We use Apple Push Notification service (APNs) for iOS, Firebase Cloud Messaging (FCM) for Android, Web Push (VAPID) for browsers, and native OS notifications for the desktop app.


7. Desktop Application

The NoteScribe desktop app (available for macOS and Windows) has the following data behaviors:

  • Auto-updater: The app periodically checks for updates via GitHub Releases. This transmits your app version and platform; no personal data is sent.

  • System tray: The app runs in your system tray for quick access. No data is collected from this feature.

  • File ingestion: You can drag and drop files onto the app to upload them. Files are transmitted directly to NoteScribe servers over TLS and are not cached locally.

  • Native notifications: Desktop notifications use your operating system''s notification system. No notification data is sent to third parties.


8. Shared Recordings

When you share a recording via a share link:

  • Recipients can view the transcript and summary without authenticating

  • Access to shared recordings is logged (timestamp, IP address) for security purposes

  • You can revoke share access at any time, which immediately invalidates the link

  • Shared recordings are read-only for recipients


9. Content Moderation & Content Holds

NoteScribe includes an automated content moderation system that may flag content that appears to violate our Terms of Service. Flagged content is:

  • Placed on hold pending admin review

  • Reviewed only by authorized NoteScribe staff

  • Either cleared (no action) or removed following review

If your content is placed on hold, you will see a notification banner on the affected recording. You may contact [email protected] if you believe a hold was placed in error.


10. Analytics & Tracking

We use the following analytics tools:

Tool

Consent required

Purpose

Google Analytics 4 (GA4)

Yes

Page views, session analytics

Microsoft Clarity

Yes

Session heatmaps, UX improvement

Sentry

No (anonymized)

Error monitoring and bug fixing

GA4 and Clarity are only loaded after you give explicit consent via the cookie banner. You can change your consent at any time (see Section 11).


We use the following cookie categories:

  • Strictly necessary: Authentication session cookies. Always active.

  • Analytics: GA4 and Clarity. Only active with your consent.

  • Error tracking: Sentry (anonymized). Always active.

You can update your preferences at any time by clicking "Cookie Preferences" in the footer of any page. Your choices are saved and applied immediately.


12. Data Sharing & Third Parties

We share data only with the following trusted service providers:

Provider

Purpose

Supabase

Database hosting, file storage, authentication

OpenRouter

AI transcription and summarization APIs

DoDo Payments

Payment processing and subscription billing

Google Analytics 4

Usage analytics (consent-gated)

Microsoft Clarity

UX analytics (consent-gated)

Sentry

Error monitoring (anonymized)

Firebase Cloud Messaging

Push notification delivery (Android)

Apple Push Notification service

Push notification delivery (iOS)

We do not sell your data or share it with advertisers.


13. Your Rights (GDPR & Privacy Laws)

If you are in the European Economic Area, UK, or other regions with applicable privacy laws, you have the right to:

  • Access: Request a copy of your personal data

  • Rectification: Correct inaccurate data

  • Erasure: Request deletion of your data

  • Portability: Export your data in a structured format

  • Objection: Object to processing based on legitimate interests

  • Withdraw consent: Change your cookie or notification preferences at any time

To exercise these rights:

  • Data export: Account Settings → Export My Data

  • Account deletion: Account Settings → Delete Account

  • Session management: Account Settings → Manage Sessions

  • Other requests: Email [email protected]

We will respond within 30 days.


14. Data Retention

Your data is retained for as long as your account is active. When you delete your account:

  • Your audio files, transcripts, summaries, and alerts are permanently deleted within 30 days

  • Push notification tokens are deleted immediately

  • Device session records are deleted immediately

  • Consent records and audit logs are retained for up to 3 years as required by law

  • Anonymized aggregate analytics data may be retained indefinitely


15. Security

We take security seriously:

  • All data is encrypted at rest and in transit (TLS)

  • Row-Level Security (RLS) ensures users can only access their own data

  • Admin actions are logged in an immutable audit log

  • Rate limiting protects against abuse

  • Access to audio files requires authenticated and authorized requests

  • Biometric data never leaves your device

  • Push tokens are scoped to individual devices and deleted on opt-out


16. Children''s Privacy

NoteScribe is not directed at individuals under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it promptly.


17. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via an in-app announcement. The updated policy will be effective on the date published. Continued use of NoteScribe after the effective date constitutes acceptance.


18. Contact

For privacy questions or to exercise your data rights:

Email: [email protected]

We aim to respond to all inquiries within 30 days.

AI-powered meeting intelligence

Upload or record your meetings. Get structured outcomes — action items, decisions, and key points — extracted automatically.

No credit card required Sign up free Large file uploads