Privacy Policy
Last updated: July 28, 2026
NOTEXEC is a note-taking and productivity application that lets you capture, organize, and act on your thoughts through voice dictation, AI-powered summaries, Google Calendar sync, and full offline support. At NOTEXEC, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service at notexec.com. Please read this policy carefully.
1. Information We Collect
1.1 Information You Provide
- Account Information: Username and password when you create an account.
- Note Content: All notes, dictations, checklists, images, tables, and other content you create or upload to the Service.
- Calendar Data: If you enable Google Calendar sync, we access your calendar events to create, read, and update them on your behalf.
- Communications: Any messages, feedback, or support requests you send to us.
1.2 Information Collected Automatically
- Usage Data: How you interact with the Service, including features used, pages visited, and actions taken.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Log Data: IP address, access times, and error logs.
- Cookies: Session cookies for authentication and preferences. See our Cookie Policy section below.
1.3 Third-Party Integrations
- Google OAuth: If you sign in with Google, we receive your Google email address and profile information as permitted by your Google account settings.
- OpenAI: When you use AI summarization features, note content is transmitted to OpenAI's API for processing. OpenAI does not train on our API data per their enterprise terms.
- Web Speech API: Voice dictation uses your browser's built-in speech recognition. Audio may be processed by your browser vendor's servers depending on your browser and settings.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process and store your notes and content
- Sync your notes with Google Calendar (when enabled)
- Generate AI summaries of your notes (when requested)
- Authenticate your account and protect against unauthorized access
- Communicate with you about service updates, security alerts, and support
- Analyze usage patterns to improve the Service
- Comply with legal obligations
3. Data Storage & Security
We implement industry-standard security measures to protect your data:
- Encryption in Transit: All communications use TLS 1.3.
- Password Hashing: Passwords are hashed using Werkzeug's strong hashing (PBKDF2-SHA256).
- Access Controls: Strict internal access controls limit employee access to user data.
- Regular Audits: We conduct regular security assessments and vulnerability scanning.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in these limited circumstances:
- With Your Consent: When you explicitly authorize us to share information.
- Service Providers: With trusted third-party providers who help us operate the Service (e.g., hosting, AI processing, email delivery), bound by confidentiality agreements.
- Legal Requirements: If required by law, court order, or governmental regulation.
- Business Transfer: In connection with a merger, acquisition, or sale of assets, provided the acquiring party agrees to honor this Privacy Policy.
5. AI & Machine Learning
Our AI summarization feature transmits your note content to OpenAI's API. Key facts about this processing:
- Content is transmitted only when you explicitly request AI summarization
- OpenAI does not use data submitted via their API for model training (per their API data usage policy)
- We do not share your data with any other AI providers
- You can use all core features of the Service without ever using AI features
6. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data we hold.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated data ("right to be forgotten").
- Portability: Export your data in a machine-readable format (Markdown, HTML, or PDF).
- Restriction: Request restriction of processing under certain circumstances.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@notexec.com. We will respond within 30 days.
7. Data Retention
- Active Accounts: We retain your data as long as your account is active.
- Deleted Accounts: Upon account deletion, your data is permanently deleted within 30 days. Some anonymized or aggregated data may be retained for analytical purposes.
- Backups: Backups may retain data for up to 90 days before automatic deletion.
- Legal Holds: We may retain data longer if required by law or pending litigation.
8. Cookies & Tracking
We use the following types of cookies:
- Essential Cookies: Session cookies for authentication and security. These are required for the Service to function.
- Preference Cookies: Store your theme preference (light/dark mode) and other settings.
- Analytics Cookies: Minimal, privacy-respecting analytics to understand usage patterns. We do not use third-party advertising cookies or tracking pixels.
You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning properly.
9. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us.
10. International Data Transfers
Your data may be stored and processed in the United States or other countries where our service providers operate. By using the Service, you consent to the transfer of your information to countries that may have different data protection rules than your country of residence.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we comply with applicable data transfer mechanisms, including Standard Contractual Clauses where appropriate.
11. California Privacy Rights
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Know what personal information is collected, used, shared, or sold
- Delete personal information held by businesses
- Opt out of the sale of personal information (note: we do not sell personal information)
- Non-discrimination for exercising CCPA rights
To exercise your CCPA rights, contact us at privacy@notexec.com with "CCPA Request" in the subject line.
12. GDPR Compliance
For users in the European Economic Area (EEA), we process personal data under the following lawful bases:
- Contractual Necessity: Processing required to provide the Service you requested
- Consent: Processing based on your explicit consent (e.g., Google Calendar sync)
- Legitimate Interests: Processing for service improvement, security, and fraud prevention
You have the right to lodge a complaint with your local data protection supervisory authority.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting a notice on the Service
- Sending an email to the address associated with your account
- Updating the "Last updated" date at the top of this policy
Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@notexec.com
Postal: NOTEXEC, Inc., 123 Innovation Drive, Suite 100, Wilmington, DE 19801, United States
Data Protection Officer: dpo@notexec.com