1 Our Privacy Philosophy
At Nota, we believe note-taking software should respect your privacy. Notes represent your thoughts, ideas, calculations, and personal projects.
We adhere to two core design principles: Local-First Privacy and Data Transparency. We do not sell your personal data, we do not show advertisements, and we do not train artificial intelligence models on your private note content.
2 Information We Collect
We collect information depending on how you choose to use Nota:
Account & Auth Data
Email address, profile name, avatar URL, and session tokens created during registration or sign-in.
Cloud-Synced Content
Notes, workspaces, and media explicitly saved to cloud workspaces for synchronization and collaboration across devices.
3 How We Use Information
We utilize the collected information strictly for the following purposes:
- Authenticating your identity and managing your workspace permissions.
- Synchronizing your cloud notes and media files across your registered devices.
- Enabling realtime collaboration when working in shared workspaces.
- Processing payments and managing Pro subscription billing via secure payment gateways.
- Fulfilling AI assistant requests when explicitly triggered by you.
4 AI Processing & Third-Party Providers
Nota offers AI editing capabilities (summarization, text generation, math solving). When you invoke AI tools:
- Bring Your Own Key (BYOK): If you supply an API key (e.g. OpenAI, Anthropic, Google), requests are routed through API calls authenticated by your key. Your custom keys are stored encrypted on your device.
- No Third-Party Model Training: Prompt text sent to supported model APIs is processed solely to generate your requested response. We specify zero-retention flags where supported by providers.
5 Local Notes & Offline Isolation
Notes stored in Local Workspaces on the Nota Desktop app reside purely on your computer's local file system.
Local notes, local media attachments, and offline drafts are never transmitted to our cloud servers. You maintain total offline control over these files.
6 Data Security & Encryption
We implement industry-standard security measures to safeguard your information:
- In Transit: All data exchanged between Nota clients and servers is encrypted using modern TLS (Transport Layer Security).
- At Rest: Cloud databases and database backups employ AES-256 encryption.
- Session Protection: Auth tokens are securely stored using HTTP-only cookies and OS keychain storage mechanisms where available.
7 Data Retention & Account Deletion
We retain cloud-synced data for as long as your account remains active. You may export your notes at any time in standard Markdown, JSON, or media formats.
If you decide to delete your account, all cloud workspaces, cloud notes, and personal metadata associated with your account will be permanently erased from our primary databases.
9 Your Privacy Rights (GDPR & CCPA)
Depending on your location, you have rights under regulations like GDPR or CCPA, including:
- Right of Access: Request a copy of the cloud personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete account details.
- Right to Erasure: Request the deletion of your cloud data.
- Right to Portability: Export your notes in standard open formats.
10 Children's Privacy
Nota is not directed to children under 13 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us immediately.
11 Contact Us
If you have questions, feedback, or data privacy requests regarding this Privacy Policy, please contact our Privacy Team at: