Privacy Policy
Last updated (MM/DD/YYYY): 10/07/2026
This policy explains what data Notebox collects, why, and who it's shared with. It's written to match what the app does today.
1. What we collect
Account data
- Email address and password, handled by our authentication provider. We never see your plaintext password.
- Display name (what the app calls you).
Your content
- We do not store your raw recordings or uploaded files. Voice recordings are sent directly to our transcription provider and never saved on our end; documents such as PDFs are read on your device, and only the extracted text is ever sent to us. Once transcription or extraction is done, the audio or file itself is discarded, and only the resulting text is kept.
- Pasted text, and the transcripts, AI-generated summaries, and note titles produced from your recordings/uploads/pasted text.
- If you use AI chat (Pro/Notetaker), the messages in each note's chat thread.
Usage data
- Counts used to enforce plan limits: notes created, voice notes used, and AI chat usage ("Ink"). These reset each billing period.
- A minimal record that a note was created: its type (voice, audio, text or document) and the date. This is kept even after you delete the note, so that your monthly quota counts every note you made. It contains none of your content.
Billing data
- Your plan tier and subscription status.
- A subscription or customer reference ID from the app store that handled your purchase. We do not collect or store your card number. The app store collects payment directly and acts as merchant of record.
What we don't collect
- No advertising or analytics trackers are embedded in the app.
- No location data.
- No access to contacts, photos, or other apps on your device beyond what you explicitly upload/record.
2. Device permissions
Notebox asks for as little as it can, and each one is used for a single thing:
- Microphone, to record audio when you start a recording, and only then.
- Notifications, so that a recording in progress can show an ongoing notification and so the app can tell you when a note has finished. Notebox sends no marketing notifications.
- Keeping the screen awake, so that a device going to sleep cannot interrupt a note while it is being made.
- Recording in the background, so that leaving the app or locking the screen during a recording does not end it.
- Internet access, to send audio for transcription and to save your notes.
Notebox does not ask for your location, your contacts, your photos, your camera, or access to your files beyond the single file you choose to upload.
3. Why we collect it
- To provide the Service: store your notes, transcribe audio, generate summaries, run AI chat, and enforce your plan's limits.
- To operate your account: authentication, plan management, billing.
- To communicate with you about your account, billing, or updates to the Service (not marketing).
4. Who we share it with
We share data only with the service providers that make Notebox work, and only the data each one needs to do its job:
- Our hosting provider runs our database, authentication and storage. Most of your content lives here, access-controlled so that only your account can read it.
- Our transcription provider receives the audio you record or upload, solely to turn it into text. Neither we nor they keep the audio once that is done.
- Our AI provider receives a note's text when a summary is generated, or when you use AI chat, solely to produce that response.
- The app store receives your payment details directly, to process subscriptions and to act as merchant of record. We never see them.
We describe these by what they do rather than by name. If you need to know exactly who they are, for a data request or any other reason, write to [email protected] and we will tell you.
We will never sell your data, or share it with advertisers.
We may disclose data if required by law, or to protect the rights, safety, or property of Notebox or our users.
5. Data retention
- We never store your raw recordings or uploaded files in the first place. See "Your content" above.
- Your notes, transcripts, and chat messages are kept until you delete them or close your account.
- You can delete individual notes at any time, or use "Clear all notes" in Settings to delete everything at once.
- When you delete a note, everything in it is erased immediately and permanently: its title, description, transcript, summary, and the whole AI chat thread attached to it. None of it can be recovered, by you or by us.
- What we keep after a deletion is the record described under "Usage data" above: that a note of a given type was created on a given date, and nothing else. We keep it so deleting a note can't refill your monthly quota for making new ones. It holds no part of what the note said, and it is destroyed when you close your account.
- Account deletion can be done at any time from Settings. It stops any subscription straight away and closes the account. Your account and everything in it are then kept for 14 days and permanently deleted after that.
- Those 14 days exist for two reasons, and we would rather say both. The first is you: deleting an account by mistake is easy and irreversible, and signing back in during that time cancels the deletion with everything still in place. The second is us: while an account is closing, its email address cannot be used to open a new one, which stops the free plan being collected over and over by the same person.
- Nothing is shared or used differently during those 14 days. The account is simply closed and waiting, and no part of it is touched except to delete it.
- Usage counters reset each billing period.
6. Security
- Data in transit is encrypted (HTTPS/TLS).
- Your notes are access-controlled at the database level (row-level security) so only your account can read them, not even other Notebox users.
- No system is perfectly secure; we can't guarantee absolute security, but we take reasonable measures and try our best to protect your data.
7. Children's privacy
Notebox isn't directed at children under 13. We don't knowingly collect data from users under that age. If you believe a child has created an account without parental consent, please contact [email protected] or delete the account.
8. Changes to this policy
We may update this policy at any time. Material changes will be announced in the app.
9. Contact
For any questions about this policy or your data, contact [email protected].