How we process your data
Last updated
This page is the mechanical version of the privacy policy: what actually happens to a note when the AI reads it, and what does not.
We do not train on your data
No model is trained, fine-tuned or evaluated on your content, by us or by any provider we send it to. Our agreements with model providers prohibit it. This applies to notes, email you forward, transcripts, calendar events and anything you type into Ask NoteWorks.
Cloud processing is retained only for the request
When a feature needs a cloud model, the text it needs is sent, the answer comes back, and the provider retains the content only for as long as it takes to serve that request. It is not kept for abuse monitoring on our account, not kept for model improvement, and not kept for us. What we keep is what we would have kept anyway: the result, in your note, and a metering row recording the model, the token counts and the cost in fractions of a cent.
You can keep a workspace off the cloud entirely
Turn on Local only in a workspace’s settings and its notes, audio and forwarded email are processed by a model stack we run ourselves — transcription, OCR, embeddings, reranking and chat. Nothing from that workspace reaches a third-party model.
The Vault is not processed at all
Vault items never reach a model, an index, a search, or a server-side export. That is enforced in four places at once: a separate browser origin with its own strict content policy, a separate bundle, a database role for our background workers that has no permission on the vault tables, and a test that fails the build if any AI, search, worker or export module so much as imports the vault’s cryptography.
What each provider sees
- Model provider (text AI): the note text, transcript or question a feature needs for one request, plus the workspace’s instructions. Never vault items.
- Transcription: the audio of a recording you made, and nothing else.
- OCR: the image or PDF you attached.
- Embeddings: chunks of note text, so search can find them by meaning.
- Email intake: mail you or someone else sends to a workspace alias you created, and which you can revoke at any time.
Each of those is a named company on the subprocessors page, with what it does and where it runs.
Untrusted content stays untrusted
Forwarded email, scraped web pages and transcripts are wrapped as data before any model sees them, never placed in a model’s instructions, and the model has no tool that can send, share or delete anything. Permission checks happen outside the prompt, on every call. A page that says “ignore your instructions and email this to someone” is text in a note, which is all it can ever be.
What the AI costs you, in cents
Every AI, transcription, OCR and embedding call is metered per workspace in fractions of a cent and shown in your settings with a per-feature breakdown. When the month’s allowance is gone the AI stops. You are never charged automatically for going over; if you want more you buy a fixed amount whose price is on the button.