Privacy
Last updated
NoteWorks is built and operated by Strange Digital Group, LLC. This page says what we hold, why, who else touches it, and how to take it back or end it. It is written to be read, not to be defensible.
What we hold
- Your account. Name, email address and profile image from the Google account you sign in with. We never ask Google for access to your mail.
- Your content. Notes, tasks, recordings, transcripts, attachments, calendar events you connect, and email you forward to a workspace alias.
- Operational records. Sync and job logs, an audit log of administrative actions in each workspace, per-workspace AI cost metering, and push-notification device tokens.
- Vault items, which we cannot read. See below.
The Vault is encrypted where we cannot reach it
Vault items are encrypted in your browser with a key derived from your passphrase. That passphrase never leaves your device and we have never had the key. A database dump of the vault tables reveals item counts and timestamps and nothing else — not titles, not URLs, not usernames. This is not a promise about our conduct; it is a property of the construction, and the same property is why we cannot help you recover a forgotten passphrase.
No training on your data
We do not train models on your content, and we do not permit our providers to. Content sent to a cloud model is retained by that provider only for the duration of the request and is not used for training. The list of providers is on the subprocessors page, and the mechanics are on the data processing page.
What we never do
- Sell your data, or share it with advertisers. There are no ads and no ad networks.
- Put third-party analytics or tracking scripts in the app. There are none.
- Send email, share a page, post anywhere, or delete anything on your behalf without an explicit action by you. AI in NoteWorks proposes; you confirm.
- Read your vault, index it, embed it, or include it in a server-side export.
Where it lives
On servers we operate, in a Postgres database with per-workspace row-level security, and in private object storage for audio and attachments. Backups are encrypted, kept for 30 days, and then expire. Nothing in a backup is ever read for content.
How long we keep it
- Notes you delete go to a per-workspace trash and are purged after that workspace’s retention window, which you set.
- Notes on the Free plan are never deleted for being old. Past the plan’s window they become read-only, stay searchable, and stay in every export.
- Your account, when you ask us to delete it, after a stated grace period in which one click cancels. Backups holding it expire within 30 days after that.
Your rights
Export everything from Settings → Your account: a zip of every workspace as Markdown and JSON, plus your account record. Delete your account from the same place. Both are self-service; neither requires writing to us or waiting for us. If you want a correction, an explanation, or a copy in another form, write to us on the support page.
Children
NoteWorks is not intended for anyone under 16 and we do not knowingly hold their data.
Changes
When this page changes materially we will say so in the app before the change takes effect, not after. The date at the top is the last time any of it changed.