Subprocessors

Last updated

These are the companies that can see part of your content while NoteWorks does its job. Each one is here because a feature needs it; each row says exactly what that one receives.

Subprocessors and what each receives
CompanyWhat it does for usWhat it receives
AnthropicText AI: classification, summaries, action items, inline rewriting, Ask NoteWorksThe note text, transcript or question one request needs. Never vault items. Not retained past the request; not used for training.
SonioxSpeech to text for recordingsThe audio of a recording you made, and its transcript on the way back.
Voyage AIEmbeddings and reranking for searchChunks of note text, so search can find them by meaning.
MistralOCR for images, PDFs and handwritingThe image or document you attached.
ResendInbound email to workspace aliases, and the one outbound email we send (a workspace invitation)Mail sent to an alias you created and can revoke; for invitations, the recipient's address and the link.
Cloudflare (R2)Object storage for audio and attachmentsEncrypted-in-transit uploads in a private bucket. No public URLs; access is by short-lived signed links.
GoogleSign-in, and Calendar if you connect itYour name, email and profile image. With Calendar connected: event times, titles and attendees. We never request access to Gmail.
StripePayments and subscription billingYour billing email and payment details, which go to Stripe directly — NoteWorks never sees a card number.

What none of them get

Your vault. It is encrypted on your device with a key we have never held, so there is nothing to hand over — see how we process your data.

Turning most of this off

A workspace with Local only enabled uses a model stack we run ourselves for transcription, OCR, embeddings, reranking and chat. For that workspace, the AI rows above do not apply.

Changes

We will announce a new subprocessor in the app before it starts processing anything, not after.