N2Inote2it
← All posts

We let Claude read your notes. Here's exactly what that means.

Connecting an AI assistant to your notes is the whole point of note2it — and it's fair to ask what that actually gives it access to. Here's the honest version: what reaches an AI, when, and how to shut it off.

Most note apps are a box you put things in. note2it is a box your AI assistant can open — search it, read it, write to it, with your permission.

That's the whole pitch. It's also, reasonably, the thing that makes people pause. "An AI can read my notes" is a sentence that deserves follow-up questions.

So here are the answers, without the legal hedging. The formal version lives in our Privacy Policy; this is the plain one.

There are two different things happening

They get conflated constantly, and they have genuinely different shapes.

Features we run for you: meeting transcription, summaries, rewriting, Page AI Chat. You press a button, we send that content to our AI provider, the result comes back into your notebook. The provider works under contract, on our instructions, and doesn't train on your content. Nothing goes anywhere until you trigger it.

Assistants you connect: Claude, ChatGPT, Perplexity, Gemini, over MCP. Different relationship entirely. Here the assistant works for you, not for us. You approve the connection on an authorization screen, you pick the permissions, and from that point it can search and read your notes — and edit them, only if you granted that.

Once content is in the assistant's hands, its provider handles it under their privacy policy, not ours. Worth reading whichever one you connect.

What a connected assistant can and can't do

It can do what you approved and nothing else.

We store three things about a connection: the app's name, the permissions you granted, and a hashed credential. Never the credential itself.

Every action a connected assistant takes on your account gets written to your audit trail. Not a summary — the actual record of what was searched, read, and changed. Edits made through MCP are precise and undoable, so an assistant that misunderstands you leaves something you can reverse rather than a mess you have to reconstruct.

And you can revoke any connection from Settings in one click. Revocation is immediate, not "within 24 hours".

Connections are off until you turn them on. We never connect an app on your behalf.

The part that involves other people

This is where we'd rather be direct than reassuring.

When you record a meeting, note2it captures your microphone and the call audio. Which means it captures other people — their voices, their words, and often their names and whatever they happened to say about their work. Those people don't have a note2it account. They never agreed to anything with us.

You're the one with the relationship to them, so you're the one who has to tell them. Say you're recording before you start. In a fair number of places, and in a fair number of workplaces, that isn't politeness — it's a requirement, and the rules differ depending on where everyone is sitting.

On our side, we make that hard to forget: before every single recording, note2it asks you to confirm that you're responsible for telling participants and getting whatever consent the law where you are requires. The checkbox comes back every time — it's not a one-time formality you clicked past in January. We don't put a bot in your meeting or a banner on anyone's screen; the recording happens in your browser, and the responsibility to speak up is yours.

The recording itself stays yours: audio is kept until you delete it — the recording, its page, or your account. And speaker labels like "Speaker 1" are estimated from the transcript text alone. No voiceprints, no biometric identifiers, ever.

We'd rather say all that plainly than bury it in a clause. A meeting recorder that never mentions the other people in the meeting is a product with a blind spot.

Where your data lives

We're a Québec company, and Québec has one of the stricter privacy regimes in North America — Law 25 applies to us directly, with no size exemption for small companies.

Here's the part that surprises people: note2it runs in Montréal. The application, your notes, your recordings, and your account data are hosted and stored in Canada. What leaves the country is specific: AI processing (OpenAI, in the United States), payments (Stripe), and transactional email. Before any transfer, we assess the protection it'll receive.

We publish who our providers are and what each one does — the full table lives on our Trust page at note2it.com/trust — so you don't have to email us to find out.

What we don't do

We don't sell your personal information.

We don't train models on your notes. Neither does our AI provider.

We don't load analytics or marketing trackers unless you opt in. Default is strictly necessary cookies only — the banner isn't theatre.

We don't make decisions about you based solely on automated processing.

Why we're writing this instead of a feature post

Every other post on this blog announces something new. This one doesn't.

We build a product whose main advantage is that an AI can reach into it. The honest consequence is that "how does that work, exactly" is the first question any careful person asks — and the answer shouldn't be buried in section 7 of a policy document.

If you have a question this doesn't cover, privacy@note2it.com goes to a real person: Vitaliano Torchia, our Privacy Officer. Security questions go to security@note2it.com.