Your notes, your AI, and who can see what
note2it connects AI assistants to your notes. That is the point of the product, and it's also the thing worth being careful about. This page explains exactly what can reach your notes, when, and how to shut it off.
If you want the legal version, that's our Privacy Policy. This is the plain one.
The short version
- Nothing reaches an AI assistant until you connect it yourself.
- Connections are per-account, permission-scoped, and revocable in one click. Revocation is immediate.
- Every action a connected assistant takes is written to your audit trail.
- We don't sell your data, and we don't train models on your notes.
- Our AI provider doesn't train on your content either.
Two different things, often confused
There are two ways AI touches your notes, and they have different privacy shapes. Worth separating them.
1. Features we run for you — meeting transcription, summaries, rewriting, Page AI Chat.
You press the button, we send that content to our AI provider, the result comes back and lands in your notebook. The provider acts as our processor: it works under contract, on our instructions, and it doesn't train on your content. This runs only when you trigger it.
2. Assistants you connect — Claude, ChatGPT, Perplexity, Gemini over MCP.
Different relationship. Here the assistant acts on your instructions, not ours. You approve the connection on an authorization screen, you choose the permissions, and from then on that assistant can search and read — and edit, only if you granted it — within the scope you approved. Its provider handles that content under its own privacy policy, which is worth reading.
We store the app's name, the permissions you granted, and a hashed credential. Never the credential itself.
What you control
| Control | Where |
|---|---|
| See every connected app | Settings → AI assistants |
| See what permissions each one has | Settings → AI assistants |
| Revoke a connection — effective immediately | Settings → AI assistants |
| Review every action taken on your account | Your audit trail |
| Export your pages as Markdown | Notebook workspace — per page, section, or notebook |
| Delete your account and everything in it | Settings → Account |
Connections are off until you turn them on. We never connect an app on your behalf.
Recording meetings: the part that involves other people
When you record a meeting, note2it captures your microphone and the call audio. That means other people's voices and words — people who may not have a note2it account and never agreed to anything with us.
You're the one with the relationship to those people, so you're the one who needs to tell them. Practically: say you're recording before you start. In some places and some workplaces, that's a legal requirement, not a courtesy — and the rules differ by province and country.
note2it doesn't show anything to the other people on your call — there's no bot in the meeting and no banner on their screen. What it does instead: before every recording, you confirm that you're responsible for telling participants and for getting any consent the law where you are requires. The checkbox comes back every single time; it's not a one-time formality.
Audio stays until you delete it — the recording itself, the page it lives on, or your account. Transcripts and summaries stay in your notebook until you delete them. Dictation clips are never stored: the audio goes to transcription, the text comes back, and the clip is gone.
Speaker labels in transcripts — "Speaker 1", "Speaker 2" — are estimated from the transcript text itself. We don't analyze voices, we don't create voiceprints, and we don't use any biometric identifiers.
If you took part in a recorded meeting and want to know what we hold, write to privacy@note2it.com. In most cases the person who recorded the meeting controls that content, so we'll route your request to them — and help as the law requires.
Where your data lives, and who touches it
note2it is a Québec company, and note2it runs in Québec: the application, your notes, your recordings, and your account data are hosted and stored in Montréal, Canada. What leaves the country is specific and listed below.
Before personal information goes to any provider outside Québec, we assess the protection it will receive. Here is every provider that touches your data, what it does, and where:
| Provider | What it does | Region |
|---|---|---|
| Vercel | Application hosting | Montréal, Canada (yul1) |
| MongoDB Atlas | Account and content storage | Montréal, Canada (ca-central-1) |
| Amazon Web Services (S3) | Uploaded media and meeting audio | Montréal, Canada (ca-central-1) |
| OpenAI | Transcription, summaries, speaker labels, AI chat | United States |
| Stripe | Payments | United States |
| Transactional email | United States | |
| Google Analytics | Analytics — only if you opt in | United States |
| Google / GitHub | Sign-in with Google or GitHub — only if you use it | United States |
| OpenStreetMap (Nominatim) | Address search in the map block — only the address you type | European Union |
We update this list before adding a provider that processes personal information.
What we don't do
- We don't sell your personal information.
- We don't train models on your notes — and our AI provider doesn't either.
- We don't load analytics or marketing trackers unless you opt in. The default is strictly necessary cookies only.
- We don't make decisions about you based solely on automated processing.
Compliance, briefly
We handle personal information under Québec's Law 25, the GDPR where it applies, and Canada's PIPEDA. If we ever have a confidentiality incident with a risk of serious injury, we notify the Commission d'accès à l'information du Québec and the people affected, as Law 25 requires.
Privacy questions go to a real person: Vitaliano Torchia, Privacy Officer — privacy@note2it.com.
Security questions: security@note2it.com.