Back

Privacy & Data Processing Notice

Last updated: June 2026

NoteGist turns meeting recordings and notes into summaries, decisions, and action items. Because meeting content can be sensitive, this notice explains what we collect, how it is processed, who processes it, and how long it is kept.

1. Data we collect

  • Account: your email address (for sign-in).
  • Meeting content: audio you upload/record, transcripts, AI summaries, decisions, open questions, action items, tags.
  • Technical / usage: IP address, approximate location (country/city), user agent, pages visited, and AI-usage metrics. These are used for security and operations.

2. How we use it

Your audio and text are processed to produce transcripts and AI summaries — the core function of the service. To do this we send the content to the sub-processors below. We do not sell your data or use meeting content for advertising.

3. Sub-processors

  • Supabase — database, authentication, and encrypted audio storage.
  • Anthropic (Claude) — generates summaries, decisions, and action items from your transcript.
  • AssemblyAI and Soniox — speech-to-text (transcription) of your audio.
  • Railway — hosts the audio-enhancement worker that produces a noise-reduced playback copy of your recording.
  • Vercel — application hosting.
  • Resend — sends transactional email (signup confirmation, renewal reminders).
  • Paddle — merchant of record for card/global payments; handles checkout, billing, and receipts.
  • PayMongo — processes Philippine local payments (GCash, Maya, QR Ph).

4. Retention

  • Audio files are automatically deleted 60 days after upload. The transcript and summary are kept.
  • Notes (transcripts, summaries, action items) are kept until you delete them or your account.
  • Technical logs are auto-deleted after 90 days; AI-usage records after 180 days.

5. Security

  • All traffic is encrypted in transit (HTTPS).
  • Your notes are isolated per account with database row-level security; the audio bucket is private and served via short-lived signed URLs.
  • Third-party integration tokens (Slack/Notion) are encrypted at rest (AES-256-GCM).

6. Your choices

You can delete individual notes at any time, and export them (Markdown, PDF, Slack, Notion). To delete your account and all associated data, contact us.

7. Philippines Data Privacy Act (RA 10173)

The practices in this notice — collecting only what the service needs (section 1), defined retention periods (section 4), encryption and access isolation (section 5), and your rights to access, export, and delete your data (section 6) — are designed to align with the Philippines' Data Privacy Act of 2012 (RA 10173). If a concern about your data isn't resolved after contacting us, you may also reach the National Privacy Commission at privacy.gov.ph.

8. Contact

Questions about your data or this notice: support@notegist.com.

See also our Terms of Service and Refund Policy.