Legal

Privacy Policy

Your notes are yours. This policy explains what data NoteWhispr collects, why, and how you stay in control of it.

Last updated: February 1, 2026

1. Who we are

NoteWhispr ("we", "us", "our") operates the website at www.notewhispr.com and the related applications. If you have any questions about this policy, email hello@notewhispr.com.

2. What we collect

Account data

  • Name and email address (required to create an account)
  • Hashed password (we never store the plaintext)
  • Profile preferences (display name, avatar, language)

Content you create

  • Notes, transcripts, recordings (audio/video), uploaded files
  • Folders, tags, and organisational metadata
  • Marketplace listings (if you choose to sell)

Usage and technical data

  • Browser type, IP address, and approximate location (country)
  • Pages viewed and actions taken within the app (for product improvement)
  • Error logs so we can fix bugs quickly

Payment data

All payments are processed by Stripe. We never see or store your full card number — only a token and the last 4 digits for receipts.

3. Why we collect it

  • To run the service (auth, storage, transcription, marketplace)
  • To bill subscriptions and pay sellers
  • To respond to your support requests
  • To improve the product (anonymised, aggregated usage analytics)
  • To meet legal obligations (tax, anti-fraud)

4. How AI handles your content

Smart Tools (Summarise, Translate, Flashcards, etc.) and audio transcription use third-party LLM providers (Google Gemini and OpenAI Whisper). When you run a tool, the relevant note or audio file is sent securely to those providers for processing only. Your content is never used to train external models, and is not retained by the providers beyond what's necessary to return the result.

5. Who we share data with

We share limited data only with the service providers who help us operate:

  • Stripe — payment processing
  • Google (Gemini) — AI text processing
  • OpenAI — audio transcription (Whisper)
  • MongoDB Atlas / cloud hosting — encrypted data storage

We do not sell your data, share it with advertisers, or use it for marketing other people's products.

6. Where data is stored

Data is stored on encrypted cloud infrastructure. Backups are encrypted at rest. If you delete an item from the Vault or delete your account, your data is removed from production systems within 30 days and from backups within 90 days.

7. Your rights

  • Access — request a copy of everything we hold about you
  • Export — download your notes and recordings as a portable archive
  • Correction — update inaccurate profile info from your Account page
  • Deletion — delete individual items or your entire account at any time
  • Object — opt out of non-essential analytics

To exercise any of these rights, email hello@notewhispr.com. We respond within 7 days.

8. Children

NoteWhispr is not directed at children under 13 (or under 16 in the EU/UK). We do not knowingly collect data from minors. If you believe a child has signed up, contact us and we'll remove the account.

9. Security

We use industry-standard practices: TLS encryption in transit, encryption at rest, hashed passwords (bcrypt), JWT-based authentication, and least-privilege access for our team. No system is 100% secure, but we take it seriously and we'll notify affected users without delay if anything material changes.

10. Changes to this policy

If we make significant changes we'll email all active users at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the current version.

11. Contact

Questions, complaints, or data requests:
hello@notewhispr.com

Original text
Rate this translation
Your feedback will be used to help improve Google Translate