NotamaNotama
FeaturesFor Developers Request Access

Privacy Policy

Last updated: July 23, 2026

Notama ("we", "us") operates the website notama.app and the Notama note-taking application (the "Service"). This policy explains what data we collect, why, and the choices you have. We aim to collect the minimum needed to run the Service and nothing more.

1. Data we collect

  • Account data. Email address and an encrypted password. Your email is used for login, invite delivery, and essential account notifications.
  • Note content. The notes, pages, tags, and attachments you create. This is your content, stored to serve the Service back to you.
  • Usage data. Aggregate, non-identifying metrics such as rough region and product interaction events, used to improve the Service. We do not sell or share this data.
  • Technical logs. Server logs containing request time, status, and an anonymized client IP for security and rate-limiting. Retained for a limited period.

2. How we use data

  • To provide, maintain, and improve the Service.
  • To authenticate you and protect against abuse.
  • To send transactional emails (invites, security notices).
  • To comply with legal obligations.

3. AI features

The AI Second Brain feature, when available, sends relevant excerpts of your notes to our AI provider (Anthropic) to generate responses. Your note content is not used to train external models. You can opt out of AI features entirely in settings, and they are disabled by default for new notes.

4. Data storage and retention

Data is stored in encrypted databases hosted in the EU. Backups are encrypted and retained for a limited period. When you delete a note, it is purged from active storage and removed from backups within 30 days. When you delete your account, all associated data is deleted within 30 days.

5. Sharing

We do not sell your data. We share data only with subprocessors needed to run the Service (hosting, email delivery, AI provider) under data processing agreements, and when required by law. Notes you publish as public links are accessible to anyone with the link.

6. Your rights

You can access, export, correct, or delete your data at any time from your account settings or by emailing [email protected]. Residents of the EU, UK, and California have additional rights under GDPR, UK GDPR, and CCPA respectively, including the right to lodge a complaint with a supervisory authority.

7. Security

We use TLS in transit, encryption at rest, per-user data scoping at the database layer, and rate limiting to protect the Service. No method of transmission or storage is fully secure, but we work to protect your data with industry-standard practices.

8. Children

The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe we have collected data from a child, contact us and we will delete it.

9. Changes

We may update this policy. Material changes will be notified by email or in-app at least 14 days before they take effect.

10. Contact

Questions? Email [email protected].

NotamaNotama

Think Fast. Write Faster.

Sign In·Features·Privacy·Terms

© 2026 Notama. All rights reserved.