Notely AI

Privacy Policy

Last updated September 21, 2026

Notely AI ("Notely", "we", "us") is a note-taking workspace with an AI assistant that can read from and act on tools you choose to connect. This policy explains what we collect, why, how it is protected, and the choices you have. We only collect what the product needs, and we never sell your data or use your notes to train AI models.

1. Information we collect

Account information. Your email address, display name and, if you sign in with Google or Microsoft, the profile picture and account identifier those providers share with us. If you create a password, we store only a salted hash of it.

Content you create. Notes, folders, tags, tasks, comments and anything you type or paste into Notely, including messages you send to the AI assistant and the assistant’s replies.

Data from connected tools. When you connect a tool (for example Gmail, Google Calendar, Google Drive, Notion, Slack or Jira), we access only the data that the permissions you approved allow, only when you or the assistant asks for it — for example the subject and sender of recent emails, upcoming calendar events, or a document’s title and text. Where a connector can write (send an email, create an event, post a message), nothing is written until you approve the specific action.

Technical and usage information. Browser type, device and operating system, IP address, approximate location derived from it, the pages and features you use, timestamps, and diagnostic logs such as error reports and request identifiers.

2. How we use information

  • To provide the service: store and sync your notes, run searches, and power the AI assistant.
  • To carry out what you ask the assistant to do across your connected tools, with your approval for any change.
  • To keep your account secure: sign you in, detect abuse, rate-limit requests and investigate incidents.
  • To operate and improve Notely: measure reliability and performance and fix bugs.
  • To communicate with you about your account, security and material changes to the service.
  • To comply with law and enforce our Terms & Conditions.

We do not sell personal information, and we do not use your notes, messages or connected-tool data to train machine-learning models.

3. Accounts and authentication

You can create an account with an email address and password or by continuing with Google or Microsoft. With federated sign-in we receive your verified email address, name, profile picture and a stable account identifier from the provider; we do not receive or store your provider password. Sessions are kept in a secure, HTTP-only cookie. You can review and revoke active sessions from your account settings.

4. Connected tools and integrations

Connecting a tool is always your choice and always uses that vendor’s own authorization (OAuth) screen, where you can see exactly which permissions are requested. Before you are sent to the vendor, Notely shows you what the assistant will be able to do with the connection and what the vendor will receive. You can choose optional permissions, and you can disconnect a tool at any time from Settings → Connections.

The access and refresh tokens a vendor issues are stored encrypted at rest and are used only to make the requests you or the assistant initiate. Disconnecting a tool revokes the token where the vendor supports it and deletes it from our systems. Data fetched from a tool to answer a question is not copied into your notes unless you or the assistant explicitly save it there.

5. Google OAuth and Google user data

Notely’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request only the scopes needed for the features you enable (for example read-only access to Gmail messages, read-only access to calendar events, or read-only access to Drive files), and we ask for write scopes (such as sending email or creating events) only if you opt in to them.
  • Google user data is used only to provide the Notely features you can see and control — never for advertising.
  • We do not transfer Google user data to third parties except as necessary to provide those features (for example, sending relevant excerpts to the AI model provider you have chosen), to comply with law, or with your explicit consent.
  • Humans do not read Google user data except with your permission for support, for security investigations, or as required by law.
  • You can revoke Notely’s access at any time in Notely or at your Google Account’s third-party access settings.

6. AI features and your own model keys

The assistant sends the parts of your notes and connected-tool data that are needed to answer a request to a large-language-model provider. Which provider depends on the deployment’s configuration or, if you add your own model under Settings → AI, on the provider and key you chose. Your own API key is stored encrypted, is never displayed again after you save it, and is used only for your requests. Model providers process the data under their own terms; we do not permit them to use it for training where the provider offers that control.

7. Cookies and similar technologies

Notely uses strictly necessary cookies: a session cookie that keeps you signed in and a security cookie that protects forms from cross-site request forgery. We do not use advertising or cross-site tracking cookies. Your browser’s local storage may hold a copy of unsaved note edits so they survive a crash; it is cleared once the server confirms the save. You can clear cookies and site data in your browser at any time; doing so signs you out.

8. Data storage and security

Data is stored on servers operated by the deployment’s hosting provider and is encrypted in transit (TLS) and at rest. OAuth tokens and your own AI keys are additionally encrypted with an application-level key. Access to production systems is restricted to authorized personnel, logged, and protected by multi-factor authentication. No method of transmission or storage is completely secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as required by law.

9. Data retention and deletion

  • Notes and content stay until you delete them. Deleted notes go to Trash and are permanently removed after 30 days or when you empty Trash.
  • Connected-tool tokens are deleted when you disconnect the tool or delete your account.
  • Diagnostic logs are kept for up to 30 days; audit records of assistant actions are kept for 12 months so you can review what the assistant did.
  • When you delete your account, your personal data and content are removed from active systems within 30 days and from backups within 90 days, except where we must keep records to comply with law.

10. Your rights and choices

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to lodge a complaint with a supervisory authority. In Notely you can edit your profile, export your notes, disconnect tools, revoke sessions and delete your account from Settings. For anything else, contact us at support@notely.app; we respond within 30 days.

12. Children's privacy

Notely is not directed to children under 16 (or the higher age required in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Changes to this policy

We may update this policy as Notely evolves. We will post the new version here, update the date at the top and, for material changes, notify you by email or in the app before they take effect. Continued use after the effective date means you accept the updated policy.

14. Contact

Questions, requests or concerns about privacy: support@notely.app. Please include enough detail for us to identify your account and the request.