Privacy

Plain-English
privacy.

What we collect, why we collect it, and how to delete everything. Written so a person can read it, not just a lawyer.

Effective
1 June 2026
Last updated
5 July 2026

tl;dr

Your voice is transcribed into text on your device — the audio is never uploaded. Notabe uses the resulting text to auto-title, tag, and (on request) summarize each note, and to generate a vector embedding for search. AI processing happens at Google (Gemini) and Anthropic (Claude) under their commercial API terms — they don't keep your inputs, and we don't opt into training. There is no account to create; identity lives on your device and syncs over iCloud. No ads, no resale, no third-party trackers in the app.

Who we are

Notabe is operated by Alican Basak, based in Istanbul. Contact: hello@notabe.app. We are the data controller for everything described below.

What we collect

Your identity

There is no sign-up, no email, and no password. When you first open Notabe, the app generates a random identifier that is stored on your device and mirrored to your private iCloud key-value store, so the same identity — and the same subscription — follows you across your Apple devices. We never receive your name or email unless you write to us.

Your notes

Every note consists of its text (typed, or transcribed from your voice on your device), an AI-suggested title, tags, an optional summary, and a captured-at timestamp. This is the core of the product. Notes live in your SwiftData store and sync via your private iCloud; the text and embedding are also processed by our backend to power AI features (below).

Voice and transcription

When you capture a voice note, speech is turned into text on your iPhone or iPad using Apple's on-device speech recognition. The audio recording is never sent to us or to any third party. Notabe keeps the transcribed text — the note — not a recording of your voice.

Embeddings

A vector embedding is a list of numbers that represents the meaning of a note's text. We use embeddings to power semantic search and the Graph of connected notes ("find that thing I said about Roman aqueducts"). Embeddings are derived from your data and are treated as your data. They are deleted when you delete the note.

Summaries and tags

When Notabe auto-titles and tags a note, or when you generate a summary, we send the note's text to Google's Gemini API (see Sub-processors) and store the result. Summaries, titles, and tags are part of the note.

Subscription state

If you upgrade, we receive billing state from Apple via RevenueCat: which plan, when it started, when it renews, whether it's active. We do not see your card number, billing address, or Apple ID email. Apple handles payment; we handle access.

Aggregate analytics

We track product events: app opened, note captured, search performed, summary generated, paywall shown, upgrade completed. We never send note text, titles, tags, transcripts, summary text, or any content you capture. Events are pseudonymous (a random identifier, not tied to your name).

What we do not collect

  • We do not see your real name or email unless you write to us.
  • We do not access your iCloud, contacts, calendar, photos, or any file on your device beyond what you explicitly save.
  • We do not track you across other apps or websites.
  • We do not have advertising partners.
  • We do not sell, rent, or share your data with anyone for marketing.
  • We do not use your notes, transcripts, summaries, or embeddings to train any AI model — neither ours nor a third party's.

How AI features work

When Notabe auto-titles and tags a note, or when you use a summary, semantic search, resurfacing, or collection suggestions, we send the necessary text to Google (Gemini API) or Anthropic (Claude API) — the choice is per-feature. Both providers are contractually obligated under their commercial API terms not to retain your inputs after processing and not to train on them. We do not opt into any training programs. After the model responds, we store only the outputs (title, summary text, suggested tags, suggested collection names) and a vector embedding generated via Voyage AI. Transcription itself never reaches these providers — it happens on your device.

You can disable AI features in Settings → Privacy → Disable AI processing. With this on, notes are kept as your own text and title only. No text is sent to Google, Anthropic, or Voyage; no summary is generated and no embedding is created. Notes are then found by their words, tags, and titles rather than by AI-ranked meaning.

Sub-processors

We use the following companies to run Notabe. Each is contractually bound to handle your data only as we direct.

  • Apple — App Store, iCloud sync, on-device speech recognition, push notifications. On-device speech and iCloud data stay within Apple's stack; we receive subscription receipts.
  • Railway — API hosting and Postgres database (with pgvector). Receives note text, embeddings, titles, tags, and summaries.
  • Google — AI processing (Gemini API) for summaries, auto-titles, auto-tags, and tag normalization. Note text for AI calls only; not retained.
  • Anthropic — AI processing (Claude API) for collection-name generation. US. Note titles for naming calls only; not retained.
  • Voyage AI — Embedding generation. US. Note text for embedding only; not retained per their terms.
  • RevenueCat — Subscription state. US. Your on-device identifier and subscription status.
  • Vercelnotabe.app landing site and legal pages. Public content only.

We will update this list before adding a new sub-processor.

Where your data lives

Our Postgres database lives in our Railway project. AI processing (Google, Anthropic, Voyage) happens in the United States; we transmit data under standard contractual clauses (SCCs) for GDPR, with retention not permitted at the processor. Your notes also live on your device and in your private iCloud.

Deleting your data

In the app: Settings → Privacy → Delete My Data. This removes your notes, embeddings, and server-side records; we erase everything within 30 days. We can also do it manually if you email hello@notabe.app.

Your rights (GDPR, KVKK, CCPA, LGPD)

You have the right to access, correct, export, and delete your data. Reach out at hello@notabe.app and we'll handle it within 30 days.

Children

Notabe is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, please email us and we will delete the account.

Changes to this policy

We post material changes here. The effective date at the top moves; the substance always matches.

Contact

For privacy questions: hello@notabe.app.