Privacy notice
Effective September 30, 2026. Plain language, specific about where your data goes.
AI Notetaker has a free local mode that needs no account, and an account service we operate. This notice covers both. The local mode uses your own AI provider keys. With a subscription, cloud sync sends finished note text from the desktop app to your workspace and copies workspace notes into the desktop library. This notice also covers the website.
This website
The site sets no advertising or analytics cookies and runs no advertising or analytics scripts. Fonts and icons are served from this site. If you create an account, we set one session cookie so you stay signed in. If a page hits an error, a technical error report may be sent to Sentry. Download links are looked up by our server, so your browser does not contact GitHub until you follow a link to it.
Local mode: your own keys
- Raw microphone and meeting audio is saved on your device before any provider request. The two channels stay separate.
- Your provider keys stay in the desktop app's operating-system credential store. Existing extension users keep their keys in protected browser storage. We never receive them.
- Audio and text go directly to the providers you configure, under their terms and retention rules.
- If you subscribe and turn on sync, finished desktop note text syncs to your workspace and workspace notes are copied into the desktop library. Web edits refresh workspace copies on sync; desktop-origin notes are protected from automatic overwrites. Deletions and settings do not sync back. Raw audio and provider keys remain on this device.
- We do not receive local-mode recordings, transcripts or notes, and local mode sends us no telemetry or error reports.
- The desktop app keeps itself up to date. It checks for a newer release on GitHub (about every six hours, and at startup). On macOS and Windows it installs update packages signed with the project's update key and restarts only when nothing is recording; on Linux it opens the release page for you to download the new .deb. GitHub, not us, receives your IP address and the app version. Turn automatic updates off in the tray menu and the app only checks when you ask.
- Google Drive export is optional. Google receives what you send it.
Accounts and sync: what we collect
- Account: your email address, a salted and hashed password, and your workspace and membership details. You can sign in from the website, the desktop app or the extension. The desktop app sends your password once, never stores it, and keeps only a revocable session token in your operating-system credential store; signing out deletes it.
- Notes: if you subscribe and sync, the transcripts, summaries, decisions and action items from your meetings, stored in your workspace.
- Billing: your plan and its status. Stripe holds your payment details, not us.
- Sign-in and security records: when you sign in we record a description of your device, your IP address and timestamps. We use them to show your signed-in devices, let you revoke them, limit repeated failed sign-ins, and investigate abuse. A session or extension token ends when you sign out, revoke it, or it expires.
- Audio: we never receive or store your recordings. They stay on your device, and there is no audio in the synced library.
Every workspace is isolated from the others. Your AI provider keys stay on your device and are never sent to us. Server logs use workspace-safe identifiers and failure categories, not audio, transcript text, keys or tokens.
Who is responsible for your notes
The people in your meetings are people too. When you record a call, the notes contain what they said. For the notes and recordings in your workspace, you (or the organization that owns the workspace) decide what is recorded and why, and we process that content only on your behalf to provide the service. For your account, sign-in, billing and security records, we decide how the data is used, as described here. If your organization needs a data processing agreement, contact us.
We do not sell your personal information, do not share it for advertising, and do not use your recordings, transcripts or notes to train AI models. The providers below receive content only to perform the task we send them and handle it under their own terms, which may include limited safety or abuse-monitoring retention.
Sensitive information
Do not record or upload information that law or contract requires a special regime for, such as protected health information, payment card data, or government identification numbers, unless you have confirmed that this service is suitable for it. The account and sync service is not offered as a HIPAA-compliant service.
Who processes data for accounts and sync
| Provider | Used for | Data involved |
|---|---|---|
| Railway | Hosting and database | Account records and synced notes |
| Stripe | Payments and billing portal | Your email and payment details, which Stripe collects directly |
| Resend | Sign-up and password-reset email | Your email address |
| Sentry | Error diagnostics for the account and sync service | Technical error details and workspace-safe identifiers, not designed to include audio or transcript text |
| Sign-in, and Drive export only if you connect it | What you choose to sync or export |
Each provider handles the data it receives under its own terms and privacy policy. Providers and the servers that run the service may be located in the United States and other countries, so your data can be processed outside the country where you live. We may add or replace providers and will update this table when we do.
Google sign-in and Drive
Connecting Google is optional and always your choice. If you connect Drive, AI Notetaker asks only for access to the files it creates in your Drive, so it can export a meeting you choose as a Google Doc. It does not request access to your other Drive files, your calendar, or your email.
- We store your Google account email and encrypted access tokens so these features keep working. Choosing Disconnect in your account deletes them.
- If you choose Continue with Google to sign in or create an account, we receive only your Google email address and whether Google has verified it. We use it to find or create your account and keep no Google access token for sign-in.
- We use Google data only to provide sign-in and Drive export. We do not use it for advertising, sell it, or use it to train AI models.
- We do not let people read your Google data unless you ask us to, it is needed to investigate abuse or a security problem, or the law requires it.
- You can also remove access at any time from your Google Account permissions.
AI Notetaker's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Keeping, deleting and exporting your data
- Delete any meeting or folder from the app. In the synced library it moves to Trash, where you can restore it for 30 days; after that, or when you delete it from Trash, its transcript and summary are removed.
- Workspace owners choose how long hosted notes are kept, and you can export your data from the account page.
- We keep account data while your account exists. After you delete an account or workspace, its notes and account records are removed, and copies in system backups are overwritten on the normal backup schedule. We keep records that the law or our tax and fraud-prevention duties require, such as billing records held by Stripe, for as long as they require.
- Clearing your browser history does not delete your notes. Synced notes live in your workspace on our servers, so they are unaffected by anything you do in your browser; if you clear cookies you only need to sign in again. The desktop app keeps new local recordings and notes in a private data folder, so clearing browser history, cookies or cache leaves them alone. They are removed if you delete that app data or reset or lose the device; nothing is stored on our servers to restore them. Existing extension users keep their local notes in the browser profile until they export them to the desktop app. Export local notes you need to preserve, or use a subscription to sync finished note text to the cloud.
- Deleting the legacy extension does not delete desktop app data, provider account data, exported files, or data held by services you connected. Delete those where they live.
Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal information, to object to some uses, to withdraw consent you gave, and to complain to your data protection authority. Most of this you can do yourself: export from the account page, delete meetings, disconnect Google, revoke devices, or delete your account. For anything else, contact us. We will not treat you worse for exercising a privacy right. If you are a participant in someone else's meeting, ask the person or organization that recorded it first, because they control that recording; we will help where we can.
Children
AI Notetaker is not for anyone under 16, and we do not knowingly collect personal information from children. If you believe a child has an account, contact us and we will delete it.
Security incidents
We protect data with access controls, workspace isolation, encryption in transit, and encrypted storage of Google tokens, but no system is perfectly secure. If an incident affects your personal information, we will notify you and the authorities where the law requires it.
Meeting participants
Always tell participants you are recording and get the consent that your local law and workplace policy require. AI Notetaker asks you to acknowledge this before every recording. It is not legal advice.
Security and contact
The source code is public. Report a suspected vulnerability privately through the security policy. For questions about this notice, email support@apercallc.com or open an issue on the project's issue tracker, and never post keys, recordings or transcripts there. We will show a new effective date whenever this notice changes, and tell signed-in users about material changes in the app or by email before they take effect.