Privacy Policy

Last updated: September 3, 2026

Noutify ("we", "us") makes a personal capture app that turns your typed notes, voice recordings, and photos into short, organized highlights. This policy explains what we collect, why, and the choices you have. Contact: support@noutify.app.

What we collect

We do not sell your data, show ads, or embed third-party analytics or tracking SDKs in the app or on our website.

How your content is processed

Your notes, highlights, and account data are stored on Noutify's own server (our database and file storage). AI processing is carried out by internally hosted AI models running on our own GPU infrastructure. These models run inside infrastructure we operate and control, and the content they process is not transmitted to an external model provider for model training or for any other secondary purpose. If we ever introduce an external AI provider, we will update this policy and the list in Third-party services below before doing so.

Our internally hosted models power these features:

In each case, only the content needed to produce the result is processed: the note text, photo, or recording itself. No account identifiers are attached — your email address, user ID, password, and session token are never included, so what the model receives is not labeled with the account it came from. Your content is, however, processed as you wrote it: if a note happens to mention your name or someone else's, that text forms part of what is processed. The result (a transcription, extracted text, or highlights) is returned to our server and the request ends there. We do not use your content to train AI models, and we do not license or sell it to anyone who might.

Memory. Noutify can identify and retain useful key points from your content — names, places, routines and similar details — to improve your experience over time. This is an application feature rather than a separate AI service, and those key points are held on infrastructure we operate. You can view everything Noutify has memorized and delete any of it whenever you choose (see "Your controls" below). Details that look like passwords, card numbers, or other secrets are detected and never stored.

Noutify is a connected app, not an offline/on-device one: your captures travel over the network (encrypted in transit) to our server, where our own models process them.

Google user data

This section covers data Noutify obtains through Google APIs, and applies in addition to everything above.

What we access. Two things, each only if you choose them:

Why we access it. Solely to let you place a highlight on your own Google Calendar, and to keep the two in step afterwards. There is no other purpose.

How Calendar access works. Your device talks to Google Calendar directly. Noutify's servers never connect to the Google Calendar API, never receive a Google access or refresh token, and hold no Google credentials of any kind. Calendar events you have not linked to a Noutify highlight are read on your device to display them to you and are never transmitted to us.

What we receive, and what we actually read. Noutify receives Google Calendar event resources from Google. When the app asks Google for an event it does not restrict which fields come back, so Google's reply arrives at your device complete — including parts we have no use for, such as the description, the guest and attendee list and their email addresses, the organizer, conferencing information and attachments. We would rather be precise than flattering about this: that data is received by the app, held in memory for the moment it is handling Google's reply. Whether we read it is a separate question, and we do not: descriptions, attendee information, organizer information, conferencing information, and other Google-authored event metadata are not read, not stored, and never transmitted for AI processing. The only fields the app reads at all are the event's identifier, its title, its start and end time, and its location — the minimum the Calendar feature needs in order to work.

Read on your device but never sent to us. The event's title and location are shown to you on the Calendar screen. Neither is transmitted to our servers, stored in our database, or used in AI processing.

What reaches our servers. Only for an event you created from Noutify:

Nothing else from your calendar is sent to us — no descriptions, guest lists, attendee names or email addresses, locations, attachments, conferencing links, free/busy information, or the contents of any calendar other than the events you linked yourself.

Renaming an event does not rename your highlight. Noutify owns the wording of your task; Google owns its timing. We deliberately do not copy text you wrote in Google Calendar into your Noutify content, so no Google-authored text can travel on into the parts of Noutify that use AI. Rescheduling and deleting still sync.

Whether it reaches AI processing. Only one thing does: the start date and time of an event you linked. Once that date is on your highlight it is ordinary Noutify content, so it is included when you search your highlights or post a progress update on one — both handled by our internally hosted models. No Google-authored text — no title, description, attendee, organizer, conferencing detail or location — ever reaches AI processing, because none of it is copied into Noutify content in the first place. Google-authored Calendar content is isolated from Noutify's general AI processing by design, not merely by policy.

A note about calendar identifiers. Google identifies a calendar by a string, and for the main calendar on an account that string is the account's email address. If you pick a specific calendar in Noutify's calendar chooser, that identifier is stored alongside your highlight so we know where its event lives — so in that case your Google email address is held in our database as a calendar identifier. If you never open the chooser, Noutify stores Google's generic primary keyword instead and no address is stored. Either way the identifier only addresses the calendar, and is never used in AI processing.

What Noutify writes into your calendar. Adding a highlight to Google Calendar creates an event carrying your highlight's text as the event title, a short quote in the event description, the date and time, and a setting telling Google not to send its own notification for it. This happens when you tap "Add to calendar", and also automatically for dated tasks once you have connected Calendar — a default you can turn off in the app. The event is rewritten the same way whenever the highlight changes.

The quote in the description is meant to be the words from your own note that the highlight came from. It is produced by the model that reads your note and is shortened by us, but we do not check it back against your note word for word — so it may occasionally be the model's rendering of what you wrote rather than an exact copy. Your highlight's text, used as the event title, is written by the model in the same way.

Whether it is stored. Yes — as part of the highlight, in our database. It is deleted when you delete the highlight (30-day trash, then permanent), when you disconnect Calendar, or when you delete your account.

What we never do with it. We do not sell Google user data. We do not use it for advertising or for any form of profiling or targeting. We do not transfer it to data brokers, information resellers, or advertising networks. We do not use it to develop, create, train, or improve generalized or foundational artificial-intelligence or machine-learning models, and we do not permit anyone else to do so with it. No human at Noutify reads it, except where you explicitly ask us to for support, where it is necessary for security purposes such as investigating abuse, or where we are required to by law.

Who Google user data is shared with. Google Workspace data that reaches Noutify is processed within our own controlled infrastructure, using the internally hosted models described in How your content is processed. It is not transferred to any external AI provider, for model training or for any other secondary purpose. We do not share, transfer, or disclose Google user data to any third party, with three narrow exceptions: to Google itself, when your device writes an event you asked us to create; to the infrastructure providers listed in Third-party services, which host our systems and never receive Calendar content; and where we are compelled by law.

Limited Use. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Noutify's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace API data is not used to create, train, or improve generalized or foundational machine-learning or artificial-intelligence models, whether our own or anyone else's.

Revoking access. You can disconnect Calendar at any time in the app, or revoke Noutify's access from your Google Account permissions page. Revoking stops all further calendar access immediately; highlights already created stay in Noutify until you delete them.

Third-party services

These are every external service Noutify uses that can receive your data. There are no others, and we do not use analytics, advertising, or tracking SDKs anywhere in the app or on this website. No external AI provider appears on this list: all AI processing runs on our own GPU infrastructure, as described in How your content is processed above.

Noutify's application servers, database, file storage, and the AI models that process your content all run on infrastructure we operate ourselves. Your notes, photos, voice recordings, highlights, memorized key points, and anything received from Google Calendar are not sent to an external AI provider.

Where it's stored and for how long

Your controls

Permissions we request

You can decline or revoke these in your device settings; the related capture mode simply won't be available.

Security

Passwords are hashed with bcrypt; access to your data requires your authenticated session token. We use reasonable technical measures to protect data in transit and at rest. No system is perfectly secure, so we cannot guarantee absolute security.

Children

Noutify is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data.

Changes

We may update this policy; material changes will be reflected here with a new date. Continued use after an update means you accept the revised policy.

Contact

Questions or requests (including data access/deletion): support@noutify.app.