Security & privacy

Your conversations. Yours alone.

Note records the meetings that matter most - so we built it to the strictest standards we could find, alongside some of the largest pharmaceutical companies in the world. Here is exactly how your words are protected.

Encrypted at every step.

From the moment you press record to the moment you read the summary, the conversation is never exposed.

01

Encrypted on the device

Every recording is encrypted with AES-256 the moment it is written to the Note's memory. The key never leaves your account. A lost, stolen or borrowed Note exposes nothing - the storage reads as noise without your key.

02

Encrypted in transit

When recordings sync to the Note app, they travel over TLS 1.3. Nothing moves in plain text - not on your Wi-Fi, not on hotel networks, not anywhere.

03

Encrypted end-to-end in the app

Inside the Note app, your recordings, transcripts and summaries stay end-to-end encrypted. We built it so the conversation belongs to you - not to us, not to a network, not to anyone in between.

How your data is handled.

Plain answers, no legal fog. What is stored, where, and what we never touch.

What the device stores

Encrypted audio only, until you sync or delete it. No account details, no contacts, no location history - the recorder knows nothing about you.

What the app stores

Your recordings, transcripts, summaries and action items - end-to-end encrypted under your account. You choose what to keep, share or delete.

What we never do

We don't sell data, we don't train models on your conversations, and we don't keep raw audio you have deleted. Your meetings are not our product.

Where processing happens

Audio is processed to produce transcripts and summaries. Enterprise customers can pin processing and storage to their own region.

GDPR controls, built in.

The controls your legal and compliance teams ask about - as product features, not paperwork.

Consent first

Note is built for lawful recording. The app reminds you to inform participants, and Enterprise policies can require a spoken consent line at the start of every recording. Always follow the recording laws that apply where you meet.

Your rights, one tap away

Access, correct, export or delete any recording, transcript or summary from the app at any time. Deletion is real deletion - when you remove a conversation, it is gone from device, app and cloud.

Retention you control

Set how long recordings and transcripts live - days, months or until you delete them. Enterprise admins can enforce retention windows across the whole fleet, so nothing outlives its purpose.

DPA and audit trail

We sign a Data Processing Agreement with every business customer. Enterprise adds audit logs, SSO and customer-managed encryption keys, so your compliance team can see exactly who touched what, and when.

The standards behind it.

Note was developed with some of the largest pharmaceutical companies in the world, and adheres to the strictest standards we could find.

GDPRSOC 2ISO 27001ISO 27701HIPAAEN 18031CEFCCUKCAULRoHS

Need the paperwork?

Security whitepaper, DPA and compliance documentation are ready for your legal and IT teams. For fleets and customer-managed keys, see Note Enterprise.