Privacy Policy

Last updated: September 30, 2026

This Privacy Policy explains how PixelPerfect Studios LLC ("Notate," "we," "us," or "our") collects, uses, and shares information when you use Notate, including the desktop, mobile, and web apps and the notate.md website (together, the "Service"). Notate is built around plain markdown files you own, and we aim to collect as little as possible.

Information we collect

  • Account information. If you create an account, we collect your email address, a display name, and a securely hashed password. If you enable two-factor authentication or a passkey, we store the associated credentials.
  • Your notes and files. If you use a paid plan with sync, your notes, folders, tags, images, and attachments are stored on our servers so they can sync across your devices. If you use Notate locally without an account, your notes stay on your device and we do not receive them.
  • Audio you record. If you use meeting or lecture transcription, the audio you record is processed to produce a transcript and may be stored temporarily to complete that processing.
  • Payment information. Paid subscriptions are processed by our payment provider. We receive limited billing details (such as plan and status) but do not store your full card number.
  • Usage and device data. We collect limited technical information needed to operate the Service, such as sync and device metadata, AI usage counts, and basic diagnostic logs.
  • Launch notification list. If you submit your email to be notified when Notate launches, we store that email address with our email provider so we can send you launch updates. You can unsubscribe at any time, and we use it only for that purpose.

How we use your information

  • To provide, maintain, and secure the Service, including sync, storage, and account authentication.
  • To provide AI features you choose to use, such as chat, summaries, and transcription.
  • To process payments and manage subscriptions.
  • To respond to support requests and send you service-related messages, such as password resets.
  • To detect, prevent, and address abuse, security issues, and technical problems.

How your notes are stored

Your notes are plain markdown files. On local and paid plans alike, the files on your device remain standard markdown you can open in any editor. On paid plans, a copy is stored on our servers to enable sync and backup.

AI features and third-party processing

When you use an AI feature, the relevant content (for example, the text of a note or the audio of a recording) is sent to a third-party AI provider to generate the result. AI features are optional and can be turned off in Settings. AI outputs can be inaccurate, so please review them before relying on them.

Your own AI keys. You can choose to connect your own Anthropic or OpenAI API key. We store it encrypted, use it only to make the requests you trigger, and never display it again after you save it. Requests made with your key are sent to that provider under your own account with them, and that provider's terms and privacy policy apply to them. You can remove your key at any time.

Tools you connect. If you turn on the Notate MCP server or the command-line tool and connect another program to your account, such as an AI assistant, that program can read and change your notes with the access you grant it. What it does with that content is governed by its own terms, not ours. These connections are off by default, and you can revoke a connected program's access at any time.

Link previews

When you paste a web link into a note, Notate can fetch that page to show its title, description, and preview image. Our servers make that request, so the website you linked to sees a request from Notate rather than from your device, and the preview image is stored with your other images. With end-to-end encryption turned on, the desktop and mobile apps fetch previews directly from your device instead, and the web app does not show them.

Service providers

We share information with vendors who process it on our behalf to run the Service, under agreements that limit their use of it:

  • Anthropic: AI chat, summaries, tagging, writing tools, descriptions of images in your notes, and turning meeting transcripts into notes.
  • OpenAI: audio transcription.
  • Voyage AI: embeddings that power semantic search.
  • Cloudflare: storage for images, attachments, link preview images, and recorded audio.
  • Railway: application hosting and the database.
  • Resend: transactional email (such as password resets) and the launch notification list.
  • Stripe: payment processing for paid plans on the web.
  • RevenueCat: in-app subscription management on iOS and Android.

When you use your own AI key, requests made with it go to that provider under your account with them rather than ours.

We do not sell your personal information, and we do not use the content of your notes to train our own models.

Data retention

We retain your account information and synced content for as long as your account is active. Deleted notes move to Trash and are removed on a retention schedule. If you delete your account, we permanently delete your account and its synced content immediately, except a minimal record we are required to retain. See Delete Your Account for exactly what is removed and what is kept.

Your rights and choices

  • Access and export. Your notes are plain files you can copy and take with you at any time.
  • Correction and deletion. You can edit or delete your notes, and delete your account, from within any Notate app or the web.
  • AI controls. You can turn AI features on or off in Settings.

Depending on where you live, you may have additional rights over your personal information. Contact us to exercise them.

Security

We protect information in transit with encryption, store passwords hashed, and offer two-factor authentication and passkeys. No method of storage or transmission is perfectly secure, but we work to protect your information and to keep the Service safe.

You can optionally turn on end-to-end encryption for your notes. When it is enabled, your note titles, content, summaries, transcripts, and tags are encrypted on your device with a key derived from your password before they reach our servers, so we store only ciphertext and cannot read them. A recovery phrase lets you restore access if you forget your password. Because AI features and server-side semantic search need to read your note text, they are unavailable while end-to-end encryption is turned on. Image files and attachments are not end-to-end encrypted in this version; they are protected in transit and stored privately, but they are not encrypted with your key.

Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you.

Contact us

Questions about this policy? Get in contact with us using Support.