Privacy

    Your conversation is not training data.

    Notuly writes the report and forgets the rest: our own servers in Amsterdam, the audio deleted within a minute of processing, no archive. This page sets out exactly what happens to your data, and where you can check it for yourself.

    Available on macOS, Windows, iOS and Android.

    Used by people at these organisations.

    Stayokay logo
    Tweede Kamer logo
    Breda University logo
    Het Scheepvaartmuseum logo
    Zozijn logo
    Nike logo

    Short answer

    Privacy at Notuly is a fact, not a promise. Your audio is processed on our own servers in Amsterdam and deleted within a minute of processing. The report lands in your inbox and is then gone from our system: no archive, no training on your conversations, no Big Tech anywhere in the process.

    Processing
    Our own AI on Dutch servers in Amsterdam
    Recording
    The audio is deleted within a minute of processing
    Archive
    None; the report lives only in your email
    AI training
    Never; your conversations are not training data
    Data processing agreement
    Under the GDPR, on Team and above
    Policy
    The full legal text is at notuly.app/terms

    We don't store your conversations.

    The audio is deleted within a minute of processing. Once your report has been sent, we no longer hold your data. What we don't keep can't leak.

    Our own servers in AmsterdamAn ISO 27001-certified data centre. Your data never leaves the EU.
    Our own AI modelSelf-hosted in the EU. No Big Tech anywhere in the process.
    No training on your conversationsWhat's said stays yours.
    Data processing agreement (GDPR)Available to organisations, on Team and above.

    We work in line with:

    ISO 27001.

    We work in line with ISO standards. Our data servers run in an ISO 27001-certified data centre in Amsterdam.

    In black and white

    What we commit to.

    At Notuly, privacy is not small print. These are our commitments, and you can check every one of them.

    • EncryptionTLS 1.2+ for everything in transit, AES-256 for the short time the audio sits on the server during processing.
    • Data breachesNotuly reports data breaches to the Dutch Data Protection Authority within 72 hours; business customers are informed within 48 hours.
    • Data processing agreementAvailable to organisations on Team and above (GDPR Article 28).
    • Your rightsAccess, rectification and erasure. We only keep your account details; delete your account, and everything is gone straight away.
    • No central archiveThere is no searchable database holding all your conversations, and so no central point that can leak.

    Our own AI

    No Big Tech looking over your shoulder.

    How it works

    From recording to deletion.

    This is how Notuly handles your data, from the moment you press record to the moment nothing is left.

    1

    You record

    Phone on the table or the desktop app switched on. Notuly takes the notes in the background: no bot joining your meeting.

    2

    Processing in Amsterdam

    The audio travels encrypted to our own servers in Amsterdam, where our own AI processes it. Your data never leaves the EU.

    3

    The report in your email

    Within ten minutes the report with the decisions and action points is in everyone's inbox. That's where it lives: in your email, not with us.

    4

    Audio deleted

    Within a minute of processing, the recording is gone. No archive, no database, no copy held by Notuly.

    On all your devices

    Also on macOS and Windows.

    Meeting on Teams, Zoom or Google Meet? The desktop app takes the notes straight from your laptop. And the iPhone and Android apps capture every conversation on the go.

    Questions.

    Where is the data hosted?+

    Notuly runs entirely on its own servers in Amsterdam; your data never leaves the EU. We use our own AI infrastructure, self-hosted in the EU: no Big Tech anywhere in the process and no public APIs that retain data.

    Is my audio stored?+

    Only temporarily, while it's being processed. Once the report is ready and has been emailed to you, the audio is deleted: within a minute of processing. Notuly keeps no archive, no cloud storage, no database.

    Are my conversations used to train AI?+

    No, never. Your conversations are not used to train AI models, not by us and not by anyone else. We run our own AI infrastructure and don't depend on outside parties.

    Does Notuly offer a data processing agreement?+

    Yes. A data processing agreement (GDPR Article 28) is available to organisations on Team and above. The standard text is on the data processing agreement page; you can request it via team@notuly.nl.

    Is Notuly GDPR compliant?+

    Yes. Servers in Amsterdam, data that never leaves the EU, audio deleted within a minute of processing and no AI training on your conversations. For organisations, a GDPR data processing agreement is available on Team and above.

    What does Notuly do if there's a data breach?+

    Notuly reports data breaches to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours; business customers are informed within 48 hours. Because the audio is deleted after processing and no archive exists, there is little to leak.

    What are my rights as a user?+

    Under the GDPR you have the right of access, rectification and erasure. We store no content (no reports, no audio), only your account details such as your name and email address. Delete your account, and everything is gone straight away.

    How do you handle cookies?+

    As sparingly as possible. Essential cookies keep you logged in; everything else sits behind your consent. You can change your choice at any time via the Cookie settings button in the footer.

    Where can I find the full privacy policy?+

    The full legal text sits with the terms and conditions at notuly.app/terms. This page explains what we do; the policy is the text that counts.

    Notuly and privacy in short: audio is processed on our own servers in Amsterdam and deleted within a minute of processing. Notuly runs its own AI infrastructure, self-hosted in the EU: no Big Tech in the processing and no data going to American servers. There is no archive and no database; the report goes to your email and is then gone from our system. Data breaches are reported to the Dutch Data Protection Authority within 72 hours, and business customers are informed within 48 hours. A GDPR data processing agreement is available to organisations on Team and above.

    Test it on your own conversation.

    Download the app, record a conversation and see what lands in your email afterwards: the report, and nothing else. Three conversations free, no payment details needed.