Legal
Privacy policy
What we collect, why we have it, who else touches it, and how to get it back or have it destroyed. Written to be read rather than to be defensible.
Last updated: 24 August 2026
Who we are
Webmatia Ltd, a company registered in England and Wales at 71-75 Shelton Street, London WC2H 9JQ, United Kingdom, operates Notepik. For the personal data of people who sign up for an account, we are the data controller. For the contents of the meetings our customers record, we are a data processor acting on their instructions, and the customer is the controller.
That distinction matters. If you were in a meeting somebody recorded with Notepik and want it deleted, the organisation that recorded it decides, not us. We will help you reach them.
What we collect
Because you gave it to us
- Your name and email address, and a hashed password if you did not use Google
- The workspace you created or were invited to, and your role in it
- Billing details, held by Stripe or PayPal rather than by us
Because you recorded a meeting
- The audio or video, either captured by our bot or uploaded by you
- The transcript, including who said what and when
- The summary, decisions and action items produced from it
- Comments your team leaves on it
This is the sensitive part. A transcript of a business meeting can contain anything the people in it said, about customers, staff, money or plans. We treat it accordingly, and it is why the whole system is built so that a workspace can only ever see its own.
Because the software runs
- Sign-in times and IP addresses, kept briefly to spot brute-force attempts
- Minutes processed and estimated model cost, so plan limits can be applied
- An audit log of administrative actions, such as changing somebody's role
- Error and performance logs, which are not deliberately linked to individuals
We do not use advertising trackers, and we do not sell or share anything with data brokers. Two things set cookies: the one that keeps you signed in, and Google Analytics, which we use to understand how people find and move around the public pages.
What Google Analytics is told is deliberately narrow. It receives the shape of a page rather than its address: a workspace appears as /app/[tenant] rather than by name, and a meeting as /app/[tenant]/meetings/[id]. It is never told anything about a meeting, never sent a search query, and never sent the address of a page whose link is itself a key. A shared meeting page is not reported to Google at all. If you would rather not be counted, any browser setting or extension that blocks Google Analytics stops it, and nothing about Notepik works differently as a result.
One thing you can do that we cannot do for you: a workspace owner or admin can publish a meeting to a public link. If they do, whoever receives that link can read that meeting without an account, and what they do with it afterwards is outside our control. Sharing is off unless somebody turns it on for a specific meeting, the link can be given an expiry, and revoking it takes effect immediately. Under the UK GDPR the workspace is the controller for that decision, and we are the processor carrying it out.
Why we are allowed to have it
- To perform our contract with you. Running your account, processing your meetings, taking payment.
- Legitimate interests. Keeping the service secure, preventing abuse, and improving reliability. Weighed against your interests, not assumed.
- Legal obligation. Tax and accounting records.
- Consent. Only where it genuinely applies, such as opting in to a digest email. Withdrawing it is a toggle in your settings, not an email to us.
Who else touches it
We use the following subprocessors. Each one gets only what it needs to do its job, and none of them is permitted to use your data for their own purposes.
- Supabase: Database and file storage. Processing region: Configurable, EU or US.
- Vercel: Application hosting. Processing region: Global edge.
- Recall.ai: Meeting recording and transcription. Processing region: Configurable.
- AssemblyAI: Transcription of uploaded recordings, deleted from AssemblyAI once transcribed. Processing region: US or EU, configurable.
- OpenRouter: AI summarisation and action item extraction. Processing region: US.
- Resend: Transactional email. Processing region: US.
- Stripe: Payment processing. Processing region: US and EU.
- PayPal: Payment processing. Processing region: US and EU.
Meeting content reaches Recall.ai, which records and transcribes it, and OpenRouter, which summarises it. Both process it to return a result and neither is permitted to train models on it. If that is unacceptable for a particular meeting, do not record that meeting.
Where data leaves the country it was collected in, transfers rely on Standard Contractual Clauses or an equivalent mechanism.
How long we keep it
- Meetings, transcripts and summaries: until you delete them, or 30 days after your workspace is closed. Closing is reversible for those 30 days; after that a scheduled job deletes the content and the workspace record together.
- Account details: for as long as the account exists.
- Email delivery records: 12 months, so “was the invite ever sent” has an answer.
- Audit logs: 24 months, because an audit log you can quietly shorten is not an audit log.
- Rate limiting counters: 24 hours.
- Invoices: as long as tax law requires, typically seven years.
Deleting a meeting removes the recording, the transcript, the summary and the action items. Backups age out on their own schedule, within 30 days.
Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to particular processing, or ask us to hand it to another provider. If you are in California, the CCPA gives you comparable rights, and we do not sell or share personal information as it defines those terms.
You can also complain to a regulator. Our lead supervisory authority is the Information Commissioner's Office in the United Kingdom. In the EU, you may complain to your own national authority.
Write to privacy@notepik.com. We answer within 30 days, and we do not charge for it.
Security
Covered properly on the security page. The summary: everything encrypted in transit and at rest, workspace isolation enforced by the database rather than by application code remembering to filter, and third-party credentials encrypted separately.
Children
Notepik is a business tool and is not for anyone under 16. We do not knowingly hold data about children, and will delete it if we find we have.
Changes
If we change this in a way that materially affects you, we will email you before it takes effect rather than editing the page and hoping you notice. The date at the top always reflects the current version.
Questions: privacy@notepik.com.
Still have a question?
Write to us and a person will answer. We do not run a ticket maze.
Get in touch