Privacy Policy

Last updated

This Privacy Policy explains how Notera("Notera," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our website at https://notera.so, our mobile applications, and related services (together, the "Services").

Notera is a collaborative planning canvas, operated by Notera, a sole proprietorship, based in California, United States. For the purposes of the EU and UK General Data Protection Regulation we are the data controller for the personal information described here. You can reach us at any time at support@notera.so.

If you do not agree with this policy, please do not use the Services.


Summary

What we collect. Your account details, the content you create on your boards, your billing status, and basic technical and usage data. Payment card details go directly to Stripe and never reach our servers.

What we do not do. We do not sell your personal information or share it for advertising. We do not run advertising on the Services. We do not use session replay and we do not record your screen. We do not use your board content to train machine-learning models.

Collaboration is visible. Boards you share with collaborators, publish via a share link, or embed elsewhere are visible to the people who can reach them. A public share link makes that board readable by anyone who has the URL, without signing in.

Your controls. You can export all of your data, correct it, or delete your account at any time from your account settings. Deletion is completed within 30 days.



1. Information we collect

Information you provide

Information collected automatically

Billing information

If you subscribe to a paid plan, payment card details are collected and processed directly by Stripe. We never receive, see, or store your full card number, expiry date, or security code. From Stripe we receive only a customer identifier, subscription status, billing interval, renewal date, and invoice history. See Stripe's privacy policy.

Sensitive information

We do not ask for, and do not intentionally collect, special-category or sensitive personal information, such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, sexual orientation, or precise geolocation. Please do not store such information on your boards. If you choose to, you remain responsible for that content, and we process it only as ordinary board content under this policy.

Google API services

Notera's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the drive.file scope, which grants access solely to the specific files you pick in the Google file picker, not to the rest of your Drive. We do not use Google user data for advertising, and we do not transfer it to others except as needed to run the import you asked for.

2. How we use your information

We use personal information to:

We do not use your board content to train machine-learning or AI models, and we do not sell it.

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 of the GDPR:

4. When and with whom we share information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose personal information only in the situations below.

Service providers (subprocessors)

We rely on the providers below to run the Services. Each processes personal information only on our instructions, under a written agreement, and only for the purpose listed. All of them store and process data in the United States.

ProviderPurposeData involved
ClerkAccount creation, sign-in, and session managementEmail address, name, profile image, authentication credentials, IP address
InstantDBPrimary application database and real-time syncProfile data, boards, cards and their contents, comments, notifications, activity history
VercelApplication hosting, plus cookieless traffic and performance analyticsIP address, request metadata, aggregated page-view and performance data
Cloudflare R2Storage for uploaded images, files, and board thumbnailsFiles you upload and their metadata
StripeSubscription billing and payment processingEmail address, billing details, payment card data (collected directly by Stripe), transaction history
PostHogProduct analytics: which features are used and where errors occurPseudonymous usage events, page views, device and browser type, coarse location derived from IP address
SentryError and crash reportingError messages, stack traces, browser and device information, user identifier
ResendDelivery of transactional and notification emailEmail address, message content, delivery status
UpstashRate limiting and abuse preventionIP address, request counts
GoogleGoogle Drive import, only if you connect your accountGoogle account email, and the specific Drive files you choose to import
PinterestPinterest import, only if you connect your accountPinterest account identifier, and the boards and pins you choose to import

Other disclosures

5. Collaboration, sharing, and public boards

Notera is built for shared work, so some information is visible to other people by design. Please read this section before putting sensitive material on a board.

6. International data transfers

Notera is operated from the United States, and every provider listed in section 4 stores and processes data in the United States. If you use the Services from outside the United States, including from the EEA, the United Kingdom, Switzerland, Japan, or South Korea, your personal information will be transferred to, stored in, and processed in the United States, whose data-protection laws may differ from those of your country.

Where we transfer personal information out of the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses(together with the UK International Data Transfer Addendum where applicable), incorporated into our agreements with the providers listed above, or on another lawful transfer mechanism such as a provider's certification under the EU–US Data Privacy Framework. Email support@notera.so if you would like more detail about these safeguards.

7. Cookies and analytics

We use a small number of cookies, and we use no advertising cookies or advertising trackers of any kind. Our Cookie Notice lists every cookie we set, what it does, and how long it lasts.

For product analytics we use PostHog in cookieless mode, meaning it stores no identifier on your device. For traffic and performance measurement we use Vercel Analytics and Speed Insights, which are also cookieless and do not build cross-site profiles.

We do not use session replay. We do not record your screen, your keystrokes, or the contents of your boards for analytics or diagnostic purposes.

8. Social logins and connected accounts

You can register and sign in using a third-party account through our authentication provider, Clerk. When you do, we receive a limited profile from that provider: typically your name, email address, and profile image. We do not receive your contact list, your friend list, or your password.

Separately, you can connect Google Drive or Pinterest to import content. If you do, we store an access token, a refresh token, your account email or identifier at that provider, and the granted scopes, so that the import can run. Tokens are encrypted at rest. You can disconnect a linked account at any time in your settings, which revokes and deletes the stored tokens.

We do not control how third-party providers process your information. Please review their privacy policies for details.

9. How long we keep your information

We keep personal information only as long as we need it for the purposes in this policy, unless a longer period is required by law.

Backups are rotated on a rolling basis. Where information persists in a backup after deletion, it is isolated from further processing and removed when that backup expires.

10. How we keep your information safe

We use appropriate technical and organisational measures to protect personal information, including encryption in transit (HTTPS), encryption at rest for stored files and OAuth tokens, database-level permission rules that restrict every record to the users entitled to it, scoped pre-signed URLs for file access, rate limiting, CSRF protection, and audit logging of privileged administrative actions.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities where the law requires it.

11. Staff access to your content

Access to production data is limited to the people who need it to operate the Services. Support and administrative tooling allows authorised staff to view account-level information and, where necessary to investigate a support request or a suspected violation of our Terms, to access an account. Privileged administrative actions are recorded in an audit log. We do not browse user boards for any other reason.

12. Children's privacy

The Services are not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will deactivate the account and delete the information promptly. If you believe a child has provided us with personal information, contact us at support@notera.so.

13. Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal information: to access it, to correct it, to delete it, to obtain a portable copy, to restrict or object to certain processing, and to withdraw consent. We do not carry out automated decision-making that produces legal or similarly significant effects.

Exercising your rights

  • Access and portability. Download a complete machine-readable copy of your data from Settings → Security → Your data. Signed in, you can also request it directly from /api/account/export.
  • Correction. Update your profile and preferences at any time in your account settings.
  • Deletion. Delete your account from your account settings. See section 9 for what happens next.
  • Marketing opt-out. Use the unsubscribe link in any marketing email, or turn off product email in your notification settings. We will still send essential service messages such as billing and security notices.
  • Anything else. Email support@notera.so and we will respond within the period applicable law requires: within 30 days under the GDPR, and within 45 days under US state privacy laws.

We do not charge for exercising your rights and we will not discriminate against you for doing so. We may ask you to verify your identity before acting on a request.

Right to complain. If you are in the EEA, the UK, or Switzerland and believe we have mishandled your personal information, we would like the chance to put it right, but you also have the right to lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner's Office; a list of EEA authorities is published by the European Data Protection Board.

Other regions. If you are in Japan, South Korea, Canada, Australia, Brazil, or another jurisdiction with its own privacy law, you may have comparable rights under that law. Email support@notera.so and we will honour any right that applies to you.

14. United States state privacy rights

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to know what personal information we collect, to access and delete it, to obtain a portable copy, to correct inaccuracies, and to appeal a decision we make about your request. Use the methods in section 13 to exercise these rights.

We have not sold personal information, and we have not shared personal information for cross-context behavioural advertising, in the preceding twelve months, including the personal information of anyone under 16. There is therefore no "Do Not Sell or Share My Personal Information" link, because there is nothing to opt out of.

Categories of personal information collected

The table below reflects the categories defined by the California Consumer Privacy Act that we have collected in the preceding twelve months.

CategoryExamplesCollected
A. IdentifiersName, alias, unique personal identifier, online identifier, IP address, email address, account nameYES
B. California Customer Records statuteName, contact information, financial informationYES: name, email, and subscription status. We do not collect card numbers.
C. Protected classification characteristicsGender, age, date of birth, race and ethnicity, national origin, marital statusNO
D. Commercial informationRecords of products or services purchased, subscription and transaction historyYES
E. Biometric informationFingerprints and voiceprintsNO
F. Internet or other network activityInteractions with our website and application, feature usage, page views, error reportsYES
G. Geolocation dataPrecise device locationNO: we derive only coarse, city-level location from IP address
H. Audio, electronic, visual, or similar informationImages and files you upload to your boardsYES
I. Professional or employment-related informationJob title, work history, professional qualificationsNO
J. Education informationStudent records and directory informationNO
K. InferencesProfiles reflecting preferences, characteristics, or behaviourNO
L. Sensitive personal informationGovernment identifiers, precise geolocation, racial or ethnic origin, health, sexual orientation, contents of messages not directed to usNO

We collect these categories directly from you, automatically from your device as you use the Services, and from the third-party providers listed in section 4. We use and retain them for the purposes in section 2 and for the periods in section 9, and we disclose them for business purposes only to the providers listed in section 4.

You may use an authorised agent to submit a request on your behalf; we will ask for proof of the agent's authority and may ask you to verify your identity directly. If we deny your request you may appeal by replying to our response, and we will inform you of the outcome and of your right to contact your state Attorney General.

15. Do-Not-Track and Global Privacy Control

There is still no uniform industry standard for Do-Not-Track ("DNT") browser signals, and we do not respond to them. California law requires us to say so.

Global Privacy Control ("GPC") signals are treated as a valid opt-out request under California law. Because we do not sell or share personal information for advertising, and use no advertising or cross-site tracking cookies, there is no processing on our side for a GPC signal to stop.

16. Changes to this policy

We may update this Privacy Policy from time to time. The revised version is indicated by the "Last updated" date at the top of this page. If we make material changes we will notify you by email or through a prominent in-app notice at least 14 days before they take effect. Where the law requires your consent to a change, we will ask for it.

17. How to contact us

For any question about this policy, or to exercise a privacy right, contact:

Notera

Notera, a sole proprietorship

California, United States

support@notera.so

We are an online-only business and handle privacy requests by email. If you need a postal address for a formal legal or regulatory notice, email us and we will provide one.