Privacy Policy

Last updated: 30 Temmuz 2026

Notal is a service that transcribes and summarizes meeting audio recordings. This policy explains what data is collected when you use the service, how it is processed and with whom it is shared. If you are in Türkiye, the statutory notice under Turkish data protection law (KVKK) is available in Turkish at KVKK Aydınlatma Metni.

1. Data controller

Data controller's legal name — contact: [DOLDURULACAK — iletişim e-postası]

2. Data we collect

DataWhy
Name, email, password (bcrypt hash only)Account creation, sign-in, password reset
Meeting audio recordings (recorded in the browser or uploaded)Producing transcripts and summaries
Transcripts, summaries, action items, decisionsThe service's output; stored in your account
Meeting title, date, duration, participant listListing recordings and restricting access
Monthly transcription time and storage countersEnforcing plan limits
IP addressBrute-force and abuse rate limiting. Kept only in server memory for a short time; never written to the database.

The legal bases for this processing are the performance of our contract with you (account data, processing your recordings, usage counters), our legitimate interest in keeping the service secure (rate limiting), and your consent where required (see international transfers below). We do not collect data for advertising, profiling or behavioral tracking, and we use no third-party analytics or advertising scripts.

3. Important notice about recordings

When you record a meeting, other participants' voices are recorded too. Informing participants and obtaining any required consent is your responsibility. In some jurisdictions, recording without all parties' consent is a crime.Notal has no direct relationship with the people in the room and does not assume this obligation.

4. Service providers (sub-processors)

To provide the service, some data is transferred to the providers below. Some of them are located outside your country (in the US); these are international transfers, and by creating an account you explicitly consent to them.

ProviderData transferredLocation
OpenAIAudio recording (for transcription), transcript text (for summarization)US
Groq (if enabled)Audio recording (for transcription)US
Stripe (once paid plans launch)Billing details. Payments are handled directly by Stripe; card numbers never reach our servers.US
ResendEmail address and the content of notification emailsUS
Hosting providerAll data (the server and database are hosted here)Country

These providers process data only on our behalf, under contract and on our instructions. We do not sell your data and do not share it with third parties for marketing.

5. Retention

Audio recordings, transcripts and summaries are kept until you delete them — for as long as the service relationship lasts. When you delete a meeting, its audio file is permanently removed from the server and its transcript and summary from the database. When you delete your account or a workspace, all meetings, audio files, invitations and API keys attached to it are deleted as well. Records we are legally required to keep (e.g. invoices) may be retained for the period required by law.

The database is backed up nightly and backups rotate after 7 days; data leaves the backups at most 7 days after deletion.

6. Access and privacy model

A meeting can only be seen by the person who created it and the workspace members added as participants — even other members of the same workspace cannot see it. There are two exceptions you should know about:

  • API keys, which workspace admins can create, are workspace-scoped and can access all meetings in that workspace.
  • If a webhook is configured, the summary and action items of every processed meeting are sent to the configured address.

7. Cookies

Only cookies strictly necessary for the service are used: a session cookie (to keep you signed in) and an active-workspace cookie. Since no analytics, advertising or tracking cookies are used, no cookie consent banner is shown. If you block these cookies you will not be able to sign in.

8. Security

Passwords are stored as bcrypt hashes; plaintext passwords are never kept anywhere. API keys are stored only as SHA-256 hashes. Password reset links are single-use, expire after one hour, and only their hash is stored in the database. All traffic runs over HTTPS and the database is reachable only from the application server. Even so, no system can guarantee absolute security; choose a strong password that you do not use anywhere else.

9. Your rights

As a data subject you have the right to access, rectify, delete and port your data, to restrict or object to processing, to withdraw consent at any time, and to lodge a complaint with your supervisory authority. You can exercise the right to erasure directly: export meeting outputs as Word (.docx), pull them in bulk via the API, and delete meetings or your entire account from Settings. For requests under Turkish law (KVKK), see the KVKK notice.

10. Changes

If this policy changes, the date on this page is updated; for material changes we notify you at your registered email address.