Privacy Policy
Last updated: 30 Temmuz 2026
Notal is a service that transcribes and summarizes meeting audio recordings. This policy explains what data is collected when you use the service, how it is processed and with whom it is shared. If you are in Türkiye, the statutory notice under Turkish data protection law (KVKK) is available in Turkish at KVKK Aydınlatma Metni.
1. Data controller
Data controller's legal name — contact: [DOLDURULACAK — iletişim e-postası]
2. Data we collect
| Data | Why |
|---|---|
| Name, email, password (bcrypt hash only) | Account creation, sign-in, password reset |
| Meeting audio recordings (recorded in the browser or uploaded) | Producing transcripts and summaries |
| Transcripts, summaries, action items, decisions | The service's output; stored in your account |
| Meeting title, date, duration, participant list | Listing recordings and restricting access |
| Monthly transcription time and storage counters | Enforcing plan limits |
| IP address | Brute-force and abuse rate limiting. Kept only in server memory for a short time; never written to the database. |
The legal bases for this processing are the performance of our contract with you (account data, processing your recordings, usage counters), our legitimate interest in keeping the service secure (rate limiting), and your consent where required (see international transfers below). We do not collect data for advertising, profiling or behavioral tracking, and we use no third-party analytics or advertising scripts.
3. Important notice about recordings
When you record a meeting, other participants' voices are recorded too. Informing participants and obtaining any required consent is your responsibility. In some jurisdictions, recording without all parties' consent is a crime.Notal has no direct relationship with the people in the room and does not assume this obligation.
4. Service providers (sub-processors)
To provide the service, some data is transferred to the providers below. Some of them are located outside your country (in the US); these are international transfers, and by creating an account you explicitly consent to them.
| Provider | Data transferred | Location |
|---|---|---|
| OpenAI | Audio recording (for transcription), transcript text (for summarization) | US |
| Groq (if enabled) | Audio recording (for transcription) | US |
| Stripe (once paid plans launch) | Billing details. Payments are handled directly by Stripe; card numbers never reach our servers. | US |
| Resend | Email address and the content of notification emails | US |
| Hosting provider | All data (the server and database are hosted here) | Country |
These providers process data only on our behalf, under contract and on our instructions. We do not sell your data and do not share it with third parties for marketing.
5. Retention
Audio recordings, transcripts and summaries are kept until you delete them — for as long as the service relationship lasts. When you delete a meeting, its audio file is permanently removed from the server and its transcript and summary from the database. When you delete your account or a workspace, all meetings, audio files, invitations and API keys attached to it are deleted as well. Records we are legally required to keep (e.g. invoices) may be retained for the period required by law.
The database is backed up nightly and backups rotate after 7 days; data leaves the backups at most 7 days after deletion.
6. Access and privacy model
A meeting can only be seen by the person who created it and the workspace members added as participants — even other members of the same workspace cannot see it. There are two exceptions you should know about:
- API keys, which workspace admins can create, are workspace-scoped and can access all meetings in that workspace.
- If a webhook is configured, the summary and action items of every processed meeting are sent to the configured address.
7. Cookies
Only cookies strictly necessary for the service are used: a session cookie (to keep you signed in) and an active-workspace cookie. Since no analytics, advertising or tracking cookies are used, no cookie consent banner is shown. If you block these cookies you will not be able to sign in.
8. Security
Passwords are stored as bcrypt hashes; plaintext passwords are never kept anywhere. API keys are stored only as SHA-256 hashes. Password reset links are single-use, expire after one hour, and only their hash is stored in the database. All traffic runs over HTTPS and the database is reachable only from the application server. Even so, no system can guarantee absolute security; choose a strong password that you do not use anywhere else.
9. Your rights
As a data subject you have the right to access, rectify, delete and port your data, to restrict or object to processing, to withdraw consent at any time, and to lodge a complaint with your supervisory authority. You can exercise the right to erasure directly: export meeting outputs as Word (.docx), pull them in bulk via the API, and delete meetings or your entire account from Settings. For requests under Turkish law (KVKK), see the KVKK notice.
10. Changes
If this policy changes, the date on this page is updated; for material changes we notify you at your registered email address.