Privacy Policy
This Privacy Policy explains how NoteHelix collects, uses, discloses, and protects personal information when you use NoteHelix Cloud.
Last updated: July 28, 2026
NoteHelix (“NoteHelix,” “we,” “us,” or “our”) operates the hosted collaborative workspace service available at notehelix.com and related domains (the “Cloud Service”). This Privacy Policy applies to the Cloud Service and our public marketing site.
Self-hosted deployments of the NoteHelix software are operated by the people who run those instances. We do not control self-hosted deployments and this Privacy Policy does not apply to them, except to the extent you interact with our public site or Cloud Service.
Related notices: GDPR & UK GDPR notice and California privacy notice. Our Terms of Service and Acceptable Use Policy also apply.
1. Who this policy covers
This policy applies to:
- Visitors to our marketing website
- Individuals who create or use a NoteHelix Cloud account
- Workspace members, guests, and collaborators invited into Cloud workspaces
- People who contact us by email at contact@notehelix.com
2. Information we collect
2.1 Account and profile information
When you register or manage an account, we may collect your email address, display name, password or authentication credentials, workspace membership details, role or permission settings, and preferences you configure in the product.
2.2 Workspace content
To provide sync and collaboration features, we process content you and your teammates create or upload in the Cloud Service. This may include notes, tasks, calendar events, kanban boards, chat messages, wiki pages, whiteboards, attachments, tags, comments, and related metadata (such as timestamps, authors, and folder structure).
Where we offer end-to-end encrypted vault features, we design those features so that vault plaintext is not available to NoteHelix operators in ordinary operation. You remain responsible for safeguarding recovery material and encryption keys under your control.
2.3 Usage, device, and log data
We automatically collect technical and usage information needed to operate and secure the service, such as IP address, browser or client type, approximate location derived from IP, device identifiers where available, pages or modules accessed, feature usage events, diagnostic logs, crash reports, and timestamps. We use this data for reliability, abuse prevention, product improvement, and billing-related metrics.
2.4 Communications
If you email us or submit feedback, we collect the content of your message, your contact email, and any information you choose to include.
2.5 Billing information
Paid plans are processed by Stripe. We receive billing-related metadata such as subscription status, plan tier, invoices, and limited payment method details (for example, card brand and last four digits). Full payment card numbers are handled by Stripe and are not stored by NoteHelix.
2.6 Cookies and similar technologies
We use cookies and similar technologies that are necessary to keep you signed in, protect sessions, remember preferences, and measure core product usage. We do not sell personal information through advertising cookies. If we introduce optional analytics or marketing cookies, we will update this policy and provide required choices.
3. How we use information
We use personal information to:
- Provide, sync, secure, and improve the Cloud Service
- Create and manage accounts, workspaces, and permissions
- Process subscriptions, invoices, and plan changes
- Communicate service notices, security alerts, and responses to your requests
- Detect, investigate, and prevent fraud, abuse, and outages
- Comply with law and enforce our Terms and Acceptable Use Policy
- Analyze aggregated or de-identified trends to improve the product
We do not use your workspace content to train public third-party AI models. If we ever introduce optional AI features that process content, we will disclose that clearly and, where required, obtain appropriate consent or provide controls.
4. How we share information
We may share personal information with:
- Service providers / subprocessors that help us host, store, email, monitor, or bill for the Cloud Service (for example, infrastructure providers, database hosting, Stripe, and email delivery providers), under contractual obligations to protect the data
- Workspace collaborators, according to the permissions configured in your workspace
- Professional advisors such as lawyers or accountants, when needed
- Authorities when required by law, legal process, or to protect rights, safety, or security
- Successors in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards
We do not sell personal information for money. We also do not “share” personal information for cross-context behavioral advertising as those terms are used under California law.
5. Retention
We retain account and workspace data for as long as your account remains active and as needed to provide the Cloud Service. After account deletion or a verified deletion request, we delete or anonymize personal data within a commercially reasonable period, except where we must retain information for legal, security, dispute-resolution, or accounting purposes (for example, billing records). Backup systems may retain residual copies for a limited period until overwritten according to our backup rotation.
6. Security
We use administrative, technical, and organizational measures designed to protect personal information, including encrypted transport (HTTPS), access controls, and monitoring. No method of transmission or storage is completely secure. You are responsible for protecting your credentials and devices, and for configuring workspace permissions appropriately.
7. International transfers
NoteHelix may process data in the United States and other countries where we or our subprocessors operate. When we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards described in our GDPR notice.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain personal information, or to object to certain processing. You can often update profile information in the product. For other requests, email contact@notehelix.com. We may need to verify your identity before fulfilling a request.
See also: GDPR rights and California consumer rights.
9. Children
The Cloud Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact contact@notehelix.com and we will take appropriate steps.
10. Third-party links and integrations
The Cloud Service or site may link to third-party websites or services. Their privacy practices are governed by their own policies, not this one.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, when changes are material, provide additional notice as appropriate (for example, by email or in-product notice). Continued use of the Cloud Service after an update means you acknowledge the revised policy.
12. Contact
For privacy questions or requests, contact us by email only at contact@notehelix.com. We do not provide telephone support for privacy requests.