Skip to content
NoteHelix

Privacy Policy

This Privacy Policy explains how NoteHelix collects, uses, discloses, and protects personal information when you use NoteHelix Cloud.

Last updated: July 28, 2026

NoteHelix (“NoteHelix,” “we,” “us,” or “our”) operates the hosted collaborative workspace service available at notehelix.com and related domains (the “Cloud Service”). This Privacy Policy applies to the Cloud Service and our public marketing site.

Self-hosted deployments of the NoteHelix software are operated by the people who run those instances. We do not control self-hosted deployments and this Privacy Policy does not apply to them, except to the extent you interact with our public site or Cloud Service.

Related notices: GDPR & UK GDPR notice and California privacy notice. Our Terms of Service and Acceptable Use Policy also apply.

1. Who this policy covers

This policy applies to:

  • Visitors to our marketing website
  • Individuals who create or use a NoteHelix Cloud account
  • Workspace members, guests, and collaborators invited into Cloud workspaces
  • People who contact us by email at contact@notehelix.com

2. Information we collect

2.1 Account and profile information

When you register or manage an account, we may collect your email address, display name, password or authentication credentials, workspace membership details, role or permission settings, and preferences you configure in the product.

2.2 Workspace content

To provide sync and collaboration features, we process content you and your teammates create or upload in the Cloud Service. This may include notes, tasks, calendar events, kanban boards, chat messages, wiki pages, whiteboards, attachments, tags, comments, and related metadata (such as timestamps, authors, and folder structure).

Where we offer end-to-end encrypted vault features, we design those features so that vault plaintext is not available to NoteHelix operators in ordinary operation. You remain responsible for safeguarding recovery material and encryption keys under your control.

2.3 Usage, device, and log data

We automatically collect technical and usage information needed to operate and secure the service, such as IP address, browser or client type, approximate location derived from IP, device identifiers where available, pages or modules accessed, feature usage events, diagnostic logs, crash reports, and timestamps. We use this data for reliability, abuse prevention, product improvement, and billing-related metrics.

2.4 Communications

If you email us or submit feedback, we collect the content of your message, your contact email, and any information you choose to include.

2.5 Billing information

Paid plans are processed by Stripe. We receive billing-related metadata such as subscription status, plan tier, invoices, and limited payment method details (for example, card brand and last four digits). Full payment card numbers are handled by Stripe and are not stored by NoteHelix.

2.6 Cookies and similar technologies

We use cookies and similar technologies that are necessary to keep you signed in, protect sessions, remember preferences, and measure core product usage. We do not sell personal information through advertising cookies. If we introduce optional analytics or marketing cookies, we will update this policy and provide required choices.

3. How we use information

We use personal information to:

  • Provide, sync, secure, and improve the Cloud Service
  • Create and manage accounts, workspaces, and permissions
  • Process subscriptions, invoices, and plan changes
  • Communicate service notices, security alerts, and responses to your requests
  • Detect, investigate, and prevent fraud, abuse, and outages
  • Comply with law and enforce our Terms and Acceptable Use Policy
  • Analyze aggregated or de-identified trends to improve the product

We do not use your workspace content to train public third-party AI models. If we ever introduce optional AI features that process content, we will disclose that clearly and, where required, obtain appropriate consent or provide controls.

4. How we share information

We may share personal information with:

  • Service providers / subprocessors that help us host, store, email, monitor, or bill for the Cloud Service (for example, infrastructure providers, database hosting, Stripe, and email delivery providers), under contractual obligations to protect the data
  • Workspace collaborators, according to the permissions configured in your workspace
  • Professional advisors such as lawyers or accountants, when needed
  • Authorities when required by law, legal process, or to protect rights, safety, or security
  • Successors in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards

We do not sell personal information for money. We also do not “share” personal information for cross-context behavioral advertising as those terms are used under California law.

5. Retention

We retain account and workspace data for as long as your account remains active and as needed to provide the Cloud Service. After account deletion or a verified deletion request, we delete or anonymize personal data within a commercially reasonable period, except where we must retain information for legal, security, dispute-resolution, or accounting purposes (for example, billing records). Backup systems may retain residual copies for a limited period until overwritten according to our backup rotation.

6. Security

We use administrative, technical, and organizational measures designed to protect personal information, including encrypted transport (HTTPS), access controls, and monitoring. No method of transmission or storage is completely secure. You are responsible for protecting your credentials and devices, and for configuring workspace permissions appropriately.

7. International transfers

NoteHelix may process data in the United States and other countries where we or our subprocessors operate. When we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards described in our GDPR notice.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain personal information, or to object to certain processing. You can often update profile information in the product. For other requests, email contact@notehelix.com. We may need to verify your identity before fulfilling a request.

See also: GDPR rights and California consumer rights.

9. Children

The Cloud Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact contact@notehelix.com and we will take appropriate steps.

10. Third-party links and integrations

The Cloud Service or site may link to third-party websites or services. Their privacy practices are governed by their own policies, not this one.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, when changes are material, provide additional notice as appropriate (for example, by email or in-product notice). Continued use of the Cloud Service after an update means you acknowledge the revised policy.

12. Contact

For privacy questions or requests, contact us by email only at contact@notehelix.com. We do not provide telephone support for privacy requests.