Privacy Policy
Noteaux is a privacy-first meeting assistant for macOS and Windows, currently under active development and offered on a pre-release basis. This policy explains what data Noteaux processes, how it is used, and the choices you have. It is written to reflect Noteaux's actual architecture rather than generic boilerplate.
1. What Noteaux is
Noteaux runs as a native desktop application. It helps you prepare for meetings, records and transcribes them, and produces summaries, decisions, action items and related meeting intelligence. Noteaux is built local-first: core recording functionality is designed to work without a live internet connection.
2. Data categories Noteaux may process
- Meeting audio captured from your microphone and/or system audio.
- Transcripts generated from that audio.
- Derived meeting intelligence: summaries, decisions, open questions, ideas and follow-up actions.
- Calendar metadata (when you connect a calendar integration), such as event titles, times and attendee email addresses.
- People and relationship information you create or that Noteaux infers from meeting and calendar context, subject to your review.
- Basic account and application configuration data, including which AI/transcription provider you have selected.
- Credentials and access tokens for any integrations you connect (for example, calendar or AI provider connections).
3. Local-first processing
Audio capture, storage of raw recordings, and core application data are designed to be handled on your device. Noteaux does not require a cloud account or an active internet connection in order to record a meeting. Cloud processing — such as sending audio to a transcription provider — only occurs where you or your organization have explicitly selected and enabled a provider for that purpose.
4. Meeting audio
Raw audio is retained on your device until the corresponding transcription has succeeded and been validated, after which retention is governed by your configured retention settings. Noteaux does not upload raw audio to any third party unless you have selected a cloud transcription provider and that specific recording is routed to it under your configuration.
5. Transcripts
The transcript produced in the meeting's original spoken language is treated as the authoritative record of what was said. Where outages, errors or gaps occur during capture or transcription, Noteaux is designed to represent these honestly rather than fabricate or infer missing content.
6. Meeting Intelligence / derived outputs
Summaries, decisions, ideas, open questions and action items are derived from the transcript by AI processing. These outputs are stored separately from, and never overwrite, the original transcript. Derived outputs may carry a degree of uncertainty and are not treated as verified fact without your review.
7. Calendar integrations
Calendar integrations are optional. When connected, Noteaux uses calendar data to show upcoming meetings, help you prepare for a specific meeting, and associate a recorded meeting with its corresponding calendar event. Calendar attendee information is treated as contact/meeting metadata only — it is never used to automatically determine who actually spoke in a meeting (see Section 9).
8. Google Calendar data
Where you connect Google Calendar, Noteaux currently requests the following scopes:
https://www.googleapis.com/auth/calendar.events.readonlyhttps://www.googleapis.com/auth/calendar.calendarlist.readonly
Noteaux uses this authorized Google Calendar data only to:
- display your upcoming calendar events within the application;
- help you prepare for an upcoming Noteaux meeting;
- associate a Noteaux meeting with its corresponding calendar event;
- read meeting-related metadata (such as title, time and attendees) needed for meeting preparation;
- keep your calendar view up to date through incremental synchronization.
Noteaux does not access Gmail, Google Drive, Google Tasks or Google Meet data through this integration, regardless of which Google APIs may otherwise be enabled in the underlying Google Cloud project. Noteaux does not read the content of your email.
Google Calendar access is entirely user-authorized, optional, and can be disconnected by you at any time from within Noteaux. Noteaux's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In line with those requirements: Google user data obtained through this integration is used only to provide or improve the user-facing calendar features described above; it is not sold to third parties; it is not used for advertising or ad targeting; and it is not used to train generalized or general-purpose AI/ML models. Access is limited to the scopes and functionality you have explicitly authorized, and human access to this data is restricted to what is necessary for security, legal compliance, or with your explicit direction.
9. Calendar / attendee privacy
A calendar attendee's email address is contact and meeting metadata — nothing more. Attendee presence on a calendar invitation is never automatically treated as verified speaker identity or biometric identity. Noteaux may, in future functionality, offer to match an attendee's email address to an existing Person in your workspace, or offer to create a new Person record and associate them with a prepared meeting — but calendar presence alone never establishes who actually spoke during a meeting.
10. Optional cloud AI/STT providers
Noteaux is designed so that AI and speech-to-text providers are interchangeable and configurable. Cloud-based processing only occurs when a provider has been selected and enabled under your or your organization's policy. Noteaux does not send meeting data to a cloud provider by default merely because a provider has been configured or credentials exist for it.
11. BYOK / user-selected providers
Where supported, you or your organization may connect a cloud AI or transcription provider using your own account credentials ("bring your own key"). In this model, the provider you select processes data under its own terms in addition to this policy, and you control which provider is used, if any.
12. Data retention
Raw audio, transcripts and derived meeting intelligence are retained according to your configured retention settings. Raw audio is not deleted before the corresponding transcription has succeeded and been validated. You can review and adjust retention behavior, and delete meeting data, from within the application.
13. Security
Credentials and access tokens for connected integrations (such as calendar or AI provider connections) are stored using your operating system's secure credential storage where supported by the platform. Noteaux does not currently claim any third-party security certification (for example, SOC 2 or ISO 27001), and this policy makes no such claim.
14. User control / disconnect / deletion
You can disconnect any integration, including Google Calendar, at any time from within Noteaux. You can also request deletion of your data by contacting us using the details below. Organizations may additionally apply policy controls that restrict or disable specific integrations or cloud processing for their users.
15. Contact
Questions about this policy or your data can be sent to pierre.osbeck@gmail.com.
16. Policy changes
As Noteaux moves from pre-release toward general availability, this policy will be updated to reflect actual product functionality. Material changes will be reflected by updating the "Last updated" date above.