Legal

Privacy Policy

Effective date: August 30, 2026 · Last updated: July 30, 2026

Contents
  1. At a glance
  2. 0. Who is responsible for your information
  3. Definitions
  4. 1. Information we collect
  5. 2. How we use information
  6. 3. Legal bases for processing
  7. 4. AI processing, meetings, and voice
  8. 5. Who we share information with
  9. 6. Selling, sharing, and targeted advertising
  10. 7. Data retention
  11. 8. Security
  12. 9. Your privacy choices and controls
  13. 10. Your privacy rights
  14. 11. Cookies and similar technologies
  15. 12. California privacy rights (CCPA/CPRA)
  16. 13. Texas and other U.S. state privacy rights
  17. 14. Children's privacy
  18. 15. International data transfers
  19. 16. Automated decision-making and profiling
  20. 17. Changes to this Privacy Policy
  21. 18. Contact

Cartex Data, LLC ("Cartex," "Noots," "we," "us," or "our") built Noots.ai. This Privacy Policy explains what information we collect, why, who we give it to, how long we keep it, and what you can do about it — across our websites, our web and desktop applications, our APIs, our AI features, our integrations, and all related products and services (together, the "Service").

This Policy applies whenever you create or use an account, use the Service, visit our websites, communicate with us, connect a third-party integration, or otherwise interact with Cartex.

If you use the Service as part of an organization, your organization's administrators control that workspace — the features available to you, your permissions, and the policies that apply. This Policy describes *our* practices. Your organization may also have its own privacy, employment, monitoring, or acceptable-use policies that apply to you.


At a glance

These are the honest headlines. The numbered sections below are the binding detail.

  • Your content is yours. We do not use the private content of your meetings, recordings, transcripts, emails, documents, or workspace to train general-purpose AI models, and our AI providers are contractually barred from doing so.
  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is no advertising in Noots — no ad server, no ad placements, no advertisers.
  • We do not have a partner-sharing arrangement with anyone, and there is no personalized or sponsored content in the Service.
  • This Policy does permit both of those things in the future, and we are not doing either today. That is what the "Personalization" and "Partner sharing" settings are for. If we ever start, you get at least 30 days' notice first, the controls work before the feature does, and your meetings, messages, and documents are not part of it. Section 6 separates what is true today from what this Policy allows later, and says which is which.
  • AI features that read what you type are switchable, and one of them is switched on by default. Mail AI and live call notes are off until somebody turns them on. Chat suggestions are on: when a message is posted in a channel, its text is sent to OpenAI so Noots can offer a board suggestion. Direct messages and group chats are never scanned, nothing on a board changes until a person clicks Accept, and an administrator can switch it off for the whole workspace — see Section 4.5. Every one of these switches is enforced on our servers rather than by hiding a button.
  • Recording a meeting sends audio to Deepgram and content to OpenAI. We say so plainly in Section 4 and we name every sub-processor in Section 5.
  • We hold no SOC 2, ISO 27001, HIPAA, PCI DSS, or FedRAMP certification, and we will not imply one. What our security actually is, in specifics, is Section 8 and our security page.
  • Deleting your account is immediate and permanent, and it deletes any organization you created — including other people's work in it. Read Section 7.4 before you do it.

0. Who is responsible for your information

Data protection law distinguishes between the party that decides why and how personal data is processed (a "controller", or a "business" in California) and the party that processes it on that party's instructions (a "processor", or a "service provider"). Cartex is both, depending on the data:

InformationOur roleWhose instructions govern
Content inside a workspace — meetings, recordings, transcripts, documents, tasks, messages, calendar and mail data synced by a memberProcessor / service providerYour organization is the controller. It decides what is recorded, who can see it, and when it is deleted.
Your account and profile, authentication, security and abuse prevention, billing, support correspondence, and how we operate and improve the Service itselfController / businessOurs.
Information collected on our public marketing websiteController / businessOurs.

What this means for you in practice. If you are a member of an organization and you ask us to delete, correct, or hand over content inside that workspace, we will normally forward your request to your organization's administrators and support them in answering it, because that content is theirs to decide about. Requests about your own account, and requests from people who use Noots without an organization, come to us directly.

For organizations: we offer a Data Processing Addendum, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply. Request one at legal@cartexdata.com.


Definitions

  • "Personal Information" — information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual. Where the GDPR or UK GDPR applies, read this as "personal data".
  • "Your Content" — as defined in our Terms of Service: meeting recordings, transcripts, documents, tasks, emails, messages, and other material you or your organization make available through the Service.
  • "AI Output" — summaries, notes, action items, recommendations, transcripts, and other content generated by the AI features of the Service.
  • "Organization" — any company, employer, educational institution, government agency, nonprofit, or other entity that administers a shared workspace.
  • "Administrator" — an individual authorized by an Organization to manage its workspace, users, permissions, subscriptions, or settings.

Capitalized terms not defined here have the meaning given in the Terms of Service.


1. Information we collect

We collect information you give us, information generated as you use the Service, information from your organization, and information from the third-party services you choose to connect.

1.1 Account and profile information

Name, email address, authentication credentials (we store a hash of your password, never the password itself), profile photograph, organization name, job title or role, account preferences, language, time zone, and appearance settings.

1.2 Meeting and workspace content

Depending on the features you or your organization enable: meeting audio and video recordings, transcripts, summaries, action items, documents, notes, tasks, projects, comments, messages, whiteboards, knowledge-base content, prompts you submit to AI features, and AI Output. We process this content to provide the functionality you or your organization asked for.

1.3 Information from services you connect

If you authorize an integration, we receive the data that integration needs: calendar events, email messages, contacts, meeting metadata, files, tasks, chat messages, and authentication tokens. We request only the scopes the feature needs — for example, we ask Google for permission to manage calendar *events*, not for full calendar access. The scopes we request from each provider are summarized on our security page, and you can revoke any connection at any time from your account or from the provider.

1.4 Billing information

Your plan, invoices, transaction history, billing email, and payment status. Payments are processed by Stripe, Inc. Cartex never receives or stores your full payment card number.

1.5 Device and technical information

IP address, browser type, operating system, device identifiers, application version, crash and diagnostic information, session identifiers, and time zone.

We do not derive your geographic location from your IP address. The Service contains no IP-geolocation lookup of any kind. IP addresses are used to apply rate limits, to enforce IP allowlists where an organization has configured one, and are recorded in our security event log (see Section 7).

1.6 Usage information

Pages viewed, features used, actions taken, meeting duration, AI feature usage, workspace activity, searches, and performance metrics.

1.7 Communications

The content of what you send us — support requests, feedback, survey responses, bug reports, sales enquiries, and legal requests.

1.8 Notice at collection

For California and other U.S. state privacy laws, this is the categorized summary of what we collect, why, and who receives it. Sources are: you, your organization, the third-party services you connect, and automatic collection as you use the Service.

Statutory categoryWhat we actually collectWhyDisclosed to
A. IdentifiersName, email, account ID, IP address, device and session identifiersProvide the Service, authenticate you, secure the Service, support, billingHosting, AI, payment, and integration providers listed in §5
B. Customer recordsName, contact details, billing email and addressBilling, support, contract administrationStripe; hosting provider
C. Protected classificationsNot collected. We never ask for race, religion, health, sexual orientation, or similar. Such information could appear inside content you upload — we do not seek it or use it.
D. Commercial informationPlan, subscription and transaction historyBilling and account administrationStripe
E. Biometric informationAudio and video recordings of meetings you choose to record. ⚠ We do not extract a voiceprint, faceprint, or other biometric template from them, and we do not use them to identify anyone. Speaker separation labels who spoke when within a single recording; it does not build an identifier that follows a person across recordings.Transcription and meeting analysis you requestedDeepgram; Recall.ai (when you use its bot); hosting provider
F. Internet or network activityPages viewed, features used, actions taken, searches, performance metricsOperate, secure, and improve the ServiceHosting provider
G. Geolocation dataNot collected. No IP geolocation, no GPS, no device location.
H. Sensory or audiovisual dataMeeting recordings, call audio, transcripts, screen shares you recordThe recording and meeting-intelligence features you enabledDeepgram; OpenAI; Recall.ai; hosting provider
I. Professional or employment informationJob title, role, team, organization, work schedule, availabilityCollaboration, scheduling, capacity featuresYour organization; hosting provider
J. Education informationNot collected as such (an educational organization may enter it as content)
K. InferencesAI Output about your work — summaries, action items, project-risk assessments, workload and capacity indicatorsProvide the AI features requestedOpenAI; hosting provider
L. Sensitive personal information(i) your account log-in credentials; (ii) the contents of your email and messages where Cartex is not the intended recipient, when you connect a mailbox or use chat.Only to provide the Service you asked for, secure it, and prevent fraud — including the chat suggestions in §4.5, which are on by default and send channel message text to OpenAISee §5; OpenAI, for channel messages (§4.5)

About category L. California law treats account credentials and the contents of mail and messages as *sensitive personal information*. We use it only for the purposes the law permits without offering a right to limit — performing the service you requested, security, and preventing fraud. We do not use it to infer characteristics about you, and we do not sell or share it. That is why the Service has no "Limit the Use of My Sensitive Personal Information" link: there is no additional use to limit. See Section 12.


2. How we use information

We use Personal Information to:

  • provide, operate, and maintain the Service;
  • authenticate you and administer accounts and workspaces;
  • join meetings and process meeting content at your request;
  • generate AI Output;
  • synchronize information with the third-party services you connect;
  • provide customer support;
  • process subscriptions and payments;
  • detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents;
  • maintain operational integrity and the backups we take;
  • communicate with you about administrative, billing, legal, security, and product matters;
  • comply with legal obligations and enforce our agreements; and
  • protect the rights, property, safety, and security of Cartex, our users, and others.

We also generate aggregated, anonymized, or de-identified information that cannot reasonably identify anyone. That is not Personal Information, and we use it for analytics, product improvement, security, and reporting. We will not attempt to re-identify it.

2.1 Optional processing you control

The Service records three optional data preferences under Settings → Data & Compliance. Two of them are permissions for things we may do later and are not doing now. Because a preference that does nothing is worse than no preference at all, here is exactly what each one does today:

SettingWhat it actually does todayDefault
Help improve NootsRecords your permission for us to use your activity and diagnostic information to improve the product. Today it is also one of two conditions that must both hold for your record to appear in the internal export described in Section 6.1 — switching either one off excludes you.On (off by default for members of paid organizations)
PersonalizationRecords your permission for personalized and sponsored content. No such feature exists in the Service, and nothing reads this setting today. It is recorded, it is exported to you on request, and an administrator can lock it — that is the whole of its present effect. We keep it rather than deleting it because it is the switch that opts you out in advance of anything built under Section 6.2. Describing an inert control as an active one would be its own kind of dishonesty, so we say plainly: today it is inert.On (off by default for members of paid organizations)
Partner sharingRecords your permission for partner sharing. We have no partner-sharing arrangement with anyone, so today no personal information has a partner to go to. Its one present-day effect is the internal export in Section 6.1, and switching it off excludes you from that export. See Section 6.2 for what it would govern if that changes.On (off by default for members of paid organizations)

Each is separate and can be switched off at any time. Switching one off applies going forward and does not undo processing already carried out. Switching one off before we introduce anything that reads it means you are never included in the first place — which is the reason these controls exist now rather than on the day a feature ships.

Organization controls. On paid plans, an Administrator can set the default for their members and can lock a category off for the whole organization, in which case no member of that organization can turn it back on. Locking a category immediately switches it off for every existing member. On free plans these controls are not available.


Where the GDPR, UK GDPR, or a similar law applies, we rely on these legal bases:

BasisWhat we rely on it for
Performance of a contract (Art. 6(1)(b))Providing the Service to you or to your Organization, administering your account, billing
Legitimate interests (Art. 6(1)(f))Securing and operating the Service, preventing fraud and abuse, troubleshooting, improving and developing the Service, and communicating with users — balanced against your rights and freedoms
Legal obligation (Art. 6(1)(c))Tax and accounting records, responding to lawful legal process, meeting regulatory requirements
Consent (Art. 6(1)(a))The optional settings in §2.1, and the AI features that are opt-in — mail triage, summarization and drafting, and live call notes. Not chat suggestions, which are on by default; see §4.5 and the note below

Where we rely on consent you may withdraw it at any time; withdrawal applies going forward and does not affect processing already carried out lawfully. Where we rely on legitimate interests you may object — see Section 10.

If we later introduce the personalization, sponsored content, or partner sharing that Section 6.2 permits, the basis for it will be consent — not legitimate interests — wherever the GDPR or UK GDPR applies. A permission written into a privacy policy is not consent, and we will not treat it as one.

Where Cartex acts as a processor for an Organization (Section 0), the lawful basis for that processing is the Organization's to establish, not ours.

Chat suggestions ([Section 4.5](#45-chat-suggestions-which-are-on-by-default)) are an example of that split, and an important one. The messages are the Organization's workspace content, the setting that governs the scan is the Organization's to set, and we process on that instruction — so the Organization is responsible for establishing the lawful basis for it and for telling its own people. We describe the processing here so that a member reading this Policy learns of it from us as well.


4. AI processing, meetings, and voice

4.1 What happens, concretely

The Service uses artificial intelligence and machine-learning systems — ours and our providers' — to transcribe meetings, summarize them, extract action items, generate tasks, analyze documents, power workspace search, and answer questions.

When you record or upload a meeting or call:

  1. the audio is sent to Deepgram, Inc. for speech-to-text with speaker separation;
  2. the resulting transcript, and the participant names, are sent to OpenAI to produce the summary, decisions, action items, topics, and other analysis;
  3. the transcript and the analysis are stored in your workspace.

If you send the meeting bot into a Zoom, Google Meet, or Microsoft Teams call, the bot may be provided by Recall.ai, which joins the call, records it, and produces its own transcript — so the meeting's audio, video, and transcript are processed on Recall's systems as well as ours.

Other AI features send the relevant content to OpenAI when you use them: the Hoot sidekick, Autopilot, AI teammates ("Nooties"), chat recaps, and — only if you switch them on — mail triage, mail summarization, and mail drafting. Mail AI is off by default and that default is enforced on our servers, not merely by hiding a button. So are live call notes (Section 4.5 explains the one exception).

Chat suggestions are that exception, and they are not like the features above. They are on by default, and they run without anyone invoking them, on every message posted in a channel. Because that is a real difference, it has its own subsection: Section 4.5.

4.2 What we do not do

  • We do not use the private content of your meetings, recordings, transcripts, emails, documents, or workspace to train general-purpose AI models.
  • We do not permit our AI providers to use that content to train their own general-purpose or publicly available models, and our agreements with them prohibit it.
  • We do not use meeting content for advertising. There is no advertising in Noots.

4.3 Voice, and why we are specific about it

Meeting recordings are recordings of people's voices. Several laws treat voice data carefully, and one of them may be yours.

What we do: we store the audio you asked us to record, we send it to Deepgram for transcription, and Deepgram returns text labelled with a speaker number for each stretch of speech. We map those speaker numbers to participant names using the meeting's own attendee list.

What we do not do: we do not create, derive, or store a voiceprint, a biometric template, or any other identifier that could be used to recognize a person's voice in a different recording. The speaker labels exist only inside the recording they came from. We do not use voice data to identify anyone, and we do not sell or disclose it for that purpose.

Your responsibility. Recording and transcription law varies enormously, and some jurisdictions require the consent of every participant. As set out in the Terms of Service, you are responsible for giving the notices and obtaining the consents that apply to your meetings, before you record. The Service does not do this for you and does not check whether you have.

4.4 AI Output can be wrong

AI Output may be inaccurate, incomplete, out of date, or unsuitable for your purpose. You are responsible for reviewing it before you rely on it. See Section 16 for what this means when AI Output is about a person.

4.5 Chat suggestions, which are on by default

Noots can read a chat message and offer to update the board it relates to — tick a checklist item, move a task to review, add a task, file a note. This feature is on by default in every workspace. It is the one AI feature in the Service that runs without anyone invoking it, so this subsection sets out exactly what happens.

What is sent, and to whom. When a message is posted in a channel, the text of that message is sent to OpenAI, together with enough of the workspace to make the suggestion specific: the names of a few candidate projects, their board column names, and the titles of open tasks and unticked checklist items in those projects. OpenAI processes it as our sub-processor (Section 5.2) and is contractually barred from using it to train its models (Section 4.2).

What is never sent — these limits are in the code, not just in this Policy:

  • Direct messages are never scanned. Neither are group chats. Only conversations of type *channel* are scanned at all.
  • A message beginning with `/` is never scanned — slash commands are excluded before anything is sent.
  • Attachments and files are never sent. Only the message text is.
  • Nothing is sent from a workspace that has switched the feature off. The check is the first thing the scan does, before it reads anything and before it builds a prompt, so switching it off stops message text leaving your workspace immediately.

Nothing happens to your board on its own. The result is a suggestion shown beside the message. It changes nothing until a person clicks to accept it, and the target is re-checked against the database — and against that person's own permissions — at the moment they do.

How to switch it off. An administrator with the *configure AI* permission turns it off at Org settings → AI & Meetings. It is a workspace-wide setting: off means off for every member and every channel.

⚠ The setting belongs to your organization, not to you. If you use Noots through an organization, whether your channel messages are scanned is your organization's choice and not yours — your administrators set it, and the organization is the controller of that content (Section 0). If you want to know whether it is on where you work, or you want it changed, ask your administrators; we cannot change one organization's setting at another person's request. You can always keep a message out of the scan by sending it as a direct message or a group chat.

We changed this default, and we are telling you rather than letting you find out. The feature first shipped switched off for everyone. In July 2026 the default was changed to on, and existing workspaces were switched on with it. The switch itself did not change, and it has always been enforced on the server.


5. Who we share information with

We disclose Personal Information only as described in this Policy or as you otherwise authorize.

5.1 Your organization

If you use the Service through an Organization, its Administrators can access, manage, export, modify, and delete information associated with that workspace, in accordance with the Terms of Service and applicable law. Other members can see what the workspace's permissions let them see.

5.2 Sub-processors and service providers

These are the third parties that process personal information or customer content on our behalf. They act on our instructions, under contracts requiring confidentiality and appropriate security. This list is intended to be complete for the Service as we operate it. We will update it before adding a sub-processor that receives customer content.

ProviderWhat it receivesWhyWhen
Hetzner Online GmbHAll data stored by the Service, as our hosting infrastructure providerServers, storage, and networking. The application and database are operated by Cartex on that infrastructure.Always
OpenAIMeeting transcripts; chat, mail, task, and project content; the prompts you type into AI features. Including the text of every message posted in a channel, and the titles of related open tasks and checklist items — see Section 4.5Summaries, action items, Hoot, Autopilot, AI teammates, recaps, opt-in mail AI, and chat suggestionsWhen an AI feature runs — and, unless your organization has switched chat suggestions off, every time a channel message is posted
Deepgram, Inc.Meeting and call audioSpeech-to-text with speaker separationWhen you record or upload a meeting or call
Recall.aiThe meeting join link, and the meeting's audio, video, and transcriptThe meeting bot that joins Zoom, Google Meet, and Microsoft TeamsOnly when you send a bot to a meeting
Stripe, Inc.Organization name, billing email, plan, and transaction dataPayment processing, checkout, and the billing portalPaid plans only
Google LLCOAuth identity; and, per connector, your calendar events or Gmail messages"Sign in with Google"; the Google Calendar and Gmail connectorsOnly if you use them
Microsoft CorporationOAuth identity; and, per connector, your Outlook calendar or Outlook mail"Sign in with Microsoft"; the Microsoft Calendar and Mail connectorsOnly if you use them
Zoom Communications, Inc.Your Zoom account identity and your scheduled meeting listThe Zoom connectionOnly if you connect Zoom
GitHub, Inc.Repository, pull-request, and branch data; we create webhooks and branches using your tokenThe GitHub integrationOnly if you connect GitHub
Giphy, Inc.Your GIF search terms. GIFs are then loaded directly by your browser from GIPHY, so GIPHY also receives your IP address and browser details.The chat GIF pickerOnly when you open the GIF picker or view a GIF someone sent
The mail host you choose (for example Gmail, Outlook, Yahoo, iCloud, or any IMAP/SMTP server you enter)Your mailbox credentials and your mail trafficConnecting your own mailboxOnly if you add one
Atlassian (Jira), Asana, Trello, monday.comThe credentials you supply and the project data being importedOne-way project importOnly when you run an import
Salesforce, HubSpotCRM records, in both directionsThe CRM connectors, where enabledOnly if enabled and connected
Anthropic; Google (Gemini)Task titles and descriptionsOptional "bring your own API key" drafting extensions, using your key and your account with that providerOnly if you install one and supply a key

Not currently enabled. Our codebase contains integrations for PostHog (product analytics) and Sentry (error reporting) that are switched off — no key is configured, and neither loads or receives anything. We currently use no third-party product-analytics, advertising, session-replay, or tag-management service on our websites or in the app. If we enable one, we will update this Policy and this list first.

Self-operated, not third parties. Our outbound email server, our WebRTC relay (TURN) server, our in-house meeting bot, and our automation infrastructure are operated by Cartex on our own hosting. They are not separate vendors.

5.3 Recipients you designate

Some features send data to destinations you choose, which we cannot enumerate in advance:

  • Outbound webhooks — event payloads go to any URL your organization registers.
  • Chat link previews — when someone pastes a link, our server fetches that page to build a preview, and your browser then loads the preview image directly from that site, which will see your IP address and browser details.
  • CRM lead enrichment — fetches a contact's company website when you ask it to.
  • Meeting bots — joining a meeting on a third-party platform necessarily discloses the bot's presence and the meeting content to that platform and its participants.

We may disclose information where we believe in good faith that it is required to comply with law, respond to lawful legal process, satisfy a governmental or law-enforcement request, protect the rights, safety, or security of Cartex, our users, or others, investigate fraud, abuse, or a security incident, or enforce our agreements. Where the law permits and it is reasonable to do so, we will try to notify you.

5.5 Business transactions

Information may be transferred as part of a merger, acquisition, financing, restructuring, bankruptcy, or sale of assets, subject to confidentiality obligations. If that happens, we will notify you and this Policy will continue to apply until the acquirer publishes its own — which, if it is materially different, will require notice to you.

5.6 Aggregated and de-identified information

We may share aggregated or de-identified information that cannot reasonably identify anyone.

5.7 Advertising and commercial partners

We disclose Personal Information to no advertising network, ad-tech vendor, data broker, or commercial partner. There is no such recipient to name, which is why none appears in the table above.

Section 6.2 reserves the right to add such recipients later. If we do, the categories of recipient and the categories of information they receive will be described here and in Section 6 before any disclosure occurs, on the notice terms in Section 6.3.


6. Selling, sharing, and targeted advertising

This section exists because these words have specific legal meanings and because we want to be exact rather than reassuring.

It has two halves, and they are labelled: what is true today, and what this Policy permits us to do later. Both are here on purpose. A privacy policy that only describes today has to be rewritten from scratch the first time anything changes, and a reader is entitled to know now what we are reserving the right to do — but it must never be possible to read a reservation as a description. So: everything in §6.1 is a statement of current fact. Everything in §6.2 is a permission we are not exercising.

6.1 What is true today

We do not sell Personal Information. We do not exchange it for money or for other valuable consideration.

We do not share Personal Information for cross-context behavioral advertising. There is no advertising in the Service — no ad server, no ad slots, no advertisers, no ad identifiers — and there is no advertising or analytics tag on our websites.

We do not engage in targeted advertising or in profiling that produces legal or similarly significant effects about you.

Sending content to our AI providers is not a sale and not a share. That includes the channel message text sent to OpenAI for chat suggestions (Section 4.5), which is on by default. We receive no money or other value for it, OpenAI processes it on our instructions as a service provider and may not use it for its own purposes or to train its models, and none of it is used for advertising. It is disclosed as processing, in Section 4 and Section 5.2 — this section is about a different thing, and we are not using one to quietly cover the other.

There is no sponsored content and no personalized advertising in the Service. No such feature has ever been built. Earlier versions of this Policy described sponsored content in the present tense, which was wrong; that description is gone, and what replaces it is the permission in Section 6.2 and the preference in Section 2.1 that switches it off in advance.

About "Partner sharing". The Service shows a Partner sharing preference, and earlier versions of this Policy described sharing data with "vetted partners" as something we did. To be precise about what exists:

  • Cartex has no partner-sharing arrangement with any third party. There is no partner integration, no partner recipient, and no automated transmission of your information to any partner. The preference is permission for something that has not happened.
  • The only mechanism the preference affects is an internal export: Cartex platform staff can manually generate a file containing, for each included user, their name, email address, account creation date, the three consent preferences, and three counts (organization memberships, tasks assigned, meetings in their organizations). It contains no task titles, no messages, no transcripts, and no workspace content. It does not leave Cartex, and it is audit-logged when it is produced.
  • Switching "Partner sharing" off excludes you from that export. So does switching off "Help improve Noots": both must be on for a record to be included, and turning off either one is enough to be excluded. (Until July 2026, either one being on was enough to include you — which meant switching partner sharing off on its own changed nothing. That was wrong and it is fixed.)

6.2 What this Policy permits us to do later

Cartex may in the future offer personalized or sponsored content, and may share personal information with commercial partners. This Policy permits both. We are doing neither today, and we have never done either. This subsection exists so that the permission is disclosed to you now, in the document that governs it, rather than introduced quietly later.

If we ever do, this is the outer boundary of what it could cover:

If we introduceWhat could be involvedWho could receive it
Personalized or sponsored content — recommendations, offers, or promotional placements selected using information about youYour account and profile information, your plan, your organization's industry and size, and how you use the Service (§1.1, §1.5, §1.6)Cartex, and any advertising, content, or measurement provider we engage — each named in Section 5.2 before it receives anything
Partner sharing — disclosing personal information to commercial partners, including for their own marketingYour name, email address, account creation date, plan, organization industry and size, and aggregate usage countsCategories of commercial partner, described in Section 5.7 and here before any disclosure occurs

Your Content is not in that table, and its exclusion is the point. We will not use the private content of your meetings, recordings, transcripts, emails, messages, documents, tasks, or workspace to select, target, supply, or measure advertising or sponsored content, and we will not disclose it to a commercial partner. If we ever proposed to, it would require your separate, express, opt-in consent obtained for that purpose and naming that content — never this Policy, never a default-on switch, and never continued use of the Service.

Nothing here is a plan, a commitment, or a prediction. It is permission. If we never build any of it, this subsection simply never applies.

6.3 What must happen first

Before any of Section 6.2 begins, all of the following happen first. These are commitments, not intentions.

  1. This Policy is updated to describe what we are actually doing — the categories of information, the categories of recipient, the purpose, and the retention — so that the permission becomes a description before the processing starts, not after.
  2. You get at least 30 days' notice, on the terms in Section 17.
  3. The controls work before the feature does. "Personalization" and "Partner sharing" are switchable off today, and a preference recorded as off on the day a feature starts means you are excluded from it from the start. We will not launch anything that reads a preference the reader has not had a fair chance to change.
  4. Where the law requires consent, we obtain consent. In the EEA, the UK, and Switzerland, advertising-style personalization and disclosure to a partner for that partner's own purposes generally require opt-in consent under the GDPR / UK GDPR (Section 3). A forward-looking clause in a privacy policy is not a lawful basis, and we will not rely on it as one.
  5. Where the law requires an opt-out mechanism, we build it before we start. For California, that means publishing a "Do Not Sell or Share My Personal Information" link, updating the notice at collection in Section 1.8 before collection for that purpose, and honoring Global Privacy Control and other opt-out preference signals (Section 12). For Texas, Colorado, Connecticut, and the other states in Section 13, it means the targeted-advertising and sale opt-outs those laws require, including universal opt-out signals where they apply.
  6. Minors are excluded. We would not include anyone we know to be under 16 in any personalization, sponsored content, or partner disclosure, in any jurisdiction.
  7. Organization locks are honored. Where an Administrator has locked a category off for their organization (Section 2.1), no member of that organization is included, regardless of individual settings.

7. Data retention

We keep Personal Information only as long as reasonably necessary to provide the Service, fulfil the purposes in this Policy, comply with law, satisfy tax, accounting, and regulatory obligations, resolve disputes, enforce our agreements, and detect fraud and security incidents.

7.1 How long, by category

CategoryHow long we keep it
Account and profile informationWhile your account exists. Deleted when you delete your account (see §7.4).
Meeting recordings, transcripts, documents, tasks, messagesUntil you or your Organization delete them. There is no automatic expiry.
Items you delete (projects, meetings, tasks)They go to the workspace's trash and are permanently purged 7 days later by default. Organizations on our Business plan can set this to 30, 90, 365, or 3,650 days. Note that "3,650 days" is ten years, not forever.
Billing and transaction recordsAs required by financial and tax law.
Security event log (rate-limit trips, suspected abuse, lockdowns) — this log includes IP addressesUntil purged by Cartex platform staff. It is not retained indefinitely by design, but it has no automatic expiry today.
Workspace activity log (who did what, without IP addresses)For the life of the workspace.
Sessions (device/browser record, no IP address)Until they expire or are revoked — a 30-day maximum, with a 6-hour idle timeout.
Support correspondenceAs long as reasonably necessary to provide support and keep a service record.
BackupsBackups are taken by our operators; copies may persist for a limited period after deletion before being overwritten or destroyed.

7.2 Backups and disaster recovery — stated honestly

We run an automated nightly backup. Every night at 00:00 UTC a consistent database dump (pg_dump) is taken, archived together with uploaded files, and copied off this server to separate cloud object storage. Recent nightly archives are retained there.

What we still do not promise. We do not operate live replication or a standby database, we do not have a documented and rehearsed disaster-recovery runbook, and we make no recovery-time or recovery-point commitment — a restore is a manual operation performed by our operators. Backups are not a substitute for your own export: use Settings → Export whenever you need a copy you control, and do not rely on Noots as the only copy of anything you cannot afford to lose.

Corrected 1 August 2026, and worth stating plainly. An earlier version of this section said backups were taken manually and that no automated system existed. That was written honestly but was wrong in both directions: an automated nightly off-site archive had been running the whole time, *and* it did not actually contain the database — the Postgres data directory is owned by another system user and was being silently skipped, so the archives held project files and no database at all. The nightly job now dumps the database explicitly, verifies the dump is inside the archive before uploading, and refuses to upload an archive without one. We are recording the error here rather than quietly rewriting the paragraph.

If you need contractual backup or recovery commitments, contact legal@cartexdata.com — we will tell you honestly whether we can meet them.

7.3 Retention for organizations

Where Cartex acts as a processor, your Organization decides how long its content is kept, within the options the Service provides. Deleting your individual account does not delete content the Organization is entitled to retain.

7.4 What happens when you delete your account

When you delete your account from Settings:

  • Every organization you created is deleted, together with its projects, tasks, meetings, and memberships. This destroys other members' work in those organizations. If you created a workspace other people use, transfer ownership or remove yourself instead of deleting your account.
  • Your user record is deleted, along with your sessions, memberships, connected accounts, and stored integration tokens.
  • Export your data first. You can download everything we hold about you at any time — see Section 9.

What survives. We keep a minimal record — your email address and any linked sign-in identifier, with the deletion date — so that the same address cannot immediately be used to register again. That cooldown lasts 30 days. ⚠ This record is currently retained after the cooldown ends rather than being deleted with it. We are changing that. In the meantime, if you want it removed, write to legal@cartexdata.com and we will remove it.

Copies may also persist in backups for a limited period, and we may retain information where the law requires it or where it is necessary to resolve a dispute, meet a financial or tax obligation, or investigate fraud or abuse.


8. Security

We maintain administrative, technical, and organizational safeguards designed to protect Personal Information. Rather than describe them in the abstract, here is what they actually are — and what they are not. Fuller detail is on our security page.

8.1 What we do

  • In transit: TLS on every connection, with HTTP Strict Transport Security preloaded for two years including subdomains. Content-type sniffing, framing, and referrer leakage are blocked at the edge.
  • Passwords: hashed with scrypt and a per-account salt. We never store the password itself. API tokens are stored as a hash and shown to you once.
  • Third-party credentials: the tokens behind your mail, calendar, meeting, CRM, and repository connections are encrypted with AES-256-GCM under a per-record random nonce. The credential vault stores secrets the same way.
  • Access control: role-based permissions enforced in the database query itself rather than in the interface; per-project visibility rules applied on every read.
  • Sessions: signed, HttpOnly, same-site, with a 30-day maximum lifetime and a 6-hour idle timeout; revocable at any time.
  • Two-factor authentication: TOTP, available to every user on every plan, with a set of ten single-use recovery codes issued when it is switched on. On Business and Enterprise plans an Organization can require it: a member who has not enrolled is stopped at an enrolment screen and cannot reach the workspace, our API, or any action within it until they do. Two exemptions apply, and we state them rather than let an administrator assume otherwise — members whose sign-in an Organization has already forced through an enforced SAML identity provider (that provider owns their second factor, and they have no password path here), and personal API tokens and the browser extension, which authenticate a deliberately issued credential rather than a sign-in and are revoked when the holder leaves the Organization or changes their password.
  • Abuse controls: rate limiting, a security watchdog with automatic lockdown, IP allowlisting for organizations that configure it, SSRF protection with re-validation on every redirect, and HMAC-signed outgoing webhooks.
  • Single sign-on: SAML 2.0 with signature verification, and SCIM 2.0 provisioning with the bearer token stored as a hash.

8.2 What we do not claim

  • Encryption at rest of the database itself is our hosting provider's, and we hold no attestation for it. What we can point to in our own code is the AES-256-GCM envelope around every third-party credential we store, and TLS on every connection. We will not describe the database as "encrypted at rest" on that basis.
  • We hold no SOC 2, ISO 27001, HIPAA, PCI DSS, or FedRAMP certification or attestation, and we do not offer a HIPAA business associate agreement.
  • We publish no uptime SLA.
  • We offer no choice of data-residency region, and there is no longer a setting that suggests otherwise. Noots runs in a single hosting region. The control that used to record a regional preference has been removed rather than left in place implying something it never did; where a value was stored before removal it is retained in our records but is read by nothing. See Section 15.
  • We operate an automated nightly backup but no rehearsed disaster-recovery process, and we publish no recovery-time or recovery-point commitment. See Section 7.2.

No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential, securing the devices you use, and telling us promptly at support@noots.ai if you suspect unauthorized access.

8.3 Breach notification

If we determine that a security incident affecting Personal Information requires notification, we will notify affected users, affected Organizations, and the relevant authorities within the timeframes the applicable law requires — including, where the GDPR applies, notification to the competent supervisory authority without undue delay and where feasible within 72 hours of becoming aware of it.

Nothing in this Policy is a contractual guarantee of a specific security standard, certification, or outcome unless we have agreed to it in a signed writing.


9. Your privacy choices and controls

Unless your Organization has restricted it, from within the Service you can:

  • update your account and profile information;
  • manage your privacy and consent preferences at Settings → Data & Compliance — including Personalization and Partner sharing, which you can switch off now, before there is anything for them to permit (Section 6.2);
  • connect and disconnect third-party services;
  • export everything we hold about you — a single download containing your preferences, consent settings, memberships, projects, tasks, comments, messages, meetings, action items, calendar events, time off, files, notifications, activity, sessions, and API tokens. It is available to every user, on every plan, with no approval step;
  • delete individual content; and
  • delete your account — read Section 7.4 first.

Chat suggestions. Whether channel messages are scanned is an organization setting, not a personal one — an administrator switches it at Org settings → AI & Meetings (Section 4.5). As an individual member you cannot turn it off for your workspace, and we will not say otherwise. What you can rely on is that direct messages and group chats are never scanned, and neither is any message beginning with /.

Marketing email. You can unsubscribe from product and marketing email at any time. We will still send you essential service messages — security alerts, billing notices, and legal notices — because they are part of providing the Service.


10. Your privacy rights

Depending on where you live, you may have some or all of the following rights. We honour these rights for everyone, everywhere, to the extent we are able to — not only where a law compels us.

RightWhat it means
AccessConfirm whether we process your Personal Information and get a copy of it
RectificationCorrect information that is inaccurate or incomplete
ErasureAsk us to delete your Personal Information, subject to legal exceptions
PortabilityReceive your data in a structured, commonly used, machine-readable format — this is what the export in §9 provides
RestrictionAsk us to limit how we process your information in certain circumstances
ObjectionObject to processing based on our legitimate interests, and to direct marketing at any time
Withdraw consentWhere processing relies on consent, withdraw it at any time
Non-discriminationWe will not treat you worse for exercising a privacy right

How to exercise them. Use your account settings and the export tool for the fastest route, or write to legal@cartexdata.com. We may ask for information reasonably needed to verify your identity. We will respond within the time the applicable law requires — one month under the GDPR (extendable by two months for complex requests), 45 days under California law (extendable once by a further 45 days).

If you are a member of an organization, requests about that workspace's content will normally be forwarded to your Organization's Administrators, because the Organization is the controller of that content (Section 0).

Authorized agents. Where the law allows, you may appoint someone to make a request on your behalf. We may verify both your identity and their authority.

When we may decline. We may decline a request that is manifestly unfounded, excessive, or repetitive, that the law prohibits us from fulfilling, or that would adversely affect another person's rights. We will tell you why, and how to appeal.

Complaints. If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA authorities is maintained by the European Data Protection Board; in the UK it is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first at legal@cartexdata.com, but you are not required to come to us before complaining.

EU/UK representative. Cartex has not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR / UK GDPR. Contact us directly at legal@cartexdata.com.


11. Cookies and similar technologies

We use cookies and local storage to keep you signed in, remember your workspace and preferences, keep the Service secure, and make it work.

The cookies and stored values we set are functional and necessary, including your session cookie, your current organization, your language, and — in local storage — your theme and appearance preferences. We set no advertising cookies and no third-party analytics cookies, because we run no advertising and no third-party analytics.

Honest statement about consent. The Service does not currently present a cookie consent banner or a cookie-preference tool. We take the position that the cookies and storage we use are strictly necessary to deliver a service you have asked for, which is the category that generally does not require consent. If we introduce any non-essential cookie or similar technology, we will implement a consent mechanism before we do, and update this Policy.

You can control or delete cookies through your browser or device settings; blocking the functional ones will prevent the Service from working.

Do Not Track and Global Privacy Control. We do not currently detect or respond to Do Not Track or Global Privacy Control signals. We do not sell personal information, do not share it for cross-context behavioral advertising, and run no targeted advertising, so there is nothing for such a signal to switch off today. If that ever changes, we will support the opt-out signals the law requires before it does — that commitment is Section 6.3, item 5.


12. California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you rights over your Personal Information.

What we collect and why is set out in the notice at collection in Section 1.8. Sources are you, your Organization, the services you connect, and automatic collection. Business and commercial purposes are in Section 2. Categories of third parties that receive it are in Section 5. Retention is in Section 7.

Your rights. To know, to access specific pieces, to correct, to delete (subject to exceptions), to obtain a portable copy, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them.

Sale and sharing. We have not sold Personal Information, and we have not shared it for cross-context behavioral advertising, in the preceding twelve months. We do not sell or share the personal information of minors under 16. Because we do neither, we publish no "Do Not Sell or Share My Personal Information" link — there is nothing to opt out of.

If that changes, the link comes first. Section 6.2 reserves the right to introduce personalized or sponsored content and partner sharing, and some of that would be a "sale" or a "share" as California defines those words. Before any of it begins we will publish the "Do Not Sell or Share My Personal Information" link, update the notice at collection in Section 1.8, and honor opt-out preference signals — see Section 6.3. See Section 6.1 for a precise account of the "Partner sharing" setting as it stands today.

Sensitive personal information. We collect the categories described in Section 1.8 (category L). We use and disclose it only for the purposes permitted under Cal. Civ. Code § 1798.121(a) and its regulations — performing the services you requested, security and integrity, and preventing fraud — and not to infer characteristics about you. Because of that, the right to limit its use does not give you anything additional here, which is why no "Limit the Use of My Sensitive Personal Information" link appears.

Authorized agents and appeals. See Section 10. If we deny a request, reply to our response and we will review it.

Shine the Light. California Civil Code § 1798.83 permits residents to request information about disclosures to third parties for their direct marketing purposes. We make no such disclosures.


13. Texas and other U.S. state privacy rights

Cartex Data, LLC is a Texas company. Residents of Texas and of other U.S. states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and others as they take effect — may have the right to confirm whether we process their Personal Information and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.

We do none of those three things. We do not sell personal data, we do not engage in targeted advertising, and we do not carry out profiling that produces legal or similarly significant effects. There is accordingly nothing for you to opt out of, and no universal opt-out signal to honour.

Section 6.2 reserves the right to introduce personalized or sponsored content and partner sharing, either of which could amount to targeted advertising or a sale under these laws. If we do, we will support the required opt-out mechanisms — including browser-based universal opt-out signals where the law requires them — before any of it begins, and give the notice in Section 6.3.

Texas Data Privacy and Security Act. Under the TDPSA we disclose that we process the categories of personal data described in Section 1.8, for the purposes in Section 2, and that we share those categories with the third parties described in Section 5. We do not sell sensitive personal data and we do not sell biometric data, so neither of the notices required by Tex. Bus. & Com. Code § 541.102 applies to us.

Texas biometric identifiers (CUBI). Meeting recordings capture voice. As explained in Section 4.3, we do not capture or use a voiceprint or other biometric identifier for the purpose of identifying an individual, and we do not sell, lease, or disclose biometric identifiers.

Exercising your rights and appealing. Use the routes in Section 10. If we decline a request, our response will tell you how to appeal; if we deny an appeal, you may contact your state attorney general — in Texas, the Office of the Attorney General's consumer protection division.


14. Children's privacy

The Service is a workplace product intended for professional, business, educational, and organizational use. It is not directed to children, and our Terms of Service require account holders to be at least 18 years old, or the age of majority where they live.

We do not knowingly collect Personal Information from anyone under 13, or under 16 in the European Economic Area and the United Kingdom (or the lower age set by an EEA member state, which is never below 13), without the consent or authorization of a parent or guardian.

Where an educational institution or other Organization enrolls individuals under 18, the Organization is responsible for obtaining every consent and authorization its law requires, including under laws protecting student data, and acts as the controller of that content.

If you believe a child has given us Personal Information, contact legal@cartexdata.com and we will take reasonable steps to delete it.


15. International data transfers

Cartex is based in the United States, and Personal Information is stored and processed in the United States. Our hosting infrastructure is provided by Hetzner Online GmbH, and our sub-processors (Section 5) may process information in the United States and elsewhere.

If you are outside the United States, using the Service means your information is transferred to a country whose data protection laws may differ from your own.

Safeguards. Where the law requires a transfer mechanism, we rely on:

  • the European Commission's Standard Contractual Clauses;
  • the UK International Data Transfer Addendum to those clauses, or the UK Addendum's equivalent, for transfers from the United Kingdom;
  • the Swiss addendum for transfers from Switzerland; and
  • contractual and technical safeguards with our sub-processors.

We will provide a copy of the relevant clauses on request to legal@cartexdata.com, and they form part of the Data Processing Addendum we offer to Organizations.

We do not participate in the EU–U.S. Data Privacy Framework, the UK Extension, or the Swiss–U.S. Data Privacy Framework, and we do not claim certification under any of them.

We do not offer data residency, and we no longer offer a setting that looks like it. Noots runs in a single hosting region, and all Personal Information is stored and processed there. Earlier versions of the product exposed a "data residency" selector on some plans; it recorded a stated policy and never routed or stored anything in a particular region, so it has been removed rather than left to imply a control that did not exist. Where an Organization set a value before the removal, that value is retained in our records but is read by nothing and has no effect. If you have a genuine data-residency requirement, talk to us at legal@cartexdata.com before you rely on Noots for it.


16. Automated decision-making and profiling

The Service generates AI Output about work — and, because work is done by people, some of it is about people. Autopilot can propose that a task be reassigned, flag work as at risk, and summarize workload and capacity. Managers may see indicators about their team's workload derived from workspace activity.

These are suggestions inside a workspace, not decisions we make about you.

  • We do not use automated processing to make decisions that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 of the GDPR. We do not use it to make or influence hiring, firing, promotion, pay, credit, insurance, or eligibility decisions.
  • Every AI proposal that changes work in a workspace can be reviewed, overridden, and undone by a person with the appropriate permission, and the more consequential ones require a person to approve them.
  • Chat suggestions read messages to propose board changes, not to assess people. (Section 4.5.) The scan produces one thing — a suggested change to a task, checklist, or note — which a person must accept. It does not score, rank, rate, or profile the people writing the messages, and nothing it produces is shown to anyone as an assessment of a person.
  • An Organization may nonetheless use what it sees in Noots to make decisions about its own people. That is the Organization's processing, not ours, and the Organization is responsible for the lawfulness, transparency, and fairness of it — including any employee-monitoring notice its law requires. ⚠ That applies with particular force to chat suggestions, which read what employees write to each other: an organization that leaves the feature on may owe its people a notice, or a works-council or similar consultation, that only it can give.

If you believe an automated feature has produced an unfair or inaccurate result about you, tell us at legal@cartexdata.com. You may ask for human review, express your point of view, and contest the outcome.


17. Changes to this Privacy Policy

We may update this Policy to reflect changes in the law, in the Service, or in our practices.

When we make a material change we will update the effective date above and give notice — by email, in the Service, or by a notice on our website — at least 30 days before it takes effect, unless a shorter period is needed to comply with law. Where the law requires your consent to a change, we will ask for it rather than assume it. Non-material changes take effect when published.

Beginning any of the processing permitted by [Section 6.2](#62-what-this-policy-permits-us-to-do-later) is a material change — personalized or sponsored content, or sharing personal information with a commercial partner. It gets the full 30 days' notice and everything else in Section 6.3, including consent where the law requires it.

Your continued use of the Service after a change takes effect means you acknowledge the updated Policy, except where the law requires additional consent.


18. Contact

Cartex Data, LLC — Texas, United States

PurposeAddress
Privacy questions, data-subject and consumer-rights requests, DPA and Standard Contractual Clause requests, legal noticeslegal@cartexdata.com
Product support, account and billing questions, reporting a suspected account compromisesupport@noots.ai

We will respond to privacy requests within the timeframes applicable law requires. If you are in the EEA, the UK, or Switzerland, you may also complain to your local supervisory authority — see Section 10.

Noots.ai is a product developed, owned, and operated by Cartex Data, LLC.

Questions about this document? Write to legal@cartexdata.com. For help with your account, write to support@noots.ai. Noots.ai is a product of Cartex Data, LLC.