The short version
• Your content is yours. We store it to run the service and never sell it or use it for advertising.
• AI features send the content you submit to model providers for processing — and only when you trigger them.
• Connecting Claude, ChatGPT, or a Custom GPT sends project content to Anthropic or OpenAI at your request, under their terms.
• Share links are public to anyone who has them. Everything else requires your sign-in.
• We use one essential session cookie. No ad trackers, no third-party analytics.
What we collect
Account information
Your email address (used to sign in and to send you sign-in links), a hashed password if you set one, and session records.
Content you create and upload
Notebook pages (ink strokes, shapes, text, typed documents), uploaded files (images, logos, spreadsheets, PDFs), generated artifacts and their version history, co-pilot chat threads, and annotations. This is the product — we store it so your work persists across devices and sessions.
Usage and billing records
Each AI operation records token counts, model used, and computed cost so your Usage & Analytics page and credit balance are accurate. These are accounting records, not content copies.
Technical data
Standard server logs (IP address, request path, timestamps) kept transiently by our infrastructure provider for security and debugging. We do not build behavioral profiles.
How we use your data
- To run Notebook — storing projects, rendering previews, generating exports and share links.
- To power AI features — when you ask the co-pilot to build, edit, analyze, or interpret images, the relevant content (your prompt, pages, attached files, current document) is sent to a model provider for processing.
- To bill accurately — usage events determine credit consumption.
- To keep the service safe — abuse prevention and debugging.
We do not sell your data, share it with advertisers, or use your content to train models ourselves.
Where your content travels
Infrastructure
Notebook runs on Cloudflare (Workers, D1, R2, Browser Rendering). Your stored content lives in Cloudflare's data centers, encrypted in transit (TLS) and at rest.
AI model providers
AI features are processed by Google Gemini models accessed through OpenRouter. The content you submit for a given operation (and only that content) is sent to them to generate the result, subject to their privacy terms. We use API access, which these providers state is not used to train their models.
Assistant connectors — Claude, ChatGPT, and Custom GPTs
If you connect an assistant, that's a channel you open. When you press Send-to-assistant in Notebook (or say “go” in your assistant), the queued request — your prompt, page images or their text interpretations, data schemas, and the current document — is delivered to Anthropic (Claude) or OpenAI (ChatGPT / Custom GPT), and what the assistant builds is saved back to your project. Content shared this way is processed under Anthropic's or OpenAI's privacy policies. Disconnect anytime from Notebook's side panel; revoke API keys under Connect › API & Keys.
Sign-in and operational emails are delivered via Resend. Your email address is shared with them solely to send those messages.
Sharing you control
Share links (/s/… and /g/…) make a snapshot of that artifact readable by anyone who has the link, without signing in. Downloaded HTML and PDF exports contain your document's content, including any data baked into it. Revoking a share link stops future access.
Cookies
One essential cookie (nb_session) keeps you signed in. We set no advertising or cross-site tracking cookies and run no third-party analytics scripts.
API keys and connector tokens
Connector tokens and Custom-GPT API keys grant access to your account — treat them like passwords. Each surface has its own revocable credential: rotate your Custom-GPT key under Connect › API & Keys (the old key stops working immediately), and revoke assistant connections from the side panel.
Retention and deletion
- Deleting a project, page, upload, or artifact removes it from your account immediately.
- Version history exists so you can roll back; deleting a project removes its versions too.
- Usage/billing records are retained as accounting data.
- To delete your entire account and its data, email us (below) from your account address — we'll confirm and complete it within 30 days.
Security
All traffic is TLS-encrypted; stored data is encrypted at rest by our infrastructure provider; secrets and keys are stored server-side and never exposed to other users. No internet service can promise perfect security — use a strong password and guard your API keys.
Children
Notebook is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we don't knowingly collect their data.
Changes to this policy
If we make material changes, we'll update the date at the top and note the change here. Continued use after a change means you accept the updated policy.
Contact
Questions, requests, or deletions: support@notebooks.live.