Privacy policy
What Nootles collects, why, and what happens to it. The short of it: this website collects nothing. The app is in beta, and beta means candour — sessions are recorded, AI interactions are kept and used to train the models, and this policy says exactly what goes where. Nothing is sold, and nothing is shown to advertisers.
Who we are and what this covers
Nootles Inc. (“Nootles”, “we”, “us”) operates www.nootles.com (the “Site”) and the application at app.nootles.com (the “App”). This policy covers both, and it is written to be read: if anything in it is unclear, ask us at privacy@nootles.com.
This website
The Site — the pages you are reading now — is static. It sets no cookies, runs no analytics, shows no advertising, and serves its fonts from our own servers, so reading it tells no third party you were here. When your browser requests a page, our hosting provider keeps standard server logs (your IP address, browser type and the page requested) to deliver the pages and defend against abuse; these are kept briefly and we add nothing to them.
What the app collects
The App is in beta, and a beta collects more than a finished product will — both to run, and to learn what to fix. In full:
- Account information. You sign in with a Google account, handled by Clerk, our sign-in provider. We receive your name, email address and profile photo — never a password, because there isn't one. Onboarding asks what you do and what you'll use Nootles for, and the answers are kept with your profile.
- Your documents. The content you create — prose, diagrams, code, tables, files you upload — together with its full edit history and your conversations with the AI, stored so you can come back to them.
- Session recordings and usage data. During the beta we record how the App is used: the actions you take, and session replays that reconstruct your screen inside the App — including document text as you type it. Recording is on for every session. Analytics run on PostHog; errors are reported to Sentry along with your account identity and recent console output, so what broke arrives with enough context to fix.
- AI interaction records. The instruction you give the AI, the document context sent with it, and what it proposed and you accepted or rejected — kept to evaluate the AI and to train and fine-tune the models that power the Service.
- Feedback. Feedback sent from inside the App carries more than the message: a screenshot of your current screen, recent console output, a summary of recent activity, a link to the session replay, and your email address — so a report arrives with enough context to act on.
- Connected services. If you connect a GitHub repository, we store your access token, encrypted, and summaries of the repository's content, which the AI may read.
- Payment details. If we ever charge and you buy a paid plan, payment will be handled by a third-party payment processor; we will never store full card numbers.
How we use it
We use this information to provide and operate the Service; to store and sync your documents; to power the AI; to train and fine-tune the models that power the Service, for as long as the beta lasts; to watch how the App is used so we can fix and improve it; to secure it and prevent abuse; to answer you; and to comply with law. We do not use your information for advertising, and we do not sell it — and never have.
AI assistance
When the AI reads or edits your document, the relevant content and your instruction are sent to third-party model providers to generate the response: inline completions go to Mistral, and chat, reformatting and diagram work goes through OpenRouter to models from providers such as Google, OpenAI and Anthropic. When the AI searches the web on your behalf, the search queries leave too. These providers process the content to provide the service and handle it under their own terms.
And plainly, because it is the price of the beta: we keep records of your AI interactions — instruction, document context, what was proposed, what you accepted — and use them to train and fine-tune the models that power Nootles. If something must stay out of a model's training data, the beta is not yet the place to write it.
Sharing and links
Pages can be shared by link, and a share link works without an account: anyone who has it can read the page, and the files on it, whose addresses are themselves durable links. Visitors to a shared page appear to its collaborators with a display name. Treat a share link like the key it is, because that is what it is.
When we share
We share personal information only:
- With service providers — Vercel (hosting), Convex (database and file storage), Clerk (sign-in), PostHog (analytics and session replay), Sentry (error reporting), the AI model providers named above, and the content-delivery networks that serve parts of the App — who may use the information only to provide their service to us;
- To comply with law, when a legal process genuinely requires it, in which case we will tell you unless we are prohibited from doing so;
- To protect rights and safety, ours, yours or others', including to investigate fraud or abuse;
- In a business transfer, if Nootles is acquired or merges, in which case this policy continues to apply to your information until you are told otherwise;
- At your direction, when you use a feature that shares something and choose to share it.
We do not sell personal information and do not share it for cross-context behavioural advertising.
Cookies
The App uses cookies and local storage to keep you signed in, to remember your preferences, and — during the beta — for the analytics and session recording described above. They are set for us and for the providers named in this policy, not for advertisers; there are no advertising cookies. Because sign-in is made of cookies, blocking them means the App cannot work.
Retention
Account information is kept while your account exists. Documents and their edit history are kept so you can come back to them — and during the beta, deleting a page or project removes it from your workspace but does not immediately erase every copy from our systems: edit history, uploaded files and AI interaction records can persist until we erase them. To have your account and everything under it erased, write to privacy@nootles.com and we will do it. Records the law requires us to keep, we keep for as long as it requires.
Security
You sign in with Google, so there is no Nootles password to steal. Connections are encrypted in transit, tokens for connected services are stored encrypted, and access to user data inside Nootles is restricted to operating the Service. No system is perfectly secure and we will not pretend ours is the exception; what we promise is that if a breach affects you, we will tell you as the law requires, and plainly.
Your rights
You can ask for a copy of your information, ask us to correct it, and ask us to erase it — write to privacy@nootles.com. Canadian privacy law (PIPEDA and its provincial counterparts) gives you rights of access and correction; the GDPR, if you are in the EEA or UK, adds rights to portability, to object to or restrict certain processing, and to complain to your data-protection authority; California's CCPA does similar work, including the right not to be discriminated against for exercising it. We will verify a request before acting on it, and we answer within the time the law sets.
Where data lives
Nootles is a British Columbia company, but the Service runs on providers in the United States and elsewhere, so your information is processed outside Canada and is subject to the law of the places it is processed in. Where the law requires safeguards for moving data across borders — such as the EU standard contractual clauses — we use them.
Children
The Service is not directed to children under 13 and we do not knowingly collect their information. If you believe a child under 13 has an account, tell us at privacy@nootles.com and we will delete it.
Changes to this policy
We may update this policy as the Service changes. Material changes will be announced — on the Site, in the App, or by email — before they take effect, and the effective date at the top is always the date of the version you are reading.
Contact
Privacy questions and requests go to privacy@nootles.com.