Legal

Privacy Policy

Last updated: March 14, 2026

Introduction

Notara ("we", "our", or "us") operates the Notara platform, including the Slack application, web dashboard, and associated services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Information We Collect

We collect information in the following categories:

  • Account information — name, email address, Slack workspace ID, and billing details provided during registration.
  • Usage data — messages sent to the Notara agent, commands executed, integrations connected, and feature usage patterns.
  • Integration data — metadata from connected third-party services (Stripe, Linear, GitHub, etc.) necessary to fulfill agent requests. Raw API responses are processed in memory and not persisted.
  • Technical data — IP addresses, browser type, device information, and log data collected automatically when you access our dashboard.

How We Use Your Information

  • To provide, maintain, and improve the Notara service.
  • To execute agent tasks on your behalf (e.g., pulling metrics, sending emails, managing tasks).
  • To maintain persistent memory within your workspace for contextual conversations.
  • To process payments and manage your subscription.
  • To send transactional communications (billing receipts, service updates, security alerts).
  • To detect, prevent, and address technical issues or abuse.

Data Storage & Security

All credentials and API keys are encrypted with AES-256-GCM at rest. We never store API keys in logs, Slack messages, or unencrypted storage. Data is hosted on infrastructure with SOC 2 Type II compliance. All data in transit is encrypted via TLS 1.3.

Sensitive actions — including sending emails, processing payments, and modifying external data — require explicit user approval before execution (human-in-the-loop).

Third-Party Services

Notara integrates with third-party services at your direction. When you connect an integration, we access only the data necessary to fulfill your requests. We do not sell, rent, or share your data with third parties for marketing purposes.

We use commercial LLM APIs to power the AI agent. Your business data is never used to train AI models. We maintain strict data processing agreements with all AI providers.

Data Retention

We retain your data for as long as your account is active. Upon account deletion, all workspace data is purged within 30 days. Billing records are retained as required by law. You may request a full data export at any time by contacting support@notara.ai.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access and receive a copy of your personal data.
  • Rectify inaccurate or incomplete data.
  • Request deletion of your personal data.
  • Object to or restrict processing of your data.
  • Data portability — receive your data in a structured format.
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, contact us at support@notara.ai. We respond to all requests within 30 days.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance.

Contact Us

If you have questions about this Privacy Policy, contact us at support@notara.ai.