Privacy notice draft
Last reviewed: 26 July 2026
JotWeave is a private notes, chat, and assistant workspace. It is not end-to-end encrypted: the service and selected providers can read content needed for the features a user invokes.
What the product stores
- Account data: email, display name, authentication, membership, and security records handled through Supabase-backed account flows.
- User content: notes, tasks, messages, meetings, files, and related workspace records created or uploaded by a user.
- Usage and service data: quota, billing-entitlement, audit, and security records needed to operate and safeguard supported workflows.
- Connected-service data: tokens and requested content for a service a user explicitly connects. Availability and permissions depend on the specific connector and deployed configuration.
Google user data
When the Google integration is configured and a user authorizes it, JotWeave can request Google Calendar and optional Gmail access for supported actions. Exact scopes, retention, transfer, and deletion behavior must be rechecked against the deployed configuration before this notice is published.
Any production use and transfer of information received from Google APIs must follow the Google API Services User Data Policy, including Limited Use requirements. Owner confirmation remains required for the final advertising, sale, model-training, transfer, and exception language.
AI processing
Supported cleanup, organization, transcription, summary, and search workflows can send relevant content to a configured, provider-abstracted AI service. Provider availability, retention, account settings, and model-training terms can differ. JotWeave does not publish a universal no-training or zero-retention promise without current contract and setting proof.
Access and storage boundaries
Repository schema uses row-level security and membership checks for covered data. Newer V2 schemas and cross-object paths still require migrated, authenticated runtime verification. JotWeave does not make a universal encryption-at-rest claim for every database, object, backup, token, queue, log, and provider path.
Deletion and retention
Supported app surfaces include deletion paths for content and connected-service tokens. Account deletion can be requested through the feedback form. The final policy still needs confirmed timing for account data, backups, derived indexes, audit records, and provider-held data.
Business policy confirmation
Sale, advertising use, subprocessors, legal disclosures, cross-border processing, and company-wide handling are business and legal commitments that application source code cannot prove. The owner must confirm those commitments and publish the approved wording before this route can be indexed as the production privacy policy.
Questions
Send questions or policy requests through the feedback form.