PRIVACY POLICY – NotuLast updated: March 2026

1. INTRODUCTION This Privacy Policy explains how Rohe Technik OÜ ("Company", "We", "Us", or "Our") collects,uses, and protects your information when you use the Notu application and services. We are committed to protecting your privacy and ensuring your data is handled securely and in compliance with the General Data Protection Regulation (GDPR).

2. DATA WE COLLECT

  • Account Information: Name, email address, and authentication data (e.g., Google or Apple ID).

  • Audio & Text Data: Voice recordings collected via your device's microphone, uploaded audio files, and the resulting AI-generated transcripts and summaries.

  • Usage Data: IP address, device type, operating system, and app interaction logs to improve service performance.

  • Payment Information: If applicable, processed securely through third-party providers (e.g., Stripe, Apple, or Google). We do not store credit card numbers.

3. HOW WE USE YOUR DATA

  • Core Service: To provide AI-powered transcription, summarization, and organization of your notes.

  • Customer Support: To respond to your inquiries via support@rohe.ai.

  • Service Improvement: To diagnose technical issues and optimize the AI’s performance for your specific account.

  • Compliance: To meet legal obligations and enforce our Terms of Service.

4. LEGAL BASIS FOR PROCESSING (EEA/UK USERS) Under GDPR, we process your data based on:

  • Contractual Necessity: To provide the Notu service you have signed up for.

  • Consent: When you explicitly grant permission (e.g., microphone access).

  • Legitimate Interest: For security, fraud prevention, and improving our internal AI workflows.

5. DATA STORAGE AND SECURITY

  • Encryption: All audio and text data are encrypted in transit (SSL/TLS) and at rest.

  • Retention: We retain your recordings and transcripts as long as your account is active. You may delete individual notes or your entire account at any time, which will trigger the permanent deletion of associated data from our active servers.

6. YOUR RIGHTS You have the right to:

  • Access & Export: Request a copy of your personal data and transcripts.

  • Rectify: Correct inaccurate information.

  • Erase: Request the deletion of your account and all associated data ("Right to be Forgotten").

  • Restrict/Object: Limit how we process your data in certain circumstances. To exercise these rights, contact support@rohe.ai.

7. THIRD-PARTY AI SUB-PROCESSORS Notu utilizes advanced AI models to generate transcripts and summaries.

  • Data Sharing: To provide these features, we transmit your audio recordings and text data to our third-party AI partners, specifically OpenAI. (Note: If you use other AI APIs like Anthropic or Google natively in the app, list them explicitly here alongside OpenAI).

  • Data Minimization: We only send the minimum data required to perform the requested AI task.

  • Equal Protection & No Training: We confirm that our third-party AI partners provide the same or equal protection of your user data as stated in this privacy policy. Furthermore, we have configured our API agreements to ensure these third parties do not use your data to train their global models.

8. INTERNATIONAL TRANSFERS Data may be processed outside the EEA (e.g., in the US). We ensure that Standard Contractual Clauses (SCCs) or other recognized safeguards are in place with all sub-processors to maintain a level of protection equivalent to the GDPR.

9. RECORDING CONSENT & USER OBLIGATION Notu is a tool for the user. As the user, you are the "Data Controller" of the audio you record. You represent and warrant that you have obtained all necessary consents from all participants in a conversation before recording or transcribing it using Notu.

10. DATA PROCESSING ADDENDUM (DPA) For our business and professional users, this section serves as a Data Processing Addendum.

  • Roles: When you use Notu to process personal data of third parties (e.g., recording a client meeting), You are the Data Controller and Rohe Technik OÜ is the Data Processor.

  • Instructions: We will process data only on your documented instructions (via app settings/usage) and for the purposes defined in our Terms.

  • Confidentiality: All personnel authorized to process your data have committed themselves to confidentiality.

  • Security Measures: We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

11. SUB-PROCESSING By using Notu, you provide general authorization for us to engage sub-processors (AI providers and cloud hosting). We will ensure these sub-processors are bound by data protection obligations no less protective than those in this policy.

CONTACT US Rohe Technik OÜ Registry code: 17165314 Address: Harju maakond, Tallinn, Kesklinna linnaosa,Tornimäe tn 5, 10145, Estonia. Email: support@rohe.ai © 2026 Rohe Technik OÜ. All Rights Reserved.

Create a free website with Framer, the website builder loved by startups, designers and agencies.