Who we are
Notka (“Notka”, “we”, “us”) is a voice-journaling service operated by Marek Wituszyński Media Works, a sole proprietorship registered in Poland (NIP 8942767220), which is the controller of the personal data described here. This policy explains what personal data we process when you use notka.ai, why, and the rights you have under the GDPR. Questions: privacy@notka.ai.
Audio is ephemeral
When you record a voice note, the audio is uploaded only to be transcribed, then deleted. We do not retain audio recordings. We keep the resulting text transcription and the structured note generated from it.
What we store
- Account data: your email address and profile preferences (timezone, language, notification settings).
- Note content: transcriptions and the AI-structured output of your notes.
- Reflections: AI-generated summaries derived from your notes.
- Replies to your letters: if you reply to a reflection email, we keep your reply – its text and the address it came from – alongside the letter it answers.
- Search embeddings: a mathematical representation of your notes used for “Ask my notes” search. These are internal and not human-readable.
- Usage and billing metadata required to operate the free and paid tiers.
Sensitive content in your journal
A journal is personal by nature. What you say or write may include sensitive reflections – about your health, mental state, relationships, or beliefs. Notka never asks for this kind of information, but it can't process your notes without also processing whatever you chose to put in them. By using Notka you explicitly consent to your journal content – including any sensitive reflections it may contain – being processed (transcribed, structured, and summarized) for the purposes described in this policy, and for no other purpose. If you withdraw that consent, stop using the service and delete your account – deletion removes the content itself.
Why we are allowed to process it
Each purpose rests on one of these legal grounds:
- Running the service – transcribing your notes, structuring them, writing your reflections, sending your letters, and keeping your account. This is how we perform the contract you entered when you signed up (Art. 6(1)(b) GDPR).
- Sensitive reflections inside your journal – your explicit consent, described in the section above (Art. 9(2)(a) GDPR).
- Keeping the service up and affordable – plan limits, the abuse guard, error monitoring, and cookieless usage counts. Our legitimate interest in a service that stays online and is not drained by abuse (Art. 6(1)(f) GDPR). You can object to this at any time.
- Invoices and tax records – kept because Polish accounting law requires it (Art. 6(1)(c) GDPR).
Notka makes no automated decision that has a legal effect on you. Reflections are generated text you read and judge for yourself – nothing about your account, access, or price is decided by a model.
How your data is processed
To provide the service we share the necessary data with the following processors. Each processes data only to deliver their part of the product. Where a processor handles data outside the EU, the transfer mechanism is listed:
- Supabase – database, authentication, and storage. Hosted in the EU – your notes stay in-region; any support access from its US entity is covered by EU Standard Contractual Clauses.
- OpenAI and Groq – speech-to-text transcription, note structuring, and embeddings. Transfers are covered by EU Standard Contractual Clauses in their data processing agreements.
- Anthropic – generating your reflections. Transfers are covered by EU Standard Contractual Clauses in its data processing agreement.
- Stripe – payment and subscription processing (we never see your card details). Certified under the EU–US Data Privacy Framework, with Standard Contractual Clauses as backstop.
- Resend – sending your letters and account emails, and receiving the replies you send back to them. Transfers are covered by EU Standard Contractual Clauses in its data processing agreement.
- Vercel – hosting and delivery. Certified under the EU–US Data Privacy Framework.
- Cloudflare – delivery and the scheduled jobs that write and send your letters. Certified under the EU–US Data Privacy Framework.
- Sentry – error monitoring, so crashes get found and fixed. It receives the error message and stack trace only: your account id, IP address, cookies, request contents, and note text are stripped before an event leaves Notka. Events are sent to its EU region.
- Upstash – short-lived counters that enforce the plan limits and the abuse guard, keyed to your account id. Hosted in the EU (Frankfurt).
- PostHog – cookieless product analytics (see below). Data is held in its EU region (Frankfurt), and PostHog is additionally certified under the EU–US Data Privacy Framework.
Your note content is not used to train third-party AI models.
Analytics runs in cookieless mode: PostHog sets no cookies and stores no persistent identifier in your browser. Usage is counted through a privacy-preserving hash instead, which is why Notka shows no cookie banner – there is nothing to consent to.
Your rights
You can export all of your notes and reflections at any time from Settings → Your data, and you can permanently delete your account and all associated data from the same screen. Deletion removes your notes, reflections, profile, usage records, and cancels any active subscription. Under the GDPR you also have the right to access, rectify, and object to processing – email privacy@notka.ai and we will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. For Notka, operated from Poland, that is the President of the Personal Data Protection Office (UODO, uodo.gov.pl) – or the data protection authority in the EU country where you live.
Data retention
How long we keep each kind of data:
- Notes, reflections, and your replies – until you delete them, or until you delete your account.
- Audio recordings – never stored. Audio is transcribed and discarded.
- Account data – for as long as your account exists; erased when you delete it.
- Payment records – held by Stripe for as long as its legal and tax obligations require, which is outside our control.
- Rate-limit counters – short-lived technical counters that expire automatically within days.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above.