Notion AI privacy audit

Is Notion AI safe? A privacy audit built from Notion AI's own documents.

The short answer

Last verified 2026-08-04

Notion AI runs inside a cloud workspace. Your pages, your prompts and the AI output are Customer Data on Notion's servers, routed to a bench of third-party model hosts to produce an answer. Notion's AI Supplementary Terms state it does not use Customer Data, and does not permit others to use it, to train the models behind Notion AI, with two carve-outs in the same section for feedback you submit and data you give permission for. That promise appears in four documents with four different subjects and scopes, and the Data Processing Addendum, the binding data-processing contract, carries no AI-training clause at all. AI Meeting Notes adds audio, consent and transcript retention on top, and the strongest retention controls are Enterprise-only. [3][1][4][2][8][9][10][12][13][18][16][6]

What Notion AI does well

  • The no-training commitment sits in a terms document, not only on a marketing page: the Notion AI and Notion Credit Supplementary Terms state Notion does not use Customer Data, and does not permit others to use it, to train the models used to provide Notion AI.
  • Third-party model retention is published with numbers rather than adjectives. Per Notion, LLM providers apply zero data retention by default for Enterprise workspaces and retain data 30 days or fewer by default for all other plans, and embeddings are deleted within 60 days of the page or workspace being deleted.
  • The AI Meeting Notes defaults that Notion does document point the private way: notes you create are private to you, local audio storage is off for all plans, sub-processors do not store audio, and the local copy is deleted after successful processing or within 24 hours, whichever comes first.
  • Consent tooling for recording is built into the product and can be enforced centrally: a text message you paste into the meeting chat, an audio message played to attendees, and a workspace-owner setting that enforces consent for all members.
  • The content license in the Master Subscription Agreement is limited-term rather than perpetual or irrevocable, sublicensable only to Notion's third-party service providers, granted solely to provide and operate the Services and fulfill Notion's obligations in the Agreement, and it expires when Notion deletes Customer Data after termination.
  • Published credentials are named and specific: a SOC 2 Type 2 report, certifications Notion states it has achieved for ISO 27001, 27701, 27017 and 27018, BSI C5, and EU-U.S., UK and Swiss Data Privacy Framework certification. Two-step verification is available on all plan types.

What deserves caution

  • The same promise is written four times with four different subjects. The AI Supplementary Terms commit Notion itself. The Security page and the AI Meeting Notes page instead say Notion's AI subprocessors are contractually prohibited from training. The Privacy Policy's own no-training sentence is narrower again: it covers Google Workspace API data ingested for Notion Mail. The Data Processing Addendum carries no AI-training clause anywhere in its text, including Annex II.
  • Two carve-outs sit in the same section as the promise: data from your use of Notion AI may be used to improve Notion's models when you submit feedback, such as labelling an output with a thumbs up or thumbs down, or when you give permission.
  • A workspace setting called "Share data to improve Notion AI" is available to owners on any plan. Notion's docs never define what "improve" covers, never connect it to the training clause either way, and never state which value a new workspace ships with.
  • The strongest retention controls are Enterprise-only: automatic transcript deletion, custom page and AI-chat retention windows between one day and 10 years, and DLP alerting that covers AI prompts and AI-generated content.
  • Content is routed to a wide model bench. The subprocessor list names Anthropic, OpenAI, Google, Fireworks, Cerebras, Baseten and X.AI for hosting large language models and embeddings, most of them captioned "Global", with AWS as the hosting substrate across the USA, the European Union, Korea and Japan.
  • An organization can claim control and ownership of a workspace created with an email address it provisioned, and the Privacy Policy states Notion may share content within that workspace with the organization. The escape hatch it offers is transferring your account to a different email address.

Training on your content

Off, per Notion's AI terms [3][10]

Opt-out

Toggle exists, default unstated [12]

Where content and audio go

Notion cloud, AWS plus LLM hosts [6][13]

Encryption

TLS 1.2+ and AES-256 [5][4]

2FA

All plans, unless SSO is enforced [16]

Certifications

SOC 2 Type 2, ISO, BSI C5 [8]

Notion AI Meeting Notes product page, the AI workspace assistant this privacy and security audit covers
Notion AI, accessed 2026-08-04

Quick facts

The privacy facts, at a glance.

How audio is captured
Only through AI Meeting Notes, and it is invoked rather than automatic: the /meet command, or a "Join and transcribe" prompt Notion Calendar shows starting 15 minutes before a meeting. No bot joins the call. The desktop app detects that another app is using your microphone in order to raise a notification, and Notion states it does not listen to that audio. [13]
Where transcription happens
In Notion's cloud, through its model subprocessors. A temporary copy of the audio sits on your device during the session, and per Notion sub-processors do not store audio. No on-device transcription path is described in any document we fetched. [13][6]
Where your data is stored
AWS, listed for the USA, the European Union, Korea and Japan. The Privacy Policy adds that all information may be transferred, processed and stored anywhere in the world. No storage region is contractually committed for AI content. [6][1]
AI training defaults
Notion states it does not use Customer Data, and does not permit others to use it, to train the models behind Notion AI. Two carve-outs sit in the same section: feedback you submit, and data used with your permission. [3]
Retention
Input and Output are classified as Customer Data and inherit the general schedule; no AI-specific retention window is stated anywhere. Deleted pages sit in Trash 30 days by default, then 30 more before they are inaccessible to everyone including workspace owners. LLM providers retain nothing by default for Enterprise and 30 days or fewer by default for other plans, per Notion. [3][15][10]
Subprocessors
AWS for hosting, and a bench of model hosts including Anthropic, OpenAI, Google, Fireworks, Cerebras, Baseten and X.AI, plus Turbopuffer for embeddings. No subprocessor on the list is described as performing human review or annotation of customer content. List last updated June 1, 2026, with a 10-day advance-notice subscription for new additions. [6][4]
Encryption
TLS 1.2 or higher in transit, AES-256 at rest for primary data stores and backups. No end-to-end encryption is claimed in any document, so content is handled in plaintext server-side by Notion and its model subprocessors. [5][4][9]
Certifications
SOC 2 Type 2, with no Type 1 claimed anywhere. Notion states it has achieved certifications for ISO 27001, 27701, 27017 and 27018, and lists BSI C5. Per its Privacy Policy, Notion has certified to the U.S. Department of Commerce under the EU-U.S., UK and Swiss Data Privacy Frameworks. HIPAA is conditional eligibility, gated on a signed BAA, an authorizing Order Form and Notion's eligibility criteria, not a blanket compliance claim. [8][1][7]
Consent features
Three consent paths ship with AI Meeting Notes: an editable text message, an audio message played to attendees, and asking out loud. A workspace owner can turn on "Enforce consent for all workspace members". Notion frames recording law as informational, not legal advice, and recommends obtaining consent from every participant. Nothing re-prompts when someone joins mid-meeting. [13]
Sharing defaults
Meeting notes are private to you by default and inherit the permissions of the page they are saved on. "Share to web" is off by default. Auto-sharing notes with internal calendar participants is a per-user toggle that is off until each member turns it on. [13][11]

Data flows

What leaves your Mac.

  1. Step 01

    Page content, prompts and AI output

    Your pages, the prompt you type and the answer you get back are Customer Data on Notion's servers, and are routed to third-party model hosts to be produced. The subprocessor list names Anthropic, OpenAI, Google, Fireworks, Cerebras, Baseten and X.AI for hosting large language models and embeddings. [3][6]

  2. Step 02

    Meeting audio

    A temporary copy sits on your device during the session, and per Notion sub-processors do not store audio. If real-time processing fails, the local audio is uploaded to Notion's servers and sent to its sub-processors to retry, and Notion retains that upload for up to 3 days. On mobile the local copy can be kept up to a week for the same retry path. [13]

  3. Step 03

    Embeddings of your content

    Content is embedded and stored in a vector database. Turbopuffer is listed for that purpose in the USA, Germany, Korea and Japan, and Notion states embeddings are deleted within 60 days from when the page or workspace is deleted. [6][10]

  4. Step 04

    Connected third-party apps

    Enterprise Search indexes content from connected apps. Notion states permission changes in the source system are reflected within 1 hour and can take longer for large workspaces, deleted content becomes unsearchable in around 30 minutes to an hour, and disconnecting a connector deletes the data within 24 hours. [14]

  5. Step 05

    Calendar, contacts and mail

    Notion Calendar stores your calendar provider user ID and an authorization token. The Google People API populates contact autocompletion when you enable that feature. For Notion Mail, Notion states it receives and sends email message content through the Gmail API and processes Directory, Workspace and Calendar API data. [1]

  6. Step 06

    Telemetry

    IP address, MAC address, cookie identifiers, mobile and advertising identifiers, browser, operating system and device details, location inferred from your IP address, and how you interact with the product, including the links you click and the frequency and duration of your activities. [1]

  7. Step 07

    Outbound web requests from Notion AI

    With web search on, Notion AI can look at external websites to answer a question, and a second setting can require confirmation before it does. Both are workspace-owner settings on any plan, and Notion's docs do not state which value either one ships with. [10]

AI training

Training defaults, in Notion AI’s own words.

Notion's position is that training is off, and it is written into a terms document rather than only a help page: the Notion AI and Notion Credit Supplementary Terms state Notion does not use Customer Data, and does not permit others to use it, to train the models used to provide Notion AI. Two exceptions sit in the same section, for feedback you submit and for data used with your permission. The complication is not the promise, it is that four documents carry it with four different subjects. The Supplementary Terms bind Notion itself. The Security page and the AI Meeting Notes product page instead say Notion's AI subprocessors are contractually prohibited from using customer data to train their models, which is a commitment about third parties. The Privacy Policy's own no-training sentence is narrower still: it covers Google Workspace API data ingested for Notion Mail. And the Data Processing Addendum, the document that actually governs processing of Customer Personal Data, carries no AI-training clause at all, including in the Annex II list of security measures. Separately, a workspace setting named "Share data to improve Notion AI" is available to owners on any plan; Notion's docs neither define what "improve" covers nor state which value a new workspace ships with. [3][1][4][8][9][10][12][14][6]

Notion does not use your Customer Data or permit others to use your Customer Data to train the artificial intelligence and machine learning models used to provide Notion AI. Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our artificial intelligence or machine learning models.
Source: Notion AI and Notion Credit Supplementary Terms, "Improving Notion AI"
We may use data we collect from your use of Notion AI to improve our models when you (i) voluntarily provide Feedback to us such as by labeling Output with a thumbs up or thumbs down; or (ii) give us your permission.
Source: Notion AI and Notion Credit Supplementary Terms, "Improving Notion AI"
Notion only processes Workspace API user data to provide the Notion Mail Services. We do not process Workspace API user data to develop, improve, or train generalized AI and/or ML models.
Source: Privacy Policy, "1. Information we collect", C. Information from Other Sources
Notion AI privacy receipt: the AI Supplementary Terms clause on not using Customer Data to train models
The receipt: Notion's AI and Notion Credit Supplementary Terms, "Improving Notion AI", accessed 2026-08-04

Can you opt out?

No control named an AI training opt-out exists in Notion's documentation, because Notion presents training as already off by contract for every plan. The nearest setting is Settings > Notion AI > "Share data to improve Notion AI", open to workspace owners on any plan and described as allowing data from your workspace to be shared with Notion to help improve Notion AI. Which value a new workspace ships with is not stated in Notion's docs, so the only way to know yours is to open it. A second adjacent control is documented without a name: Notion states certain AI-powered features may require data-retaining LLMs, that it will make available workspace settings for administrators to turn those on, and that they otherwise remain off by default. The exact label and menu path for that one are not published. Feedback is a third thread, and Notion's two statements about it read differently: the help center says thumbs up and thumbs down feedback is not used to train Notion AI and is instead shared with the Notion team to improve the experience, while the Supplementary Terms name Feedback as one of the two cases where collected data may be used to improve its models. Both were live on the access date.

Third-party AI providers

Per Notion, its AI subprocessors are contractually prohibited from using Customer Data to train their models, and the Enterprise Search article states that no customer data is used to improve Notion's or any third-party's models. On retention, Notion states LLM providers apply zero data retention by default for Enterprise plan workspaces and by default retain Customer Data 30 days or fewer for all non-Enterprise workspaces. The subprocessor list names the providers this covers: Anthropic, OpenAI, Fireworks, Google, Cerebras, Baseten, X.AI and Parallel Web Systems, all captioned as hosting large language models and embeddings.

Sharing defaults

Who can see your notes.

Meeting notes start private, per Notion

Notion's stated baseline for AI Meeting Notes is that a note belongs to whoever created it until they act. [13]

By default, meeting notes you create are private to you.
Source: AI Meeting Notes (beta), "Control who can access your meeting notes"

What actually decides who sees a note is the page it sits on

Meeting notes inherit the permissions of the page they are saved on, so a note captured on a shared page is shared with everyone who can already open that page. Two toggles sit around that. "Auto-share with internal calendar event participants" at Settings > Notion AI sends notes from a Notion calendar event to workspace-member participants, and it is a personal setting each member configures for their own notes. "Share to web" in a page's Share menu publishes the page to anyone with the link, and Notion states it is always turned off by default. [13][11]

Your employer can claim the workspace

The Master Subscription Agreement lets account administrators claim control and ownership of workspaces created by a user registered with an email address the organization provisioned, where an administrative user on such an address is present. The Privacy Policy states the individual-facing half of the same mechanic, and names workspace content among what may be shared. The escape hatch it offers is transferring your account to a different email address if you do not use Notion in connection with your organization. [2][1]

If you register a Notion account or associate a Notion account with an email address provisioned by your organization, Notion may share information about you and any Workspaces owned or managed by you with your organization.
Source: Privacy Policy, "Managing Workspaces for Organizations"

The license you grant, and when it ends

Ownership stays with you, and the license Notion takes is bounded on its face: worldwide, non-exclusive, limited-term, royalty-free, sublicensable only to Notion's third-party service providers, and granted solely to provide and operate the Services and fulfill Notion's obligations in the Agreement. It is not perpetual and not irrevocable, and the MSA states it expires when Notion deletes Customer Data after termination, following a 30-day retrieval window. Feedback is handled differently and has no expiry: the MSA assigns Notion all right, title and interest in Feedback, and states Notion is free to use it without payment, attribution or restriction. [2]

Notion's license to Customer Data will expire upon such deletion.
Source: Master Subscription Agreement, 10.4 "Post-Termination Obligations; Customer Data Retrieval"

Who at Notion can open your pages

The published controls are least privilege and need to know: access to production systems holding Customer Data is provisioned and de-provisioned through documented processes and reviewed periodically, with administrative access protected by strong authentication controls, including multi-factor authentication where supported. The DPA's Annex II adds that access to the Services by Notion personnel is uniquely identifiable, logged and monitored. What is not published is a gate requiring your consent or a support ticket before staff can open workspace content. That is an absence of documentation in the sources we read, not a finding about behavior. On legal demands the DPA is more specific than the Privacy Policy: Notion agrees to notify the customer in writing on receipt of a demand for Customer Personal Data, to give at least 48 hours' notice before disclosing, and to use all reasonable and available legal mechanisms to challenge national-security demands and their non-disclosure provisions. [5][4][1]

Connected apps and agents widen the surface, with lags

Enterprise Search indexes connected third-party apps, and the timings Notion publishes are not instant: source-system permission changes are reflected within 1 hour and can take longer for large workspaces, deleted content becomes unsearchable in around 30 minutes to an hour, and disconnecting a connector deletes the data within 24 hours. For agents, Notion states workspace admins manage Custom Agents across the organization through an Agent Directory, creation controls, content search, audit logs, AI analytics and ownership transfer. [14][19]

Hardening checklist

Settings that make Notion AI more private.

If you use Notion AI and want to keep it, these are the settings worth changing, straight from the vendor’s own documentation.

  1. Step 01

    Open the improve-AI setting and decide it yourself

    Where

    Settings > Notion AI > "Share data to improve Notion AI". Workspace owners, any plan.

    Notion names and describes this toggle but never states which value a new workspace ships with, and never defines what "improve" covers or how it relates to the no-training clause in its AI terms. Those are three separate gaps in the same setting, so set it deliberately rather than inheriting it. [12][3]

  2. Step 02

    Turn on two-step verification

    Where

    Settings > {your name} > Account security > "Add verification method" next to 2-step verification, then "Code from authenticator" or "Text me a code".

    Your workspace is only as private as the login. Notion states the feature is available to all plan types, and prints two prerequisites: you must have a password, and you must not be in an organization that requires login through an identity provider. On an SSO-enforced org, that means MFA has to be configured at the identity provider instead. [16][17]

  3. Step 03

    Check where a meeting note is saved before you record

    Where

    Leave Settings > Notion AI > "Auto-share with internal calendar event participants" off, and capture sensitive notes on a private page. Workspace owners who do not want the feature at all: Settings > Notion AI > "Workspace availability".

    This is the one place Notion documents its defaults clearly, and they point the private way: notes are private to you and auto-share is off unless you turn it on. The part that is easy to miss is inheritance. Notion states meeting notes take the permissions of the page they are saved on, so the parent page, not the toggle, is what decides who can read the transcript. [13]

  4. Step 04

    Use the consent tooling, and enforce it if you own the workspace

    Where

    Workspace owners: Settings > Notion AI > AI Meeting Notes > "Enforce consent for all workspace members". Individually: Settings > Notion AI > AI Meeting Notes > "Auto play consent message on start".

    Notion presents recording law as informational rather than legal advice and recommends complying with the strictest consent laws, obtaining consent from every participant. Two mechanics from its own article change how you use it: the audio consent message plays through your computer speakers rather than the conferencing mic, so headphones must come off for the room to hear it, and nothing re-prompts when someone joins mid-meeting, which Notion lists as a manual step for you. [13]

  5. Step 05

    Delete transcripts you would not want kept, and learn the two windows

    Where

    AI Meeting Notes block > slider icon > "Delete transcript". Local audio: slider icon > hover "Audio Recordings" > "Delete recordings". Enterprise retention: Settings > Security > "Data retention" tab, and Settings > Notion AI > "Automatic transcript deletion".

    Notion states deleting the transcript also deletes the accompanying locally stored audio from the recorder's device. Deleting a page is slower than it looks: pages remain in Trash 30 days by default, then are retained a further 30 days before becoming inaccessible to everyone including workspace owners. Automatic transcript deletion and custom retention windows between one day and 10 years are Enterprise-only, and Notion states the automatic schedule does not delete transcripts on pages under legal hold. [13][15][18]

  6. Step 06

    Set the web-search controls, and on a team put SSO in front

    Where

    Settings > Notion AI: "Enable web search for workspace" and "Require confirmation for web requests". SSO on Business: Settings > General > Identity tab > "Enable SAML SSO". On Enterprise: workspace switcher > "Manage organization" > General tab > "Enable SAML SSO".

    Both web-search settings are documented for workspace owners on any plan, and Notion does not state which value either one ships with, so both need checking. SSO is Business and Enterprise only and requires at least one verified domain. Setting "Login method" to "Only SAML SSO" removes every other login path, and Notion states that only organization owners can bypass an organization-level configuration, or workspace owners a workspace-level one. [10][17]

Policy changelog

What changed, and when.

Each entry records a dated re-verification of this audit against the vendor’s documents. Policy changes land here as dated diffs.

2026-08-04

Audit created. Verified against the Privacy Policy (Last Updated September 29, 2025), the Master Subscription Agreement (Last Updated April 2, 2026), the Notion AI and Notion Credit Supplementary Terms (last updated July 27, 2026), the Data Processing Addendum (last updated February 22, 2023), the undated Security Exhibit incorporated into the MSA, the subprocessor list (last updated June 1, 2026), the Business Associate Agreement (Last Updated August 5, 2024), the undated Security and Compliance page, the AI Meeting Notes product page, ten help-center articles that print no date of any kind, and a search of the public court records. Litigation status at verification: no privacy or consent case naming Notion Labs, Inc. was found in the court records and top-tier reporting searched on August 4, 2026, which is an absence of findings in those sources rather than proof that none exists.

FAQ

Questions people ask.

Is Notion AI safe to use?

It depends on what lives in the workspace. Notion publishes real security work and states in its AI terms that your content is not used to train the models behind Notion AI, with carve-outs for feedback and permission. It is still a cloud service: pages, prompts and outputs sit on Notion's servers, are routed to third-party model hosts, and are handled in plaintext server-side, because no end-to-end encryption is claimed anywhere. For ordinary work notes that trade is a normal SaaS trade. If the workspace holds regulated or client-confidential material, the Enterprise-only retention and DLP controls are where the answer actually gets decided. [3][5][6][10]

Does Notion AI train on my data?

Notion states it does not. The AI Supplementary Terms say Notion does not use your Customer Data, and does not permit others to use it, to train the models used to provide Notion AI. Two carve-outs sit in the same section: data may be used to improve Notion's models when you submit feedback, such as a thumbs up or thumbs down on an output, or when you give permission. Read the subject of each promise, because it changes across documents: the Security page and the AI Meeting Notes page commit Notion's subprocessors rather than Notion, the Privacy Policy's own no-training sentence covers only Google Workspace API data for Notion Mail, and the Data Processing Addendum has no AI-training clause at all. [3][8][9][1][4]

Can I opt out of Notion AI training?

There is nothing to opt out of by that name, because Notion presents training as already off by contract on every plan. The one training-adjacent setting is Settings > Notion AI > "Share data to improve Notion AI", available to workspace owners on any plan, and Notion's docs neither define what "improve" covers nor state which value a new workspace ships with. Notion also documents an unnamed admin setting for data-retaining LLMs used by certain AI features, which it states are off by default. [12][10][3]

Is Notion being sued over Notion AI and privacy?

No privacy or consent lawsuit naming Notion Labs, Inc. was found in the court records and top-tier reporting we searched on August 4, 2026, and no FTC action, EU data-protection decision or state attorney-general action naming Notion surfaced either. That is an absence of findings in the sources checked, not a clean bill of health: those searches cover federal dockets, regulator publications and major outlets, so state courts, arbitration and unreported matters are outside them. [20]

Has Notion had a data breach?

No breach of Notion's systems is documented by Notion or by any source meeting this directory's evidence bar, which is court records, regulator filings or top-tier reporting. That is not the same as proof that none occurred. Claims and security-research write-ups circulate outside that bar; they are not reported here as fact, and this audit will record any that a primary or top-tier source later confirms. [20][8]

Does Notion sell my data?

Two documents answer differently because they govern different data. For Customer Personal Data processed through the service, which is your workspace content, the DPA is unconditional: Notion shall not sell it, and shall not share or process it for cross-context behavioral advertising or targeted advertising. The Privacy Policy, which governs account and website data more broadly, hedges: disclosures to advertising and analytics partners may be considered a "sale" or "sharing" under applicable law, and its California table lists identifiers, network activity, geolocation and inferences as disclosed to advertising partners, while stating commercial information, sensory data and professional information are not sold or shared. [4][1]

Is Notion HIPAA compliant?

Notion frames HIPAA as conditional eligibility rather than a certification, which is the accurate framing, since HIPAA has no certification regime. Its Security page states that businesses subject to HIPAA may process PHI in their workspace provided they use the Enterprise-grade security features it describes and sign Notion's Business Associate Agreement. The BAA gates further: it also requires an Order Form authorizing a HIPAA-enabled account and meeting Notion's other eligibility criteria, and it bars storing PHI that includes sensitive biometric information such as fingerprints, iris and retina scans and facial recognition imaging. The DPA separately has the customer warrant to Notion that Customer Personal Data will not contain biometric information, an obligation on you rather than a commitment by Notion (section 9.5). The same clause also bars health information subject to HIPAA, which is why the BAA path exists. [8][7][4]

Who can see my Notion AI content and meeting notes?

By default, you and the people who can already open the page. Three things widen that. Meeting notes inherit the permissions of the page they are saved on, so the parent page decides. An organization can claim control and ownership of a workspace created with an email address it provisioned, and the Privacy Policy states workspace content may be shared with that organization. And Notion staff access is governed by least-privilege, MFA and logging rather than by a published consent gate; no document we read states that your permission or a support ticket is required before content can be opened. [13][2][1][5]

Sources

Every claim, receipted.

Every claim on this page maps to one of these documents. Dates are when we last read each one.

  1. [1]

    Notion Privacy Policyaccessed 2026-08-04

    Effective April 10, 2025; Last Updated September 29, 2025.

  2. [2]

    Notion Master Subscription Agreementaccessed 2026-08-04

    Effective April 2, 2026 (May 1, 2026 for existing customers); Last Updated April 2, 2026. Section 3 carries the content license and the Feedback assignment, 4.5 the domain-management claim mechanic, 10.4 the post-termination retrieval window.

  3. [3]

    Notion AI and Notion Credit Supplementary Termsaccessed 2026-08-04

    Last updated July 27, 2026. The only contractual document carrying the no-training clause, in its "Improving Notion AI" section, together with the Feedback and permission carve-outs. It also classifies Input and Output as Customer Data.

  4. [4]

    Notion Data Processing Addendumaccessed 2026-08-04

    Effective and last updated February 22, 2023. Carries the service-provider no-sale certification (3.3), the 48-hour disclosure-notice commitment (3.10), the 10-day subprocessor notice (3.6), the deletion schedule and the encryption measures in Annex II. It contains no AI-training clause anywhere in its text.

  5. [5]

    Notion Security Exhibitaccessed 2026-08-04

    No standalone date shown; incorporated into the Master Subscription Agreement. Section 4 carries the access-control statements, section 5 the encryption claims.

  6. [6]

    Notion's List of Subprocessorsaccessed 2026-08-04

    Last updated June 1, 2026. AWS is listed for the USA, European Union, Korea and Japan; the model hosts under "Platform" are mostly captioned "Global". No entry is described as performing human review or annotation of customer content.

  7. [7]

    Notion Business Associate Agreementaccessed 2026-08-04

    Last Updated August 5, 2024. Gates PHI processing on an authorizing Order Form and Notion's eligibility criteria, and bars PHI containing sensitive biometric information.

  8. [8]

    Notion Security & Complianceaccessed 2026-08-04

    No date shown. Carries the certification list and the AI-governance wording that places the no-training obligation on Notion's AI subprocessors.

  9. [9]

    Notion AI Meeting Notes (product page)accessed 2026-08-04

    No date shown. Marketing page, not a legal document; it repeats the subprocessor-contract framing of the no-training promise and claims TLS 1.2 or greater in transit without an at-rest claim.

  10. [10]

    Notion Help Center: Notion AI security & privacy practicesaccessed 2026-08-04

    Notion's help-center articles print no visible effective or last-updated date, so every help source here is dated by access date only. This article carries the LLM-provider retention numbers, the embeddings deletion window, the web-search settings and the unnamed data-retaining-LLM admin setting.

  11. [11]

    Notion Help Center: Security practicesaccessed 2026-08-04

    Carries the "Share to web" default and the product-security feature list.

  12. [12]

    Notion Help Center: What is Notion AI? FAQsaccessed 2026-08-04

    Names the "Share data to improve Notion AI" setting for workspace owners on any plan without stating its shipped value, and states that thumbs up and thumbs down feedback is not used to train Notion AI.

  13. [13]

    Notion Help Center: AI Meeting Notes (beta)accessed 2026-08-04

    The load-bearing help article for audio: the private-by-default statement, the audio pipeline and retry windows, the local-audio and workspace-availability toggles, the consent options and their enforcement setting, and the Enterprise automatic transcript deletion schedule with its legal-hold exception.

  14. [15]

    Notion Help Center: Delete & restore contentaccessed 2026-08-04

    Carries the 30-day Trash window and the further 30 days before deleted pages become inaccessible to all users.

  15. [16]

    Notion Help Center: Two-step verificationaccessed 2026-08-04

    States the feature is available to all plan types, and excludes users in organizations that require identity-provider login.

  16. [17]

    Notion Help Center: SAML SSO Configurationaccessed 2026-08-04

    Business and Enterprise only, gated on domain verification. Carries the per-plan menu paths, the "Only SAML SSO" login method and the bypass rules.

  17. [18]

    Notion Help Center: Custom data retention settingsaccessed 2026-08-04

    Enterprise Plan only. Custom windows from one day to 10 years for pages and AI chats, defaulting to 30 days. Whether a changed window applies to content already awaiting deletion is not addressed.

  18. [19]

    Notion Help Center: Custom Agents security featuresaccessed 2026-08-04

    Describes the admin oversight surface for agents. It names no training-exclusion, domain-restriction or audio-stripping control.

  19. [20]

    CourtListener search: Notion Labs, Inc. (federal dockets and opinions)accessed 2026-08-04

    Searches run 2026-08-04 across federal dockets and opinions returned no privacy or consent case naming Notion Labs, Inc. Coverage is federal only: state courts and arbitration are not indexed, so this means no such suit is documented in federal court records, not that none exists. Searches for FTC, EU data-protection and California attorney-general actions naming Notion also returned nothing.

This audit quotes Notion AI’s own public documents and reputable public records. It is not legal advice, and filed lawsuits are allegations, not findings.

Related audits

How Routines handles the same data

Routines, the app behind this audit, handles the same job differently: your notes and files are read locally on your Mac, and everything it produces is markdown files on your Mac that open in any editor. No cloud bill, no per-minute costs, and it works offline. All transparency audits