LEGAL

Privacy Policy

Effective July 2026

This policy explains what data NoteX (operated by LISAN AI - FZE) collects when you use the desktop app and the web workspace, why, and the control you have over it. It is written to be read, not to be survived.

The local-first difference

On the desktop app, notes are files on your own disk. If you never sign in, your note content never reaches us at all: there is no account, no telemetry pipeline of your writing, nothing to request deletion of. Sync, shared workspaces, and the web app are the parts that involve our servers, and they are opt-in by nature.

What we collect (when you use cloud features)

  • Account data: your name, email, and workspace membership, so you can sign in and share notes.
  • Note content: notes you sync or create on the web are stored in your workspace so they can appear on your other devices and with your collaborators. This is the product: without storing the note, there is nothing to sync.
  • Attachments and covers: images and files you add to notes, stored privately in your workspace.
  • Metadata: note titles, timestamps, and workspace structure, so trees, favorites, and trash work.
  • API usage logs: when you create API keys, we log method, path, status, and latency per request so you can audit key activity. Key secrets are stored hashed.
  • Operational logs: basic request and error logs to keep the service running and secure.

AI features

AI features only see what you send them. On web, the NoteX AI sidebar processes the pages and selections you point it at to produce answers and proposed edits. On desktop, AI add-ons (Claude Code, Codex, Continue) run under your own accounts with those providers, governed by their terms; NoteX does not proxy or store those conversations. Our AI features are never used to train models on your notes.

What we do not do

We do not train AI on your notes. We do not sell your data. We do not show third-party advertising.

Sharing controls

Notes are private by default. Private-space notes are visible only to you; workspace notes are visible to your workspace; public share links exist only when you create them and can carry expiry dates. Workspace admins manage members, not a feed of everyone's private notes.

Deletion and your rights

You can delete notes (trash with restore, then permanent), delete API keys, and request deletion of your account and all its data. You can export your notes as Markdown, HTML, or PDF at any time, so nothing is locked in. Contact support@lisan.com.

Where your data lives

Local notes live on your device. Synced notes live on the server you chose: Lisan Cloud by default, or your own self-hosted server on enterprise setups, in which case note content stays inside your network. See security.

Contact

Questions about this policy: support@lisan.com.