Privacy policy
Effective August 31, 2026
DoodleNote is operated by Onyx Dev Labs. This policy explains how the DoodleNote apps, website, and optional hosted Sync service handle information.
Local app behavior
DoodleNote can record, transcribe, store, search, and summarize meetings on your device without a DoodleNote account. DoodleNote does not upload meeting audio as part of Sync. Local data leaves your device only when you enable an optional cloud feature or direct the app to use an external provider.
Information we process
- Account details such as your name, email address, and sign-in provider.
- Contact-form details such as your name, email address, optional company and phone number, and the message you send us.
- Workspace membership, invitations, linked devices, and security tokens.
- When Sync is enabled, meeting titles, notes, transcripts, speaker labels, timestamps, folders, tags, and attachments.
- Subscription, invoice, and payment-status identifiers from Stripe.
- Optional integration data for features you enable, such as calendar, email invitation, AI provider, hosted agent, or voice calling data.
- Operational logs needed to secure, diagnose, and maintain the service.
How we use information
We use information to provide the features you request, authenticate accounts and devices, keep workspaces separated, process billing, deliver invitations, prevent abuse, troubleshoot failures, and improve reliability. We do not sell personal information or use meeting content for advertising.
Optional providers
Hosted features may use Vercel for application and object hosting, Neon for PostgreSQL, Stripe for billing, Resend for account, invitation, billing, and contact-form email, Twilio for optional voice features, and Microsoft or Google for sign-in and calendar access. If you choose an external AI provider, the content you submit is sent to that provider under its terms. Local AI and Ollama do not require DoodleNote to receive that content.
Sharing and link access
Meeting sharing is off by default. Anyone with an enabled public share link can view the content included in that link until it expires or is revoked. Synced attachments use difficult-to-guess object URLs, but a person who receives an attachment URL may be able to open it. Do not sync or share content you are not authorized to disclose.
Retention and deletion
Local data remains on your device until you remove it. Hosted data is retained while needed to provide your account and Sync service, meet legal obligations, resolve disputes, and maintain security records. Deleting a synced meeting removes the active cloud record through the normal sync process.
When you schedule cancellation, Cloud Sync remains available through the date Stripe shows in the billing portal. On that date, DoodleNote permanently deletes the active cloud copy of meetings, transcripts, notes, folders, tags, public share links, and attachments in your Personal workspace and disconnects your linked Sync devices and hosted-agent tokens. Local notes and recordings remain on your devices. Content in shared workspaces is retained for the other workspace members, while your access through the canceled subscription ends. Encrypted provider backups may retain deleted records until they age out through the provider's normal backup rotation, but those records are not available through the service.
Billing, email-delivery, security, and deletion audit records may be retained when required for legal, fraud-prevention, and operational accountability purposes. To request account or other hosted-data deletion, emailteam@onyxdev.io.
Security and choices
We use encrypted transport, scoped account and workspace access, and hashed device and agent tokens. No system can guarantee absolute security. You can keep all meetings local, disable Sync, revoke share links and devices, disconnect integrations, or request deletion.
Children and policy changes
DoodleNote is not directed to children under 13. We may update this policy as the product changes. Material changes will be posted here with a new effective date.
Questions about this policy can be sent to team@onyxdev.io. Security reports should follow the private process in the repository's security policy.