Notebook.

Privacy

How Notebook handles your information. Version 1, September 2026.

Notebook reads business correspondence that you connect to it, finds the commitments in it, and shows them to you with the exact sentence they came from. This page says what we collect, what we do with it, and how you make us delete it. It is written to be read, not skimmed.

Who we are

Notebook is operated by Notebook (notebookcrm.ai). Questions about this page or your data: privacy@notebookcrm.ai.

Signing in

You sign in with your Google account. We receive your name, email address and profile picture, and nothing else from that sign-in. We use them to know who you are inside your workspace and to show your name to the people you work with. Signing in does not give Notebook access to your mail.

Connecting a mailbox

Connecting a mailbox is a separate, explicit step, and it asks for read-only access. Notebook never sends, changes or deletes email. You can revoke the access at any time in your Google account settings, and Notebook removes it itself when a run finishes.

For the period and volume you choose, Notebook reads the messages, strips quoted earlier replies and signatures, and keeps from each message only what is needed to point back to it: sender, recipients, date, subject and message identifiers. Message bodies are processed and discarded; they are not stored on our servers. Attachments are not read. Newsletters, notifications and automated mail are dropped before analysis.

Processing by a model provider

The text of each message is sent, one message at a time and only for the duration of the request, to a model provider we name in your pilot agreement, under paid terms that exclude the use of your data for training. We do not use free tiers, and we do not fall back to another provider without telling you. From the model's answer we keep only the commitments it found, and only after checking that each quote appears word for word in the message. Anything that does not check out is discarded.

What we keep

Mailbox access tokens are encrypted at rest and deleted when a run completes. We do not sell any of this, use it for advertising, or use it for anything other than providing Notebook to your workspace.

Who can see it

People in your workspace, according to their role. On our side, the people who operate the service, for setup and support only. Our hosting and model providers process data on our behalf under their terms; we list them in your pilot agreement.

Deletion

Deleting a connection in Notebook removes everything read through it: the token, the message references and the commitments. Removing a person from a workspace signs them out everywhere. To delete a workspace and everything in it, write to privacy@notebookcrm.ai; we confirm by email when it is done. Data held by the model provider is deleted on their schedule, stated in your agreement.

Security

Connections are encrypted in transit. Servers are reachable only over HTTPS and by key-based administrator access. The database is not exposed to the internet. Access tokens are encrypted at rest, and message contents are kept out of logs.

Changes

If this page changes in a way that matters, we tell workspace owners by email before the change takes effect and keep the previous version available on request.

Notebook · Home · Privacy