NoetixNoetixNoetix
ContactLog in
Get early access
Legal

Privacy Policy

What we collect, why we collect it, and what we will never do with it. Written to be read, not to be survived.

Effective
2 August 2026
Last updated
2 August 2026

On this page

  • 1. Who we are
  • 2. What we collect, and why
  • 3. What we don't do
  • 4. Cookies and local storage
  • 5. Your content, and the sources you connect
  • 6. Who else touches your data
  • 7. International transfers
  • 8. How long we keep things
  • 9. Security
  • 10. Your rights
  • 11. Children
  • 12. Changes to this policy
  • 13. Contact

1. Who we are

Noetix is an AI memory platform that turns the tools a company already uses into a knowledge graph its AI agents can query. This policy covers www.noetix.dev, the waitlist, the contact form, and the early-access product available to invited teams.

For the purposes of the UK and EU General Data Protection Regulation, the data controller is Ahmed Tarek, trading as Noetix, reachable at founder@noetix.dev. Noetix is an early-stage product and is not yet incorporated as a company; when that changes, this section and the contracting party in our Terms of Use will be updated and the change noted below.

For anything in this policy, including any request about your own data, write to founder@noetix.dev. A real person reads that inbox.

2. What we collect, and why

We collect as little as we can get away with, and we'd rather ask you for something later than hoard it now. Here is the complete list as of the date at the top of this page.

WhatWhere it comes fromWhy we have itLegal basis (GDPR)
Your email addressThe waitlist formTo tell you when a spot opens up, and to reply to you personallyConsent — you gave us the address for exactly this
Your company domainDerived from your email address, not asked for separatelyTo understand what kind of teams are signing up and in what order to onboard themLegitimate interests — understanding demand for a product we are building
Your name and messageThe contact formTo answer the question you askedLegitimate interests — responding to someone who contacted us
Account details: email, and an authentication identifierSigning in to early accessTo create your account, keep you signed in, and keep your workspace separate from everyone else'sContract — we cannot provide the service without them
Content from sources you connect: messages, documents, files, and their metadataThe tools you choose to connect, via their official APIs, with your permissionTo build the knowledge graph that is the entire product, and to answer your queries against itContract — this is the service you asked us to perform
Technical logs: IP address, browser and device type, pages requested, timestamps, error tracesAutomatically, by our hosting providers, when you use the site or the appSecurity, abuse prevention, and finding out why something brokeLegitimate interests — keeping the service running and secure
Your theme preference (light or dark)Stored in your own browser, never sent to usSo the site looks the way you left itNot personal data — it never leaves your device

We do not ask for, and have no use for, special category data: health, race, religion, political opinions, biometrics, sexual orientation. If content you connect happens to contain such data, we process it only as part of your knowledge graph and never analyse it in its own right.

3. What we don't do

Worth stating plainly, because these are the assumptions people reasonably bring to a form that asks for an email:

  • We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising.
  • We do not train AI models on your content, and we do not permit our providers to train theirs on it.
  • We do not run advertising trackers, analytics pixels, or third-party marketing scripts on this site. As of the date above, the marketing site sets no cookies at all.
  • We do not add you to a general mailing list because you used the contact form.
  • We do not read your connected content ourselves. It is processed by machines to build your graph; a human at Noetix only ever looks at specific data if you ask us to help with a specific problem, or if we are legally compelled to.

4. Cookies and local storage

The marketing pages — everything you can reach without signing in — set no cookies. Your light-or-dark preference is kept in your browser's local storage, which stays on your device and is never transmitted to us.

Signing in to early access sets a small number of strictly necessary cookies that keep you authenticated and protect the session. They cannot be switched off without breaking sign-in, and under the ePrivacy Directive they do not require consent. We will not add analytics or advertising cookies without asking you first, and if we ever do, this section changes before they ship.

5. Your content, and the sources you connect

This is the part that matters most, so it gets its own section rather than a line in a table.

When you connect a source — Slack, Google Drive, Notion, Gmail, or anything else we support — you authorise us through that provider's own OAuth flow. We receive an access token scoped to the permissions you granted, and we ask for the narrowest scopes that let the feature work. We never see or store your password for those services.

  • Your content is yours. Connecting a source does not transfer ownership of anything to us. We hold it only to run the service for you.
  • Your graph is isolated to your team. Nothing is shared between customers, and no other customer's queries can reach your data.
  • To answer a query, relevant excerpts of your content are sent to a large-language-model provider acting as our processor. They are contractually barred from training on it or using it for their own purposes, and they retain it only transiently.
  • Disconnect a source and we stop syncing immediately, revoke the token, and delete the content and the graph nodes derived from it within 30 days.
  • You can also revoke our access from inside the provider — Google, Slack and Notion all offer this — which has the same effect from their side.

If you connect a workspace containing other people's personal data, which is the normal case for a shared Slack or Drive, you are the controller of that data and we are your processor. You are responsible for having a lawful basis to connect it and for telling the people concerned. We will sign a data processing agreement — ask, and we'll send one.

6. Who else touches your data

We use a small number of vendors to run the service. Each is bound by a contract to process data only on our instructions, and each is listed here so the list is a fact you can check rather than a category you have to trust.

ProviderWhat they do for usWhere
VercelHosts and serves this websiteUnited States and global edge network
RailwayHosts the Noetix backend and processing pipelineUnited States / EU region
SupabaseDatabase and authentication — this is where waitlist entries, contact messages and accounts are storedRegion-selected cloud infrastructure
Large-language-model providers (currently OpenAI; others may be used)Extract entities and generate answers from excerpts of your content, as a processor and without training rightsUnited States
The sources you connect (Google, Slack, Notion and similar)Provide your content to us at your instruction; they are not our processors but your own service providersPer that provider

Outside that list, we disclose personal data only in three situations: when the law compels us and we have satisfied ourselves that it does; when it is necessary to protect someone's safety, our rights, or the security of the service; and if Noetix is ever acquired or merged, in which case your data moves with the business and we will tell you before it does, in time for you to delete your account first.

7. International transfers

Our providers are largely United States-based, so if you are in the UK, the EEA, or Switzerland, your data will be transferred outside your country. Where that happens we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), or on an adequacy decision where one covers the provider. You can ask us for a copy of the safeguards in place for any specific transfer.

8. How long we keep things

  • Waitlist entries: until we launch and you either become a customer or decline, or until you ask us to remove you — whichever comes first. If we abandon the product, we delete the list.
  • Contact messages: up to 24 months, so we have the thread if you write again.
  • Account data: for as long as your account is open, and 30 days after you close it, so an accidental deletion can be undone.
  • Connected content and the graph derived from it: until you disconnect the source or close your account, then deleted within 30 days.
  • Technical logs: up to 90 days, then deleted or aggregated into figures that cannot identify anyone.

Backups lag deletion slightly by design. Anything deleted from the live system falls out of encrypted backups within a further 30 days and is never restored into service.

9. Security

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production systems is limited to people who need it, protected by multi-factor authentication, and the database enforces row-level isolation between customers rather than relying on application code to remember.

Noetix is an early-stage product built by a very small team. We have taken security seriously from the first commit, but we are not going to claim certifications we do not hold. If you find a vulnerability, email founder@noetix.dev and we will work with you; we will never pursue anyone for a good-faith report. If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where required, and tell you directly without undue delay where the risk to you is high.

10. Your rights

Depending on where you live, you have some or all of the following rights. We extend them to everyone who asks, regardless of where they live, because operating two standards is more work than operating the higher one.

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have anything inaccurate corrected.
  • Erasure — have it deleted. For a waitlist entry this is immediate and unconditional.
  • Portability — receive your data in a structured, machine-readable format, or have it sent to another provider.
  • Restriction and objection — ask us to stop or limit a particular use, including anything we do on the basis of legitimate interests.
  • Withdraw consent — at any time, without affecting anything done before you withdrew it.
  • Complain — to your local data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the supervisory authority where you live.

To exercise any of these, email founder@noetix.dev from the address you signed up with. We will respond within 30 days, free of charge, and we will not make the service worse for you because you asked.

If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, and we have not in the preceding twelve months, so there is nothing to opt out of. You also have the right not to be discriminated against for exercising these rights, which we honour. The categories we collect and our purposes for collecting them are the table in section 2.

11. Children

Noetix is a product for companies and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

12. Changes to this policy

The product is going to change quickly, and this policy will change with it. When it does, we update the date at the top of the page. For any change that materially affects how we handle data you have already given us — a new purpose, a new category of sharing — we will email everyone on the waitlist and every account holder before it takes effect, not after.

13. Contact

Questions, requests, complaints, or a correction to something above: founder@noetix.dev.

Something here unclear, or something we got wrong? Write to founder@noetix.dev and we'll fix it.

NoetixNoetixNoetix

Give your AI a brain that knows your company.

Questions? founder@noetix.dev

ProductUnder the hoodContact
LegalPrivacy PolicyTerms of Use

© 2026 Noetix. All rights reserved.