What we collect, why we collect it, and what we will never do with it. Written to be read, not to be survived.
Noetix is an AI memory platform that turns the tools a company already uses into a knowledge graph its AI agents can query. This policy covers www.noetix.dev, the waitlist, the contact form, and the early-access product available to invited teams.
For the purposes of the UK and EU General Data Protection Regulation, the data controller is Ahmed Tarek, trading as Noetix, reachable at founder@noetix.dev. Noetix is an early-stage product and is not yet incorporated as a company; when that changes, this section and the contracting party in our Terms of Use will be updated and the change noted below.
For anything in this policy, including any request about your own data, write to founder@noetix.dev. A real person reads that inbox.
We collect as little as we can get away with, and we'd rather ask you for something later than hoard it now. Here is the complete list as of the date at the top of this page.
| What | Where it comes from | Why we have it | Legal basis (GDPR) |
|---|---|---|---|
| Your email address | The waitlist form | To tell you when a spot opens up, and to reply to you personally | Consent — you gave us the address for exactly this |
| Your company domain | Derived from your email address, not asked for separately | To understand what kind of teams are signing up and in what order to onboard them | Legitimate interests — understanding demand for a product we are building |
| Your name and message | The contact form | To answer the question you asked | Legitimate interests — responding to someone who contacted us |
| Account details: email, and an authentication identifier | Signing in to early access | To create your account, keep you signed in, and keep your workspace separate from everyone else's | Contract — we cannot provide the service without them |
| Content from sources you connect: messages, documents, files, and their metadata | The tools you choose to connect, via their official APIs, with your permission | To build the knowledge graph that is the entire product, and to answer your queries against it | Contract — this is the service you asked us to perform |
| Technical logs: IP address, browser and device type, pages requested, timestamps, error traces | Automatically, by our hosting providers, when you use the site or the app | Security, abuse prevention, and finding out why something broke | Legitimate interests — keeping the service running and secure |
| Your theme preference (light or dark) | Stored in your own browser, never sent to us | So the site looks the way you left it | Not personal data — it never leaves your device |
We do not ask for, and have no use for, special category data: health, race, religion, political opinions, biometrics, sexual orientation. If content you connect happens to contain such data, we process it only as part of your knowledge graph and never analyse it in its own right.
Worth stating plainly, because these are the assumptions people reasonably bring to a form that asks for an email:
This is the part that matters most, so it gets its own section rather than a line in a table.
When you connect a source — Slack, Google Drive, Notion, Gmail, or anything else we support — you authorise us through that provider's own OAuth flow. We receive an access token scoped to the permissions you granted, and we ask for the narrowest scopes that let the feature work. We never see or store your password for those services.
If you connect a workspace containing other people's personal data, which is the normal case for a shared Slack or Drive, you are the controller of that data and we are your processor. You are responsible for having a lawful basis to connect it and for telling the people concerned. We will sign a data processing agreement — ask, and we'll send one.
Our providers are largely United States-based, so if you are in the UK, the EEA, or Switzerland, your data will be transferred outside your country. Where that happens we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), or on an adequacy decision where one covers the provider. You can ask us for a copy of the safeguards in place for any specific transfer.
Backups lag deletion slightly by design. Anything deleted from the live system falls out of encrypted backups within a further 30 days and is never restored into service.
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production systems is limited to people who need it, protected by multi-factor authentication, and the database enforces row-level isolation between customers rather than relying on application code to remember.
Noetix is an early-stage product built by a very small team. We have taken security seriously from the first commit, but we are not going to claim certifications we do not hold. If you find a vulnerability, email founder@noetix.dev and we will work with you; we will never pursue anyone for a good-faith report. If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where required, and tell you directly without undue delay where the risk to you is high.
Depending on where you live, you have some or all of the following rights. We extend them to everyone who asks, regardless of where they live, because operating two standards is more work than operating the higher one.
To exercise any of these, email founder@noetix.dev from the address you signed up with. We will respond within 30 days, free of charge, and we will not make the service worse for you because you asked.
If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, and we have not in the preceding twelve months, so there is nothing to opt out of. You also have the right not to be discriminated against for exercising these rights, which we honour. The categories we collect and our purposes for collecting them are the table in section 2.
Noetix is a product for companies and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
The product is going to change quickly, and this policy will change with it. When it does, we update the date at the top of the page. For any change that materially affects how we handle data you have already given us — a new purpose, a new category of sharing — we will email everyone on the waitlist and every account holder before it takes effect, not after.
Questions, requests, complaints, or a correction to something above: founder@noetix.dev.
Something here unclear, or something we got wrong? Write to founder@noetix.dev and we'll fix it.