Notavi Privacy Policy
Effective date: May 22, 2026
Notavi LLC (“Notavi,” “we,” “us,” or “our”) makes Notavi, a Mac and Windows application that turns your screenshots into step-by-step standard operating procedures (SOPs) with the help of AI. This Privacy Policy explains what information we collect, how we use it, who processes it on our behalf, and the choices you have.
If you have any questions, contact us at hello@notavi.ai.
The short version
- Your work stays in storage you control. The screenshots you capture and the SOPs Notavi builds from them are kept in the location you choose — a folder on your computer, or a folder in cloud storage you already own (such as OneDrive, iCloud, Dropbox, Proton Drive, or SharePoint). Notavi never hosts them on our servers.
- Nothing is captured in the background. Notavi records a step only when you press a capture shortcut — it does not log your keystrokes or capture on its own. And using AI is optional: you can build SOPs entirely by hand, in which case no content is ever sent for processing.
- You decide when content leaves your device. Through Notavi, content is transmitted only when you submit a session for AI processing or export a finished SOP. If you keep your library in a cloud-sync folder, that syncing is handled by your own storage provider under your account — not by us.
- We don’t store your content. When you submit a session, your screenshots and prompt pass through our backend to Anthropic for processing. Our backend is an authenticated relay — it does not save your screenshots or SOPs. Our database holds only your account information.
- We don’t sell your data, and we don’t train AI on your content.
The rest of this policy explains each point in detail.
1. Scope
This policy covers the Notavi application for macOS and Windows and the account, subscription, and AI-processing services that support it (together, the “Service”). It also covers our marketing website at notavi.ai.
2. Information we collect
Account information
When you create an account, we collect:
- Your email address.
- Your password, stored only as an Argon2id hash. We never store your password in plain text and cannot recover it.
Subscription and billing information
When you subscribe to a paid plan, we store:
- Your subscription status and plan tier (Lite or Pro).
- A Stripe customer ID that links your account to your billing record at Stripe, our payment processor.
We do not collect or store your full payment card number or other card details. Payment information is collected and processed directly by Stripe. See Service providers below.
Usage information
To enforce plan limits, we store a running usage figure for the current billing period (a count of AI-processing usage / tokens). This is a numeric total only — it does not include the content of your captures or SOPs.
Content you create
The screenshots you capture and the SOPs you build are your content. They are created and stored in the location you choose — locally, or in a folder in cloud storage you already own (OneDrive, iCloud, Dropbox, Proton Drive, SharePoint). We do not collect, upload, or store this content in the normal course of using the app, and capturing happens only when you trigger it — never in the background.
Content you submit for AI processing
When you choose to submit a session, the screenshots in that session and a generated text prompt are transmitted (over HTTPS) through our backend to Anthropic for processing. Our backend buffers this content only in memory for the duration of the request and does not persist it. See How your content is processed below.
Email we send you
We send transactional email — such as email-address verification codes, password-reset links, and account or usage notifications (for example, a warning as you approach a usage limit) — through our email provider, Resend. These messages are part of the Service and are always sent. We may also occasionally send product-update email (for example, news about new features, or messages to our launch waitlist). You can opt out of product-update email at any time, and every such message includes an unsubscribe link. All of these messages are tied to your email address.
Information collected automatically
When your app or browser communicates with our backend, our infrastructure provider (Cloudflare) processes standard technical request metadata — such as IP address, request path, response status, and timing — for security, abuse prevention, and diagnostics. This metadata does not include the content of your captures, SOPs, or prompts.
Our website and app do not use advertising or cross-site tracking cookies. The app keeps you signed in using a session token stored locally on your device, not a tracking cookie.
3. How we use information
We use the information above to:
- Create and maintain your account and keep you signed in.
- Process the sessions you submit and return AI-generated SOPs to your device.
- Process subscription payments and enforce plan limits.
- Send you transactional messages such as verification codes, password resets, and usage notifications, and — unless you opt out — occasional product-update email.
- Operate, secure, debug, and improve the Service.
- Comply with legal obligations and enforce our agreements.
We do not use your captures or SOPs to train AI models, and we do not sell your personal information.
4. How your content is processed
Your captures and SOPs live in storage you control — locally, or in a cloud folder you already own — and you control when any content leaves your device. Using AI is optional: if you build a SOP by hand, nothing is sent for processing.
When you submit a session for AI processing:
- Your screenshots and a generated prompt are sent over an encrypted (HTTPS) connection to our backend, an authenticated relay running on Cloudflare Workers.
- Our backend forwards the request to Anthropic (the maker of Claude) for processing, then returns the result to your device. Our backend holds the content only in memory for the round-trip and does not store it.
- Anthropic processes the data under its commercial API terms, which currently provide that customer data is not used for model training and is retained only for a limited period — currently up to about 30 days — for trust-and-safety purposes before deletion. These terms are set by Anthropic and may change; the retention window is controlled by Anthropic, not by us.
When you export a SOP, the file is written wherever you choose to save it on your device. Anything you do with an exported file afterward is up to you.
5. Service providers and sub-processors
We use a small number of third-party providers to operate the Service. Each processes only the data needed for its role:
| Provider | Role | What it processes |
|---|---|---|
| Anthropic | AI processing (Claude) | Screenshots and the prompt for sessions you submit. Per Anthropic’s commercial API terms, this data is not used for model training and is retained only briefly (currently about 30 days). |
| Stripe | Payment processing | Your payment card details and billing information, entered directly with Stripe. We receive only a customer ID and subscription status. |
| Cloudflare | Hosting and backend relay | Technical request metadata (e.g., IP address, path, status, timing) for security and diagnostics. Does not store your content. |
| Resend | Transactional email | Your email address and the contents of transactional messages we send you (e.g., verification codes, password resets). |
Each provider operates under its own terms and privacy policy. We do not permit these providers to use your information for their own independent purposes beyond providing their service to us, except as described in their terms (for example, Anthropic’s limited safety retention). If we add other providers in the future, we will update this list.
6. Data retention
- Account, subscription, and usage data: retained for as long as your account is active. If you close your account or ask us to delete it, we delete this data within 30 days, except where we must keep certain records (such as billing or tax records) to comply with the law.
- Submitted session content: not retained by us. Anthropic retains it for a limited period (about 30 days) as described above.
- Backend request metadata (Cloudflare): retained for about 7 days for diagnostics.
- Billing records (Stripe): retained by Stripe according to its policies and applicable financial/tax recordkeeping laws.
7. How we protect your data
- All communication between the app, our backend, and our providers is encrypted in transit (HTTPS/TLS).
- Passwords are stored only as Argon2id hashes, never in plain text.
- Our backend stores account data only and never your captures or SOPs.
- Access to our systems is limited to what is needed to operate the Service.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential.
8. Your rights and choices
Depending on where you live, you may have rights regarding your personal information, including the right to access, correct, export, or delete it, and to object to or restrict certain processing.
You can exercise these rights as follows:
- Access / correction: view and update your email and subscription details from your account, or contact us.
- Deletion: contact us at hello@notavi.ai to request deletion of your account and associated data, and we will delete it within 30 days (other than records we must retain by law).
- Your content: because your captures and SOPs live in storage you control, you can delete them at any time directly, wherever you keep them.
- Product-update email: transactional messages are part of the Service, but you can opt out of occasional product-update email at any time using the unsubscribe link in any such message.
We will not discriminate against you for exercising any of these rights.
9. Children’s privacy
Notavi is intended for use by adults in a professional or personal-productivity context. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
10. Where your information is processed
Notavi LLC is based in the United States, and our providers process data in the United States and potentially other countries where they operate. If you access the Service from outside the United States, you understand that your information may be processed in the United States.
11. Selling or sharing of personal information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with the service providers listed above, to operate the Service, or when required by law.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the effective date above and notify you through the app or by email before the change takes effect. Your continued use of the Service after a change takes effect means you accept the updated policy.
13. Contact us
Questions, concerns, or requests about your data:
Notavi LLC 1932 Remuda Ln Spearfish, SD 57783 United States hello@notavi.ai