Konchatzi (talk | contribs)
Added more references
Konchatzi (talk | contribs)
Line 24: Line 24:


==Incidents==
==Incidents==
===Users Privacy violations (''2025'')===
=== Users Privacy Violations (2025) ===
[[File:Locked out.png|thumb|User unable to access Notability unless the new Privacy Policy is accepted]]
[[File:Locked out.png|thumb|Users report being unable to access notes unless the new Privacy Policy is accepted (October 2025).]]
In July 2025, Notability updated its [https://notability.com/privacy Privacy Policy]. All users, including those who purchased the app before November 2021, were locked out of the app and their notes until they accepted the new terms. User reports and concerns are discussed in these Reddit threads ([https://www.reddit.com/r/notabilityapp/comments/1msjoi7/has_anyone_read_the_updated_privacy_policy/ 1], [https://www.reddit.com/r/notabilityapp/comments/1my5fe2/read_the_privacy_policy_and_now_deleting_account/ 2], [https://www.reddit.com/r/notabilityapp/comments/1mabkou/notabilitys_new_privacy_policy_ai_and_voice_notes/ 3]).


Key concerns raised about the updated policy include:
Notability updated its [https://notability.com/privacy Privacy Policy] in 2025. Following this change, users reported being unable to access their previously created notes until they accepted the new terms. This included users who purchased the app before it moved to a subscription model in late 2021. Public reports and discussion appear in the following Reddit threads: [https://www.reddit.com/r/notabilityapp/comments/1msjoi7/has_anyone_read_the_updated_privacy_policy/ 1], [https://www.reddit.com/r/notabilityapp/comments/1my5fe2/read_the_privacy_policy_and_now_deleting_account/ 2], [https://www.reddit.com/r/notabilityapp/comments/1mabkou/notabilitys_new_privacy_policy_ai_and_voice_notes/ 3].


*'''AI processing of personal notes and voice''': Notability uses AI services to process notes and voice recordings for features like transcripts, summaries, and quizzes. Although they state data is deleted after processing, temporary retention and the use of unnamed third-party providers raise transparency and control concerns.
Concerns raised about the updated policy language include:
*'''Persistent storage of audio transcripts''': Original audio is deleted after processing, but the resulting text transcripts are retained indefinitely on Notability servers unless a user requests deletion.
 
*'''No clear opt-out or local processing''': There is no obvious option to run transcripts or summaries entirely on-device. These features send content to third-party processors, and users are not clearly informed at the moment of use that data will leave their device.
*'''Processing of notes and recordings''' – The policy states that notes, handwritten content, images, documents, and audio synced with “the Services” may be processed using AI features such as transcription and summarisation. It does not clearly restrict this to Notability Cloud.
*'''Data sharing in case of acquisition or merger''': The terms allow transferring user data if the company is acquired or merges. Given the sensitivity of personal and educational notes, this presents potential risks if ownership changes.
*'''Storage of transcripts''' – While original audio may be deleted after processing, transcripts created during processing may remain stored on Notability servers unless a user requests removal.
*'''Limited transparency about AI vendors''': The policy references “AI providers” without naming them, preventing users from assessing their reliability or compliance.
*'''No obvious local-only option''' – The app does not provide a clear way to use transcription or AI features entirely on-device without content being uploaded to external processors.
*'''Children’s privacy protections''': While certain features are not intended for users under 16, protections appear to rely on self-reported age, meaning data could be collected from minors who do not disclose their age.
*'''Broad data-transfer terms''' The policy allows transferring user data if the company is sold or merges with another business, affecting users who store personal or educational material.
*'''Unnamed third-party processors''' The policy refers to “AI providers” and other external processors without identifying them, limiting transparency about how data is handled.
*'''Under-16 uncertainty''' – The policy states features are not intended for users under 16, but protections rely on self-reported age, which may not prevent minors’ data from being processed.
 
These concerns have led users to question whether continued access to local notes should depend on accepting terms that permit external processing and storage of private content. Requests for clearer boundaries and data segregation remain ongoing across public forums and support channels.


=== Policy change timeline ===
=== Policy change timeline ===