Legal
Privacy policy
Last updated: 2026
This is the formal version. The plain-language explanation says the same things more directly and is the better place to start.
Who is responsible
Noema is operated by Lewis Francis, Lowestoft, United Kingdom, who is the data controller for the purposes of UK GDPR. Contact: lewis@inpello.co.uk.
What is collected
- Account information — your email address, your name if you provide one, and the date you registered.
- Your notes — the text of what you write, any meetings you record, and the keywords derived from that text.
- Audio recordings — only if you use those features, and only temporarily (see retention below).
- Usage information — which features and pages are used, and for how long. This never includes the content or identifiers of individual notes.
- Subscription information — held by Stripe, our payment processor. Card details are never received or stored by us.
- Feedback and reviews — if you choose to send them.
Special category data
Notes about personal religious reflection are likely to constitute special category data under Article 9 of UK GDPR. The lawful basis for processing this is your explicit consent, given when you create an account and again each time you choose to write a note. You may withdraw that consent at any time by deleting your account, which erases the data.
How your notes are protected
Note content is stored in a database to which the administrative interface has no read access. This is enforced by database-level permissions rather than by policy: the account used for administration has not been granted the privilege to read the tables containing notes, meetings, keywords or reading plans. Administrative queries against those tables are refused by the database.
The exception: reviews and feedback you submit are visible to the operator, because they are submitted for that purpose. This is categorically different from note content. Nothing you write in a review is published unless you give explicit consent at the time of submission.
Retention
- Notes — kept until you delete them or delete your account.
- Audio recordings — deleted within 48 hours of the transcription being confirmed. There is no long-term storage of originals.
- Usage records — retained in aggregate.
- Account deletion — deleting your account permanently erases your notes, meetings, keywords and reading plans. This is a genuine deletion, not a hidden flag, and it cannot be reversed.
Who else processes your data
- DigitalOcean — hosting and storage, within the United Kingdom or European Union.
- Stripe — payment processing, if you subscribe.
- Google and Microsoft — only if you choose to sign in with one of them, and only to verify your identity.
Your notes are not sent to any third party for processing, analysis or training. Keyword extraction happens on our own server and does not involve an external service.
Your rights
Under UK GDPR you have the right to:
- Access the personal data held about you — the export feature in your settings provides your notes immediately.
- Have inaccurate data corrected.
- Have your data erased — account deletion does this.
- Restrict or object to processing.
- Receive your data in a portable format — the export is plain Markdown.
- Complain to the Information Commissioner's Office at ico.org.uk.
Cookies
Only a session cookie, used to keep you signed in. There is no advertising, no analytics service, and no tracking across other sites.
Children
This service is not directed at children under 13, and accounts should not be created for them.
Changes
If this policy changes in a way that affects how your data is handled, registered users will be told by email before it takes effect.
Project by Lewis Francis, Lowestoft