privacy policy
last updated: 28th july, 2026
noven, meeting intelligence for macos
1. Introduction
This Privacy Policy explains how NOVEN ("Noven", "we", "us", "our") collects, uses, shares and protects personal data when you use the Noven desktop application, our websites and any related services (together, the "Service").
Noven records conversations, transcribes them, and turns them into structured context — summaries, commitments, decisions, questions, topics and people. That means we handle recordings and their contents, which can be sensitive. This policy sets out exactly what happens to that material, who else touches it, and what control you have over it.
Please read this policy together with our Terms and Conditions. If you do not agree with this policy, please do not use the Service.
1.1 Summary
This summary is for orientation only and does not replace the full policy.
Question
Short answer
Is my audio uploaded to Noven's servers?
No. Audio files are written to your own Mac, sent directly to our transcription provider for processing, and deleted from your Mac once processing completes.
Is my transcript stored?
Yes. Transcripts and everything derived from them are stored in our database so you can search, browse and ask questions about them.
Do you train AI models on my data?
No. We do not train models on your content, and we use our AI provider's API on terms under which your content is not used to train their models.
Do you sell my data?
No. We do not sell or share personal data for advertising, and we run no advertising or analytics trackers in the app.
Can I get my data deleted?
Yes. See section 13. Deleting your account deletes the associated records.
Where is data stored?
In our hosting provider's data centres in India, with processing by sub-processors as listed in section 9.
2. Who we are and how to reach us
Data controller. Noven, #88, Ground floor, Ashoka Ave Road, K.R. Garden, Murugeshpalya, Bengaluru - 560017, is the controller of personal data processed through the Service, except where we act as a processor on behalf of a business customer under a separate written agreement.
Contact. support@heynoven.com
Data protection contact / Grievance Officer (India). Umang D Shah, hello@heynoven.com. See section 19.D.
3. Scope of this policy
This policy applies to:
- the Noven macOS application;
- our websites and marketing pages;
- support, billing and other communications with us.
It does not apply to third-party services you choose to connect or that you use alongside Noven — for example your video-conferencing provider, your calendar provider, or your email provider. Their handling of your data is governed by their own policies.
Personal data means any information relating to an identified or identifiable natural person. Where local law uses a different term — personal information, personally identifiable information, or digital personal data — this policy should be read as covering that term as well.
4. The information we collect
4.1 Information you give us
Category
Examples
Why we have it
Account data
Email address, password (stored only as a salted hash), display name, account identifier, sign-in method
To create and secure your account
Profile data
Your name as you enter it during onboarding, theme and assistant preferences
To operate the Service and label your side of a conversation
Billing data
Plan, subscription status, billing identifiers held by our payment processor
To operate paid plans. We do not store full payment card numbers
Support data
Messages you send us, including any attachments or logs you choose to share
To answer you and to fix problems
4.2 Conversation data
This is the core of the Service and the most sensitive category we handle.
Category
What it is
Audio recordings
Two separate audio files per recording: your microphone, and the audio played by your Mac (for example the other side of a video call). Both are written to your own device
Transcripts
The text of what was said, with per-segment timestamps, and a speaker label per channel
Meeting records
Title, start and end time, duration, processing status, and an optional calendar event identifier
Derived context
Summaries, commitments and their deadlines, decisions, questions, topics, and people mentioned or spoken to
People records
Names, and any role, relationship, email address, company or notes you add yourself
Notes and folders
Notes and documents you write, and the folders you organise anything into
Chats
Your questions to the Noven assistant, its answers, and the context items you attach to a chat
Search embeddings
Numerical representations of your content, used to find relevant material when you ask a question
Conversation data may contain personal data about you and about other people, and may contain special category or sensitive data if such matters are discussed. Section 15 explains your responsibilities in relation to other participants.
4.3 Information from your device
- Microphone access, which is required for the Service to function at all.
- Screen Recording access, which macOS requires before any application may capture system audio. Noven uses this permission solely to capture audio. It requests the minimum possible video configuration, never reads or records the image of your screen, never captures screenshots, and never transmits any image data.
- Calendar access, which is optional. If granted, Noven reads event titles, times and attendee names in order to name a recording and identify who was present.
- Device and diagnostic information, such as application version, macOS version and technical error logs, used to diagnose faults.
4.4 Information from third parties
- Sign-in providers. If you sign in with Google, we receive your email address, name and profile image from Google. We do not receive your password.
- Payment processor. We receive subscription status and limited billing metadata. We do not receive full card details.
4.5 What we do not collect
We want to be specific about this, because a recording tool invites reasonable suspicion.
- We do not capture images of your screen, screenshots, or video of any kind.
- We do not log your keystrokes, track which applications you use, or monitor your activity outside a recording you start.
- We do not embed advertising networks, analytics SDKs, session-replay tools or third-party trackers in the application.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not record continuously or in the background. Recording starts only when you start it, and the on-screen indicator is visible for the whole of it.
5. How we use your data
We use personal data only for the purposes set out below. Where the General Data Protection Regulation or a comparable law applies, the legal basis for each purpose is given in the third column; section 8 explains those bases.
Purpose
What this involves
Legal basis
Providing the Service
Recording, transcribing, summarising and structuring your conversations; storing the result; letting you search, browse, edit and export it
Performance of a contract
Speaker attribution
Keeping your microphone and your system audio as separate channels so that what you said can be told apart from what others said
Performance of a contract
Answering your questions
Retrieving the parts of your context relevant to a question you ask, and generating an answer from them
Performance of a contract
Search
Creating and querying embeddings so that searching finds material by meaning as well as by keyword
Performance of a contract
Naming and attributing meetings
Reading calendar events, where you have allowed it, to title a recording and identify participants
Consent
Accounts and authentication
Creating your account, signing you in, keeping your session secure
Performance of a contract
Billing and plan limits
Recording minutes used against your allowance, operating paid plans, preventing abuse of free allowances
Performance of a contract; legitimate interests
Security and integrity
Detecting, investigating and preventing fraud, abuse, and unauthorised access
Legitimate interests; legal obligation
Support
Responding to you, diagnosing faults, and restoring service
Performance of a contract; legitimate interests
Improving the Service
Diagnosing failures and understanding aggregate reliability. We do not use your conversation content to train artificial intelligence models
Legitimate interests
Communications
Service messages you cannot opt out of, such as security notices; and product updates, which you can opt out of at any time
Legitimate interests; consent for marketing
Legal compliance
Meeting our obligations, responding to lawful requests, and establishing or defending legal claims
Legal obligation; legitimate interests
5.1 What we never do with your data
- We do not use your conversations, transcripts, notes or chats to train artificial intelligence models, whether our own or a third party's.
- We do not sell your personal data.
- We do not use your conversation content for advertising or profiling.
- We do not permit our staff to browse your content. Access is restricted, logged, and used only where you have asked for support or where required for security or law.
5.2 Automated decision-making
The Service uses automated processing to produce summaries and extract commitments, decisions, questions, topics and people. This processing produces informational output for your own use. It does not produce legal effects concerning you or similarly significantly affect you, and we do not use it to make decisions about you. Output is generated by a language model and may be incomplete or wrong; you should not rely on it as a record of fact without checking it.
6. How a recording is handled, step by step
Because this is the question that matters most, here is the actual sequence.
1. You start a recording. Nothing is captured before this. A visible indicator appears on your screen and stays there until you stop.
2. Audio is written to your Mac. Two files are created in Noven's application support folder on your own device: one for your microphone, one for system audio. They are not uploaded to us.
3. You stop the recording. The files are finalised.
4. The audio is transcribed. The audio files are sent directly from your Mac to our transcription provider over an encrypted connection, and text is returned. Long recordings are split into parts for this purpose.
5. The audio is deleted from your Mac. Once processing has completed successfully, Noven removes the local audio files. If processing fails, the files are retained so the recording can be retried, and removed once it succeeds or you delete the record.
6. The transcript is analysed. The text is sent to our AI provider, which returns the summary and the extracted commitments, decisions, questions, topics and people.
7. The result is stored. The transcript and everything derived from it are stored in our database under your account, protected by row-level security so that only your account can read them.
Net effect: we hold your transcript and the structured context built from it. We do not hold your audio.
7. Artificial intelligence
The Service depends on third-party artificial intelligence providers for four things: transcribing audio, extracting structured context from a transcript, answering your questions, and generating search embeddings.
When you use these features, the relevant content — audio, transcript text, or the parts of your context relevant to a question — is transmitted to that provider for processing and a result is returned.
We use these providers under their commercial API terms, on which:
- content submitted through the API is not used to train their models;
- content may be retained by the provider for a limited period for abuse monitoring, after which it is deleted;
- the provider acts as our processor and is bound by contractual confidentiality and security obligations.
Our current providers are listed in section 9. We may change providers, and will update this policy and the sub-processor list if we do.
8. Legal bases for processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following bases:
- Performance of a contract — to deliver the Service you have signed up for.
- Consent — for optional features such as calendar access, and for marketing messages. You may withdraw consent at any time, without affecting processing already carried out.
- Legitimate interests — to secure the Service, prevent abuse, diagnose faults, and communicate with you about the product. We balance these against your rights, and you may object (see section 13).
- Legal obligation — to comply with law and respond to valid legal process.
Where we process special categories of personal data because you have chosen to record a conversation in which such matters are discussed, we do so on the basis of your explicit consent to use the Service for that recording, or because you have manifestly made the data public. You should not use the Service to record conversations involving special category data unless you have a lawful basis for doing so.
9. Who we share data with
We do not sell personal data. We share it only as set out here.
9.1 Sub-processors
Provider
What it does
What it receives
Supabase
Database, authentication and hosting
Account data, transcripts, derived context, notes, chats, embeddings
OpenAI
Transcription, extraction, chat answers and embeddings
Audio for transcription; transcript text; the context relevant to a question you ask
Supabase
Transactional email such as password resets
Email address and message content
An up-to-date list of sub-processors is available at https://heynoven.com/subprocessors. Each is bound by a written agreement requiring appropriate security and restricting use of the data to the services provided to us.
9.2 Other disclosures
- Legal and safety. Where we are required by law, or where disclosure is reasonably necessary to enforce our Terms, protect our rights, or protect the safety of any person. We will notify you of a legal demand for your data unless prohibited from doing so.
- Business transfer. If we are involved in a merger, acquisition, financing or sale of assets, your data may be transferred as part of that transaction. We will give you notice and you will remain protected by this policy or a policy at least as protective.
- With your direction. Where you export, share or otherwise direct us to disclose your data.
10. International data transfers
We are based in India and our providers operate internationally. Your personal data may therefore be transferred to, stored in, and processed in countries other than your own, including the United States and India, which may not offer the same level of protection as your home country.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on one or more of:
- an adequacy decision by the European Commission or the relevant authority;
- the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable;
- supplementary technical and organisational measures, including encryption in transit and at rest and access controls.
For transfers out of India, we comply with the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Central Government. You may request a copy of the safeguards we rely on by writing to support@heynoven.com..
11. How long we keep data
Data
Retention
Local audio recordings
Deleted from your device once processing completes. Retained only while a failed recording is awaiting retry
Audio held by the transcription provider
Retained by the provider for a limited abuse-monitoring window under its API terms, then deleted. Not used for training
Transcripts and derived context
Kept until you delete the item or close your account
Notes, folders and chats
Kept until you delete them or close your account
Account and profile data
Kept for the life of the account, then deleted or anonymised within [30] days of closure
Billing records
Kept for the period required by tax and accounting law in the relevant jurisdiction, typically up to [7] years
Security and diagnostic logs
Typically [90] days
Backups
Deleted content persists in encrypted backups for up to [30] days before being overwritten
We may retain data for longer where required to comply with law, resolve disputes, or enforce our agreements.
12. Security
We take the following measures, among others:
- Encryption in transit for all connections between the application, our servers and our providers.
- Encryption at rest for data stored by our hosting provider.
- Row-level security in the database, so that queries can return only rows belonging to the authenticated user. Isolation between accounts is enforced by the database itself and not only by application code.
- Audio minimisation, in that audio is never uploaded to our servers and is deleted from your device once processed.
- Access control, with staff access restricted to those who need it, and only for support, security or legal reasons.
- Password hashing — we never store passwords in a form we can read.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by applicable law, including within 72 hours of becoming aware where the GDPR applies, and within the timelines set by the Digital Personal Data Protection Act, 2023 and the CERT-In directions where Indian law applies.
13. Your rights and choices
Subject to your local law, you have the following rights. We will respond within the period required by applicable law, and in any event within one month where the GDPR applies and 45 days where United States state privacy laws apply.
Right
What it means
Access
Obtain confirmation of whether we process your data, a copy of it, and information about how it is used
Rectification
Have inaccurate data corrected and incomplete data completed
Erasure
Have your data deleted where there is no overriding reason for us to keep it
Restriction
Have processing limited in certain circumstances, for example while accuracy is contested
Portability
Receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller
Objection
Object to processing based on legitimate interests, and to direct marketing at any time
Withdraw consent
Withdraw consent for anything based on it, such as calendar access, without affecting prior processing
Complain
Lodge a complaint with your supervisory authority (see section 19)
Non-discrimination
Not be treated worse for exercising your rights
13.1 Exercising your rights
Many rights can be exercised directly in the application: you can edit or delete individual meetings, transcripts, commitments, decisions, questions, topics, people, notes and chats at any time, and you can export a transcript to a file.
For anything else, including access to all of your data, portability, or deletion of your entire account, write to support@heynoven.com. We may need to verify your identity before acting, and will do so using information already associated with your account rather than by asking for additional identity documents wherever possible.
You may use an authorised agent where your local law allows it. We may require the agent to provide proof of authority and may still contact you to confirm.
There is no charge for exercising your rights, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and will tell you why.
14. Cookies and similar technologies
The Noven desktop application does not use advertising or analytics cookies. It stores small amounts of information on your device — such as your session token, your selected theme and your last-used sidebar tab — which are necessary for the application to work and are not used to track you.
Our websites may use strictly necessary cookies and, where required by law, will ask for your consent before setting any that are not strictly necessary. See https://heynoven.com/cookies-policy.
15. Other people in your recordings
A conversation has more than one person in it. This section is important.
You are responsible for obtaining consent. When you record a conversation, you are the person who decides to do so, and in many jurisdictions you must inform every participant and obtain their consent before recording. Some jurisdictions require the consent of all parties; recording without it can be a criminal offence as well as a civil wrong. Our Terms and Conditions set out this obligation in full, and you agree to it when you use the Service.
Our role. In respect of other participants' personal data captured in your recordings, we act as a processor or service provider on your behalf, and you act as the controller. We process that data only to provide the Service to you and in accordance with this policy.
If you are not a Noven user and your data appears in someone's recording. You may contact us at support@heynoven.com. Because the recording belongs to the account that created it, we will ordinarily refer your request to that account holder, who is the controller of it, and will assist them in responding. Where we are required by law to act directly, we will.
16. Children
The Service is not directed to children and is not intended for use by them.
- You must be at least 18 years old to use the Service in India, where the Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child and requires verifiable parental consent.
- You must be at least 16 years old in the European Economic Area and the United Kingdom, or the lower age set by your member state where applicable, and not below 13.
- You must be at least 13 years old elsewhere, and of the age of majority required to enter into a contract in your jurisdiction.
We do not knowingly collect personal data from children. If we learn that we have, we will delete it. If you believe a child has provided us with personal data, contact support@heynoven.com.
17. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top. If the change is material — for example a new purpose for using your data, or a new category of recipient — we will give you notice in the application or by email before it takes effect, and where the law requires it, we will ask for your consent.
Previous versions are available on request.
18. How to contact us
Noven
Operated by Abhinav Madke and Umang D Shah
Registered Address: #88, Ground floor, Ashoka Ave Road, K.R. Garden, Murugeshpalya, Bengaluru - 560017
General and support: hello@heynoven.com
Legal: support@heynoven.com
Privacy: support@heynoven.com
Grievance Officer (India): Umang D Shah, hello@heynoven.com, +91 9036209871
19. Region-specific information
The following supplements apply where the relevant law applies to you. Where a supplement conflicts with the rest of this policy, the supplement governs.
A. European Economic Area, United Kingdom and Switzerland
Controller. As stated in section 2.
Legal bases. As set out in section 8.
Your right to complain. You may lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. In the United Kingdom this is the Information Commissioner's Office. In Switzerland it is the Federal Data Protection and Information Commissioner.
Transfers. As set out in section 10.
Automated decision-making. As set out in section 5.2. We do not carry out decision-making producing legal or similarly significant effects within the meaning of Article 22.
B. California
This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
Categories of personal information collected in the past 12 months: identifiers; customer records information; commercial information; internet or other electronic network activity information limited to application diagnostics; audio and electronic information, being recordings and transcripts you create; professional or employment-related information where it appears in your content; and inferences drawn to produce summaries and structured context. Sensitive personal information may be present in the contents of recordings you choose to make.
Sources, purposes and disclosures. As set out in sections 4, 5 and 9.
Sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.
Use of sensitive personal information. We use sensitive personal information only to perform the Service and for purposes permitted without a right to limit under the CCPA. We do not use or disclose it to infer characteristics about you.
Your rights. To know, access, correct, delete, opt out of sale or sharing, limit the use of sensitive personal information, and not to be discriminated against for exercising them. Exercise these rights as set out in section 13.1.
Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
C. Other United States state privacy laws
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have rights to access, correct, delete and obtain a copy of your personal data, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not carry out targeted advertising, sale, or such profiling.
Where your state provides a right to appeal a refusal, you may appeal by writing to support@heynoven.com with the subject line "Privacy appeal". We will respond within the period your state's law requires and, if we deny the appeal, will tell you how to contact your state Attorney General.
D. India
This section applies where the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under them apply to you.
Data Fiduciary. Noven is the Data Fiduciary in respect of your personal data. You are the Data Principal.
Notice and consent. We process your personal data for the purposes set out in section 5, on the basis of your consent given at the point of collection or for legitimate uses permitted by the Act. You may withdraw consent at any time by writing to support@heynoven.com or by using the controls in the application; withdrawal will not affect processing carried out before it, and may prevent us from continuing to provide the Service.
Your rights as a Data Principal. Access to a summary of your personal data and the processing carried out; correction, completion, updating and erasure; grievance redressal; and nomination of another individual to exercise your rights in the event of death or incapacity.
Your duties. The Act requires that you do not impersonate another person, suppress material information, or register a false or frivolous grievance, and that you provide only verifiably authentic information.
Grievance Officer. In accordance with the Act and the Information Technology (Intermediary Guidelines) Rules, our Grievance Officer is:
- Name: Umang D Shah
- Designation: Co-founder
- Email: hello@heynoven.com
- Address: #88, Ground floor, Ashoka Ave Road, K.R. Garden, Murugeshpalya, Bengaluru - 560017
- Telephone: +91 9036209871
The Grievance Officer will acknowledge a complaint within 24 hours and resolve it within 15 days of receipt. If you are not satisfied, you may approach the Data Protection Board of India.
Children. As set out in section 16, we do not permit use of the Service by anyone under 18 in India, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
E. Canada
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation, including Quebec's Law 25. You may request access to and correction of your personal information, and may complain to the Office of the Privacy Commissioner of Canada. Where Law 25 applies, you also have rights of portability and de-indexing, and we will inform you before transferring your personal information outside Quebec.
F. Australia
We handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles. You may request access to and correction of your personal information, and may complain to us and then to the Office of the Australian Information Commissioner. We will notify eligible data breaches as required by the Notifiable Data Breaches scheme.
G. Brazil
We handle personal data in accordance with the Lei Geral de Proteção de Dados. You have rights of confirmation, access, correction, anonymisation, blocking, deletion, portability, information about sharing, and revocation of consent. You may complain to the Autoridade Nacional de Proteção de Dados.
H. Everywhere else
Where your local law grants you rights not listed above, we will honour them. Write to support@heynoven.com.