1. Who we are
RoomX is the meeting room AI assistant in the NoteX AI family of apps, operated by Notionis Ltd., the same company behind NoteX AI. In this policy, "we," "us," and "our" refer to that company.
NoteX AI is a family of products that includes:
- NoteX - personal AI meeting assistant for individuals
- RoomX - shared AI assistant for company meeting rooms
For the purposes of data protection laws including the EU General Data Protection Regulation (GDPR) and similar regulations, we act as the data controller for individual users of our consumer-facing service and as a data processor when providing services to business customers ("Workspaces").
If you are using RoomX through your employer or organization, that organization is the data controller for your meeting data. You should review your organization's privacy notice for information about how they handle your data.
2. Scope of this policy
This Privacy Policy applies specifically to RoomX, including:
- The RoomX tablet application
- RoomX-specific features within the NoteX mobile app (e.g., scanning a QR code to join a room meeting)
- The RoomX section of the NoteX admin console
- RoomX-related pages on
notexapp.com
For information about NoteX (the personal app) data practices, see the NoteX Privacy Policy. Practices that are shared across both products are noted in the following section.
3. Shared services with NoteX
Because RoomX is part of the NoteX AI family, certain services are shared between RoomX and NoteX:
- Account system: Your NoteX account is used to sign in to RoomX features
- Workspace: RoomX meetings live in the same Workspace as your NoteX meetings
- Authentication providers: Google, Microsoft, Apple, or email sign-in
- Infrastructure: Shared cloud hosting, transcription pipeline, and security controls
This means that the account information you provide for NoteX is the same account used for RoomX. Meeting content captured by RoomX is stored alongside other meeting content in your Workspace, subject to the access controls described below.
4. Data we collect
Account & profile data
When you sign in or are added to a Workspace, we collect:
- Name and email address
- Profile picture (if provided through your sign-in method)
- Authentication identifiers from your sign-in provider (Google, Microsoft, Apple, or email)
- Role within your Workspace (e.g., member, admin)
Meeting content
When you use RoomX to capture a meeting, we collect:
- Audio recordings of the meeting (only when explicitly started)
- Transcripts generated from the audio
- AI-generated summaries, action items, and meeting highlights
- Attendee list (people who joined via QR scan or were added)
- Meeting metadata (start time, duration, room name)
Device & technical data
- Device type, model, and operating system version
- App version and language settings
- IP address (used for security and basic geolocation)
- Device identifier for tablet pairing purposes
- Crash logs and diagnostic information
Usage data
- Features you use within the app
- Frequency and duration of sessions
- Errors encountered
- Performance metrics
Communication data
If you contact us via email or support channels, we collect the content of your communications and any attachments you provide.
5. How we use your data
We use the data we collect to:
| Purpose | Data used |
|---|---|
| Provide the core service (record, transcribe, distribute) | Audio, transcripts, attendee list, account data |
| Authenticate users and secure accounts | Account data, device data, IP address |
| Improve transcription accuracy and AI quality | Anonymized usage patterns and performance metrics |
| Provide customer support | Communication data, account data |
| Send service notifications (transcript ready, new attendee added) | Account data, meeting metadata |
| Detect fraud, abuse, and security threats | Device data, usage data, IP address |
| Comply with legal obligations | As required by applicable law |
| Send product updates and marketing (opt-in only) | Email address, usage data |
We do not use your meeting content to train AI models. Your audio recordings and transcripts are processed to provide the service, not to improve foundation models for general use.
6. Legal bases (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your data under the following legal bases:
- Contract: To provide the service you signed up for
- Legitimate interests: To improve our service, ensure security, and communicate with users
- Consent: For marketing communications and optional features
- Legal obligation: To comply with applicable laws
You can withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
7. Sharing & disclosure
We share your data only in the following circumstances:
Within your Workspace
Meeting content is shared based on the access controls of your Workspace. By default, only meeting attendees can access transcripts. Workspace administrators may have audit access to meeting records for compliance purposes; such access is logged.
With service providers
We share data with vendors who help us operate the service (see Subprocessors). These vendors are contractually bound to protect your data.
Legal requirements
We may disclose data when required by law, court order, or to protect the rights, property, or safety of our users or others.
Business transfers
If we are involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.
We do not sell your personal data to third parties. We do not share your meeting content with advertisers.
8. Subprocessors
We use a limited, audited set of subprocessors to operate NoteX.
Cloud Infrastructure
| Subprocessor | Service | Data Processed | Location |
|---|---|---|---|
| Google Cloud Platform | Primary cloud infrastructure, compute, storage, networking | All app data (encrypted at rest) | USA / EU |
| Amazon Web Services (AWS) | Backup storage, CDN, regional redundancy | Encrypted backups, static assets | USA / EU |
AI Models (No Training Use)
| Subprocessor | Models Used | Data Processed | Location |
|---|---|---|---|
| Google (Gemini) | Gemini Pro / Flash | Audio, transcripts, text — transiently | USA |
| OpenAI | GPT-4o / Whisper | Audio, transcripts, text — transiently | USA |
| Anthropic | Claude 3.x | Text, summaries — transiently | USA |
Analytics, Payments & Notifications
| Subprocessor | Service | Data Processed | Location |
|---|---|---|---|
| Google Analytics & Firebase | Product analytics, push notifications, A/B testing, crash reporting | Anonymized usage events, device tokens, crash logs | USA |
| RevenueCat | In-app subscription management (iOS & Android) | Purchase tokens, subscription status (no card data) | USA |
| LemonSqueezy | Web payment processing & billing | Billing info, email — card data handled by LemonSqueezy directly | USA |
To request a copy of any subprocessor's DPA or to object to a new subprocessor, contact hello@notexapp.com.
9. International transfers
Your data may be processed in countries outside your country of residence, including the United States and Singapore. When we transfer personal data out of the European Economic Area, United Kingdom, or Switzerland, we rely on appropriate safeguards such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions where applicable
- Other legally recognized transfer mechanisms
Enterprise customers may request data residency in specific regions; contact us for details.
10. Data retention
We retain your data for as long as necessary to provide the service and comply with legal obligations.
| Data type | Default retention |
|---|---|
| Meeting audio recordings | 365 days after meeting, then automatically deleted |
| Transcripts and summaries | Retained for the lifetime of your Workspace subscription |
| Account data | Retained until account deletion |
| Usage and diagnostic data | Up to 24 months |
| Support communications | Up to 3 years |
| Demo Mode data | Reset every 30 minutes; no permanent storage |
Workspace administrators may configure custom retention policies for their organization. You may request earlier deletion of your data (see Your rights).
11. Security
We take the security of your data seriously and implement industry-standard practices including:
- Encryption in transit: All data is transmitted using TLS 1.3 or higher
- Encryption at rest: Data is encrypted using AES-256
- Access controls: Strict role-based access for our internal team, with audit logging
- Authentication: Support for SSO, multi-factor authentication, and strong password policies
- Network security: Firewalls, intrusion detection, and regular security testing
- Incident response: Documented procedures for detecting and responding to security incidents
While we use commercially reasonable means to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
If you discover a security vulnerability, please report it to hello@notexapp.com.
12. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Correction: Update or correct inaccurate data
- Deletion:Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a machine-readable format
- Objection: Object to certain types of processing
- Withdraw consent: Where processing is based on consent
- Complain: Lodge a complaint with a data protection authority
To exercise these rights, email hello@notexapp.com. We will respond within 30 days. If your data is held within a Workspace, we may direct you to your Workspace administrator.
13. Cookies & tracking
Our website and admin console use cookies and similar technologies for the following purposes:
- Essential cookies: Required for authentication, security, and core functionality
- Functional cookies: Remember your preferences (language, theme)
- Analytics cookies: Help us understand how the service is used (anonymized)
The mobile and tablet applications do not use third-party advertising trackers or cross-app tracking identifiers. You can manage cookie preferences through your browser settings or our cookie consent banner.
14. Children's privacy
RoomX is a business tool designed for adult use in workplace settings. We do not knowingly collect personal data from children under 16 (or the relevant age in your jurisdiction). If you believe we have collected data from a child, please contact us and we will delete it promptly.
15. Demo Mode
RoomX offers a Demo Mode that lets anyone explore the app without creating an account. In Demo Mode:
- We do not record real audio
- Sample transcripts and meetings shown are fictional
- Session data is reset after 30 minutes of inactivity
- No personal data is permanently stored
- Basic device and usage information may be collected for service operation
16. Recording & consent
RoomX records meetings only when a user explicitly initiates recording. The tablet displays a clear recording indicator at all times while recording is active.
It is the responsibility of the meeting organizer and Workspace administrator to ensure that all meeting participants are informed about and consent to recording in accordance with applicable laws. Many jurisdictions require all-party consent for recording conversations.
Participants may request that a meeting not be recorded or that their contributions be redacted from a transcript. Contact your Workspace administrator or hello@notexapp.com.
17. Third-party services
RoomX integrates with third-party services such as:
- Identity providers (Google, Microsoft, Apple)
- Calendar services (Google Workspace, Microsoft 365)
- Communication platforms (Zoom, Microsoft Teams, Google Meet)
When you connect these services, we access only the data necessary to provide the integration. Each service has its own privacy policy and we encourage you to review them.
18. California rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, and share
- Right to delete personal information we collect
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use of sensitive personal information
- Right to non-discrimination for exercising your rights
RoomX does not sell personal information as defined by the CCPA. To exercise California-specific rights, contact hello@notexapp.com.
19. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last updated" date
- Sending an email to registered users for significant changes
- Displaying an in-app notice where appropriate
Your continued use of RoomX after changes become effective constitutes acceptance of the updated policy.
20. Contact us
If you have questions about this Privacy Policy or our data practices:
- Privacy inquiries: privacy@notexapp.com
- Security issues: security@notexapp.com
- RoomX support: roomx@notexapp.com
- General support: support@notexapp.com
- Website: roomx.notexapp.com
For users in the European Economic Area, our EU representative can be contacted at hello@notexapp.com.