Quick answer: Before uploading handwriting to an AI note-taking service, identify exactly what leaves your device, why it is processed, which companies receive it, whether it trains models, how it is protected, where it may be transferred, how long it remains, how deletion works, what integrations copy it, and whether the service is approved for the sensitivity of your notes.
Editorial disclosure: This article is published by XNote. The checklist applies to any AI note-taking service, and the XNote-specific section links to XNote's current policies. It is general information, not legal or security advice. XNote policy details were checked on August 19, 2026 against the Privacy Policy dated March 26, 2026.
Why a handwritten page can carry more risk than it appears to
A single notebook page may contain customer names, health details, internal plans, access codes, financial figures, or a private comment in the margin. Once the page is digitized, different data can be created or transmitted: pen strokes, page images, recognized text, prompts, summaries, audio, transcripts, embeddings, account identifiers, and usage logs.
The useful question is therefore not “Is AI private?” It is “Is this specific data flow appropriate for this specific note?” Answer that before enabling cloud processing, sharing, or integrations.
The ten questions to ask every AI note-taking provider
- What leaves the device? Distinguish digital ink, images, recognized text, audio, prompts, derived outputs, and metadata.
- Why is each type of data processed? Capture, device sync, backup, handwriting recognition, search, transcription, and generative AI are separate purposes.
- Which organizations receive it? Ask about infrastructure, database, AI, analytics, monitoring, payment, and integration subprocessors.
- Where can it be processed? Identify storage regions and international transfers that may apply.
- Is customer content used for model training? Read the exact promise and whether it covers the provider and its AI subprocessors.
- How is it protected? Look for specific statements about encryption, access control, monitoring, and incident response—not only the word “secure.”
- How long is it retained? Check active content, deleted content, backups, operational logs, and third-party retention separately.
- Can you export and delete it? Understand both individual-content deletion and complete account deletion.
- What do integrations and sharing links copy? A note sent to Slack, a calendar, or another service becomes subject to that destination's controls and retention.
- Is the service approved for this data? Workplace rules, contracts, consent obligations, school policy, and regulated-data requirements may prohibit an otherwise convenient workflow.
What XNote's current Privacy Policy says
The following are XNote's published statements, not an independent security audit. Read the current XNote Privacy Policy and any agreement that applies to your account before relying on them.
| Question | Published XNote policy statement checked August 19, 2026 |
|---|---|
| What content may be processed? | The policy lists notes, handwritten inputs, metadata, audio or video where applicable, transcripts, summaries, structured outputs, semantic embeddings, and other AI-derived insights. |
| Is customer data used to train general-purpose AI? | The policy says XNote does not use customer data submitted through the services to train or improve general-purpose AI models. |
| Are subprocessors involved? | Yes. The policy gives examples including Hetzner, Supabase, Microsoft Azure OpenAI, AssemblyAI, PostHog, Mixpanel, Sentry, Apple, Google, Shopify, and Adapty. The list may change. |
| Can data cross borders? | Yes. The policy says data may be processed outside a user's country, including the United States, with safeguards such as Standard Contractual Clauses where required. |
| How is data protected? | The policy describes encryption in transit and at rest where applicable, least-privilege and role-based access, monitoring, infrastructure protections, and security reviews. |
| How does deletion work? | The policy says user-deleted content is removed from active systems without undue delay; account deletion is completed within a reasonable period and no later than 14 days, subject to limited legal or technical retention. |
| What about backups and logs? | The policy says backup retention typically does not exceed 7 days and operational logs are generally retained for up to 14 days; third-party retention may follow provider policies. |
What the policy does not mean
Encryption does not make every note appropriate to upload. A “no general-purpose model training” statement does not mean no processing occurs; AI features still require selected providers to process relevant content. A deletion window does not control copies you intentionally sent to integrations or people. And a privacy policy does not replace a Data Processing Agreement, Business Associate Agreement, institutional approval, or security review when one is required.
XNote's policy also states that the services are not specifically designed for sensitive personal data—including health information, biometric data, or other special categories—unless processing is explicitly agreed under a separate arrangement with appropriate safeguards. That is an important limitation, not fine print.
Classify the note before using AI
| Note type | Reasonable starting action |
|---|---|
| Personal brainstorming with no sensitive details | Review settings, secure the account and device, and use normal judgment. |
| Internal project information | Follow company policy, limit integrations, and confirm sharing destinations. |
| Customer, employee, or student information | Confirm authorization, applicable agreements, retention, and consent requirements. |
| Health, legal, financial, biometric, credential, or highly confidential data | Do not upload unless an authorized workflow and appropriate contractual safeguards explicitly permit it. Redact or keep the note offline when possible. |
Seven privacy habits that remain under your control
- Never store passwords, recovery codes, private keys, or one-time authentication codes in an AI notebook.
- Keep sensitive and ordinary notes in separate workflows.
- Review recognized text before sharing; recognition errors can expose the wrong meaning or person.
- Check every connected integration and remove access you no longer need.
- Review the destination before sending a summary or task notification.
- Test export and deletion with low-risk content before adopting a service for important records.
- Record the policy version and review date when a vendor decision affects clients, employees, or regulated work.
How to read security claims responsibly
XNote's Security page describes layered controls, role-based access, monitoring, recovery, and privacy-focused AI processing. Those statements are useful inputs, but no online system can guarantee complete security. For organizational use, ask for the documents your review process requires and contact the vendor when published material does not answer a material question.
Frequently asked questions
Does XNote use customer notes to train general-purpose AI models?
XNote's Privacy Policy dated March 26, 2026 says it does not use customer data submitted through the services to train or improve general-purpose AI models.
Does that mean notes never leave the device?
No. The policy says relevant content may be processed by XNote and third-party service providers to deliver requested features.
Does XNote identify subprocessors?
Yes. The current policy lists examples across infrastructure, databases, AI processing, analytics, monitoring, payments, and integrations, and says the list may change.
How quickly does XNote say account data is deleted?
The current policy says account-associated personal data is deleted within a reasonable period and no later than 14 days, subject to limited legal or technical retention.
Is XNote designed for sensitive health or biometric information?
The current policy says the services are not specifically designed for sensitive personal data unless separate contractual arrangements and safeguards apply.
Is encryption enough for confidential notes?
No. Encryption is one control. Authorization, device security, access, retention, contracts, integrations, and user behavior also matter.
Should a company rely on this article for approval?
No. Use the current policy, security documentation, contracts, and your organization's legal and security review process.
Make the privacy decision before the upload
Start with the lowest-risk page you can use to test capture, search, AI, export, and deletion. If the workflow will include confidential or regulated information, stop and obtain the required approval before moving real data. Review the XNote Privacy Policy and XNote Security page, or contact privacy@xnote.ai with a specific question.
Sources and update policy
This guide was checked against XNote's current product documentation on August 19, 2026. Features can change, so confirm critical workflow, privacy, and integration details before relying on them.