Esment logo
Esment

Privacy Policy

Last updated: July 19, 2026

This policy explains how NotasAI Inc. (“we”), the company behind Esment, handles personal data. It covers your rights under the GDPR, the CCPA/CPRA, and similar laws.

Esment is local-first: your memories, notes, and knowledge graph are stored on your own device and never reach our servers, unless you opt in to our cloud memory service. This policy is mainly about the account, billing, and diagnostic data needed to run the product.

1. Who we are

  • Company: NotasAI Inc., Delaware, USA
  • Address: 131 Continental Dr, Suite 305, Newark, DE 19713, USA
  • Contact: privacy@notas.ai

2. What we collect

  • Account — email and a hashed password.
  • Billing — handled by Stripe. We see your plan and billing status, never full card numbers.
  • Sales — name, email, company, and notes, if you contact sales.
  • License & activation — a device fingerprint, app version, and heartbeats, to enforce activation limits and stop abuse.
  • Trial signups — email, IP, and device fingerprint, to stop repeat free trials.
  • Usage telemetry — off by default. If you turn it on, we receive counts only (memories, tenants, LLM tokens) — never memory content.
  • Website analytics — PostHog, only if you consent. See our Cookie Policy.

What we don’t collect: the content of your memories. That stays on your device.

3. Third-party AI (your own keys)

Optional features like the dashboard assistant use your own API key for OpenAI or Anthropic. We relay the request but never store your key, prompts, or the AI’s response. Your data is then subject to that provider’s own policy.

4. Why we use it

  • Run the service and your account — contract.
  • Take payment via Stripe — contract.
  • Prevent abuse and secure the service — legitimate interest.
  • Improve the product and site — your consent.
  • Send you emails (sign-in, receipts, support) — contract.
  • Meet legal and tax obligations — legal obligation.

5. Who we share it with

We never sell your data. We use these processors:

  • Stripe — payments.
  • Resend — transactional email.
  • PostHog — product analytics and session replay, only with consent.
  • Render — hosting.
  • GitHub — app downloads.

6. International transfers

We’re based in the US. Where we transfer data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or an equivalent safeguard.

7. How long we keep it

  • Account data — while your account is active, plus a short legal retention period.
  • Billing records — as required by tax law.
  • Trial anti-abuse data — only as long as needed to prevent repeat abuse.

Deleting your account deletes or anonymises your data, except where the law requires us to keep records.

8. Your rights

Export or delete your data anytime from Account → Privacy. You also have the right to access, correct, restrict, object to, or port your data, and to withdraw consent at any time.

California residents

We don’t sell or share your data for cross-context advertising. You have the right to know, access, delete, and correct your data without discrimination for exercising these rights.

To exercise any right, email privacy@notas.ai.

9. Cookies

We use necessary cookies to run the site, and analytics cookies only with your consent. See our Cookie Policy.

10. Security

We use encryption in transit, hashed passwords, and least-privilege access. No system is perfectly secure, but we take reasonable measures to protect your data.

11. Children

Esment isn’t directed at children. We don’t knowingly collect data from anyone under 16.

12. Changes

We’ll update the date above when this policy changes, and notify you of material changes.

13. Contact

Questions? Email privacy@notas.ai.

EEA/UK residents can also lodge a complaint with their local data protection authority.