Legal
This Privacy Policy explains how Priyora Company collects, uses, stores, shares, and protects your personal data when you use Prinotes, our meeting-notes service, including the Prinotes website (prinotes.com) and application (app.prinotes.com). We are committed to protecting your privacy in line with the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations. Our guiding principle is simple: your data is yours.
Prinotes is a service operated by Priyora Company, a company registered in the Kingdom of Saudi Arabia. In this Policy, "Prinotes" refers to the product, and "Priyora", "we", "us", or "our" refers to Priyora Company, the entity responsible for your personal data (the data controller).
This Policy applies to everyone who visits our website or uses our application (together, the "Service"), whether you are an individual user or a member of an organization that uses Prinotes.
By using the Service, you acknowledge that you have read and understood this Policy. Where the law requires your consent for a specific activity, we ask for it separately and clearly, and you are never asked to agree to unrelated uses in a single step.
We design Prinotes to collect the minimum data needed to provide the Service, and to keep it only where it directly benefits you.
The data controller responsible for your personal data is:
For any question about this Policy, or to exercise your rights, contact our privacy team at privacy@prinotes.com
For general help, contact support@prinotes.com
Where required by law, we will appoint a Data Protection Officer.
You sign in with your Google or Microsoft account. Prinotes does not use passwords. When you sign in, we receive your name, email address, profile picture, and the account identifier from your provider.
When you record or upload a meeting, we process the audio, the transcript we generate from it, and the summaries, minutes, decisions, and action items we extract. This also includes meeting details you provide, such as titles, dates, and participant names.
By default, the audio is deleted from our systems as soon as processing finishes: we keep only the transcript and the notes generated from it. Audio is kept only if you have turned on audio retention (see Section 12). If you have connected Drive or OneDrive, a copy of the audio is saved to your own cloud storage and is not affected by this deletion (see Section 10).
If you connect Google Workspace or Microsoft 365, we access only what is needed for the features you enable, such as calendar events, tasks, files created through Prinotes, and contacts read to suggest attendees. Where you grant Drive or OneDrive access, your meeting audio and transcripts are saved to your own cloud storage automatically unless you turn that off (see Section 10). You can disconnect at any time.
Prinotes offers a free plan and paid plans. If you subscribe to a paid plan, payments are handled by Moyasar, our payment provider in Saudi Arabia. Prinotes never receives or stores your full card number: we store only limited details such as the card brand, the last four digits, and your subscription and invoice history.
To operate and secure the Service, we process technical information such as your device and browser type, IP address, log data, and the essential cookies described in Section 14.
What is required and what is optional. Your sign-in data and, when you use the core features, your meeting content are necessary to provide the Service: without them we cannot create your account or process a meeting. Connecting Google Workspace or Microsoft 365, and receiving marketing messages, are entirely optional: declining them only means those features or messages are unavailable, and nothing else.
We use your personal data for the purposes below. Under the PDPL, each purpose relies on a specific legal basis:
| Purpose | Legal basis under the PDPL |
|---|---|
| Provide the Service: record, transcribe, summarize, and sync your meetings | Implementation of the agreement to which you are a party (Art. 6(2)) |
| Authenticate you and keep your account secure | Implementation of the agreement to which you are a party (Art. 6(2)) |
| Send you service and transactional messages | Implementation of the agreement to which you are a party (Art. 6(2)) |
| Maintain, improve, and protect the reliability and security of the Service | Legitimate interest (Art. 6(4)), never involving sensitive data, and always within your reasonable expectations |
| Comply with legal, accounting, and tax obligations | Processing pursuant to law (Art. 6(2)) |
| Send marketing or promotional messages | Your separate, opt-in consent (Art. 5) |
Your consent, your control: We ask for consent separately for each purpose that requires it, and never bundle unrelated purposes together. You can withdraw consent at any time, and it is as easy to withdraw as it was to give.
You can withdraw any consent at any time from your account settings or by emailing privacy@prinotes.com; withdrawal takes effect without undue delay and does not affect processing that relies on another legal basis.
Prinotes relies on artificial intelligence for its core features: converting speech to text (transcription) and generating summaries, minutes, and action items from your meetings.
To do this, we use trusted third-party AI providers, currently OpenAI and Google Gemini, for transcription, structuring, and summaries. These are listed on our Sub-processors page.
We do not train AI on your content: Your content is not used to train AI models, neither ours nor our AI providers'. We use these providers on paid tiers that do not train on customer content.
Our AI providers may retain content for a short period (approximately 30 days*) solely to detect abuse and keep their services safe, after which it is deleted. They do not use it to train their models, and we do not retain or use your raw audio to train or improve our own models.
* Based on the published API data-usage policies of our AI providers (OpenAI and Google Gemini, paid API tiers), which do not use customer content for training. Exact windows are set by each provider and may change; see our Sub-processors page.
AI output can be inaccurate or incomplete and should be reviewed before you rely on it. See our Terms of Service for details. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
You are in control of what you record. Prinotes records on your own device (microphone and/or system audio) or processes recordings you upload.
Important: Prinotes does not notify other participants or obtain their consent on your behalf. You are responsible for informing participants and obtaining any consent required by law before recording, transcribing, or processing a meeting.
Recording conversations is regulated in many places, and some jurisdictions require the consent of all participants. Please review Section 5 (Recording Consent) of our Terms of Service, which sets out your responsibilities in full.
A Prinotes user may record or upload a meeting in which you took part. In that case, we process the meeting audio, the transcript, and the content generated from them, which may include your voice, your name, and things you said, in order to provide the Service to that user, on the basis of our legitimate interest in operating the Service under the PDPL. The user who records the meeting is responsible for informing you and obtaining any consent required by law before recording.
We do not use meeting content to identify anyone biometrically, and we do not use it to train AI models. The meeting audio is deleted from our systems as soon as processing finishes, and is kept only if the account holder has turned on audio retention. The transcript and the notes generated from it are kept until the account holder deletes them (see Section 12).
Even if you are not a Prinotes user, you have the rights described in Section 13 for your personal data, including access, correction, and deletion. Contact privacy@prinotes.com; to protect everyone's data we may need to verify your identity and involve the account holder to locate the relevant content.
If you connect your Google or Microsoft account, we request only the access needed for the features you turn on:
Limited Use: Prinotes's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft data likewise follows Microsoft's terms. We do not sell any of your data, including your Google or Microsoft data, and we do not use your Google or Microsoft data for advertising or to train AI models.
We do not store copies of your Google or Microsoft calendar, tasks, drive, or contacts. Contacts are read live and never stored: when you type, we read contact names and emails from your account only to show suggestions, and keep no copy. We store only the minimal references needed to link a meeting to an item you created (for example, an event identifier).
Copies in your own cloud storage: If you connect Google Drive or OneDrive, Prinotes automatically saves your meeting audio and transcripts there unless you turn auto-save off. Those files belong to you and live in your own account, which also means they are outside our control: deleting a meeting in Prinotes, deleting your account, or the automatic deletion of audio from our systems does not delete the copies in your Drive or OneDrive. You must delete those yourself from your Google or Microsoft account.
You can turn auto-save off at any time in your Prinotes settings, or decline the Drive/OneDrive permission entirely, in which case no files are ever sent there.
You can disconnect a connected account at any time in your Prinotes settings, or revoke access directly from your Google or Microsoft account's security settings. When you disconnect, we delete the stored access tokens for that account.
Your account and meeting data are stored on infrastructure located in the Kingdom of Saudi Arabia, encrypted at rest in both locations: primary data in Riyadh and encrypted backups in Jeddah, both within the Kingdom.
To transcribe and summarize your meetings, your content is transferred outside the Kingdom to our AI providers (located in the United States or operating globally). These transfers are carried out in accordance with the Saudi Regulation on Personal Data Transfer Outside the Kingdom, are limited to the minimum data necessary to provide the feature, and are covered by data-processing agreements with each provider.
Wherever your data is processed, your rights under the PDPL continue to apply and remain enforceable.
We keep personal data only for as long as it is needed for the purpose it was collected, or as required by law.
| Data | Retention |
|---|---|
| Meeting audio (recordings & uploads) | Deleted immediately after processing completes. Kept only if you have turned on audio retention* |
| Transcripts, summaries & action items | Kept until you delete the meeting or your account |
| Account data | Kept while your account is active |
| Billing & tax records | Kept as required by applicable accounting and tax law |
| Security & audit logs | Kept for about 12 months, then deleted (including from backups) |
| Operational & error logs | Kept only as long as needed for security, debugging, and legal purposes |
* Kept only if you are on a paid plan and have turned on audio retention, for the period included in your plan. See our Pricing page for the retention included with each plan.
You can delete a meeting at any time. When you delete your account, your meetings, transcripts, files, and recordings are erased from our live systems, and your account is deactivated with your display name removed. For abuse-prevention and legal compliance, we retain a limited record: your email address, your profile-picture link, the sign-in provider you used (Google or Microsoft), and basic account timestamps (when your account was created and last signed in), together with a security audit entry.
When you delete your data, it is removed from our live systems immediately and purged from our encrypted backups within 30 days.
How to delete or export your data: You can download a copy of your data or permanently delete your account at any time from your account settings, under Privacy (Download my data / Delete account). If anything goes wrong or you need help with a request, email privacy@prinotes.com
Under the PDPL, you have the right to:
You can download your data in two parts: a machine-readable JSON file with your profile, meeting details, and action items; and, because transcripts, summaries, and recordings are not included in that file, you can export those from each meeting as DOCX or PDF.
To exercise these rights, use the controls in your account settings under Privacy (download your data or delete your account), or email privacy@prinotes.com for any other request or if something goes wrong. We will respond within 30 days, which may be extended by a further 30 days where a request requires disproportionate effort or is one of several requests, in which case we will notify you of the extension and its reasons.
If you believe your rights have not been respected, you may lodge a complaint with SDAIA, the competent authority for personal data protection in the Kingdom of Saudi Arabia.
We use reasonable technical and organizational measures to protect your data, including:
Please note: No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security.
If something goes wrong. If a personal data breach occurs that may harm you or affect your rights, we will notify SDAIA within 72 hours of becoming aware of it and will inform you without undue delay, in clear language, including what happened, the potential risks, and our recommendations to protect yourself.
Access to your data is limited to authorized Priyora staff who need it to operate, support, or secure the Service.
Staff access is limited and audited: access by authorized Priyora staff to your meeting content requires a time-limited access session (up to one hour), used for support and security purposes only, and every such session is fully audited.
We never sell your data, and we never use your meeting content for advertising or to build profiles about you.
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact privacy@prinotes.com and we will delete it.
We may update this Policy from time to time. Where a change involves a new processing purpose that requires your consent under the PDPL, we will ask for that consent separately before the change applies to you. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice. Your continued use of the Service after an update means you accept the revised Policy.
For privacy questions or to exercise your rights: privacy@prinotes.com
For general support: support@prinotes.com
Priyora Company (شركة برييورا) · Jeddah 23532, Kingdom of Saudi Arabia.