Legal

Privacy Policy

Last updated 28 July 2026

This Privacy Policy explains how Priyora Company collects, uses, stores, shares, and protects your personal data when you use Prinotes, our meeting-notes service, including the Prinotes website (prinotes.com) and application (app.prinotes.com). We are committed to protecting your privacy in line with the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations. Our guiding principle is simple: your data is yours.

01

Introduction & Scope

Prinotes is a service operated by Priyora Company, a company registered in the Kingdom of Saudi Arabia. In this Policy, "Prinotes" refers to the product, and "Priyora", "we", "us", or "our" refers to Priyora Company, the entity responsible for your personal data (the data controller).

This Policy applies to everyone who visits our website or uses our application (together, the "Service"), whether you are an individual user or a member of an organization that uses Prinotes.

By using the Service, you acknowledge that you have read and understood this Policy. Where the law requires your consent for a specific activity, we ask for it separately and clearly, and you are never asked to agree to unrelated uses in a single step.

We design Prinotes to collect the minimum data needed to provide the Service, and to keep it only where it directly benefits you.

02

Who We Are (Data Controller)

The data controller responsible for your personal data is:

  • Priyora Company (شركة برييورا), a single-member Limited Liability Company registered in the Kingdom of Saudi Arabia.
  • Registered in: Jeddah 23532, Kingdom of Saudi Arabia.
  • Registered with: the National Register for Personal Data Protection (NDGP, SDAIA), registration No. 3260007171.

For any question about this Policy, or to exercise your rights, contact our privacy team at privacy@prinotes.com

For general help, contact support@prinotes.com

Where required by law, we will appoint a Data Protection Officer.

03

Definitions

  • Personal Data: any information that identifies you or could reasonably be linked to you, such as your name, email address, or voice.
  • Meeting Content: the audio you record or upload, the transcripts we generate, and the summaries, minutes, decisions, and action items produced from them.
  • Processing: any operation performed on personal data, such as collecting, storing, using, sharing, or deleting it.
  • Sub-processor: a third-party service that processes personal data on our behalf to help us provide the Service.
  • Service: the Prinotes website and application, together with all related features.
  • PDPL: the Saudi Personal Data Protection Law, the Kingdom's data-protection law regulated and enforced by the Saudi Data & Artificial Intelligence Authority (SDAIA).
  • NDGP: the National Data Governance Platform, operated by the Saudi Data & Artificial Intelligence Authority (SDAIA), which hosts the National Register for Personal Data Protection.
04

What Information We Collect

Account & identity data

You sign in with your Google or Microsoft account. Prinotes does not use passwords. When you sign in, we receive your name, email address, profile picture, and the account identifier from your provider.

Meeting Content

When you record or upload a meeting, we process the audio, the transcript we generate from it, and the summaries, minutes, decisions, and action items we extract. This also includes meeting details you provide, such as titles, dates, and participant names.

By default, the audio is deleted from our systems as soon as processing finishes: we keep only the transcript and the notes generated from it. Audio is kept only if you have turned on audio retention (see Section 12). If you have connected Drive or OneDrive, a copy of the audio is saved to your own cloud storage and is not affected by this deletion (see Section 10).

Integration data (only when you connect)

If you connect Google Workspace or Microsoft 365, we access only what is needed for the features you enable, such as calendar events, tasks, files created through Prinotes, and contacts read to suggest attendees. Where you grant Drive or OneDrive access, your meeting audio and transcripts are saved to your own cloud storage automatically unless you turn that off (see Section 10). You can disconnect at any time.

Billing data

Prinotes offers a free plan and paid plans. If you subscribe to a paid plan, payments are handled by Moyasar, our payment provider in Saudi Arabia. Prinotes never receives or stores your full card number: we store only limited details such as the card brand, the last four digits, and your subscription and invoice history.

Technical & usage data

To operate and secure the Service, we process technical information such as your device and browser type, IP address, log data, and the essential cookies described in Section 14.

What is required and what is optional. Your sign-in data and, when you use the core features, your meeting content are necessary to provide the Service: without them we cannot create your account or process a meeting. Connecting Google Workspace or Microsoft 365, and receiving marketing messages, are entirely optional: declining them only means those features or messages are unavailable, and nothing else.

05

How We Use Your Information & Legal Basis

We use your personal data for the purposes below. Under the PDPL, each purpose relies on a specific legal basis:

PurposeLegal basis under the PDPL
Provide the Service: record, transcribe, summarize, and sync your meetingsImplementation of the agreement to which you are a party (Art. 6(2))
Authenticate you and keep your account secureImplementation of the agreement to which you are a party (Art. 6(2))
Send you service and transactional messagesImplementation of the agreement to which you are a party (Art. 6(2))
Maintain, improve, and protect the reliability and security of the ServiceLegitimate interest (Art. 6(4)), never involving sensitive data, and always within your reasonable expectations
Comply with legal, accounting, and tax obligationsProcessing pursuant to law (Art. 6(2))
Send marketing or promotional messagesYour separate, opt-in consent (Art. 5)

Your consent, your control: We ask for consent separately for each purpose that requires it, and never bundle unrelated purposes together. You can withdraw consent at any time, and it is as easy to withdraw as it was to give.

You can withdraw any consent at any time from your account settings or by emailing privacy@prinotes.com; withdrawal takes effect without undue delay and does not affect processing that relies on another legal basis.

06

AI Processing

Prinotes relies on artificial intelligence for its core features: converting speech to text (transcription) and generating summaries, minutes, and action items from your meetings.

To do this, we use trusted third-party AI providers, currently OpenAI and Google Gemini, for transcription, structuring, and summaries. These are listed on our Sub-processors page.

We do not train AI on your content: Your content is not used to train AI models, neither ours nor our AI providers'. We use these providers on paid tiers that do not train on customer content.

Our AI providers may retain content for a short period (approximately 30 days*) solely to detect abuse and keep their services safe, after which it is deleted. They do not use it to train their models, and we do not retain or use your raw audio to train or improve our own models.

* Based on the published API data-usage policies of our AI providers (OpenAI and Google Gemini, paid API tiers), which do not use customer content for training. Exact windows are set by each provider and may change; see our Sub-processors page.

AI output can be inaccurate or incomplete and should be reviewed before you rely on it. See our Terms of Service for details. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

07

Recording & Your Responsibility

You are in control of what you record. Prinotes records on your own device (microphone and/or system audio) or processes recordings you upload.

Important: Prinotes does not notify other participants or obtain their consent on your behalf. You are responsible for informing participants and obtaining any consent required by law before recording, transcribing, or processing a meeting.

Recording conversations is regulated in many places, and some jurisdictions require the consent of all participants. Please review Section 5 (Recording Consent) of our Terms of Service, which sets out your responsibilities in full.

08

If You Are a Meeting Participant (Not a Prinotes User)

A Prinotes user may record or upload a meeting in which you took part. In that case, we process the meeting audio, the transcript, and the content generated from them, which may include your voice, your name, and things you said, in order to provide the Service to that user, on the basis of our legitimate interest in operating the Service under the PDPL. The user who records the meeting is responsible for informing you and obtaining any consent required by law before recording.

We do not use meeting content to identify anyone biometrically, and we do not use it to train AI models. The meeting audio is deleted from our systems as soon as processing finishes, and is kept only if the account holder has turned on audio retention. The transcript and the notes generated from it are kept until the account holder deletes them (see Section 12).

Even if you are not a Prinotes user, you have the rights described in Section 13 for your personal data, including access, correction, and deletion. Contact privacy@prinotes.com; to protect everyone's data we may need to verify your identity and involve the account holder to locate the relevant content.

09

How We Share Information

We do not sell your personal data, and we do not use your meeting content for advertising.

We share personal data only in these situations:

  • With sub-processors who help us run the Service, under contracts that require them to protect your data and use it only on our instructions. A summary is below, with the full list on our Sub-processors page.
  • To comply with the law, respond to lawful requests, enforce our Terms, or protect the rights, safety, and security of our users and the public.
  • In a corporate transaction (such as a merger or acquisition), where your data continues to be protected under this Policy.
Sub-processorPurposeLocation
OpenAIAI processing of meeting contentUnited States
Google GeminiAI processing of meeting contentUnited States / global
Oracle Cloud InfrastructureHosting & encrypted storageSaudi Arabia
CloudflareContent delivery & securityUnited States / global
SentryError monitoringEuropean Union / United States
MoyasarPayment processing for paid plansSaudi Arabia

See our full, up-to-date list, including Google Workspace and Microsoft 365 (used only when you connect them), on our Sub-processors page.

10

Google & Microsoft Integrations

If you connect your Google or Microsoft account, we request only the access needed for the features you turn on:

  • Calendar: to read, create, and manage the events created through Prinotes for your meetings and follow-ups.
  • Tasks / To Do: to add the action items we extract to your task list, keep their completion status in sync, and delete them at your request. This is limited to the tasks Prinotes creates, not your other tasks.
  • Drive / OneDrive: to save your meeting audio and transcripts to your own cloud storage (limited to the files Prinotes creates). This is on by default when you grant Drive or OneDrive access; you can decline the permission, turn auto-save off during onboarding, or turn it off at any time in your settings.
  • Contacts: read-only, to suggest attendees and assignees as you type.

Limited Use: Prinotes's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft data likewise follows Microsoft's terms. We do not sell any of your data, including your Google or Microsoft data, and we do not use your Google or Microsoft data for advertising or to train AI models.

We do not store copies of your Google or Microsoft calendar, tasks, drive, or contacts. Contacts are read live and never stored: when you type, we read contact names and emails from your account only to show suggestions, and keep no copy. We store only the minimal references needed to link a meeting to an item you created (for example, an event identifier).

Copies in your own cloud storage: If you connect Google Drive or OneDrive, Prinotes automatically saves your meeting audio and transcripts there unless you turn auto-save off. Those files belong to you and live in your own account, which also means they are outside our control: deleting a meeting in Prinotes, deleting your account, or the automatic deletion of audio from our systems does not delete the copies in your Drive or OneDrive. You must delete those yourself from your Google or Microsoft account.

You can turn auto-save off at any time in your Prinotes settings, or decline the Drive/OneDrive permission entirely, in which case no files are ever sent there.

You can disconnect a connected account at any time in your Prinotes settings, or revoke access directly from your Google or Microsoft account's security settings. When you disconnect, we delete the stored access tokens for that account.

11

International Data Transfers

Your account and meeting data are stored on infrastructure located in the Kingdom of Saudi Arabia, encrypted at rest in both locations: primary data in Riyadh and encrypted backups in Jeddah, both within the Kingdom.

To transcribe and summarize your meetings, your content is transferred outside the Kingdom to our AI providers (located in the United States or operating globally). These transfers are carried out in accordance with the Saudi Regulation on Personal Data Transfer Outside the Kingdom, are limited to the minimum data necessary to provide the feature, and are covered by data-processing agreements with each provider.

Wherever your data is processed, your rights under the PDPL continue to apply and remain enforceable.

12

Data Storage, Retention & Deletion

We keep personal data only for as long as it is needed for the purpose it was collected, or as required by law.

DataRetention
Meeting audio (recordings & uploads)Deleted immediately after processing completes. Kept only if you have turned on audio retention*
Transcripts, summaries & action itemsKept until you delete the meeting or your account
Account dataKept while your account is active
Billing & tax recordsKept as required by applicable accounting and tax law
Security & audit logsKept for about 12 months, then deleted (including from backups)
Operational & error logsKept only as long as needed for security, debugging, and legal purposes

* Kept only if you are on a paid plan and have turned on audio retention, for the period included in your plan. See our Pricing page for the retention included with each plan.

Deleting your data

You can delete a meeting at any time. When you delete your account, your meetings, transcripts, files, and recordings are erased from our live systems, and your account is deactivated with your display name removed. For abuse-prevention and legal compliance, we retain a limited record: your email address, your profile-picture link, the sign-in provider you used (Google or Microsoft), and basic account timestamps (when your account was created and last signed in), together with a security audit entry.

When you delete your data, it is removed from our live systems immediately and purged from our encrypted backups within 30 days.

How to delete or export your data: You can download a copy of your data or permanently delete your account at any time from your account settings, under Privacy (Download my data / Delete account). If anything goes wrong or you need help with a request, email privacy@prinotes.com

13

Your Rights

Under the PDPL, you have the right to:

  • Be informed of how and why your personal data is processed.
  • Access the personal data we hold about you.
  • Obtain a copy of your data in a readable, machine-readable format.
  • Correct data that is inaccurate, incomplete, or out of date.
  • Delete your data when it is no longer needed.
  • Withdraw consent at any time, where processing is based on consent.

You can download your data in two parts: a machine-readable JSON file with your profile, meeting details, and action items; and, because transcripts, summaries, and recordings are not included in that file, you can export those from each meeting as DOCX or PDF.

To exercise these rights, use the controls in your account settings under Privacy (download your data or delete your account), or email privacy@prinotes.com for any other request or if something goes wrong. We will respond within 30 days, which may be extended by a further 30 days where a request requires disproportionate effort or is one of several requests, in which case we will notify you of the extension and its reasons.

If you believe your rights have not been respected, you may lodge a complaint with SDAIA, the competent authority for personal data protection in the Kingdom of Saudi Arabia.

14

Cookies & Similar Technologies

We use only essential cookies that are strictly necessary to run the Service:

  • A session cookie to keep you signed in.
  • A short-lived security cookie used during the sign-in process.
  • Our security and content-delivery provider (Cloudflare) may set a strictly necessary security cookie if your visit triggers a security check (for example, during an attack on our Service). It is not used for tracking.

The application also uses your browser's local storage to remember interface preferences such as language and theme. This never contains tracking identifiers and stays on your device.

We do not use advertising or analytics cookies. Our website sets no tracking cookies and self-hosts its fonts, so no data is shared with third-party font or analytics services for that purpose.

Because we use only essential cookies, no cookie-consent banner is required. You can control or clear cookies through your browser, but disabling essential cookies may prevent the Service from working.

15

Data Security

We use reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit using TLS 1.2 and 1.3, and encryption at rest using AES-256; connected-account tokens are additionally encrypted at the application layer.
  • Encrypted backups, encrypted before they leave our servers, with decryption keys held separately and offline.
  • Per-tenant data isolation enforced at the database level, and least-privilege access controls.
  • Rate limiting and a web application firewall, plus audit logging of access to data.

Please note: No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security.

If something goes wrong. If a personal data breach occurs that may harm you or affect your rights, we will notify SDAIA within 72 hours of becoming aware of it and will inform you without undue delay, in clear language, including what happened, the potential risks, and our recommendations to protect yourself.

16

Who Can Access Your Data

Access to your data is limited to authorized Priyora staff who need it to operate, support, or secure the Service.

Staff access is limited and audited: access by authorized Priyora staff to your meeting content requires a time-limited access session (up to one hour), used for support and security purposes only, and every such session is fully audited.

We never sell your data, and we never use your meeting content for advertising or to build profiles about you.

17

Children's Privacy

The Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact privacy@prinotes.com and we will delete it.

18

Changes to This Policy

We may update this Policy from time to time. Where a change involves a new processing purpose that requires your consent under the PDPL, we will ask for that consent separately before the change applies to you. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice. Your continued use of the Service after an update means you accept the revised Policy.

19

Contact Us

For privacy questions or to exercise your rights: privacy@prinotes.com

For general support: support@prinotes.com

Priyora Company (شركة برييورا) · Jeddah 23532, Kingdom of Saudi Arabia.