Privacy Policy
Effective date: August 17, 2026
Contact: Jacob.Metcalf@appomatix.com
Warp Notes ("the app") is a voice-note organizer made by Appomatix โ personal by default, and shared with your team when you use Warp Notes Business. This policy explains what we collect, why, and what happens to it.
What we collect
- Account information. Your email address (email sign-up) or the identity provided by Sign in with Apple / Google Sign-In. Used to authenticate you and keep your notes private to you. If you join a shared workspace, your email and display name are visible to that workspace's members.
- Voice recordings. Audio you record in the app is uploaded to our servers so it can be transcribed and organized.
- Transcripts and derived data. Transcriptions of your recordings, plus AI-generated titles, summaries, action items, follow-ups/reminders, and the categories and groups your notes are filed into.
- Search queries. Questions you type into Search are processed to retrieve and answer from your own notes. Your recent-searches list is stored only on your device.
- Calendar linkage. If you turn on calendar sync, the app creates events in the device calendar you choose and stores only the event identifiers. Your calendar contents are never uploaded to our servers.
- People you mention. When you mention someone by name in a note, the app builds a contact card for them inside that category โ their name, plus any company, role, phone number, email address, website, or street address you actually said. This information about other people is derived only from your own recordings and can be edited or deleted at any time. In a personal category it is private to your account; in a shared workspace it is visible to the workspace's members (see below).
- Contacts you import. You can add a person by picking them from your phone's contacts ("Import from Contacts"). Only the single card you pick is received and stored โ the app never reads your address book in the background or in bulk. On iOS the picker runs outside the app entirely, which is why no contacts permission prompt ever appears; on Android the standard contacts permission is requested at the moment you import.
- Place lookups. When you tap a place the AI spotted in a note, we look it up with Google's Places service to find the real address. To keep results local to you, the lookup is biased using your home base (a city/state you can optionally set in Settings) โ or, if you haven't set one, an approximate city-level location derived from your IP address via the ipapi.co service. We never access your device's GPS location.
We do not access your device's GPS location, browsing history, or advertising identifiers, and we never read your contacts except for the single card you deliberately import (above). There are no ads and no analytics brokers in the app.
Shared workspaces (Warp Notes Business)
Warp Notes Business adds shared workspaces โ categories a team records into together. Sharing only ever happens in workspaces you deliberately create or accept an invitation to join. Inside a shared workspace:
- Notes you record into it are visible to its members โ the audio, transcript, and AI-derived data (titles, summaries, extracted details). Your personal categories are unaffected and remain private to you.
- Team records are shared. Companies, contact cards, and places created in the workspace โ whether typed or extracted from members' notes โ are visible to and editable by the workspace's members.
- Your identity is visible. Members can see your email address and display name (used for things like assigning accounts by name).
- Uncertain filings stay private. When the AI isn't confident a note belongs in a shared workspace, the note stays private to you until you confirm where it files.
- Territories are organization, not privacy. Territory assignments filter what members see day-to-day, but they are a viewing convenience โ every member of a workspace can access the workspace's data regardless of territory.
- The workspace owner administers it โ membership, paid seats, territories, and territory auto-assignment rules. Rule text an owner writes is processed by OpenAI the same way note text is.
- If you leave a workspace (or are removed), the workspace keeps the notes and records you contributed to it โ like leaving a shared drive. Your personal categories always remain yours alone.
How your data is processed
- Hosting & storage: Your data is stored with Supabase (database, file storage, authentication). Every record is protected by row-level security so it is only readable by your account โ and, for shared workspaces, by the workspace's members.
- AI processing: Audio is transcribed and note text is summarized, organized, and answered using OpenAI APIs. Per OpenAI's API policy, data sent via the API is not used to train their models.
- Place resolution: When you tap a detected place, its name is sent to Google's Places API to find matching real-world locations. If you haven't set a home base, your IP address is sent to ipapi.co once per lookup to estimate your city so results are nearby. Neither request includes your notes.
- Payments: Subscriptions โ including per-seat Warp Notes Business subscriptions โ are handled by Stripe. Checkout opens in your browser and your card details go straight to Stripe โ we never see or store them. We keep only your subscription status, seat assignments, and Stripe's customer and subscription identifiers, so the app knows what you and your team are entitled to.
What we never do
- We never sell your data.
- We never share your notes with third parties beyond the processors listed above. The only people who ever see your notes are you and the members of shared workspaces you deliberately record into.
- We never use your notes to train AI models.
Retention & deletion
Your data is kept until you delete it. You can delete individual notes, groups, or categories at any time (audio files are removed with them). You can permanently delete your entire account and all data in the app: Settings โ Delete account & all data. Deletion is immediate and irreversible. Calendar events previously added to your own device calendar remain on your device until you remove them.
Shared workspaces are the one exception. Records you contributed to a workspace someone else owns โ companies, notes, and contact cards inside that workspace โ remain with the workspace after you delete your account, the same as if you had simply left it. They are business records belonging to that organization, and removing them would erase the shared history other people rely on. Those records keep your name as text so colleagues can see who added them, but they are no longer connected to any account: your login, your personal categories, your recordings, your reminders and your billing details are all destroyed, and nothing that remains can be used to identify or contact you through Warp Notes.
If you want records you contributed to a shared workspace removed as well, ask the workspace owner โ they can delete them directly โ or contact us at the address below.
Security
Data is encrypted in transit (HTTPS/TLS). Access is scoped per-account โ and per-workspace-membership for shared workspaces โ via row-level security. Server-side API keys are never shipped in the app.
Children
Warp Notes is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes materially, we'll update this page and the effective date above.