CantoNotes

Legal

Privacy Policy

What data CantoNotes processes, why we process it, who helps us run the service, and how to contact us about your data.

Last updated: 30 July 2026

1. Who we are

This Privacy Policy explains how Liminal AI Limited (“Liminal”, “we”, “us”, or “our”) collects, uses, and shares personal data when you use CantoNotes (the “Service”). CantoNotes is a product associated with CantoSub AI. Liminal is a company incorporated in Hong Kong.

Contact for privacy requests: support@cantonotes.com.

2. Scope

This Policy covers personal data processed in connection with the CantoNotes websites, web application, and related services. It does not cover third-party websites or apps that we do not control (for example meeting platforms or identity providers), which have their own privacy practices.

3. Personal data we collect

Depending on how you use the Service, we may process:

  • Account data: name, email address, password hash (if you use password sign-in), language preferences, and account settings.
  • Authentication data from identity providers: identifiers and profile information provided by Google or Microsoft when you choose those sign-in methods.
  • Billing data: subscription plan, credit usage, and payment-related metadata handled by our payment processor (Stripe). We do not store full card numbers on our servers.
  • Meeting and workspace content: audio or other media you upload or that meeting bots ingest, transcripts, AI notes, action items, glossary terms, project membership and roles, chat or agent messages, and related metadata (such as titles, timestamps, and bot status).
  • Calendar integration data: when you connect a supported calendar integration, event metadata needed to schedule meeting bots (subject to the scopes you authorise).
  • Usage and technical data: approximate usage of credits and features, device/browser information, IP address, and logs needed to operate, secure, and debug the Service.
  • Support communications: messages you send to us by email or through support channels.

Meeting recordings and transcripts may include personal data of people who speak in or are mentioned in a meeting. You (or your organisation) are responsible for informing participants and obtaining consents where required.

4. How we collect data

  • Directly from you when you register, configure settings, upload media, or contact us.
  • Automatically when you use the Service (sessions, logs, usage metrics).
  • From identity providers if you sign in with Google or Microsoft.
  • From integrations you enable (for example calendar or meeting-bot providers).
  • From payment processors when you purchase a plan or credits.

5. How we use personal data

We use personal data to:

  • Provide, operate, and maintain the Service (including transcription, note generation, search, retrieval, and agent features).
  • Authenticate users, manage sessions, and enforce project permissions.
  • Process payments, manage subscriptions, and track credit usage.
  • Send transactional emails (for example verification, password reset, and important service notices).
  • Monitor security, prevent abuse, and troubleshoot issues.
  • Improve the Service using aggregated or de-identified information where practical; we may also access account or content data when needed to provide support you request or to investigate abuse/security incidents.
  • Comply with legal obligations and enforce our Terms of Service.

When you connect a calendar integration, we use event metadata (such as title, time, and meeting URL) to schedule meeting bots and show upcoming meetings. Meeting audio and transcripts produced after a bot joins (or after you upload media) are processed by AI providers solely to deliver product features for your account—not to train generalized or foundational AI/ML models for CantoNotes or third parties.

We do not sell your personal data.

7. Sharing and processors

We share personal data with service providers that process it on our behalf to run the Service. Depending on features you use, this may include:

  • Cloud object storage for meeting audio and related files (Amazon Web Services S3).
  • Meeting-bot, recording ingest, and calendar-integration services (Recall.ai).
  • Speech-to-text / transcription services (ElevenLabs).
  • Large language model and embedding APIs used for meeting notes, titles, search, and the in-product agent (xAI; OpenAI).
  • Payment processing (Stripe).
  • Transactional email delivery (Resend).
  • Identity providers you choose (Google, Microsoft).
  • Infrastructure and hosting providers necessary to run the application and databases.

Calendar connection credentials and event metadata used for bot scheduling are processed by Recall.ai and CantoNotes. Meeting audio and derived transcripts/notes may be sent to ElevenLabs, xAI, and/or OpenAI to provide transcription, notes, embeddings, and agent features. We select API offerings whose terms do not permit use of that customer content to train foundational or generalized AI/ML models (except where a provider requires an explicit opt-in, which we do not enable for CantoNotes).

We may also disclose data if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with appropriate safeguards).

Collaborators you invite to projects can access User Content according to their roles. You control those invitations.

8. Google Workspace APIs and Limited Use

CantoNotes’ use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Google Workspace APIs (including Google Calendar) will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace user data—including raw, aggregated, or derived data—to create, train, or improve foundational or generalized machine learning or artificial intelligence models. We do not transfer Google Workspace user data to third parties for those training purposes.

Google Sign-In (when enabled) is used only for authentication. Google Calendar access, when you connect it, is used to read event metadata needed to schedule meeting bots. We do not request Gmail, Drive, or Google Photos access.

9. International transfers

We are based in Hong Kong. Our processors and infrastructure may process data in other countries. Where we transfer personal data internationally, we take steps appropriate to the nature of the transfer and applicable law. We do not claim that all data is stored only in Hong Kong.

10. Retention

We retain personal data for as long as your account is active and as needed to provide the Service. Meeting audio, transcripts, and related content are retained while associated with your account or projects, unless deleted earlier through product controls or a verified deletion request.

After account closure or a deletion request, we will delete or anonymise personal data within a reasonable period, except where we must retain information for legal, accounting, dispute, or security purposes (for example billing records or abuse logs).

11. Security

We use technical and organisational measures appropriate to the Service, including encryption in transit (TLS) and access controls such as project-level roles. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

12. Your rights and choices

Subject to applicable law, you may request access to, correction of, or deletion of personal data we hold about you, and you may object to or ask us to restrict certain processing. To make a request, email support@cantonotes.com from the address associated with your account. We may need to verify your identity before acting.

  • You can update certain profile and preference information in the app Settings.
  • You can disconnect supported OAuth or calendar integrations where the product provides that control.
  • You can opt out of non-essential marketing emails if we send them (transactional mail will continue).

If you are in Hong Kong, you may also have rights under the Personal Data (Privacy) Ordinance. If you believe we have not handled a request appropriately, you may contact us first; you may also have the right to complain to the Office of the Privacy Commissioner for Personal Data (PCPD) or another competent authority.

13. Cookies and similar technologies

We use cookies and similar technologies that are necessary to authenticate sessions, remember preferences (such as language), and operate the Service securely. We do not use these technologies to sell advertising profiles.

14. Children

The Service is not directed to children under 16. If you believe a child has provided personal data, contact support@cantonotes.com and we will take appropriate steps to delete it.

15. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. For material changes, we will provide notice through the Service or by email when practical.

16. Contact

Privacy questions and requests: support@cantonotes.com. Liminal AI Limited, Hong Kong.