Legal
Privacy Policy
What data CantoNotes processes, why we process it, who helps us run the service, and how to contact us about your data.
Last updated: 30 July 2026
1. Who we are
This Privacy Policy explains how Liminal AI Limited (“Liminal”, “we”, “us”, or “our”) collects, uses, and shares personal data when you use CantoNotes (the “Service”). CantoNotes is a product associated with CantoSub AI. Liminal is a company incorporated in Hong Kong.
Contact for privacy requests: support@cantonotes.com.
2. Scope
This Policy covers personal data processed in connection with the CantoNotes websites, web application, and related services. It does not cover third-party websites or apps that we do not control (for example meeting platforms or identity providers), which have their own privacy practices.
3. Personal data we collect
Depending on how you use the Service, we may process:
- Account data: name, email address, password hash (if you use password sign-in), language preferences, and account settings.
- Authentication data from identity providers: identifiers and profile information provided by Google or Microsoft when you choose those sign-in methods.
- Billing data: subscription plan, credit usage, and payment-related metadata handled by our payment processor (Stripe). We do not store full card numbers on our servers.
- Meeting and workspace content: audio or other media you upload or that meeting bots ingest, transcripts, AI notes, action items, glossary terms, project membership and roles, chat or agent messages, and related metadata (such as titles, timestamps, and bot status).
- Calendar integration data: when you connect a supported calendar integration, event metadata needed to schedule meeting bots (subject to the scopes you authorise).
- Usage and technical data: approximate usage of credits and features, device/browser information, IP address, and logs needed to operate, secure, and debug the Service.
- Support communications: messages you send to us by email or through support channels.
Meeting recordings and transcripts may include personal data of people who speak in or are mentioned in a meeting. You (or your organisation) are responsible for informing participants and obtaining consents where required.
4. How we collect data
- Directly from you when you register, configure settings, upload media, or contact us.
- Automatically when you use the Service (sessions, logs, usage metrics).
- From identity providers if you sign in with Google or Microsoft.
- From integrations you enable (for example calendar or meeting-bot providers).
- From payment processors when you purchase a plan or credits.
5. How we use personal data
We use personal data to:
- Provide, operate, and maintain the Service (including transcription, note generation, search, retrieval, and agent features).
- Authenticate users, manage sessions, and enforce project permissions.
- Process payments, manage subscriptions, and track credit usage.
- Send transactional emails (for example verification, password reset, and important service notices).
- Monitor security, prevent abuse, and troubleshoot issues.
- Improve the Service using aggregated or de-identified information where practical; we may also access account or content data when needed to provide support you request or to investigate abuse/security incidents.
- Comply with legal obligations and enforce our Terms of Service.
When you connect a calendar integration, we use event metadata (such as title, time, and meeting URL) to schedule meeting bots and show upcoming meetings. Meeting audio and transcripts produced after a bot joins (or after you upload media) are processed by AI providers solely to deliver product features for your account—not to train generalized or foundational AI/ML models for CantoNotes or third parties.
We do not sell your personal data.
6. Why we process personal data
We process personal data as needed to perform our contract with you, to operate a legitimate business (including securing and improving the Service), where you have given consent (for example certain optional integrations), and where required to meet legal obligations. If you are in a jurisdiction with additional privacy laws, we will handle requests under those laws to the extent they apply to us.
8. Google Workspace APIs and Limited Use
CantoNotes’ use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Google Workspace APIs (including Google Calendar) will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace user data—including raw, aggregated, or derived data—to create, train, or improve foundational or generalized machine learning or artificial intelligence models. We do not transfer Google Workspace user data to third parties for those training purposes.
Google Sign-In (when enabled) is used only for authentication. Google Calendar access, when you connect it, is used to read event metadata needed to schedule meeting bots. We do not request Gmail, Drive, or Google Photos access.
9. International transfers
We are based in Hong Kong. Our processors and infrastructure may process data in other countries. Where we transfer personal data internationally, we take steps appropriate to the nature of the transfer and applicable law. We do not claim that all data is stored only in Hong Kong.
10. Retention
We retain personal data for as long as your account is active and as needed to provide the Service. Meeting audio, transcripts, and related content are retained while associated with your account or projects, unless deleted earlier through product controls or a verified deletion request.
After account closure or a deletion request, we will delete or anonymise personal data within a reasonable period, except where we must retain information for legal, accounting, dispute, or security purposes (for example billing records or abuse logs).
11. Security
We use technical and organisational measures appropriate to the Service, including encryption in transit (TLS) and access controls such as project-level roles. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Your rights and choices
Subject to applicable law, you may request access to, correction of, or deletion of personal data we hold about you, and you may object to or ask us to restrict certain processing. To make a request, email support@cantonotes.com from the address associated with your account. We may need to verify your identity before acting.
- You can update certain profile and preference information in the app Settings.
- You can disconnect supported OAuth or calendar integrations where the product provides that control.
- You can opt out of non-essential marketing emails if we send them (transactional mail will continue).
If you are in Hong Kong, you may also have rights under the Personal Data (Privacy) Ordinance. If you believe we have not handled a request appropriately, you may contact us first; you may also have the right to complain to the Office of the Privacy Commissioner for Personal Data (PCPD) or another competent authority.
14. Children
The Service is not directed to children under 16. If you believe a child has provided personal data, contact support@cantonotes.com and we will take appropriate steps to delete it.
15. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. For material changes, we will provide notice through the Service or by email when practical.
16. Contact
Privacy questions and requests: support@cantonotes.com. Liminal AI Limited, Hong Kong.
