Privacy Policy

Last updated July 6, 2026

This Privacy Policy explains how Notch ("Notch", "we", "us", or "our") collects, uses, shares, and protects information in connection with notch.build, the Notch application, our free online tools, and any related products and services (together, the "Service"). Notch is operated from Ontario, Canada. By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

1. Scope and our role

This policy applies to visitors of our websites, users of the Notch application, people who use our free tools, and recipients of documents shared through the Service. Our roles differ depending on the data:

  • Workspace content. When you or your organization upload and manage content within a workspace (drawings, markups, measurements, comments, chat messages, and files), the workspace owner — for example, your employer or the company that created the workspace — decides how that content is used. The workspace owner is the data controller of that content; Notch processes it on the workspace owner's behalf as a processor/service provider under our customer terms. If you have questions about content in a workspace you belong to, contact the workspace owner first.
  • Everything else. For our websites, marketing, free tools, account registration, billing, support, and product analytics, Notch is the data controller and this policy applies directly.

2. What is "personal information"?

"Personal information" (or "personal data") means information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual. It does not include anonymized or aggregated data that can no longer reasonably be associated with a specific person; we may use such de-identified data for any lawful purpose and commit to not re-identifying it.

3. Information we collect

Information you provide to us:

  • Account and profile data — your name, email address, password (stored only in hashed form), avatar, job details you choose to add, and workspace or company name.
  • Single sign-on data — if you sign in with Google or Microsoft, we receive basic profile details from that provider (such as your name, email address, and profile picture). We never receive your password for those services.
  • Workspace content — the drawings and PDF sets you upload and everything you create on them: markups, measurements and takeoffs, calibration settings, layers, stamps, comments and chat messages, document names and organization, and edit history.
  • Billing data — when you purchase a subscription, our payment processor (Stripe) collects your payment card details directly; we never see or store full card numbers. We keep subscription status, seat counts, plan details, billing contact information, and invoice history.
  • Communications — messages you send us through contact or feedback forms, support requests, and survey responses.
  • Free-tool and marketing submissions — if you use our free PDF tools, we ask for an email address before you download your result, and we record which tool you used. The files you process with our free tools are handled entirely in your browser and are never uploaded to our servers.
  • Share-link guest data — if you access a document through a share link and choose to identify yourself (for example, to receive notifications), we collect the details you provide, such as your name and email address.

Information collected automatically:

  • Device and connection data — IP address, browser type and version, operating system, screen size, language, and referring pages.
  • Usage data — pages viewed, features used, actions taken in the app (for example, which tools are used, not the content of your drawings), session duration, and error and performance diagnostics.
  • Log data — server logs recording requests to the Service, including timestamps, IP addresses, and status codes, used for security, debugging, and abuse prevention.

Information from third parties: limited data from our service providers, such as subscription and payment status from Stripe, profile details from your chosen sign-in provider, email delivery and engagement status from our email provider, and aggregate campaign performance data from advertising platforms.

4. Cookies, analytics, and advertising

We use the following categories of cookies and similar technologies:

  • Strictly necessary — authentication and session cookies that keep you signed in and secure. These cannot be switched off without breaking the Service.
  • Product analytics — we use PostHog to understand how the application is used (feature adoption, funnels, errors) so we can improve it. Analytics events describe actions (for example, "markup created"), not the content of your drawings.
  • Marketing-site analytics and advertising — on our public marketing pages (not inside the application), we may use Google Analytics and the Meta (Facebook) Pixel. These providers may set cookies and receive your IP address and page-visit information.
  • Conversion measurement — we may send Meta a server-side event when a conversion occurs (for example, that you downloaded a free tool, completed sign-up, started a trial, or made a purchase), so we can measure which ads work. Some of these milestones happen inside the application. The event includes your IP address and browser user-agent, your email address, name, and our internal account identifier — all of which are hashed before sending, except the IP address and user-agent, which Meta requires in plain form — and, if you arrived from one of our ads, the advertising identifiers from that click. It never includes your drawings or any workspace content.

You can control cookies through your browser settings; disabling some cookies may affect how the Service works. Where required by law, we honor opt-out preference signals such as Global Privacy Control (GPC) as a valid request to opt out of targeted advertising or "sharing". Because there is no industry standard for older "Do Not Track" signals, we do not respond to DNT headers, but we do honor GPC where the law requires it.

5. How we use information

We use the information we collect to:

  • provide, maintain, and operate the Service, including hosting your content, syncing your work, and rendering your drawings;
  • authenticate users and enforce workspace access controls;
  • process subscriptions, seats, invoices, and payments;
  • provide customer support and respond to your questions and requests;
  • send transactional messages (such as workspace invitations, welcome emails, billing notices, and security alerts);
  • send marketing communications about Notch where permitted by applicable law (including Canada's anti-spam legislation, CASL) — every marketing message includes an unsubscribe mechanism, and you can opt out at any time via that link or your settings;
  • understand how the Service is used and improve its features, performance, and design;
  • power AI-assisted features you invoke (see Section 6);
  • measure and improve our marketing on our public websites;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

Legal bases (EEA/UK/Switzerland). Where the GDPR or similar laws apply, we process personal information on these bases: performance of a contract (providing the Service you signed up for); legitimate interests (securing and improving the Service, preventing abuse, and marketing our products, balanced against your rights); consent (where required, for example for certain cookies or marketing — you may withdraw consent at any time); and legal obligation (tax, accounting, and lawful requests).

6. AI-assisted features

Some features of Notch use large language models and other AI systems provided by third parties (currently Anthropic and Google). When you use an AI-assisted feature, the relevant content — for example, a prompt you type or the portion of a document the feature operates on — is sent to the AI provider to generate the result. We use these providers under agreements that restrict their use of your content to providing the service to us, and we do not permit them to use your content to train their general-purpose models. AI features are optional: they run only when you invoke them, and AI output may be inaccurate — always verify it before relying on it.

7. How we share information

We do not sell your personal information, and we do not share workspace content with advertisers. We share personal information only as described below:

  • Service providers (subprocessors). We use trusted vendors to run Notch, under contracts that limit their use of your information to providing services to us. They fall into these categories: cloud infrastructure — database, authentication, file storage, hosting, background jobs, caching, and content delivery (such as Supabase, Vercel, and Upstash); payment processing (such as Stripe); product analytics (such as PostHog); email and communications delivery (such as Loops); AI model providers that power AI features (such as Anthropic and Google); and document processing services that convert file formats you upload (for example, converting an Office or CAD file to PDF). Vendors within these categories may change as we improve the product; processing stays limited to providing the service. You can request the current vendor list any time at team@notch.build.
  • Within your workspace. Your profile details (name, email, avatar) and the content you create are visible to other members of your workspace as needed to collaborate. Workspace admins can see member and activity information for their workspace.
  • Via share links. If you or a workspace member creates a share link, anyone who has that link can view the shared document and its markups without signing in. Manage and revoke share links in the app.
  • Advertising measurement. As described in Section 4, our public marketing pages may transmit page-visit data to Google and Meta, and we may send Meta conversion events — including ones for milestones reached inside the application, such as starting a trial. Under some U.S. state laws this may be considered "sharing" for cross-context behavioral advertising; you can opt out as described in Sections 4 and 12. We never use workspace content for advertising.
  • Corporate transactions. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of the transaction, subject to this policy or an equally protective one.
  • Legal and safety. Where required by law, subpoena, or other legal process, or where necessary to protect the rights, property, or safety of Notch, our users, or the public, including to enforce our terms and prevent fraud or abuse. Where lawful and practicable, we will notify affected customers before disclosing their data in response to a government request.
  • With your direction or consent — for example, when you connect a third-party integration or ask us to share something.

8. Data retention

We retain personal information for as long as your account is active or as needed to provide the Service, and afterwards as needed to comply with legal obligations (for example, tax and accounting rules), resolve disputes, and enforce our agreements. In general:

  • Workspace content is retained while the workspace is active. Content you delete in the app is first soft-deleted (and recoverable) and then permanently removed from our active systems in the ordinary course; residual copies are removed from encrypted backups on a rolling schedule.
  • Account data is deleted or anonymized within a reasonable period after a verified deletion request or account closure, except where retention is required by law.
  • Server logs and analytics data are retained for shorter operational periods appropriate to their purpose.
  • Billing records are retained as required by tax and financial regulations.

9. Security

We use physical, technical, and administrative safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, database-level tenant isolation (row-level security enforced in the database itself), least-privilege access controls, and audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work continuously to protect your data and will notify you and the relevant authorities of a data breach where the law requires it. See our Security page for more detail, and report suspected vulnerabilities to team@notch.build.

10. International data transfers

We are based in Ontario, Canada, and may process and store information in Canada, the United States, and other countries where we or our service providers operate — jurisdictions whose data-protection laws may differ from those where you live, and where information may be accessible to local authorities under local law. Where we transfer personal information out of the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement, as applicable), adequacy decisions, or other lawful transfer mechanisms.

11. Your choices and controls

  • Account information — review and update your profile in your account settings.
  • Marketing email — opt out via the unsubscribe link in any marketing message. We will still send transactional messages (invitations, billing, security) necessary to operate the Service.
  • Cookies and advertising — use your browser settings and GPC as described in Section 4.
  • Workspace content — content in a workspace is controlled by the workspace owner. Contact the workspace owner to exercise choices over that content; we will support them in responding, and will refer requests we receive directly to them where appropriate.
  • Export and deletion — you can export your content from the app and request deletion of your account and data at any time by emailing team@notch.build.

12. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal information: to access it (including in a portable format), to correct inaccuracies, to delete it, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to opt out of targeted advertising, "sales", or "sharing" and of profiling that produces legal or similarly significant effects.

Canada: we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. You may request access to and correction of your personal information and withdraw consent (subject to legal or contractual restrictions and reasonable notice). If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.

U.S. state residents (including California, Colorado, Connecticut, Texas, Utah, Virginia, and other states with comprehensive privacy laws): you may exercise the rights above, and you have the right not to receive discriminatory treatment for doing so. We do not sell personal information, and we do not knowingly collect or sell the personal information of anyone under 16. As described in Sections 4 and 7, limited advertising-measurement disclosures on our marketing site may qualify as "sharing" under California law; opt out via GPC or by emailing us. For California residents, the categories of personal information we collect are described in Section 3 (they map to identifiers; commercial information; internet or other electronic network activity; professional information; and inferences), the purposes in Section 5, and the recipients in Section 7. If we decline a request, you may appeal by replying to our decision; where applicable you may also use an authorized agent to submit requests.

EEA, UK, and Switzerland: you may lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.

To exercise any right, email team@notch.build from the address associated with your account (or provide information sufficient for us to verify your identity). We respond within the time required by applicable law. Note that for workspace content we act as a processor and may need to route your request to the workspace owner.

13. Children's privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children under 16; if you believe a child has provided us personal information, contact us and we will delete it.

14. Third-party links and services

The Service may link to or integrate with third-party sites and services (for example, sign-in providers or cloud-storage services you choose to import from). Their handling of your information is governed by their own privacy policies, not this one. We encourage you to review those policies.

15. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. We will revise the "last updated" date above and, for material changes, provide additional notice (such as by email or an in-app notice) before the changes take effect. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

16. Contact us

Questions, concerns, or requests about privacy? Email team@notch.build and we will get back to you promptly.