Czytaj po polsku ↗
Please read this document carefully — so that you understand what of your data we process, for what purposes, on what basis, whom we share it with, how we store it and what rights you have in this respect.
1. Who is the controller of your personal data?
The controller of your personal data is Notilabs Prosta Spółka Akcyjna, with its registered office in Poznań (61-735), ul. Solna 3/14, KRS: 0001247730, NIP: 7831955923, registry court: Sąd Rejonowy Poznań – Nowe Miasto i Wilda w Poznaniu, VIII Wydział Gospodarczy Krajowego Rejestru Sądowego (the “Controller”, “We”).
2. How to contact us?
You can contact us by email (email address: prywatnosc@notibox.ai) or by post (address: 61-735 Poznań, ul. Solna 3/14).
3. What data do we process?
- If you visit the NotiBox website (https://notibox.ai/) – only analytics data (Vercel Analytics) is collected, allowing us to monitor site traffic, user behaviour and performance; we collect only aggregated counters - without user identification, cookies, Google Analytics, Facebook Pixel or fingerprinting.
- If you enter into an agreement with us to purchase a NotiBox or the Managed Plan service – in order to conclude, amend or terminate that agreement, as well as for settlements and payments, we process your basic data:
- consumers: first name, surname, home address, phone number, email address, delivery address, bank account number.
- persons making a purchase in connection with business activity: first name, surname, phone number, company name, its address, email address, delivery address, bank account number, NIP.
- If you use the Newsletter service - in order to deliver the Newsletter to you we process your email address.
- If, through the NotiBox, you connect to an AI model provider:
- in the Managed Plan model – to the extent necessary to enable you to use this service, we transmit the content of the communication from the NotiBox device through a gateway on the NotiBox server to the AI model provider appropriate for your plan, but it passes through our gateway only in transit - we do not store or save it, and in settlements we record only metadata: the number of tokens, the cost and the model name — without the message content. An exception to this rule concerns remote support via Tailscale (see section 3(h) of the Policy).
- in the local (BYOK) model – your data (e.g. Telegram token, API key, history and content of communication with the AI model provider) is stored locally, on your device, in an encrypted key store on the SSD. In this mode the content of your communication (including Google data) does not reach our infrastructure at all - we have no access to it and do not transmit it anywhere. The history and content of communication with the AI model provider is stored on your device for 30 days (in the settings you can extend or shorten this period or disable storage entirely). An exception to this rule concerns remote support via Tailscale (see section 3(h) of the Policy).
- If you use the text and voice assistant via Telegram – as part of device diagnostics and telemetry we process only your Telegram user identifier. Your NotiBox device communicates directly with Telegram - we do not mediate in this communication.
- If you integrate the NotiBox with your Google account – we additionally process your data to the extent described in section 16 of the Policy (in particular: a one-time Google authorization code passes through our backplane, and in the Managed Plan the content of your queries and data from your Google account is additionally transmitted by us to the AI model provider appropriate for your plan).
- If you use the NotiBox both in the local (BYOK) model and in the Managed Plan model – we may additionally process operational data characterising the way you use this service: identifiers identifying you, identifiers identifying the termination of the telecommunications network or the ICT system you use, information about the start, end and scope of each use of the service, the AI usage volume.
- If you use NotiBox remote technical support – to the extent necessary to provide you with technical assistance we may additionally, at your request and with your express consent on each occasion, connect remotely to your NotiBox via Tailscale;
- in which case we may have access to the system files of your device (but not to the encrypted store holding your keys) – whereby we will use this access solely to the extent necessary to provide you with remote support and resolve the reported technical problem,
- during such a connection we do not save or store the content of communication between your NotiBox and the AI models, the gateway does not log the content of queries,
- in the NotiBox panel you will always see the number and time of such logins,
- you can terminate such a connection at any time and disable Tailscale in the NotiBox panel,
- without your consent we can only see whether the device is powered on and connected to the network — we do not see any of your content or files.
- Remote updates (OTA) – both in the local (BYOK) model and in the Managed Plan model, your device connects daily to the NotiBox server and asks about available updates - the following are then transmitted to us: device serial number, OS version, country (determined from the IP address). If a new update is available - it downloads and installs at night between 2:00 and 5:00 (configurable). You can always roll back to the previous version.
- NotiBox diagnostic data and telemetry - both in the local (BYOK) model and in the Managed Plan model your device sends us a package of technical data – it is processed by us solely to the extent necessary to maintain the device, update it and support it. This data includes: device identifier, configuration code, software versions, status of system services, degree of disk occupancy, the result of the automatic assistant correctness test, the state of the home automation module if enabled, remote update status, information about backups, masked fragments of API keys (the first 8 and last 4 characters - we never receive the full value) - solely to determine whether a key is set and whether it has changed, operational data: the number of messages in the last 24 hours, the number of tokens broken down by model, identifiers of accounts paired with the assistant (e.g. the Telegram user identifier) and the date of last activity. This data does not include the content of your communication with AI or data retrieved from your accounts.
- Security alerts – both in the local (BYOK) model and in the Managed Plan model your device may automatically send us messages about potential threats, anomalies or security-related incidents – they are processed by us solely to the extent necessary for your security and the security of the system.
4. Where do we get your data from?
The data we process:
- you provided to us yourself (by email, by phone or on the NotiBox website),
- was obtained by us from the NotiBox website,
- was obtained by us from the NotiBox device.
5. Legal basis and purpose of processing your data
The GDPR provides for several legal bases for processing personal data - in the case of purchasing a NotiBox or using our services one of the following will apply:
- where it is necessary to conclude an agreement concerning the NotiBox, the Managed Plan service or the Newsletter service, or to perform that agreement, e.g.:
- ensuring the functionality of the NotiBox,
- ensuring additional functionalities covered by the Managed Plan,
- providing software updates and technical support,
- exercising warranty rights,
- handling complaints,
- contact on technical and settlement matters.
- where it is necessary for us to fulfil obligations arising from legal provisions, e.g.: those arising from the Payment Services Act, the Act on Counteracting Money Laundering and Financing of Terrorism, tax acts, the Accounting Act, the Act on Providing Services by Electronic Means, the Consumer Rights Act, the Act on the National Cybersecurity System.
- where it is necessary to pursue our legitimate interests, including:
- improving our services and adapting them to the needs and convenience of users,
- establishing, pursuing and defending claims,
- ensuring the security of services, monitoring, preventing and detecting possible fraud or abuse,
- enforcing compliance with the NotiBox Sales Terms,
- conducting research and analyses, among others in terms of the functionality of the IT system and improving the operation of services,
- keeping statistics.
- where you give your consent to it: with respect to data for which we have no other basis for processing, we may ask you for consent to their processing. Giving such consent is entirely voluntary. We will always ask you for it explicitly. You may withhold it; you may also withdraw consent once given at any time by contacting us by email (email address: prywatnosc@notibox.ai).
6. Do you have to provide us with your personal data?
Providing your personal data is voluntary.
In most cases, providing the data we ask you for is necessary to conclude an agreement between us, to perform it or to fulfil our legal obligations, and failure to provide it will prevent us from achieving these purposes (e.g. if you do not provide us with your email we will not be able to send you the Newsletter).
In those few cases where the basis for processing is solely your consent, giving it is entirely voluntary – and withholding or withdrawing it is not a condition for concluding an agreement concerning the NotiBox or for using the Managed Plan service.
7. How long do we process your personal data?
We process your data for the duration of the agreement concerning the NotiBox, the Newsletter service or the Managed Plan service, and also after their termination for the purposes of:
- pursuing claims in connection with the performance of the agreement and defending against such claims – until the claims lapse or become time-barred (usually 3 years),
- fulfilling obligations arising from legal provisions - for as long as these provisions require (usually 5 years).
If the basis for processing personal data is solely your consent (e.g. to receive the Newsletter), we will process your data until you withdraw it.
Technical data concerning your device: telemetry and diagnostic data, security alerts, remote support logs (Tailscale) – we store for 12 months.
The history and content of communication with the AI model provider is stored on your device for 30 days (in the settings you can extend or shorten this period or disable storage entirely).
8. When and to whom do we share your data?
Without your consent we do not share your data with third parties, except where:
- We are required to do so by law (e.g. requiring us to provide certain data to law enforcement authorities, regulatory bodies and other public administration authorities).
- Such disclosure is necessary in order to perform the agreement, our legitimate interests or obligations arising from legal provisions. The recipients of your data may be:
- banks or payment service providers (data necessary to carry out the payment service),
- other entities cooperating with us to perform the agreement (e.g. entities providing hosting, data storage, email delivery, courier companies),
- auditors and statutory auditors, legal advisors, tax advisors, accountants,
- entities providing us with IT support and cybersecurity services, IT system providers, telecommunications services,
- other entities processing your personal data on our behalf under personal data processing entrustment agreements (so-called processors),
- if you use the Managed Plan service - we transmit the content of communication from your device to the AI model providers appropriate for your plan (you will find more details in section 14 of the Policy),
- if you use the text and voice assistant via Telegram – your data is transmitted between Telegram and the NotiBox (you will find more details in section 15 of the Policy),
- if you integrate your NotiBox with your Google account – data from your Google account is transmitted to your NotiBox device and then to the AI model providers (you will find more details in section 16 of the Policy).
The third parties to whom we share your personal data have a limited (by law or contractually) ability to process your personal data. With respect to all such entities, we make sure that they are subject to confidentiality and security obligations consistent with this Privacy Policy and legal provisions.
Apart from the situations indicated in this Privacy Policy, we will not share your personal data with any other entities without prior notice to you, and in a situation where such sharing would require obtaining your consent – without such consent.
9. Entrustment of data processing
We cooperate with external entities (so-called processors) that provide us with services related to the NotiBox and, to the extent necessary to perform these services, process your personal data on our behalf. They are entitled to process personal data solely for specified purposes and in accordance with our instructions (this is set out in personal data processing entrustment agreements).
Our main processors are:
- Google LLC, USA (language model provider in the Managed Plan model)
- Anthropic, USA (language model provider in the Managed Plan model)
- OpenAI, USA (language model provider in the Managed Plan model)
- xAI, USA (language model provider in the Managed Plan model)
- Vercel, Inc. (website hosting)
- Hetzner Online GmbH, Finland/Germany (service panel hosting)
- Cloudflare, Inc., USA (store traffic protection)
- Resend, USA (sending email notifications)
- Tailscale Inc., USA (remote support).
10. Do we transfer your data outside the EEA?
Our service panel (vendor.notibox.ai) is located on our own server at Hetzner Online GmbH in Helsinki (Finland, EU), while many of our processors (see section 9 of the Policy) have their registered offices in the United States, therefore your data may be transferred outside the European Economic Area (EEA) - to the USA.
In the case of Google LLC, Vercel Inc., Cloudflare, Inc., the transfer takes place on the basis of an implementing decision of the European Commission stating an adequate level of data protection issued pursuant to Article 46(1) of the GDPR (EU-US Data Privacy Framework) — these entities hold an active certification.
Details of these safeguards can be found here:
In the case of Anthropic, OpenAI, xAI, Resend and Tailscale the basis for the transfer is the standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR, forming part of the data processing entrustment agreements concluded with these entities.
Details of these safeguards can be found here:
To obtain copies of these safeguards or more information about where they are made available, send an email to: prywatnosc@notibox.ai
11. Do we apply automated decision-making, including profiling?
We do not apply profiling or any other automated decision-making.
12. How do we protect your data?
We care about the security of the personal data we process. We apply technical and organisational security measures intended to ensure confidentiality, protection against unauthorised or unlawful processing and against accidental loss, destruction or damage to your data.
Here are the basic protective measures:
- your keys and tokens are stored separately, in an encrypted key store on the SSD of your device;
- your Google token never leaves your device; the authorization code is one-time and deleted immediately after being read;
- connections in transit are encrypted (TLS);
- the Managed Plan gateway does not log the content of your queries;
- remote support takes place solely via Tailscale (with access control lists, each time with the user’s express consent, the number and time of such connections is visible in your user panel);
- we apply control and restrictions on our personnel’s access to data.
13. What rights do you have regarding the processed data?
You have certain rights related to the processing of your personal data, and we, as the controller, are responsible for exercising them in accordance with the GDPR.
If you have questions about your rights or would like to exercise them, contact us by email (email address: prywatnosc@notibox.ai).
Here are the rights you have in connection with the processing of your personal data:
- Right of access to personal data. You have the right to access your data, obtain a copy of it and obtain from us information concerning your data that we process.
- Right to update and rectify personal data. You have the right to request that your data be updated or rectified if it is out of date, incorrect or incomplete.
- Right to erasure of personal data. In some situations you have the right to request that we erase your data (e.g. if it is no longer necessary for the purposes for which it was collected or if we processed it on the basis of your consent, which you have withdrawn).
- Right to withdraw consent. If we process your data on the basis of your consent, you can withdraw it at any time. We will then cease processing this data, unless we have another legal basis for its further processing. However, withdrawing consent will not affect the lawfulness of the processing we carried out on the basis of your consent before its withdrawal.
- Right to restrict the processing of personal data. In some situations you have the right to request that we restrict the processing of your data.
- Right to object to the processing of personal data. You have the right, on grounds relating to your particular situation, to object to our processing of your personal data in the exercise of our legitimate interests.
- Right to data portability. The right to data portability applies to data that is processed by automated means on the basis of your consent or an agreement.
- Right not to be subject to automated decision-making. Automated decision-making (including profiling) consists in an electronic system using personal data to make a decision without human intervention. You have the right not to be subject to such a process if such actions produce legal effects concerning you or otherwise significantly affect you. We do not apply such practices.
14. Third-party AI model providers
NotiBox uses external language models to answer your questions and commands and to act on your data. The model provider may vary, e.g. Google Gemini, Anthropic Claude, OpenAI or xAI.
In the local (BYOK) model you choose the AI provider(s) yourself.
In the Managed Plan model you can use the AI model provider appropriate for your plan (you will find more details in section 3(d) of the Policy). In such a case the AI model provider processes your personal data on our behalf under a processing entrustment agreement.
In the Managed Plan we use paid AI models that do not use the data transmitted to them to train models.
To obtain more information, review the privacy policy of the given provider. Here you will find the privacy policies of the main AI providers:
15. Telegram
The NotiBox text and voice assistant feature uses the Telegram messenger. During this communication:
- your queries and commands are sent via Telegram to your NotiBox,
- then from the NotiBox they are directed either directly to the AI model provider chosen by you (local BYOK model) or, through our mediation, to the AI model provider appropriate for your Plan (Managed Plan model),
- the response comes back the same way.
If you decide to use the AI assistant via Telegram, your NotiBox device will communicate directly with Telegram - we do not mediate in this communication. Telegram is a separate personal data controller and processes it in accordance with its own policy - NotiBox has no influence over it. To obtain more information, review Telegram’s privacy policy: https://telegram.org/privacy
16. Integration with a Google account
NotiBox may — optionally and only with your consent — connect to your Google account in order to act as an assistant on data from your Google account (Gmail email, Drive, Calendar, Contacts, Sheets and Docs). Integration with a Google account is an additional option that you enable yourself in the device panel and can disable at any time.
How to connect NotiBox with a Google account
You connect your Google account through the standard Google consent screen (OAuth). You authorize exactly those scopes that you see on the consent screen.
- After your consent, Google returns a one-time, short-lived authorization code. Our backplane (vendor.notibox.ai) mediates solely in transmitting this code to your NotiBox device. The code is one-time and deleted immediately after being read.
- The exchange of the code for a token (including a refresh token) takes place locally on your device. The token goes to an encrypted key store (keychain) that is separate for each user on the NotiBox SSD.
- The token never reaches our servers. We do not have a copy of your Google token and cannot log in to your account from our infrastructure.
How and why NotiBox uses Google data
Data from Google APIs is used solely to carry out the AI assistant functions visible to you: reading and summarising emails, sending and organising mail, managing events, working on documents and sheets, addressing messages by contacts. We do not use it for advertising, profiling or training models.
How NotiBox stores Google data
- The access token and refresh token — locally on your device, in an encrypted key store (keychain) on the SSD (not on our server).
- Content (emails, documents) — is processed on the fly. We do not create a copy of your mailbox or Drive on our side.
Transfer of Google account data to AI models
When the assistant summarises or analyses the content of your Google data (e.g. an email, document, event), that content is sent to the AI model in order to carry out the function you request. The same two models of cooperation with AI apply as in standard operation - the local (BYOK) model and the Managed Plan model (you will find more details in section 3(d) of the Policy).
In both models the chosen AI provider processes the content in accordance with the rules set out in section 14 of the Policy. We only transmit the data (and only in the Managed Plan model) - apart from that transit we do not sell your Google account data and do not transfer it to other entities, except in the situations described in the Limited Use rules below.
How to revoke access and delete data
- In the NotiBox panel: /integrations → “Disconnect Google account”. The token is removed from the device’s key store (keychain).
- On Google’s side: in the account settings (myaccount.google.com/permissions) you can revoke NotiBox’s access to the Google account at any time.
- Disconnecting stops any further reads and actions on your Google account data.
Permission scopes
We ask only for the permission scopes needed for the assistant to function. Some of them are classified by Google as sensitive or restricted (RESTRICTED) — they require Google verification and are subject to the Limited Use rules described below.
| Scope | Classification | Why we use it |
|---|
gmail.modify | RESTRICTED | Reading and summarising emails, sending replies, organising the mailbox (labels, archiving) at your command. |
gmail.settings.basic | RESTRICTED | Reading and changing basic mail settings (e.g. signature, autoresponder) when you ask for it. |
gmail.settings.sharing | RESTRICTED | Configuring mail forwarding and delegation when you ask for it. |
drive | RESTRICTED (full) | Reading existing files and creating and saving new documents on your Drive. |
calendar | Sensitive | Creating, reading and managing events in your calendar. |
contacts, contacts.other.readonly, directory.readonly | Sensitive | Access to contacts so the assistant can address emails and recognise people. |
spreadsheets (+ drive) | Sensitive | Reading and editing Google Sheets. |
documents (+ drive) | Sensitive | Reading and editing Google Docs. |
openid, email, userinfo.email | Basic | Identification of the account you are connecting. |
We ask for the full drive and gmail.modify scope deliberately: the assistant is meant not only to read, but also to create and organise content at your command. The scope of actual access always corresponds to what you approve on the Google consent screen.
17. Limited Use — compliance with Google policy
NotiBox’s use of information received from Google APIs and its transfer to any other application is carried out in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means four commitments:
- We use data from Google APIs solely to provide or improve user-visible features in the application (assistant: reading and summarising emails, managing the calendar, working on documents, etc.).
- We do not transfer data to third parties, except: (a) where it is necessary to provide or improve NotiBox features and with your consent, (b) for security reasons, (c) to comply with legal requirements, (d) as part of a merger or acquisition, after prior notice to the user.
- We do not use data from Google APIs to display ads (including personalised ads, remarketing or advertising profiling).
- We do not allow humans (e.g. our employees or those of our service providers) to read your data, unless: (a) you have given express consent to read specific data, (b) it is necessary for security reasons (e.g. investigating abuse), (c) it is required by law, or (d) the data is aggregated and anonymised and serves internal operations.
The above commitments are consistent with how NotiBox actually operates. The transfer of content to the chosen AI provider (commitment no. 2) takes place solely in order to carry out a function visible to you that you yourself trigger. Commitment no. 4 — no reading of your data by humans — concerns the NotiBox infrastructure: in BYOK mode the content of your communication with the AI model provider does not reach it at all, and in the Managed Plan the gateway does not log content, so personnel and support have no access to it. An exception to this rule concerns remote support via Tailscale (see section 3(h) of the Policy).
18. Questions, concerns and complaints
If you have questions, reservations or complaints regarding our Privacy Policy or the way we process your data, or would like to exercise the rights available to you – send an email to: prywatnosc@notibox.ai
You also have the right to lodge a complaint with the supervisory authority dealing with the protection of personal data: the President of the Personal Data Protection Office (https://uodo.gov.pl/pl).
If you consider that your rights have been infringed, you can pursue them before a court.
19. Changes to this Policy
Current version: 1.0 dated 20 July 2026. If we change something material — we will notify you about it 30 days before the change takes effect by sending an email to the address you provided.
The Polish version of the Privacy Policy is the binding version. The English version (
wersja polska / Polish version) is for informational purposes only — in case of any discrepancy, the Polish version prevails.