noodle

Privacy Policy

Last updated: August 1, 2026

The short version

  • Your audio never leaves your phone. Noodle transcribes it on the device itself — we never receive it, and we never store it.
  • Your transcripts and summaries live on your device and sync through your own iCloud account. They aren't stored on our servers.
  • To generate summaries and nudges, Noodle sends transcript text to a third-party AI provider and gets a response back. Nothing about that exchange is persisted, except temporarily to mitigate abuse.
  • We won't train AI models on your content, and we won't sell your data.
  • You can delete your content and your account at any time.

Who we are

Noodle is operated by Cartographer ApS, a company registered in Denmark under CVR no. 46298578. We're the data controller for the information described here. You can reach us about anything on this page at privacy@joinnoodle.com.

What stays on your device

When you record a session, the audio is transcribed on your device using on-device speech recognition. The audio itself is never written to a file, never uploaded, and never reaches us or anyone else. It exists only for as long as it takes to turn it into text.

The results — your transcripts, summaries, threads, topics, reports and the thinking profiles you write — are stored in Noodle's database on your device. If you're signed in to iCloud, they sync between your own devices through your private iCloud account, which is governed by Apple's privacy policy. We have no access to your iCloud data.

What we send for AI features

Summaries, titles, threads, nudges and document suggestions are generated by an AI model. To do that, Noodle sends the relevant transcript text — plus any thinking-profile instructions you've written — to our cloud provider.

We don't store the text of those requests or responses. What we do record is metering data: which feature was used, which model, how many tokens it consumed and what it cost, so we can bill credits accurately. That record contains no part of what you said.

Our cloud providers are bound by data processing agreements that let them use your content only to serve your request and keep their service secure. We may change providers as the product evolves; the commitments on this page apply whoever they are, and we'll tell you if the protections ever change.

Our AI providers may keep a log of requests for up to 60 days as part of their standard terms, used only to mitigate abuse.

What we store on our servers

Our servers hold your account, not your content:

  • Account details — your email address, your name, and either a hashed password or, if you sign in with Google, the account identifier and profile details Google gives us (name, email, avatar).
  • Sign-in sessions — a session token, its expiry, and the IP address and browser or device identifier the session was created from. We keep these to sign you in and to spot suspicious access.
  • Credits and purchases — your balance and a ledger of every grant, purchase, charge and refund. For purchases, the transaction identifier and amount from Apple or Stripe. We never see your card details.
  • Usage metering — the per-request model, token counts and cost described above.

Who else handles your data

We use a small number of providers to run Noodle. Each acts on our instructions and none of them uses your data for their own purposes.

  • Cloudflare — cloud compute provider.
  • Google — cloud compute provider.
  • Apple — iCloud sync and in-app purchases.
  • Stripe — processes credit purchases made on the web.

We're based in Denmark, inside the EU. Our hosting, AI, sign-in and payment providers are all United States companies, so the account data described above — and the transcript text sent for AI processing — is transferred to and processed in the United States, and potentially in other countries where those providers operate.

Where your data leaves the EU, we rely on the European Commission's standard contractual clauses to keep equivalent protections travelling with it.

Legal basis for processing your data

If you're in the UK or the EEA, the law asks us to name a legal basis for each thing we do. Ours are: performance of a contract for running your account, delivering AI features and handling purchases; legitimate interests for keeping the service secure, preventing abuse and metering usage; and legal obligation for keeping financial records of what you've bought.

How long we keep it

  • Your recordings — never stored, so nothing to keep.
  • Transcripts and summaries — on your device and in your iCloud for as long as you keep them. Delete them in the app and they're gone from both.
  • Account details — until you delete your account.
  • Purchases, credits and usage metering — kept as financial records even after you delete your account, stripped of your name and email so they're no longer linked to you.
  • Sign-in sessions — until they expire or you sign out.
  • Server logs — 30 days.

Backups roll off within 30 days of deletion.

What we won't do

  • We won't use your recordings or transcripts to train AI models — not ours, not anyone else's.
  • We won't sell or share your personal data for advertising, to data brokers, or to anyone else.
  • We won't read your sessions. We can't — they aren't on our servers.

Your rights and controls

You can delete any session from inside the app, which removes it from your device and from your iCloud. You can delete your whole account from Settings in the app, or from your dashboard on the web. It happens immediately: your name, email, profile picture, password and Google sign-in are erased, every session is signed out, and any tokens you have left are forfeited. You'll be asked whether to delete your sessions and transcripts from this device and your iCloud at the same time — that part is your choice.

What we keep is the record of what you bought and what you spent. We're required to hold on to financial records, so your purchases, credit entries and usage metering stay in our books — with your name and email already removed, so they no longer point at you. Your payment records also stay with Stripe and Apple, who keep them for their own tax and accounting obligations. If you'd rather we handled the deletion for you, email privacy@joinnoodle.com and we'll do it within 30 days.

If you're in the EEA or the UK you also have the right to access a copy of your data, correct it, have it erased, restrict or object to how we use it, take it elsewhere in a portable format, and withdraw consent where we've relied on it. Ask us and we'll act within one month.

If you think we've got it wrong, you can complain to the Danish Data Protection Agency — Datatilsynet — or to the supervisory authority where you live. We'd encourage you to reach out to us first.

Cookies

Our website uses cookies for one thing: keeping you signed in. There are no advertising or analytics cookies, so there's nothing to opt out of.

Security

Everything travels over encrypted connections. Passwords are hashed, never stored in readable form, and your sign-in token is held in the iOS Keychain. No system is perfect, but the strongest protection here is architectural: the content you'd most want kept private is on your own device, not ours.

Children

Noodle isn't intended for anyone under 13, and we don't knowingly collect their data.

Changes

If we update this policy, we'll let you know via email.