Privacy Policy
How NotebookLM.work handles — and mostly avoids handling — your information.
Last updated: 28 August 2026 · Effective: 28 August 20261. Summary
The short version. NotebookLM.work has no user accounts and keeps no library of your documents. Your notebooks and files are stored on your device. When you ask for a summary, an answer or an audio overview, the app sends only the excerpts needed for that request to an AI processing provider over an encrypted connection; the result comes back and the excerpt is not retained for training. We do not sell or share personal information, we do not run advertising networks, and we do not build a profile of you.
This summary is for orientation only. The sections below are the policy that actually applies.
2. Who we are
This Privacy Policy explains how the operator of the NotebookLM.work mobile application and the website at notebooklm.work (“we”, “us”, “our”) handles personal information. We are the data controller for the limited personal information described here.
You can reach us at any time at info@notebooklm.work. This policy covers the app and this website. It does not cover any third-party service you choose to open from within them.
3. Information we collect
We have deliberately kept this list short. It is complete.
| Category | What it is | Where it goes |
|---|---|---|
| Notebook content | The documents, files, links and notes you add, plus the questions you ask and the responses generated. | Stored on your device only. Excerpts are transmitted transiently for AI processing (see section 5). |
| Diagnostics & crash data | Anonymous crash reports and basic performance metrics: crash stack traces, app version, device model, OS version. | Only if you have opted in, or through Apple’s own analytics sharing setting. Not linked to your identity. |
| Support correspondence | Your email address and whatever you choose to tell us when you write to us. | Our email provider, so that we can reply to you. |
| Website request logs | Standard server logs generated when you load this site: IP address, timestamp, user agent, page requested. | Our hosting provider, for security and reliability. Retained for a short period, then discarded. |
4. What we do not collect
- No name, account, username, password or social login.
- No contacts, calendar, photo library, health data or precise location.
- No advertising identifier (IDFA), and no advertising or attribution SDKs.
- No cross-app or cross-site tracking of any kind. We do not ask for App Tracking Transparency permission because we do not track you.
- No cloud copy of your notebooks. We cannot open, read, recover or hand over documents we never receive.
This website uses no advertising cookies and no third-party analytics cookies. Any storage the site uses is limited to your local browser preferences.
5. How your content is processed
Understanding this section is the best way to understand the app.
On your device
Importing, storing, organising, indexing and searching your sources all happen locally. Your library never leaves the device as a whole.
Remotely, per request
Generating a summary, answering a question, building a study guide or producing an audio overview requires a large language model, which runs on remote infrastructure. When you trigger one of these actions:
- The app selects only the passages relevant to that request, together with your instruction.
- That excerpt is sent over TLS to our AI processing provider.
- The provider generates the response and returns it to your device.
- The excerpt and response are processed to fulfil your request and are not used to train models and not retained beyond any short abuse-monitoring window the provider applies under its enterprise terms.
We do not store a copy of these excerpts, do not associate them with an identity, and do not keep a history of your requests on our systems.
If a document is confidential enough that you would not paste an excerpt of it into a cloud service, do not add it to a notebook and then request AI generation on it. Local reading, organising and search remain fully offline.
6. Why we process data
- To provide the app’s core functions — producing the summaries, answers and study material you request.
- To keep the app working — diagnosing crashes and fixing defects.
- To respond to you — handling support requests and legal enquiries.
- To protect the service — preventing abuse, fraud and security incidents.
- To meet legal obligations — where a law that applies to us requires it.
We do not use your information for advertising, profiling, automated decision-making with legal effects, or model training.
7. Legal bases (EEA and UK users)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract (Art. 6(1)(b)) — processing the excerpts you submit so the app can return what you asked for.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and fixing defects, balanced against your rights.
- Consent (Art. 6(1)(a)) — optional diagnostics sharing, which you may withdraw at any time in iOS Settings.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information by law.
8. Sharing and sub-processors
We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose information only to the service providers listed below, each bound by contract to process it solely on our instructions.
| Provider | Role | Data involved |
|---|---|---|
| AI model provider | Generates summaries, answers and audio from submitted excerpts | Transient content excerpts and prompts |
| Google Firebase Hosting | Hosts this website | Website request logs |
| Crash reporting provider | Aggregated, anonymous crash and stability reports | Diagnostics, if enabled |
| Apple Inc. | App distribution, in-app purchases, optional Apple analytics | Handled by Apple under Apple’s own privacy policy; we receive only aggregate sales and crash statistics |
| Email provider | Delivers and stores support correspondence | Your email address and message |
We may also disclose information if we are legally required to do so, or where necessary to establish, exercise or defend legal claims — noting that we simply do not hold your notebooks and so cannot produce them. If our business is ever transferred, this policy travels with it and you will be told before anything changes.
9. Device permissions
The app requests the minimum iOS permissions it needs, only at the moment they are needed, and works without them:
- Files & document picker — to import a document you select. We receive access only to that file.
- Microphone (optional) — only if you dictate a note or question. Audio is used for that purpose and is not retained by us.
- Notifications (optional) — to tell you when a long generation has finished.
- Network access — required to generate AI responses.
You can review or revoke any of these at any time in iOS Settings › NotebookLM.work.
10. Retention
- Notebook content: kept on your device until you delete it. We hold no copy, so there is nothing for us to retain.
- Processing excerpts: transient. Retained by the AI provider only for the brief period its abuse-monitoring terms permit, then deleted.
- Diagnostics: aggregated and retained no longer than 90 days.
- Support email: retained up to 24 months so we can follow up on related issues, then deleted.
- Website logs: retained for a short period for security purposes.
11. Security
All network traffic between the app and our providers uses TLS 1.2 or higher. Notebook data on your device sits in the app’s sandboxed container and inherits iOS data protection, which is tied to your device passcode and hardware encryption. Access to our own systems is limited to the people who need it and protected by multi-factor authentication.
No system is perfectly secure. Keeping your device updated and locked with a passcode or biometric is the single most effective protection for the data in the app. If we ever become aware of a security incident affecting personal information, we will notify affected users and any regulator as required by applicable law.
12. International transfers
Our providers may process data in countries other than yours, including the United States. Where personal information is transferred out of the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), together with supplementary technical measures such as encryption in transit. You may request further information at info@notebooklm.work.
13. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal information, to data portability, and to withdraw consent. Residents of California and other US states with comprehensive privacy laws additionally have the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
Because the app has no accounts, most of your notebook data is under your direct control and is never in our possession — deleting it in the app is the fastest and most complete way to exercise deletion. For anything we do hold (support email, diagnostics), write to info@notebooklm.work and we will respond within 30 days, or sooner where the law requires. We may need to verify your request, which for email-based records simply means replying from the address concerned.
If you are in the EEA or UK and believe we have handled your information improperly, you may lodge a complaint with your local supervisory authority, though we would appreciate the chance to resolve it first.
14. Deleting your data
- A single item: swipe on a source or notebook in the app and choose Delete.
- Everything in the app: use Settings › Reset all data inside the app.
- Absolutely everything: delete the app from your device. Because there is no server-side account, uninstalling removes all notebook data permanently. Deleted content is not recoverable by us or by you, so export anything you want to keep first.
- Support records: email us and ask; we will delete them.
15. Children
The app is not directed at children under 13 (or under the minimum age of digital consent in your country, which may be up to 16 in parts of the EEA), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact info@notebooklm.work and we will delete it. Parents and guardians can restrict app downloads and purchases using Apple’s Screen Time and Family Sharing controls.
16. Purchases
If the app offers a paid tier or subscription, the transaction is handled entirely by Apple through the App Store. We never see or store your payment card, billing address or Apple Account credentials. We receive only Apple’s anonymised transaction receipt, which tells the app whether an entitlement is active. Manage or cancel any subscription in iOS Settings › your name › Subscriptions.
17. App Store privacy labels
Our App Store “App Privacy” label reflects this policy: Data Not Collected for identifiers, contact info, location, contacts, browsing history and purchases, and Data Not Linked to You for optional diagnostics. We do not use data for tracking as Apple defines it. If the label and this policy ever appear to disagree, tell us — it is a mistake on our side and we will correct it.
18. Changes to this policy
We will update this page when our practices change and revise the “Last updated” date above. If a change is material — for example, if we began collecting a new category of data — we will give prominent notice in the app before it takes effect. Continuing to use the app after a change takes effect means you accept the updated policy.
19. Contact
Questions, requests or complaints about privacy:
We aim to acknowledge every privacy enquiry within two business days and to resolve it within 30 days.