Privacy Policy
Last updated: July 1, 2026
Notis, LLC (“Notis,” “we,” “us”) operates the website at notis.io and the Notis AI data egress gateway and control plane (together, the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Information we collect
- Account & contact information — name, email address, organization, and hashed credentials when you register, join the waitlist, or contact us.
- Usage & audit metadata — when you route traffic through the Service, we process request and response streams to enforce your policies and produce an audit trail. By default we store audit metadata (for example: detection categories and counts, timestamps, workload identifiers, model and provider) — not the raw prompt or response content.
- Website data — essential cookies and limited, privacy-respecting analytics.
- Communications — messages you send us and related contact details.
What we do not store
By design, the gateway inspects content in memory to apply your policies; raw prompt and response content is not persisted by the Service by default. If you enable optional content logging in your own environment, that content remains in your environment.
How we use information
- Provide, operate, secure, and improve the Service;
- Enforce the policies you configure and generate audit logs;
- Respond to support requests and communicate with you;
- Comply with legal obligations and enforce our terms.
Cookies
We use essential cookies for authentication and session management, plus minimal analytics to understand site usage. You can control cookies through your browser settings.
Third parties and subprocessors
We rely on infrastructure providers to host and operate the Service. When you use the Service, your traffic is forwarded to the AI or LLM provider you designate (for example, OpenAI, Anthropic, or Azure); your use of those providers is governed by their own terms and privacy policies. We do not sell your personal information.
Data retention
We retain account information for the life of your account and audit metadata according to your configuration and retention settings. We delete or anonymize information when it is no longer needed for the purposes described here.
Security
We use encryption in transit, hashed credentials, and access controls to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your rights
Depending on your location, you may have the right to access, correct, delete, export, or object to the processing of your personal information (for example, under the GDPR or CCPA). To exercise these rights, contact us using the details below.
International data transfers
The Service is operated in the United States and may be available in other regions. Regional deployment options may apply for certain customers.
Children’s privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate.
Contact us
Questions about this policy or your information? Reach us at privacy [at] notis [dot] io.