Enot Privacy Policy
Last updated: 30 September 2026
Service: Enot (voice / meeting notes into Obsidian). API host: enot.upl.one
Controller: Danila Nekrasov
Contact / privacy requests: nekrasov.pr@gmail.com
This policy describes how personal data is processed when you use the Enot cloud API and the Enot Obsidian plugin. It is written to match how the service actually works. It is not legal advice.
1. Who is responsible
Danila Nekrasov operates Enot and decides why and how personal data is processed for this product (controller under the GDPR where it applies).
Hosting and processors (they process data on our instructions or as separate services you also contract with):
| Party | Role |
|---|---|
| Contabo (Germany) | Virtual server / disk hosting for the Enot API and temporary storage |
| Vast.ai (or similar GPU providers we configure) | Optional remote speech recognition workers |
| OpenRouter | Large-language-model API used to structure notes from transcripts |
| Whop | Paid subscriptions and checkout (billing has its own terms and privacy policy) |
Contabo is not the controller of Enot user accounts or meeting content. Contabo hosts infrastructure that we configure.
2. What we process
Depending on how you use Enot, we may process:
- Account identifiers:
install_id,user_id, API key, registration time, optional register IP (abuse prevention) - Preferences: UI/speech language, timezone, write-target folder flags
- Audio / video you upload or record for processing (temporary)
- Transcripts and generated Markdown notes (including action items / agreement sidecars) until delivered to your vault and acknowledged
- Voice / glossary helpers you sync (name hints, brand hints, calibration metadata, clarify queue) stored in your server-side user vault mirror
- Usage metering: audio seconds / hours, plan key, Whop membership ids, paid-until timestamps
- Technical logs needed to run and secure the service (errors, job status)
We do not sell your personal data.
3. Why we process it (purposes)
- Provide speech-to-note processing and sync finished notes to your Obsidian vault via the plugin
- Authenticate API requests and prevent abuse
- Meter trial / paid quotas and fulfill Whop-linked entitlements
- Improve reliability and security (debugging, rate limits)
- Comply with legal obligations and respond to your deletion / privacy requests
Legal bases (where GDPR applies) typically include contract (providing the service you request), legitimate interests (security, abuse prevention, limited metering records), and consent where required for optional features or where you accept Terms/Privacy at registration.
4. Retention
- Audio: deleted from our job store when processing finishes or fails permanently (not kept as a media library)
- Note body / sidecars / calibration append on jobs: kept only until the plugin acknowledges delivery (
inboxack); then purged from the job row. Billing metadata (timestamps, duration, status) may remain - Account + server-side user vault mirror: until you delete your account (plugin Settings → Danger zone, or email us) or we terminate abuse / legal holds
- Whop: retention follows Whop's policies; deleting Enot does not automatically cancel a Whop membership. Cancel in Whop separately.
Third parties (OpenRouter, GPU workers) may retain technical logs under their own policies for a limited time.
5. Transfers
Processing primarily runs on Contabo in the EU (Germany). Subprocessors such as OpenRouter, Vast, and Whop may process data in other countries. Where required, we rely on appropriate safeguards those providers document (e.g. standard contractual clauses) and limit what we send to what is needed for the feature.
6. Your rights
Subject to applicable law, you may request access, correction, erasure, restriction, portability, or objection. Practical erasure path:
- In the Enot Obsidian plugin: Settings → Danger zone → Delete Enot account & server data
- Or email nekrasov.pr@gmail.com from a contact we can reasonably link to your account
You may lodge a complaint with a supervisory authority (for example in the EU member state of your habitual residence).
7. Children
Enot is not directed at children. Do not use the service if you are under the age required by your jurisdiction to agree to these terms.
8. Security
We use API keys, transport encryption (HTTPS), network restrictions on ops endpoints, and deletion of audio after jobs. No method is perfectly secure; you remain responsible for protecting your vault and API key on your devices.
9. Changes
We may update this policy. The "Last updated" date will change; material changes may also be reflected in the plugin or at registration. Continued use after an update constitutes acceptance where permitted by law.
10. Contact
Danila Nekrasov · nekrasov.pr@gmail.com
Service: enot.upl.one