Notion did not let our reader in: privacy policy (HTTP 401), subprocessors (HTTP 404). Facts below come only from what was readable; anything marked "not stated" may simply be behind that block. We retry daily and rebuild the record the moment the documents open. Work for Notion? Claim the profile and send us the text.
Trains on customer data
no
“User data is never used to train or influence Notion AI models.”
Opt-out mechanism
none described
Not stated in the documents we could read. An absence here is an unknown, not a no.
AI features
none stated
Not stated in the documents we could read. An absence here is an unknown, not a no.
Retention
AI embeddings are deleted within 60 days of page or workspace deletion.
“AI embeddings are deleted within 60 days of page or workspace deletion.”
Hosting regions
not stated
Not stated in the documents we could read. An absence here is an unknown, not a no.
Subprocessor notice
not stated
Not stated in the documents we could read. An absence here is an unknown, not a no.
Downstream
Who's behind Notion, as listed in its own subprocessor documents. 17 listed.
Model providers
- AnthropicGlobal
- Fireworks AIGlobal
- OpenAIunstated
Hyperscalers
- Amazon Web ServicesUSA
- Google Cloudunstated
Other subprocessors
- 1Passwordunstated
- AmplitudeUSA
- Boxunstated
- Cloudflareunstated
- Discordunstated
- Figmaunstated
- FivetranUSA
- MailgunUSA
- Oktaunstated
- SplunkUSA
- TwilioUSA
- Vercelunstated
Reviewer notes
Extracted by deterministic rules (rules/v1), no language model. Coverage is limited to recognisable clauses and a gazetteer of common subprocessors; absent values mean 'not matched', not 'not present'.
Documents read
- privacy policy https://www.notion.com/privacyHTTP 401 · 2026-09-06
- subprocessors https://www.notion.com/help/subprocessorsHTTP 404 · 2026-09-06
- dpa https://trust.notion.com/legal/dpaHTTP 200 · 2026-09-06
Document changes
- high 2026-09-06 · dpa +3 / −9 lines
show diff
+ Notion's security and compliance program is built on transparency, trust, and enterprise-grade protection. Explore our certifications, security controls, policies, and subprocessors to understand how Notion safeguards your data. * Annual third-party audits: SOC 2 Type II, ISO 27001/17/18/701, HIPAA, BSI C5. * Annual third-party penetration testing. * Bug bounty program through [HackerOne](https://hackerone.com/notion). * 99.9% uptime SLA ([notion-status.com](https://www.notion-status.com/)). * [Privacy policy](https://www.notion.). * [Data processing addendum](https://www.notion.). * [Subprocessor list](https://notion.notion.).+ and PrivacyBug Bounty+ Loading content...− Notion's security and compliance program is built on transparency, trust, and enterprise-grade protection. Explore our certifications, security controls, policies, and subprocessors to understand how Notion safeguards your data. * Annual third-party audits: SOC 2 Type II, ISO 27001/17/18/701, HIPAA, BSI C5. * Annual third-party penetration testing. * Bug bounty program through [HackerOne](https://hackerone.com/notion). * 99.9% uptime SLA ([notion-status.com](https://www.notion-status.com/)). * [Privacy policy](https://www.notion.so/notion/Privacy-Policy-3468d120cf614d4c9014c09f6adc9091). * [Data processing addendum](https://www.notion.so/notion/Data-Processing-Addendum-361b540101274b1fa7e16b90402b0d99). * [Subprocessor list](https://notion.notion.site/Notion-s-List-of-Subprocessors-268fa5bcfa0f46b6bc29436b21676734).− OverviewDocumentationControlsSubprocessorsUpdatesTerms and PrivacyBug Bounty− See all 2 updates− Aug 31, 2026− SOC 2, SOC 3 Type II, HIPAA, and C5 reports now available− Aug 25, 2026− Security Pentest Retesting Reports now available− Notion has published its SOC 2 Type II and SOC 3 Type II reports, along with a HIPAA Compliance Attestation Report and a C5 Cloud Security Attestation Report. Reviewers can access all four documents in the trust center to support their security and compliance evaluation.− Notion has added three Security Pentest Retesting Reports to its trust center. Reviewers can access these reports to evaluate the results of our security audit retesting.
Fact changes
No changes recorded yet. Changes appear here when a later reading differs from an earlier one.
Corrections
No correction requests. Anyone may dispute a fact with a source; requests and resolutions are public and ledger-entered.
Facts are as stated in Notion's public documents on the date read. This is a record, not legal advice. Work for Notion? Claim this profile · Something wrong? Request a correction.