Back to Home

Notion Privacy Summary

notion.soLast updated: 08/23/2026
Productivity

Notion is a collaborative productivity platform combining notes, documents, databases, and calendar integrations for individual and team workspace organization.

This summary was generated using AI and may contain errors or omissions. Learn about our methodology. Always refer to the original privacy policy for legal purposes.

Quick Summary

  • What They Collect: Account details, workspace content, contacts, device identifiers, calendar and integration data (inferred location and profiles).
  • How They Use & Share It: Provide collaboration features, analytics, and targeted marketing; share with service providers, affiliates, advertisers, and legal authorities.
  • Your Rights: Access, correct, delete, restrict processing, opt-out of sale/sharing, and regional portability/appeal rights.

Why You Should Care About Notion's Privacy Practices

  • Notion collects high-risk workspace content, messages, contacts, and calendar data used for collaboration and potentially shared for advertising and business purposes.
  • Behavioral profiling and cross-device tracking enable targeted advertising and personalized marketing based on browsing and device identifiers.
  • Employer or workspace owners can access your profile and workspace content, affecting employee privacy and corporate visibility of personal data.
  • Vague retention policies mean your data may be kept indefinitely for legal, business, or merger purposes, increasing long-term privacy risk.

Why High Exposure?

  • Policy permits cross-device tracking and sharing of identifiers with advertising partners for targeted marketing, which enables behavioral profiling across sites.
  • Information includes workspace content, contacts, calendar data, and messages which may be disclosed to organizations, advertisers, or during mergers and legal requests.
  • Retention is vague: data kept ‘as long as you use the Services’ or as necessary, creating indefinite retention risk for deleted data.
Learn more about our methodology →

Privacy Highlights

What They Collect

  • Account information
  • Profile information
  • User content and files
  • Payment information
  • Demographic information
  • Feedback data
  • Support data
  • Contact sync data
  • Linked account data
  • Device and technical identifiers (cookies, MAC, device IDs)

How They Share Data

  • Service providers (payments, customer support, IT, fraud prevention)
  • Affiliates and subsidiaries
  • Business partners
  • Advertising partners / ad networks
  • Analytics and measurement partners
  • Government authorities and law enforcement
  • Acquirers or successors in sale or merger scenarios
  • Subprocessors / Third-party API providers (Google APIs)

Data Retention

Policy states data is retained 'for as long as you use our Services' or as necessary to fulfill purposes, resolve disputes, enforce agreements, and comply with law

Your Rights

  • Access data
  • Rectify data
  • Erase or limit processing
  • Object to processing
  • Data portability (region-specific: EEA/UK/CA/CCPA notices)
  • Withdraw consent
  • Opt-out of marketing
  • Delete account
  • Cookie preferences / Do Not Sell or Share My Info opt-out

Detailed Analysis

Concerning Practices

  • Cross-device and cross-site tracking for advertising and matching browsing patterns across devices (enables behavioral profiling)
  • Sharing or 'selling' online identifiers and browsing data with advertising partners for targeted advertising (CCPA sale/sharing)
  • Vague/indefinite retention: data kept 'as long as you use our Services' or as necessary, without specific timelines
  • Organization/workspace owners can access profile and workspace content, enabling employer or account-owner access to member data
  • Collection of non-user contact data via Google People API / contact sync features (data about people who are not users)
  • Use of third-party data enrichment providers to improve B2B marketing and sales outreach (third-party demographic enrichment)
  • Explicit profiling/inferences: policy references creation of consumer profiles and inferences from other personal information
  • Positive AI practice: Notion Mail explicitly states Workspace API user data is NOT used to train generalized AI/ML models

Personal Data Types

Account informationProfile informationUser content and filesPayment informationDemographic informationFeedback dataSupport dataContact sync dataLinked account dataDevice and technical identifiers (cookies, MAC, device IDs)

Tracking Methods

CookiesPixel tagsWeb BeaconsLocal storageCookie identifiersMobile advertising identifiers

Third Parties

Service providers (payments, customer support, IT, fraud prevention)Affiliates and subsidiariesBusiness partnersAdvertising partners / ad networksAnalytics and measurement partnersGovernment authorities and law enforcementAcquirers or successors in sale or merger scenariosSubprocessors / Third-party API providers (Google APIs)

User Controls

Access dataRectify dataErase or limit processingObject to processingData portability (region-specific: EEA/UK/CA/CCPA notices)Withdraw consentOpt-out of marketingDelete accountCookie preferences / Do Not Sell or Share My Info opt-out

Frequently Asked Questions About Notion

Legal Disclaimer

This analysis is provided for informational purposes only and should not be used as legal advice. Privacy Exposure ratings and summaries are AI-generated assessments based on publicly available privacy policies — they are not statements of fact and may contain errors. Learn how ratings are determined. Consult with legal professionals for matters requiring legal guidance.