Noticings — Privacy Policy
Last updated: September 30, 2026
1. What this policy covers
This policy explains how Noticings handles personal information. Noticings is a private AI-assisted professional documentation tool for educators. Educators use it to capture short observation notes about classroom learning and to prepare draft report-card language (i.e., "Communication of Learning" drafts). It is a working notebook for the educator — not a system of record, not a parent-facing platform, and not a service provided to children.
This policy applies solely to the Noticings mobile app, our website (noticingsapp.com), and any related services we operate. By using the Noticings app and related services, you agree to all terms and conditions in our Terms of Service and this Privacy Policy.
2. Our privacy commitments, in plain language
These are design decisions built into the product, not aspirations:
- Audio is never saved or sent anywhere. Voice notes are transcribed directly on your device. The audio is processed in your phone's memory and discarded. No recording is ever written to storage or transmitted to us or anyone else.
- We store the minimum about students. Students exist in Noticings as a first name and a last initial — nothing else. Our database physically has no fields for last names, dates of birth, photos, health information, or family contact information. This is enforced at the database level, not just in the app.
- Student names never reach the AI. Before any note text is sent for draft generation, every name on your student roster is replaced with a placeholder token (for example, {{S1}}) on your device. If this replacement cannot be fully verified, nothing is sent at all. The AI provider never receives the names of the students on your roster, and names are re-inserted only on your device.
- Your data lives in Canada. Our primary database is hosted in the AWS Canada (Central) region.
- Delete means delete. Deleting a student, a note, or your account performs a permanent hard delete, not a soft archive. You can export everything as JSON and erase everything, at any time, from Settings.
- No ads, no trackers, no selling data. The current version of the app contains no advertising, no third-party analytics SDKs, and no crash-reporting SDKs. We never sell or rent personal information.
3. Information we collect
Information about you (the educator):
- Account details: your email address and, optionally, a class name and (for co-educators) a display name shown to the teacher whose class you join.
- Subscription and billing information is handled by the Apple App Store or Google Play when paid plans are available. Apple or Google processes your payment under its own terms; Noticings does not receive or store your payment card information.
- Correspondence: anything you send us in support emails.
- Website waitlist: if you join our waitlist, your email address, the time you signed up, and whether you chose to also receive marketing emails from us. Waitlist data is stored with Cloudflare in its “Eastern North America” region, which may be outside Canada. You can remove your email at any time using the form on our privacy page or the unsubscribe link in any email we send.
Information about students, entered by you:
- A first name and a single last initial per student.
- The text of your observation notes and generated report drafts. Note text is free-form: you write or dictate it, and you control what it contains. Section 10 sets out your responsibilities for what goes into it.
Technical information:
- We do not use analytics, advertising, or crash-reporting SDKs in the current version, and we do not write personal information to our application logs. Our infrastructure providers maintain standard technical logs (such as IP addresses and request timestamps) to operate and secure their services. Apple may share crash reports with us through the App Store or TestFlight if you have enabled that in your device settings.
- A local copy of your data is stored on your device (in the app's private storage) so the app works offline.
Information the app does not ask for: raw audio recordings; students' last names; dates of birth; photos or video; health or diagnostic information; parent or guardian contact information. The app has no fields for any of these. Free-text notes are written or dictated by you, and Section 10 sets out your responsibility to keep this information out of note text.
4. How we use information
We use personal information only to:
- Provide the service: store your notes, sync them across sessions, and generate draft report language you request.
- Share your class with co-educators you invite: a co-educator you add to your class can see the students and notes in that class, within the permissions you set, until you revoke their access. Sharing happens only on your instruction; we never share your class with anyone you have not invited.
- Authenticate you and secure your account.
- Manage subscriptions (when paid plans exist); payment itself is handled by the App Store.
- Respond to support requests.
- Meet our legal obligations.
We do not use your content or your students' information for advertising, profiling, or training AI models, and we do not disclose it to third parties except the service providers listed in Section 6, acting on our instructions.
5. AI processing and pseudonymization
When you generate a report draft, the app sends your note text to our own server (a server we control), which forwards it to our AI provider, Anthropic, via its commercial API. Before anything leaves your device:
- Every name on your student roster is replaced with a placeholder token. Names that are not on your roster (for example, a sibling or a parent mentioned in a note) are not replaced, which is why Section 10 asks you to keep note text minimal. The mapping between tokens and names never leaves your device.
- A fail-closed check verifies no name from your student roster remains in the text. If any name survives, the request is blocked and nothing is sent.
Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's models by default. Anthropic retains API inputs and outputs for up to 30 days. AI processing occurs on servers located primarily in the United States; Section 8 addresses this transfer.
6. Service providers
We use a small number of service providers, each bound by their terms to process data only to deliver their service to us:
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase | Database hosting and authentication | Canada (AWS ca-central-1) |
| Cloudflare | API proxy between the app and the AI provider (transient processing only; no personal data stored); website hosting and waitlist storage | Global edge network; waitlist in “Eastern North America” |
| Anthropic | AI draft generation (receives pseudonymized note text only — never the names on your student roster) | Primarily United States |
| Apple App Store / Google Play | Subscription billing when paid plans launch (Noticings receives no payment card data) | Per Apple / Google |
| Resend | Sign-in (magic-link) emails to educators | United States (us-east-1); delivery logs retained 30 days |
| Google (Gmail) | Support and privacy mailbox (email you send to hello@ or privacy@) | United States |
7. Disclosures
In extremely limited situations, we may share your information with third parties who are not our service providers:
- Where it is necessary to protect our lawful interests: we may disclose personal information as permitted or required by law; when it is necessary to protect our rights or to comply with a legal process; or to prevent, investigate or take action regarding unlawful, illegal or suspicious activities that violate our Terms of Service or this Privacy Policy.
- Business transactions: in accordance with applicable legal requirements, we may disclose or transfer personal information with business entities or people involved in negotiations if we are involved in a transaction concerning the transfer of some or all of our business assets.
- When you consent: We may share information about you with third parties if you give us permission or direct us to share the information.
8. Where data is stored and cross-border transfers
Your primary data (account, students’ first name and last name initials, notes, reports) is stored in Canada. Three limited exceptions involve data processing outside Canada: (a) during draft generation, pseudonymized note text — with all roster names removed — is transmitted through Cloudflare's network and processed by Anthropic on servers primarily located in the United States; and (b) sign-in emails are sent by Resend from the United States, and support email you send us is held in our Google mailbox in the United States (your own email provider may also store mail outside Canada); and (c) the website waitlist is stored with Cloudflare in its “Eastern North America” region. Information processed outside Canada is subject to the laws of those jurisdictions, and courts or authorities there may be able to compel access under their local law.
9. Retention and deletion
- We retain your data while your account is active.
- Year-end reset: the Noticings app is built around the school year. Settings include a one-tap flow to export all your data as a standard machine-readable file (JSON) and then permanently erase everything. We encourage educators to run it each June.
- Primary account deletion: available in-app at any time. It permanently deletes your account and all associated data, including your login identity. Deletions cascade — removing a student removes their linked notes and reports.
- Co-educator account deletion: if you use Noticings as a co-educator in another teacher’s class, the notes you create there are controlled by that teacher (the primary account holder). When you delete your co-educator account, those notes stay with the primary account; your name is removed from them and they are labelled “former co-educator”. Any request to delete those notes should be directed to the primary account holder.
- Our database provider does not keep restorable backups on our current plan, so deleted data is not retained in any backup. If we add backups in future, we will state the backup retention period here before doing so.
- Audio is never retained, so there is no audio to delete.
10. Your responsibilities as an educator
Noticings is a tool for your own professional working notes — similar to a paper notebook, with materially stronger safeguards. Using it responsibly means:
- Enter only what the app asks for: a first name and last initial per student.
- Keep free-text notes professional and minimal. Do not include students' last names, health or diagnostic information, family details, or contact information in note text.
- Confirm that your use of Noticings complies with your employer's and school board's policies, including any acceptable-use policy covering professional tools, and your professional obligations. You are responsible for that confirmation.
- Final, official report content belongs in your board's official systems. Noticings drafts are working material, and the official student record (including under Ontario Student Record guidelines) remains with your board.
11. Children's information
Noticings is for adult educators. We do not offer accounts to anyone under 18, do not interact with children, and do not knowingly collect information from children. The limited student information in the system (first name, last initial, and your observation text) is entered by educators for professional documentation purposes. Because this information concerns young children, we treat it as sensitive and apply the heightened safeguards described in this policy — data minimization, pseudonymized AI processing, Canadian residency, and hard deletion.
12. Your rights
You can, at any time:
- Access and export all your data (Settings → export as JSON).
- Correct any information by editing it in the app.
- Delete individual students, notes, and reports, or your entire account.
- Withdraw consent by stopping use of the service and deleting your account.
- Ask questions or complain by contacting us via the methods below under “Contact Us”. If you are not satisfied with our response, you may complain to your relevant privacy authority, such as the Office of the Privacy Commissioner of Canada (priv.gc.ca).
13. Security
Our safeguards include: encryption in transit (TLS) and at rest; database row-level security so no account can read another account’s data, except a co-educator the teacher has explicitly invited, within the permissions the teacher set; client-side pseudonymization with a fail-closed check before any AI call; a minimal-field schema that cannot hold prohibited data categories; no personal information in application logs; and hard-delete cascades. No system is perfectly secure, but our architecture is designed so that the most sensitive things — children’s voices and full identities — are never in the system to begin with.
14. If a breach occurs
We maintain records of any breach of security safeguards. Where a breach creates a real risk of significant harm to an individual, we will notify affected users and report to the applicable privacy authorities as required by law, and we will tell you plainly what happened, what information was involved, and what we are doing about it.
15. Changes to this policy
If we change this policy, we will update the “Last updated” date and, for material changes, notify you in the app or by email before the change takes effect. We will never retroactively weaken the commitments in Section 2 for data already collected without your express consent.
16. Contact Us
Adam Birch, Privacy Officer · Noticings (Adam Birch, operating as Noticings) · 5343 Dundas St W, Ste 601 #114, Etobicoke, ON M9B 6H8, Canada · [email protected]
Privacy questions and access requests: [email protected]. We aim to respond within 30 days.