Notion AI — privacy & data policy

Provider: Notion. PromptPrivacy score: 94/100. Last verified August 26, 2026.

What happens to your data?

When you use Notion AI, your requests and relevant workspace context are converted into embeddings and sent via encrypted connections to vetted AI providers to generate answers. Your data is isolated from other customers, never used to train AI models, and retained by AI providers for 30 days or less (or zero days on Enterprise plans).

Does it train on your data?

By default, Notion and its third-party AI subprocessors (such as OpenAI and Anthropic) do not use customer data or workspace content to train machine learning models.

Can you opt out?

Yes. Model training is disabled by default and not permitted under Notion's agreements. Additionally, workspace administrators can manage AI web search access and choose whether to enable data-retaining LLM features.

Data retention

By default, LLM providers maintain zero data retention for Enterprise workspaces, and retain customer data for 30 days or fewer for non-Enterprise workspaces before deletion. Embeddings stored in vector databases are deleted within 60 days after page or workspace deletion. Deleted Notion pages or workspaces can be restored for up to 30 days, after which data is permanently unrecoverable.

Encryption & security

Data sent to third parties is encrypted in-transit using TLS 1.2 or greater. Notion AI is covered by Notion's SOC 2 Type 2 report and ISO 27001 certification, and its vector database providers are SOC 2 Type 2 certified. Notion AI also supports HIPAA compliance.

Is it safe for work?

Yes. Notion AI is safe for business and enterprise use. It contractually prohibits model training on customer data, segregates customer environments, uses TLS 1.2+ encryption, complies with SOC 2 Type 2 and ISO 27001 standards, offers zero data retention for Enterprise plans, and supports DLP and HIPAA compliance.

Source policy: https://www.notion.so/help/notion-ai-security-practices