Notion AI — privacy & data policy

Provider: Notion. PromptPrivacy score: 88/100. Last verified July 26, 2026.

What happens to your data?

Your data is used to generate embeddings and responses within your workspace but is not used to train AI models. It is processed by third-party sub-processors under strict contractual security obligations and is encrypted during transit.

Does it train on your data?

Notion and its AI Subprocessors do not use Customer Data to train any models by default, and this is prohibited by contractual agreements.

Can you opt out?

Yes, users can manage AI settings via the workspace settings menu, and administrators can control the use of data-retaining LLMs.

Data retention

For Enterprise plans, LLM providers use zero-retention. For non-Enterprise plans, LLM providers retain data for 30 days or fewer. Embeddings are deleted within 60 days of page/workspace deletion. Deleted content is recoverable for 30 days.

Encryption & security

Data is encrypted in-transit using TLS 1.2 or greater. Notion maintains SOC 2 Type 2 and ISO 27001 certifications, and vector databases used for embeddings are also SOC 2 Type 2 certified.

Is it safe for work?

Yes, the service includes enterprise-grade security features, compliance certifications (SOC 2, ISO 27001), and contractual prohibitions against model training, making it suitable for business use.

Source policy: https://www.notion.so/help/notion-ai-security-practices