Skip to content
Notis
How Notis.ai Keeps Your Data Secure (Without Security Theatre)

How Notis.ai Keeps Your Data Secure (Without Security Theatre)

A plain-English look at how Notis handles integrations, model training, human access, deletion, and the limits founders should understand before trusting any AI assistant.

The fastest way to make a founder suspicious is to say, “Don’t worry, it’s secure.” Secure how? Against whom? And what happens when the AI assistant has access to your inbox, calendar, files, customer conversations, and the half-finished strategy note you recorded at 1:17 a.m.? A secure AI assistant is not one with the loudest compliance badge wall. It is one that limits access, explains where data goes, lets you revoke connections, avoids training models on your private content, and gives you a real deletion path. Here is how Notis approaches those questions, what the current documentation actually promises, and where you should still use your own judgment.

What “secure” should mean for an AI assistant

An AI assistant is useful precisely because it can touch important things. If it can only rewrite a paragraph in a blank box, the security model is simple—and the product is not much of an assistant. Once it can read Gmail, update Notion, schedule a meeting, remember context, or act from WhatsApp, the trust surface gets bigger. That does not mean “never connect anything.” It means the security conversation should follow the workflow. Which data is authorized? Where are credentials stored? Can access be revoked? Who can inspect a conversation? Is the content used to train a model? What happens after deletion? Those questions are more useful than asking whether a landing page has a shield icon. We generated one for the hero, obviously. I am still a marketer.

How Notis handles connected accounts

Notis uses Composio for many connected-app authentications and actions. According to the Notis privacy and security documentation, OAuth is provisioned to perform the actions you enable, tokens are stored encrypted, and integrations can be disconnected in Notis or revoked at the original provider. The integration guide also explains that Composio handles authentication and refresh for supported connectors. That distinction matters. Your assistant does not need your Gmail password scribbled into a database cell. OAuth grants defined access through the provider, and revocation gives you an exit. The right founder habit is boring but effective: connect only what the workflow needs, review permissions, and disconnect integrations you no longer use.

Your conversations are not model-training fodder

The most common question is also the most sensible: “Will my private data train the model?” Notis says no. Its security documentation states that personal data and conversations are not incorporated into LLM training datasets. The primary model provider is OpenAI, whose API data controls state that business/API inputs and outputs are not used to train models by default. There is an important nuance here. “Not used for training” does not mean “never processed.” An AI service must process the prompt to produce an answer. Connected processors may also handle data to deliver the feature you requested. The useful promise is narrower: your private content is processed for the service, not quietly recycled into a public model-training corpus.

Human access is restricted, not magically impossible

Notis documents a deliberately narrow production-access policy: only Flo is authorized in suppliers’ production databases, and the team says it asks for permission before viewing a user conversation for debugging, with the user free to refuse. The privacy policy, last updated January 4, 2026, similarly says humans do not read Google user data unless the user explicitly consents, access is necessary for security or legal reasons, or the law requires it. I prefer this plain statement to pretending humans do not exist. Software breaks. Debugging exists. Legal obligations exist. The test is whether access is limited, purposeful, and disclosed—not whether a company writes “zero trust” seventeen times in a PDF.

Data deletion has a clock

You can disconnect an integration without deleting your entire Notis account. If you do request deletion, the security documentation says personal data is removed from active systems within 30 days, usually much sooner, and purged from encrypted backups within 90 days. Account deletion is also available through the user settings flow. This is not instant oblivion, and honest retention policies rarely are. Backups exist for resilience. The meaningful part is that the policy names a process and a maximum window instead of saying data may be retained “for as long as necessary,” which can mean almost anything.

The five-question security check

<table header-row="true" header-column="false"> <tr> <td>Question</td> <td>Documented Notis answer</td> <td>Why it matters</td> </tr> <tr> <td>Who authorizes app access?</td> <td>The user, through provider scopes/OAuth</td> <td>Access should follow your explicit connection</td> </tr> <tr> <td>Can I revoke it?</td> <td>Yes, in Notis or at the provider</td> <td>You need an exit without deleting everything</td> </tr> <tr> <td>Is my content used for training?</td> <td>No, according to Notis documentation</td> <td>Private work should not become training material</td> </tr> <tr> <td>Can staff read conversations?</td> <td>Production access is restricted; debugging access requires permission, subject to security/legal exceptions</td> <td>Human access needs controls and a stated purpose</td> </tr> <tr> <td>What happens after deletion?</td> <td>Active systems within 30 days; encrypted backups within 90 days</td> <td>A deletion promise should include a timeline</td> </tr> </table>

What Notis does not claim

Vendor certifications are not transferable stickers. Notis works with infrastructure and processors that publish standards such as SOC 2 or ISO 27001, but that does not automatically make every product in the chain independently certified. The documentation also says EU hosting is used when available, which is more precise than claiming every byte stays in one European bunker forever. No connected AI assistant can promise zero risk. Your own choices matter: what you send, which scopes you approve, whether you connect a production database, and whether a custom MCP server is trustworthy. If a task involves crown-jewel credentials, regulated records, or irreversible financial actions, add human approval and tighter boundaries. Convenience is not a substitute for governance.

Who should trust Notis—and who should wait

Choose Notis if you want a messaging-native assistant, understand that useful automation requires controlled data processing, and value encrypted tokens, revocable integrations, restricted human access, no model training on personal data, and a documented deletion timeline. It is a pragmatic security model for founders who want work executed without self-hosting an agent stack. Wait if your company requires a specific independent certification, a signed enterprise security schedule, guaranteed data residency for every processor, or a bespoke retention policy. Those are valid requirements. They simply need procurement and legal review, not a reassuring blog post. The useful question is not, “Is this AI assistant perfectly secure?” Nothing connected to the internet deserves that sentence. Ask whether the product is transparent about access, processors, training, revocation, and deletion—and whether those controls match the sensitivity of the work you delegate. That is security without theatre. Less dramatic. Much more useful.

is the founder of Mind the Flo, an Agentic Studio specialized into messaging and voice agents.

Related posts