Privacy Policy
Last updated: May 2026
This policy explains what data CloseNote collects, how we use it, and your rights. For technical security controls, see our Security page.
What we collect
- Account information: email address and bcrypt-hashed password (we never store your password in plain text).
- Call transcripts and AI-generated notes (summary, pain points, objections, next steps, follow-up notes) — encrypted at rest.
- Call metadata: contact name, company, and phone number (stored in plaintext for display and Salesforce matching).
- Salesforce OAuth tokens (access token, refresh token, instance URL) — encrypted at rest when you connect Salesforce.
- Feedback you submit through the in-app feedback form.
- Basic usage data: account creation date, login activity, and call counts.
What we do NOT collect
- We do not retain your audio recordings after processing. Audio is deleted once transcription completes (success or failure).
- We do not sell your data to third parties.
- We do not use your call content to train AI models.
- We do not access your Salesforce org beyond searching contacts/leads when you push notes and creating the tasks you explicitly request.
How we store and protect your data
- All persistent data is stored on servers in the United States (Railway + PostgreSQL).
- Transcripts, AI note fields, and Salesforce tokens are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256).
- Passwords are hashed using bcrypt and cannot be recovered.
- Sessions use signed, HttpOnly cookies. Password changes and resets invalidate existing sessions.
- All state-changing requests require CSRF protection. Auth endpoints are rate-limited.
- Public traffic is encrypted with TLS (HTTPS) via Railway and Cloudflare.
How AI processing works
- When you record a call, audio is sent to Groq for speech-to-text transcription.
- The resulting transcript text is sent to OpenAI to generate structured sales notes.
- Audio is not retained on CloseNote servers after transcription completes.
- Only the minimum data required for each step is sent to these providers.
- We do not opt in to using your data for model training.
Your rights
- You may permanently delete your account and all associated data at any time from Settings (password + confirmation required).
- You may copy your notes from the notes page at any time.
- You may disconnect Salesforce at any time from Settings, which removes stored OAuth tokens.
- You may request information about your data by emailing [email protected].
Subprocessors
- We use trusted third-party services to operate CloseNote. Each receives only the data needed for its function:
- Groq — speech-to-text transcription (audio during processing only).
- OpenAI — structured note generation from transcript text.
- Salesforce — CRM integration when you connect your account (OAuth; we read contacts/leads for matching and create tasks you request).
- Railway — application hosting and infrastructure (United States).
- Cloudflare — TLS termination, CDN, and optional Web Analytics on public pages.
- Resend — transactional email (welcome messages, password resets, feedback delivery).
- PostgreSQL (via Railway) — persistent database storage.
Data retention
- Account data, calls, and notes are retained until you delete them or delete your account.
- Account deletion is immediate — all calls, transcripts, notes, feedback, and Salesforce tokens are removed.
- Audio is never retained after transcription completes.
- Password reset tokens expire after one hour and are single-use.
Recording laws
- You are solely responsible for complying with applicable call recording laws in your jurisdiction.
- Many states and countries require all parties to consent before recording a call.
- CloseNote requires you to accept our Terms (including recording responsibility) before using call recording features.
- We are not liable for any legal issues arising from your use of call recording features.
Contact
- Privacy questions: [email protected]
- Security reports: [email protected]