Do you record my calls?
No. CallNote does not record calls, does not join your meetings and does not store call audio. It works from a transcript that already exists: one you paste, upload or forward by email, or one your phone or meeting system has already made. For Aircall, Dialpad and Microsoft Teams we fetch the written transcript only.
There is one place where audio is involved. If you use the voice memo option, you dictate your own recap after a call or meeting. That audio is sent to Deepgram, a speech-to-text service, and comes back as text. We do not save the audio file. We send it with Deepgram’s model improvement program switched off for that request, and Deepgram says it keeps opted-out audio only for as long as it takes to process it.
We do keep the transcript text. It is stored with your note, so there is a record of what the note was written from.
Where is my data kept?
Your account, transcripts, notes and audit log are stored in a database hosted by Supabase on Amazon Web Services in Sydney (region ap-southeast-2). The app itself runs on Vercel, with its server functions set to run in Sydney.
Supabase states that customer data is encrypted at rest with AES-256 and in transit with TLS. CallNote is served over HTTPS only. The tokens that connect CallNote to your phone system or CRM are encrypted again, with AES-256-GCM, before they are saved.
Stored in Sydney does not mean nothing leaves Australia. Writing a note, sending an email and a few other jobs are done by providers overseas. They are listed next.
Who else handles it?
These are the companies we use to run CallNote, what each one receives and where it is. Where a provider is outside Australia, we say so.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database and sign-in | Everything you keep in CallNote: account details, transcripts, notes, earlier versions and the audit log. | Sydney, Australia (Amazon Web Services, region ap-southeast-2) |
| Vercel | Runs the website and the app | Requests to CallNote pass through it, including the transcripts and notes in them. It keeps technical logs of requests and errors. | Our server functions are set to run in Sydney. Vercel is a United States company with a global network. |
| Anthropic | Writes the note, using its Claude AI models | The transcript and your note template. If you build a template from a past note, that note too. | Outside Australia. Anthropic is a United States company. |
| Deepgram | Turns a voice memo into text | The audio of a recap you dictate yourself. Only if you use the voice memo option. | Outside Australia. Deepgram is a United States company. |
| Postmark | Receives emails you forward to your CallNote address | The forwarded email, including the transcript in it. Only if you use Email-in. | Outside Australia. Postmark is run by a United States company. |
| Resend | Sends our emails to you | Your email address and the emails we send: sign-in codes, team invites, billing notices and summaries that count your notes. Not the text of your notes. | United States. Resend has no Australian region. |
| Stripe | Takes payment | Your billing details. You enter card details on a page run by Stripe, so they do not pass through CallNote. | Outside Australia. Stripe is a United States company. |
| Sentry | Tells us when something breaks | A technical report of the error. Cookies and sign-in details are left out and screen recording is off. If a request fails part way through, the report can include part of that request, which may include transcript text. | United States |
| PostHog | Counts how the product is used | Page addresses with record numbers removed, a fixed list of event names such as "note generated", and a random account ID. No names, emails, notes or transcripts. | European Union |
Systems you connect are your choice. When you publish a note to HubSpot, Microsoft Dynamics 365 or Clio, or send one to Slack, Notion or Zapier, the note goes to that system under your own account with them.
Who can see my notes?
Every record in CallNote belongs to one firm, and the database will not return one firm’s records to another firm’s account.
Inside a firm, a member sees only the notes they created. Owners and admins see every note in the firm. The same rule covers the transcripts behind those notes, their earlier versions and the audit log. These rules are enforced in the database itself, not only on the screens.
Access to the production database is restricted to CallNote staff who need it to run or support the service.
Can a note be changed after it is published?
Yes, but not quietly. When you publish a note it is sealed with a SHA-256 checksum, and who published it and when are recorded. Those publish details cannot be changed afterwards.
The database refuses any change to the text of a published note unless it comes with a new seal and a new amendment time. When you edit a published note in CallNote, the earlier version is kept and the amendment is written to the audit log with the old and new checksums. The transcript behind a published note is locked.
The audit log records actions such as a note being generated, edited, published, amended, exported or deleted, and changes to your team and connections. Audit log entries cannot be edited or deleted from inside CallNote.
Is my data used to train AI?
No. We do not train AI models on your data, and we do not build AI models of our own.
Notes are written by Anthropic’s Claude models through Anthropic’s commercial API. Anthropic’s published policy is that, by default, it does not use what is sent through its commercial API, or what comes back, to train its models. Voice memo audio is sent to Deepgram with its model improvement program switched off.
What we never do
- We do not sell or rent your data, and we do not use it for advertising.
- We do not read your notes for analytics. Our analytics only accepts a fixed list of fields, such as which page was opened or that a note was generated. It does not record your screen or what you type.
- We do not see your card number. Payment details are entered on a page run by Stripe.
- We do not send your password to a breach-checking service. When you choose a password, your browser checks it against a public list of passwords found in data breaches, and only the first five characters of a scrambled version of it leave your device for that check.
How do I delete my data?
You can export a note to PDF from the note screen.
Deleting notes is switched off to begin with, so a record cannot be removed by accident. An owner or admin can switch it on in Settings. When a note is deleted, the audit log keeps a permanent entry of the deletion, which includes the note’s title and a copy of the first part of its text.
To close your account and have your data deleted, email privacy@callnote.com.au. There is no button for this in the app yet, so a person does it. Our privacy policy sets out how long it takes and what we may be required to keep.
What we do not claim
CallNote does not hold a security certification such as ISO 27001 or SOC 2, and we will not imply that we do. CallNote is built to help you keep the records your work needs. It does not make you compliant with any law, and nothing on this page is legal advice.
How to report a security concern
If you think you have found a security problem, or something on this page does not match what you see in the product, email hello@callnote.com.au. A person who works on the product reads it. Please do not include client information in the email.
Try it on your next five calls.
Paste a transcript and see your file note. Never records. Built in Australia.
