Last updated: July 2026 (version 2026-07)
This Privacy Notice for Norian(“we”, “us”, or “our”) describes how and why we access, collect, store, use, and share your personal information when you use our services (“Services”). This notice applies when you visit norian.ai, use the Norian application, or otherwise engage with us.
Norian is a SaaS application that connects to your email account (Gmail and Microsoft Outlook) in read-only mode. It monitors email conversations with your clients, automatically detects unresolved commitments and requests, and sends you a daily digest notification. Norian never sends, modifies, or deletes emails on your behalf.
Questions or concerns? Contact us at privacy@norian.ai.
What we collect:Your email address and job title (from our waitlist form); your account name and email address (via OAuth from Google or Microsoft); subscription status from Stripe; usage analytics via PostHog; email metadata derived from your connected email account; and - when the “Scan contacts using personal email addresses” setting is enabled (on by default) - the email addresses of contacts who communicate with you via personal email services such as Gmail or Outlook.
What we do not collect: Raw email bodies (processed in memory only, never stored); sensitive personal data; payment card details (handled by Stripe directly).
Who we share it with: Only the service providers listed in section 4, under written data processing agreements. We never sell your data.
How long we keep it: For as long as your account is active. Data held by Norian is deleted within 60 seconds of account deletion, and access to your inbox is revoked within 24 hours.
Your rights: Access, rectify, erase, port, or object to processing of your data at norian.ai/settings or by emailing privacy@norian.ai.
Payment data. All payment processing is handled by Stripe. You can find their privacy notice at stripe.com/privacy. Norian receives only a customer ID and subscription status.
Sensitive information. We do not process sensitive personal information (health data, ethnicity, religion, biometrics, etc.).
Google API. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We process your personal information for the following purposes:
This section is primarily relevant to EEA, UK, and Swiss residents under the GDPR and equivalent laws.
Our role - controller and processor.For the core monitoring of your mailbox, you are the data controller of your clients' personal data and Norian acts as your processor, handling that data only on your instructions under a data processing agreement (see our Data Processing Agreement). For our own purposes - product analytics, security, and service improvement - Norian is an independent controller and relies on the legal bases below.
People who email you (your contacts). Your clients and contacts did not sign up for Norian. We process their names, email addresses, subject lines, and one-line summaries of their messages solely to surface commitments and requests to you. In the core monitoring flow we do this as your processor, on your legal basis as their controller; where Norian acts as its own controller (for example, security), the basis is our legitimate interest, balanced against their rights and freedoms.
Canada: We process your information on the basis of express or implied consent, or where otherwise permitted under applicable Canadian privacy law (PIPEDA / Law 25). You may withdraw consent at any time by contacting us.
We share personal information only with the sub-processors listed below, under written data processing agreements. We do not sell, rent, or trade your personal information.
| Provider | Purpose | Data shared | Location | Privacy policy |
|---|---|---|---|---|
| UniPile | Email API intermediary - OAuth token management and email access (Gmail and Outlook) | Encrypted OAuth token and message-level metadata (recipients, message/thread identifiers, timestamps, attachment indicators), retained while the account stays connected and deleted on revoke; email bodies accessed transiently in memory only, never persistently stored | EU - France / Scaleway | UniPile |
| Microsoft (Graph) | Direct API access to your Microsoft account, in read-only mode, for Outlook mail and any Microsoft Teams chats you designate for monitoring | Encrypted OAuth refresh token; email and Teams chat content accessed transiently in memory only, never persistently stored (only structured summaries are kept). Your tenant content stays in your tenant's geography | Microsoft global endpoint; EU tenant content stays in EU | Microsoft |
| Slack Technologies, LLC (a Salesforce company) | Slack Connect message processing for the Slack integration - reading commitments and requests from connected Slack Connect channels | Bot-token access to the Slack Connect channels you designate for monitoring; message content accessed transiently in memory only, never persistently stored (only structured summaries are kept) | United States; EU-US Data Privacy Framework (via Salesforce) + 2021 Standard Contractual Clauses | Slack |
| Scaleway | EU infrastructure hosting (UniPile's email-API service) | Hosting infrastructure for UniPile - encrypted OAuth token and account metadata | EU (France) | Scaleway |
| OpenAI | AI text analysis - commitment and request detection | Pre-processed one-line summaries only. No raw email bodies. No email addresses. | United States (SCCs apply) | openai.com |
| Supabase | Database hosting | Account data, extracted summaries, email metadata, subscription status | EU (Frankfurt) | supabase.com |
| Vercel | Application hosting | Application traffic, IP addresses, usage logs | EU | vercel.com |
| Stripe | Payment processing | Customer reference ID, subscription status. Stripe independently collects payment details - we never see them. | US / EU (SCCs apply) | stripe.com |
| Resend | Transactional email delivery | Your email address; digest notification content | EU | resend.com |
| PostHog | Product analytics | Anonymised usage events, IP address, browser type, account ID. No email addresses or names. | EU (eu.i.posthog.com) | posthog.com |
We may also disclose your information: (a) if required by law, court order, or governmental authority; (b) to protect the rights, property, or safety of Norian, our users, or the public; or (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and require the receiving party to honour this policy.
We use two categories of cookies:
We do not use advertising, targeting, or social media tracking cookies.
For full details, see our Cookie Notice: norian.ai/cookie-policy.
Yes. We use OpenAI's GPT-4o-mini to analyse email content and extract structured data about commitments and requests. This is central to the core functionality of Norian.
What happens to your email data during AI processing:
No automated decisions with legal effect. Norian's AI flags items for your review. You always decide what action to take. No automated decisions with legal or significant personal effects are made.
Opting out: AI processing is necessary to deliver the core service. To stop all processing, disconnect your email account or delete your account from norian.ai/settings.
Norian's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We access your Gmail account via read-only OAuth authentication using the gmail.readonly scope - the minimum necessary to provide the service. We access your emails solely to detect unresolved commitments and requests between you and your clients.
Specifically:
We access your Microsoft account via read-only OAuth authentication using the Mail.Read scope - the minimum necessary to provide the service. The same data handling principles apply:
Our primary infrastructure is EU-based (Netherlands). We transfer data to the United States via sub-processors including OpenAI (AI text analysis), Stripe (payment processing), Microsoft (Outlook mail and Microsoft Teams chat access via Graph), and Slack (Slack Connect channel access, via Slack Technologies, LLC, a Salesforce company).
These transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) in accordance with GDPR Article 46. Our SCCs and sub-processor agreements can be provided upon request at privacy@norian.ai.
We retain personal information only for as long as your account is active. Specific retention periods:
When you delete your account, all personal data held by Norian is permanently deleted within 60 seconds, and access to your inbox (via UniPile) is revoked within 24 hours. The only exception is the waitlist application record described above, which is pseudonymised (irreversibly hashed) immediately upon deletion and fully removed after 90 days. No other personal data is retained after account deletion, except where required by applicable law (e.g. tax or accounting obligations).
Our security measures include:
No electronic transmission or storage can be guaranteed 100% secure. If you become aware of a potential security issue, please notify us at privacy@norian.ai.
Under the GDPR and equivalent laws (EEA, UK, Switzerland, Canada), you have the right to:
To exercise your rights, visit norian.ai/settings or email privacy@norian.ai. We will respond within 30 days in accordance with GDPR Article 12.
If you believe we are unlawfully processing your personal data, you have the right to lodge a complaint with the Dutch data protection authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). UK residents may contact the ICO.
Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have additional rights including the right to know, access, correct, delete, and port your personal information, and to opt out of profiling or sale of personal data.
We do not sell personal data, use it for targeted advertising, or create consumer profiles.
| Category | Collected |
|---|---|
| A. Identifiers (email address, IP address, account name) | YES |
| B. Personal information (California Customer Records) - name, job title | YES |
| C. Protected classification characteristics | NO |
| D. Commercial information (subscription status) | YES |
| E. Biometric information | NO |
| F. Internet or network activity (usage analytics) | YES |
| G. Geolocation data (approximate, from IP) | YES |
| H. Audio, electronic, sensory information | NO |
| I. Professional information (job title) | YES |
| J. Education information | NO |
| K. Inferences / consumer profiles | NO |
| L. Sensitive personal information | NO |
To exercise your rights, visit norian.ai/settings or email privacy@norian.ai. To appeal a decision, email privacy@norian.ai. If your appeal is denied, you may contact your state attorney general.
California “Shine the Light”: We do not disclose personal information to third parties for their direct marketing purposes.
Free beta users have agreed, as a condition of free access, to participate in occasional feedback requests. This may include email surveys or short interviews. Participation in individual activities is voluntary beyond the initial consent. Beta access may be deactivated for accounts inactive for an extended period, in accordance with the beta participation agreement accepted at signup.
We may update this notice from time to time. The version date at the top of this document identifies the current version (format: YYYY-MM). We conduct an annual review in line with CASA recertification requirements.
For material changes - particularly those affecting how we process your email data or that require fresh consent under GDPR - we will notify you by email and display a notice within the application before changes take effect. Continued use of the service after notification constitutes acceptance. If you do not accept material changes, you may disconnect your email account or delete your account from norian.ai/settings.
For privacy-related enquiries, data subject requests, or questions about this notice:
Email: privacy@norian.ai
Post: Norian, Ruyschstraat 31A, Amsterdam, Noord-Holland 1091 BS, Netherlands
We aim to respond to all privacy enquiries within 30 days. For data subject access requests under GDPR, you may also use the self-service tools at norian.ai/settings.
To report a security vulnerability or suspected data breach, email security@norian.ai immediately. We are required to notify the Autoriteit Persoonsgegevens of qualifying breaches within 72 hours.