1. Introduction
Notary Advisor ("we," "us," or "our") operates notary-advisor.com and our AI product NORA (Notary On-Demand Resource Assistant). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
By using our platform, you agree to the collection and use of information as described in this policy. If you do not agree with the terms of this policy, please do not use our service.
2. Information We Collect
2.1 Information You Provide Directly
- Name (first and last)
- Email address
- Password (hashed and encrypted — we never store plaintext passwords)
- Phone number (optional, for profile)
- Business name and address (optional, for profile)
- Professional profile: notarization volume, work setting, specialty, years commissioned, employer type
- Profile picture and company logo (stored in Supabase Storage)
- Commission expiration date and commission number
- Referral source ("How did you hear about us?")
2.2 Information Collected Automatically
- Questions you ask NORA (stored verbatim for quality and compliance purposes)
- NORA responses (stored in full)
- Citations referenced in each response
- Input method (typed or voice)
- Ratings you give NORA responses (thumbs up / thumbs down)
- Session data: device type, browser user agent, login timestamps
- Question subject category (auto-tagged asynchronously by AI)
- UTM parameters and referral codes from URLs at signup
- Last active date and total session count
2.3 Payment Information
We use Stripe to process payments. We do not store your credit card number, CVV, or billing address on our servers. Stripe handles all payment data under their own PCI-DSS compliance program.
2.4 Cookies and Tracking
We use the following cookies and tracking technologies:
- Authentication cookies (Supabase): Required for login sessions. These are essential and cannot be disabled.
- Analytics (PostHog): We use PostHog to track product usage, page views, and feature adoption. This helps us improve the platform.
- UTM attribution cookies: Session-based cookies that track how you found us. These expire when you close your browser tab.
We do not use advertising cookies. We do not sell your data to advertisers. We do not allow third-party advertising networks on our platform.
3. How We Use Your Information
- To provide and operate the Notary Advisor platform and NORA
- To process your subscription and manage billing through Stripe
- To send transactional emails (account confirmation, password reset, commission expiry reminders) via Resend
- To improve NORA's accuracy and compliance guidance
- To analyze usage patterns and improve the platform (PostHog analytics)
- To identify potential enterprise customers based on employer type patterns (aggregate analysis only)
- To notify you when NORA becomes available in your state (waitlist)
- To comply with applicable laws and prevent fraud
4. How We Share Your Information
We do not sell your personal information. We share data only with the following service providers who process it on our behalf:
- Supabase (database, authentication, file storage) — supabase.com
- Anthropic (AI responses via API) — anthropic.com — see Section 6 for AI data handling
- Stripe (payment processing) — stripe.com
- Resend (transactional email) — resend.com
- PostHog (product analytics) — posthog.com
- Vercel (hosting and infrastructure) — vercel.com
Each provider is bound by their own privacy policy and data processing agreements. We do not share your individual question history with any third party except as described above.
5. Enterprise White Label Accounts
If you access Notary Advisor through an employer or enterprise account (e.g., a title company or law firm subdomain), your questions and usage data may be visible in aggregate to your organization's administrator. Individual question text is hidden from enterprise administrators at the database level via Row Level Security. Only Notary Advisor platform administrators can view full question content for quality assurance purposes.
6. AI Data and Anthropic
NORA is powered by Anthropic's Claude AI via their API. When you ask NORA a question, the text of your question and relevant context from our knowledge base are sent to Anthropic's API to generate a response.
Under Anthropic's standard API terms, data submitted via the API is not used to train Anthropic's models by default. You can review Anthropic's privacy policy at anthropic.com/privacy.
We recommend you do not include personally identifiable information about third parties (such as signers' names or ID numbers) in your NORA questions.
7. Data Retention
- Account data: Retained for the life of your account plus 30 days after deletion
- NORA question history: Retained for the life of your account to power your usage history and improvements
- Payment records: Retained for 7 years as required by tax law
- Waitlist entries: Retained until your state launches and you convert, or until you unsubscribe
- Deleted accounts: Personal data removed within 30 days; anonymized usage data may be retained
8. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Data portability: Request your data in a machine-readable format
- Opt-out of analytics: Contact us to opt out of PostHog tracking
To exercise these rights, email legal@notary-advisor.com. We will respond within 30 days.
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information is collected and how it is used
- The right to delete personal information
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your CCPA rights
To submit a CCPA request, email legal@notary-advisor.com with the subject line "CCPA Request."
10. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS for all connections)
- Encryption at rest (Supabase database encryption)
- Row Level Security (RLS) policies on all database tables
- Hashed passwords (we never store plaintext passwords)
- API keys stored as server-side environment variables (never exposed to browsers)
Despite these measures, no system is 100% secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access.
11. Children's Privacy
Notary Advisor is intended for professional notaries public and is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on our platform. The "Last Updated" date at the top of this policy reflects the most recent revision.
NORA is an educational tool, not legal counsel. This Privacy Policy does not constitute legal advice.