90 Days Gen AI Risk Trial -Start Now
Book a demo
Productivity·Free; Plus $10/user/mo; Business $20/user/mo (AI included); Enterprise custom·notion.so

Notion AI

Notion AI is an in-workspace assistant that writes, summarizes, searches, builds autonomous agents, and transcribes meetings across the Notion docs and database platform.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Notion AI is embedded across Notion's docs, wiki, and database surface, offering writing assistance, Q&A over workspace content, Enterprise Search across connected apps (Slack, Drive, GitHub), AI Meeting Notes, and agentic workflows via Notion Agent and Custom Agents. Notion is SOC 2 Type 2, ISO 27001/27701/27017/27018, and BSI C5 certified. Enterprise plans offer HIPAA BAA, zero data retention with LLM subprocessors, SCIM, and audit logs. AI subprocessors are contractually prohibited from training on customer data.

Risk factors

3
  • Integrates with user-generated content, potentially sharing data
  • Cloud-based service with third-party data handling
  • User data may be used for training and improvement

Recommendations

2
  • Evaluate data processing agreements
  • Consider opt-out options for training data usage

Data handling

Storage
AWS US-based primary infrastructure with multi-region replication; TLS 1.2+ in transit, AES-256 at rest. Subprocessors include OpenAI and Anthropic for AI features.
Retention
30-day retention with LLM subprocessors on non-Enterprise plans; zero data retention on Enterprise. Workspace data retained until user deletion.
Training on inputs
AI subprocessors contractually prohibited from using customer data to train models; no customer-data training by Notion.