← Back to all vendors
productivity

Notion

notion.so

3 flagged clauses across 3 risk dimensions

A
πŸ€–

AI training

1 flag
  • Severity 4
    "By using our Services, you grant us a worldwide, non-exclusive, royalty-free license to use your content to improve our products, including for the training of machine learning models."

    Notion can use anything you put in their product to train their AI models, with no end date and no payment to you.

    If you handle confidential customer data, this clause exposes that data to model training pipelines you do not control.

πŸ”„

Auto-renewal

1 flag
  • Severity 3
    "Subscriptions automatically renew at the end of each billing period at the then-current rate unless cancelled."

    Notion renews you at whatever the price is at the time, with no requirement to warn you about increases.

    You can be locked into significantly higher pricing at renewal without explicit consent.

    Matches FTC v. Vonage β€” settled for $100M (2022)
πŸ’Έ

Price hikes

clear

No flags in this category.

🌍

Data residency

clear

No flags in this category.

πŸšͺ

Termination friction

clear

No flags in this category.

βš–οΈ

Liability caps

clear

No flags in this category.

πŸ›‘

Indemnification

clear

No flags in this category.

πŸ‘»

Silent term changes

1 flag
  • Severity 4
    "We reserve the right to modify these Terms at any time. Continued use of the Services constitutes acceptance."

    Notion can change the rules whenever they want, and just continuing to use the product is treated as agreement.

    You have no real veto over future changes. Any clause they add later applies to you retroactively.

Recent changes detected

Sep 2, 2024

Notion added OpenAI and Anthropic as sub-processors and quietly removed the EU-only residency guarantee for workspaces using AI features. EU customer data now routes to US-based AI providers regardless of the workspace's stated region.

EU companies on Notion paying for the AI add-on (or using free AI features) β€” their data is now flowing to US sub-processors, putting GDPR Schrems II compliance at risk.