data report card

Data Report Card · Notion

Notion Data Report Card

Workspace · notes & docs
Data
Practices
1Access2Portability1Friction1Deletion1Sells2Trains AI
=
C
8/12
Agent
Readiness
1Access 2Portability 2API access
=
B
5/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

Help me make a request →
Reviewed Jun 2026 · policies are checked weekly for changes  ·  stated — every cell is read from Notion's published policy; none has been tested (run by us) yet.
1Accessstated
Self-serve export covers only content you authored; the personal data Notion holds about you (account, logs, analytics) is request-only via privacy@makenotion.com with identity verification — no self-serve rights portal.
Notion — Privacy Policy §6 · accessed Jun 2026 ↗
2Portabilitystated
Any user can self-serve Export all workspace content to Markdown, CSV (databases) and HTML with uploaded files — structured and machine-readable.
Notion — Export your content · accessed Jun 2026 ↗
1Frictionstated
Export and deletion are self-serve but asynchronous (emailed link, valid 7 days); formal access/deletion rights run through email with no self-serve portal, inside the statutory window.
Notion — Privacy Policy §6 · accessed Jun 2026 ↗
1Deletionstated
Self-serve account deletion purges your private workspace (30-day backup window), but content you created in shared workspaces owned by others persists on removal, with no stated anonymization.
Notion — Delete your account · accessed Jun 2026 ↗
1Sells / sharesstated
Notion’s third-party ad/analytics cookies "may be considered a ‘sale’ or ‘sharing’ under the CCPA"; a "Do Not Sell or Share My Info" opt-out is offered in the footer.
Notion — Privacy Policy §12 · accessed Jun 2026 ↗
2Trains AIstated
"By default, Notion and its AI Subprocessors do not use Customer Data to train any models"; training is opt-in only, with contractual bars on subprocessors.
Notion — AI security & privacy practices · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
A public OAuth 2.0 API lets any user authorize a third-party app to read, create and update nearly all workspace content — pages, databases, comments — available to non-enterprise users; it is a content-integration API, not a data-rights mechanism.
Notion — Developers (public API / OAuth) · accessed Jul 2026 ↗
Source-verified Jul 2026 from Notion’s own pages. All cells are "stated" (read from published policy and help docs); no live export or deletion has been run to mark any cell "tested."

How to request your data from Notion

  1. Go to https://www.notion.so — Notion's data-request entry point.
  2. Settings → General → Export all workspace content (emailed link); DSAR via privacy@makenotion.com.
  3. Expected wait: no firm published response window; export link valid 7 days — Notion's stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact Notion — privacy@makenotion.com: privacy@makenotion.com.

These steps reflect Notion's documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.