Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from Notion's published policy; none has been tested (run by us) yet.
1Accessstated
Self-serve export covers only content you authored; the personal data Notion holds about you (account, logs, analytics) is request-only via privacy@makenotion.com with identity verification — no self-serve rights portal.
Notion — Privacy Policy §6 · accessed Jun 2026 ↗
1Frictionstated
Export and deletion are self-serve but asynchronous (emailed link, valid 7 days); formal access/deletion rights run through email with no self-serve portal, inside the statutory window.
Notion — Privacy Policy §6 · accessed Jun 2026 ↗
1Deletionstated
Self-serve account deletion purges your private workspace (30-day backup window), but content you created in shared workspaces owned by others persists on removal, with no stated anonymization.
Notion — Delete your account · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
A public OAuth 2.0 API lets any user authorize a third-party app to read, create and update nearly all workspace content — pages, databases, comments — available to non-enterprise users; it is a content-integration API, not a data-rights mechanism.
Notion — Developers (public API / OAuth) · accessed Jul 2026 ↗
Source-verified Jul 2026 from Notion’s own pages. All cells are "stated" (read from published policy and help docs); no live export or deletion has been run to mark any cell "tested."