Evernote logo

Evernote

evernote
Moderate Risk
Updated August 4, 2026

Evernote is a note-taking and content-storage service operated by Bending Spoons entities. The consumer terms are user-favorable on content ownership (users retain copyright) and include a notable pro-user commitment not to use AI Feature Input/Output to train models unless directed. However, the terms grant Evernote a broad, sub-licensable, transferable, irrevocable license over user Content; impose mandatory individual arbitration with a class-action waiver; disclaim warranties broadly; and permit advertising and third-party sharing. The privacy policy claims GDPR alignment but names no third-party security certifications (no SOC 2, ISO 27001, etc.), and the collected data includes significant PII plus optional sensitive categories (device identifiers, location, contacts, audio/video). Review is advised before storing sensitive or proprietary data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Low Risk

Users retain copyright and pre-existing rights in the Content they upload, and Evernote acknowledges it obtains no ownership beyond a limited operational license. This is a user-favorable ownership position.

Confidence
90%

Output Data Ownership

Moderate Risk

The consumer terms treat all uploaded material as 'Content' owned by the user but do not separately address ownership of AI-generated output beyond a reference to 'Input or Output from an AI Feature' in the privacy policy. Feedback and derived information tied to Early Access Services and Contributions are claimed by Evernote, creating some ambiguity around generated or derived material.

Confidence
55%

Training Data Usage

Low Risk

The privacy policy makes an explicit, user-favorable commitment not to use AI Feature Input or Output to train its AI models unless the user directs it to. It also states that automatic analysis powering features does not require anyone to view Content.

Confidence
80%

Data Retention & Deletion

Moderate Risk

Users can close their account at any time, upon which Content is deleted automatically and becomes unrecoverable. However, the documents provide no specific retention schedule, no deletion SLA, and no security-related retention obligations, and note that content may be retained where legally required.

Confidence
60%

Third-Party Data Sharing

Moderate Risk

Evernote engages service providers, resellers, and payment processors, and the license grant permits passing Content rights to contractual partners for service provision. It may also display third-party advertising and share data for marketing/advertising purposes, though disclosure exists and the policy states it does not sell data outright. The breadth of the sub-licensable/transferable Content license and ad-related sharing warrants moderate concern.

Confidence
65%

Opt-Out Rights

Low Risk

The policy provides several concrete opt-out mechanisms: unsubscribing from promotional communications, changing contact preferences in account settings, opting out of personalized ads via the Cookie Notice, and a 30-day window to opt out of the arbitration agreement. These are limited in scope but explicitly available.

Confidence
78%

Compliance & Certifications

Moderate Risk

The privacy policy explicitly claims compliance with the GDPR and Italian Legislative Decree 196/2003, and references a data controller and Data Protection Officer, but no third-party security certifications (SOC 2, ISO 27001, ISO 42001, etc.) are named or attested. As a consumer_general tool, it is assessed against the universal baseline plus COPPA (minors); COPPA-relevant language exists but no certification. No independent audit evidence is provided, so compliance is claimed rather than certified.

Confidence
70%

Model Explainability & Auditability

High Risk

The documents provide no information on model explainability, transparency into AI behavior, or enterprise auditing of AI features. Beyond stating automated analysis powers features and a no-training commitment, there is no disclosure supporting auditability. Silence on this topic is a risk signal.

Confidence
40%

Security Practices & Breach History

Moderate Risk

The policy references security features such as two-step verification and encryption and commits to notifying users of a breach, and analyzes content to detect spam and malware. However, no specific technical controls (encryption at rest/in transit specifics, penetration testing, bug bounty) are detailed, no certifications are cited, and no breach history is disclosed. A security tips page is referenced but not a full trust center.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The consumer documents indicate free vs. paid tiers differ in features and limits, and that Enterprise accounts are governed by separate agreements where an Administrator may control End User data. The consumer terms note free users do not receive all subscriber benefits, but no enterprise agreement was supplied to confirm materially different data handling. The delta is acknowledged but not fully specified.

Confidence
50%

Human Review of User Inputs

Moderate Risk

Evernote states no one views Content unless the user gives permission or it is legally necessary, and customer support access is subject to user consent. However, it reserves the right to ask permission to review portions of Content to refine features, and systems automatically analyze emails and shared notes for security. Human review is limited and consent-gated but not entirely foreclosed.

Confidence
68%

Regulatory & Litigation Exposure

Moderate Risk

The documents disclose that Evernote will disclose information in response to legal process and enforceable government requests, including to law enforcement, and reference a section on responding to legal requests. The terms also impose mandatory individual arbitration, a class-action waiver, and a one-year claim limitation period, which shift dispute-resolution risk toward the user. No active litigation is disclosed.

Confidence
65%

PII & SPI Data Inventory

Moderate Risk

Evernote collects significant PII (email, billing/payment info, IP address, device identifiers including IMEI/SIM, location, usage data, contacts) and optional categories that can be sensitive (mobile geolocation, audio/video recordings, photos, telephone number, calendar). Collection is disclosed with stated purposes and much is opt-in, but the breadth of identifiers and potential sensitivity of user-stored Content warrant moderate concern.

Confidence
72%

Policy–Product Currency

Moderate Risk

Both the Terms of Service and Privacy Policy carry an Effective Date of January 1, 2026, which is well within 12 months of the analysis date, and the privacy policy addresses AI Features and a no-training commitment, showing awareness of current AI capabilities. However, no PRODUCT SURFACE was supplied to verify coverage of the shipped product, so under the insufficient-evidence rule the rating is capped at YELLOW.

Confidence
50%

Cross-Document Consistency

Low Risk

Two documents were supplied and analyzed (Terms of Service and Privacy Policy). They are consistent with one another on ownership, data location, arbitration, and third-party engagement, with the privacy policy elaborating on data handling addressed generally in the Terms. No contradictions were identified between the two documents.

Confidence
70%

You've read all 15 risk ratings for Evernote. Create a free account to see the exact policy wording behind each rating.