Evernote
evernoteEvernote is a note-taking and content-storage service operated by Bending Spoons entities. The consumer terms are user-favorable on content ownership (users retain copyright) and include a notable pro-user commitment not to use AI Feature Input/Output to train models unless directed. However, the terms grant Evernote a broad, sub-licensable, transferable, irrevocable license over user Content; impose mandatory individual arbitration with a class-action waiver; disclaim warranties broadly; and permit advertising and third-party sharing. The privacy policy claims GDPR alignment but names no third-party security certifications (no SOC 2, ISO 27001, etc.), and the collected data includes significant PII plus optional sensitive categories (device identifiers, location, contacts, audio/video). Review is advised before storing sensitive or proprietary data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain copyright and pre-existing rights in the Content they upload, and Evernote acknowledges it obtains no ownership beyond a limited operational license. This is a user-favorable ownership position.
Output Data Ownership
The consumer terms treat all uploaded material as 'Content' owned by the user but do not separately address ownership of AI-generated output beyond a reference to 'Input or Output from an AI Feature' in the privacy policy. Feedback and derived information tied to Early Access Services and Contributions are claimed by Evernote, creating some ambiguity around generated or derived material.
Training Data Usage
The privacy policy makes an explicit, user-favorable commitment not to use AI Feature Input or Output to train its AI models unless the user directs it to. It also states that automatic analysis powering features does not require anyone to view Content.
Data Retention & Deletion
Users can close their account at any time, upon which Content is deleted automatically and becomes unrecoverable. However, the documents provide no specific retention schedule, no deletion SLA, and no security-related retention obligations, and note that content may be retained where legally required.
Third-Party Data Sharing
Evernote engages service providers, resellers, and payment processors, and the license grant permits passing Content rights to contractual partners for service provision. It may also display third-party advertising and share data for marketing/advertising purposes, though disclosure exists and the policy states it does not sell data outright. The breadth of the sub-licensable/transferable Content license and ad-related sharing warrants moderate concern.
Opt-Out Rights
The policy provides several concrete opt-out mechanisms: unsubscribing from promotional communications, changing contact preferences in account settings, opting out of personalized ads via the Cookie Notice, and a 30-day window to opt out of the arbitration agreement. These are limited in scope but explicitly available.
Compliance & Certifications
The privacy policy explicitly claims compliance with the GDPR and Italian Legislative Decree 196/2003, and references a data controller and Data Protection Officer, but no third-party security certifications (SOC 2, ISO 27001, ISO 42001, etc.) are named or attested. As a consumer_general tool, it is assessed against the universal baseline plus COPPA (minors); COPPA-relevant language exists but no certification. No independent audit evidence is provided, so compliance is claimed rather than certified.
Model Explainability & Auditability
The documents provide no information on model explainability, transparency into AI behavior, or enterprise auditing of AI features. Beyond stating automated analysis powers features and a no-training commitment, there is no disclosure supporting auditability. Silence on this topic is a risk signal.
Security Practices & Breach History
The policy references security features such as two-step verification and encryption and commits to notifying users of a breach, and analyzes content to detect spam and malware. However, no specific technical controls (encryption at rest/in transit specifics, penetration testing, bug bounty) are detailed, no certifications are cited, and no breach history is disclosed. A security tips page is referenced but not a full trust center.
Enterprise vs. Consumer Risk Delta
The consumer documents indicate free vs. paid tiers differ in features and limits, and that Enterprise accounts are governed by separate agreements where an Administrator may control End User data. The consumer terms note free users do not receive all subscriber benefits, but no enterprise agreement was supplied to confirm materially different data handling. The delta is acknowledged but not fully specified.
Human Review of User Inputs
Evernote states no one views Content unless the user gives permission or it is legally necessary, and customer support access is subject to user consent. However, it reserves the right to ask permission to review portions of Content to refine features, and systems automatically analyze emails and shared notes for security. Human review is limited and consent-gated but not entirely foreclosed.
Regulatory & Litigation Exposure
The documents disclose that Evernote will disclose information in response to legal process and enforceable government requests, including to law enforcement, and reference a section on responding to legal requests. The terms also impose mandatory individual arbitration, a class-action waiver, and a one-year claim limitation period, which shift dispute-resolution risk toward the user. No active litigation is disclosed.
PII & SPI Data Inventory
Evernote collects significant PII (email, billing/payment info, IP address, device identifiers including IMEI/SIM, location, usage data, contacts) and optional categories that can be sensitive (mobile geolocation, audio/video recordings, photos, telephone number, calendar). Collection is disclosed with stated purposes and much is opt-in, but the breadth of identifiers and potential sensitivity of user-stored Content warrant moderate concern.
Policy–Product Currency
Both the Terms of Service and Privacy Policy carry an Effective Date of January 1, 2026, which is well within 12 months of the analysis date, and the privacy policy addresses AI Features and a no-training commitment, showing awareness of current AI capabilities. However, no PRODUCT SURFACE was supplied to verify coverage of the shipped product, so under the insufficient-evidence rule the rating is capped at YELLOW.
Cross-Document Consistency
Two documents were supplied and analyzed (Terms of Service and Privacy Policy). They are consistent with one another on ownership, data location, arbitration, and third-party engagement, with the privacy policy elaborating on data handling addressed generally in the Terms. No contradictions were identified between the two documents.
You've read all 15 risk ratings for Evernote. Create a free account to see the exact policy wording behind each rating.