Nnotrai

Legal · Privacy

Privacy Policy

Last updated September 3, 2026

Notrai.com provides California Notary Public education approved by the California Secretary of State. This policy describes what personal information we collect, why, who receives it, and the rights you have over it under California law. It is written to describe what the application actually does rather than to reserve the broadest possible permissions.

What we collect

CategoryWhy we have it
Account details — name, email addressTo create and secure your account. Held by our authentication provider, not in our own database.
Payment detailsProcessed entirely by Stripe. We never see or store your card number.
Government photo ID — type, number, expiration, issuing state or countryUsed to establish the identity of a student receiving a Proof of Completion, under the procedures CCR § 20800.1(d) requires. CCR §§ 20800.5(c)(3) and 20800.6(a)(6) require these details on the certificate and on the list of attendees. The ID number is encrypted at rest.
Course records — time on task, quiz responses, scores, completionRequired by CCR §§ 20800.1(e) and 20800.5(b) to evidence the six (or three) hours of instruction the state mandates (Gov. Code § 8201).
Tutor conversationsTo answer your questions and to show your own history back to you.
Marketing-site analyticsTo understand which pages bring people to the course. See Advertising and analytics.

We never collect Social Security numbers

CCR § 20800.6(b) states: “An approved vendor shall not collect the social security numbers of any attendees.” No field for one exists anywhere in this application. If you are ever asked for an SSN by someone claiming to be notrai, it is not us.

Your course records are restricted by law

Under CCR § 20800.6(c), the attendee list and the information in it may be released only to the California Secretary of State, a District Attorney, a city attorney, or the Attorney General.

That restriction is stricter than an ordinary privacy promise and we treat it as a hard boundary. Your name, photo-ID details, identity-verification records and course completion are not shared with advertisers, analytics providers, data brokers, or partners — not in aggregate, not pseudonymised, not ever. We are required to retain the list of attendees, with your name, your photo-ID details and whether you were issued a Proof of Completion, for two years from the date of your Proof of Completion.

Who else receives data, and why

  • Clerk — authentication. Holds your email and login credentials.
  • Stripe — payments. Holds your billing details; we hold only a record that a purchase occurred.
  • Didit — identity verification. Performs the government photo-ID check required for a certificate.
  • Neon — database hosting for course records.
  • Crisp — the support chat widget, if you use it.
  • An AI provider — the tutor sends your question and recent quiz context to a language-model provider to generate an answer. It is never sent your legal name, photo-ID details, or identity-verification records; those fields are excluded in code rather than by policy.

Advertising and analytics

On our public marketing pages only, we may use Meta, Google Ads and Google Analytics to measure which pages lead people to enrol and to show ads to people who visited without enrolling. Under the CPRA this counts as sharing personal information for cross-context behavioral advertising, and we disclose it as such.

These tags do not load anywhere inside your account. They are absent from the dashboard, the course, the exam, the tutor and the certificate pages. No advertising network receives a page view, URL or identifier from any page that could indicate you are a student, what you scored, or that you obtained a certificate.

We do not sell personal information for money, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.

Do Not Sell or Share My Personal Information

You can opt out of the advertising described above in either of these ways.

  • Global Privacy Control (automatic). If your browser or an extension sends a GPC signal, we honour it automatically — the advertising and analytics tags are not loaded at all, so there is nothing to remove after the fact. You do not need to contact us.
  • By email. Write to support@notrai.com with the subject “Do Not Sell or Share” and we will apply the opt-out to your account.

Your California rights

Under the CCPA/CPRA you may request to know what personal information we hold about you, request its deletion or correction, opt out of sharing for advertising, and not be discriminated against for exercising any of these rights. Email support@notrai.com and we will respond within the statutory period.

One limit worth stating plainly: we cannot delete course records we are legally required to keep. CCR § 20800.6(a) obliges us to keep the list of attendees, including whether each attendee was issued a Proof of Completion, for two years from the date of issuance. A deletion request will be honoured for everything outside that obligation, and we will tell you exactly what was retained and why.

Security

Photo-ID numbers are encrypted at rest. Access to course and identity records is restricted to administrators and to auditors authorised by the Secretary of State. Payment card data never touches our systems.

Contact

notrai — California Secretary of State–approved notary education vendor, certificate nos. 608712 (six-hour) and 308732 (three-hour).
404 W. 4th Street, Santa Ana, CA 92701
support@notrai.com

See also our Refund Policy.