Guide
Is Notion AI safe for confidential legal work? What it does with your data
Is Notion AI safe for confidential legal work? What Notion says it does with your data, what that does not settle, and a five-step AI policy for firms.
By Raghav R Handa, practising lawyer17 min read
TL;DR
- Notion states that neither it nor its AI subprocessors use customer data to train models, and that retention differs by plan: 30 days or fewer on non-Enterprise plans, zero data retention on Enterprise.
- Whether that is safe enough is a judgement about your data, your clients and your regulator, not a feature. Decide by data tier and by task, and write it down.
- The biggest practical risks are over-broad access, unverified output (including invented citations) and agents acting on untrusted content, not the vendor's training policy.
- Start with low-risk tasks, keep a lawyer reviewing every output, and write a one-page policy. ABA Formal Opinion 512 and equivalent guidance expect competence, confidentiality, supervision and honest billing.
Notion AI can be used for confidential legal work if you take reasonable steps, and Notion's published terms are better than many. Notion states that it and its AI subprocessors do not use customer data to train models. Whether that makes the tool safe for your matter is still your professional judgement, made by data tier and by task. This guide gives you what Notion says, what that does and does not settle, a task-by-task risk view, a verification routine and a policy. It is practical information, not legal advice.
What Notion says it does with your data
| Question | Notion's stated position (checked 2026-10-03) |
|---|---|
| Is customer data used to train models? | No. Neither Notion nor its AI subprocessors may use it, by contract. |
| How long do LLM providers keep data? | Non-Enterprise plans: 30 days or fewer. Enterprise: zero data retention. |
| Is my data mixed with other customers'? | Stated to be kept separate in production. |
| What happens to embeddings after deletion? | Deleted within 60 days of the page or workspace being deleted. |
| Can deleted content be restored? | Pages and workspaces can be restored for a period, after which data is deleted and unrecoverable. |
Source: Notion's AI security and privacy practices. Read the current version; vendors revise these pages, and the answers may differ by plan.
What that does not settle
- Retention is not zero on every plan. For highly sensitive matters, 30 days at a provider may be 30 days too many.
- AI sees what you can see. If an AI search or agent has access to a workspace, anything in that workspace is in scope. Broad workspace permissions mean broad AI reach.
- Connected sources widen it further. Connecting other apps so AI can search them extends the reach to those apps' content.
- Output is not advice. It can be fluent and wrong, including invented authorities.
- Your client may say no. Insurer, bank and government outside-counsel rules often restrict AI use.
- The professional duties are yours. Competence, confidentiality, supervision, candour and honest billing do not transfer to the vendor.
The risk model, in six parts
| Risk | What it looks like | Control |
|---|---|---|
| Data leaves your control | Content is sent to AI subprocessors for processing | Tier your data; keep tier 3 and 4 out; read the vendor statement; prefer plans with stronger terms for sensitive work |
| Over-broad access | An agent or search reads matters it should not | Restrict spaces; keep sensitive matters outside AI's reach; review connections |
| Hallucination | Invented facts, quotes or citations in output | Verify against primary sources; never file unverified output |
| Prompt injection | Text in a page or document steers an agent to do something unintended | Limit agent permissions and tools; review actions; do not let agents act on untrusted content unreviewed |
| Privilege and confidentiality arguments | A third party processed privileged content | Tier decisions; consent where appropriate; document your reasoning |
| Client restrictions | A client's guidelines forbid AI use | Record on the matter; filter AI workflows to skip restricted matters |
Decide by data tier
Use the same four tiers as in the client data guide:
| Tier | AI use |
|---|---|
| 1. Low (templates, procedures, anonymised precedents) | Yes, with review |
| 2. Ordinary client (matter status, notes, tasks) | Permitted under your policy, with review, unless the client restricts it |
| 3. Sensitive (privileged advice, draft pleadings, identity or health detail) | Case by case; informed client consent where appropriate; or keep outside AI |
| 4. Never | Never |
A task-by-task risk matrix
| Task | Risk | Why | Safeguard |
|---|---|---|---|
| Summarise an internal procedure into a checklist | Low | No client data | Review for accuracy |
| Search the firm wiki in plain English | Low | Internal knowledge | Check status and review date of results |
| Draft an internal status note from matter fields | Low to medium | Uses matter data | Lawyer review; stay within policy |
| Turn your own meeting notes into action items | Medium | May contain client detail | De-identify where policy requires; review |
| First outline of an internal memo | Medium | Reasoning may be flawed | Lawyer rewrites; verify authorities |
| Summarise a long client document | Medium to high | Confidential content processed | Tier check; client restrictions; verify summary |
| Draft a client email from matter notes | Medium to high | Tone, accuracy, confidentiality | Lawyer reviews and sends in their own words |
| Legal research and citations | High | Hallucinated authorities | Verify every citation in a primary source or citator |
| Draft a court filing | High | Candour duty; invented citations | Full verification; lawyer responsible |
| Analyse privileged advice | High | Privilege and confidentiality | Keep outside AI or obtain informed consent |
Prompt hygiene: use less than you think you need
Give AI the minimum the task needs. Where a task does not depend on identity, replace names and identifiers with roles, and remove details that could identify the client. For example, instead of "Our client Maria Gomez of 12 Elm Street is suing Acme Ltd for unpaid wages of $18,400", use "Our client (an employee) is claiming unpaid wages from the employer". De-identification is imperfect, because context can identify a client, so it reduces risk and does not remove it. Never rely on it for tier-3 matters.
Verification protocol for every output
- Facts: check each fact against the source documents.
- Quotes: confirm each quotation exists, word for word, in the source.
- Authorities: locate every case, statute and rule in a primary source or citator; confirm it says what the output claims and is still good law.
- Jurisdiction and date: confirm the law applies where and when you need it.
- Reasoning: read as you would a junior's work; do not assume it is right because it is fluent.
- Tone and confidentiality: check nothing is disclosed that should not be.
Courts have sanctioned lawyers who filed AI-generated submissions containing invented citations. The lesson is not that AI cannot help; it is that a lawyer who signs a document owns every word in it.
What the profession expects
ABA Formal Opinion 512 (2024) on generative AI covers competence, confidentiality, communication with clients, supervision, candour to tribunals and reasonable fees. Regulators in the UK, Canada, Australia, India and elsewhere have issued or are issuing their own guidance. Read yours. The constant themes: understand the tool, protect confidences, supervise the output, be candid with courts, and do not bill for time AI saved without thinking about how you charge. See the ABA Model Rules for cloud and AI and the ethics of using AI in legal practice.
Billing and fees
Time saved by AI raises a fee question. Common approaches: fixed or value-based fees that reflect outcomes and expertise (so AI efficiency benefits both sides), hourly billing only for time actually spent, and treating AI tool subscriptions as overhead unless the client agrees otherwise. Whatever you choose, be transparent in the engagement letter and never bill for time not spent.
Three scenarios
1. Summarising an internal procedure
A paralegal asks Notion AI to turn a long onboarding procedure into a checklist. No client data is involved. Low risk: review the checklist for accuracy and publish it to the wiki.
2. Summarising a privileged memo
A lawyer wants a summary of a privileged advice memo on a sensitive matter. This is tier 3. Options: do not use AI on it, keep the memo outside AI's reach, or obtain informed client consent after considering retention and your regulator's guidance. Record the decision either way.
3. An agent drafting a client email
An agent reads matter notes and drafts a status email. Risks: it reads more than intended, it produces an inaccurate statement, and a lawyer sends it unread. Controls: restrict the agent to the matter, require lawyer review before sending, and never let it send on its own.
A practical AI policy for a small firm
- List the tasks AI may help with and those it may not, using the matrix above.
- Start with public or de-identified material.
- Limit what AI can reach: keep your most sensitive matters in a space it cannot read, and review connections.
- Require a lawyer to review every output before it reaches a client or court.
- Record client restrictions on the matter, and filter AI workflows to skip them.
- Review the policy twice a year and whenever terms change.
A ready-to-adapt version is in the firm AI policy template, with client wording in the consent template. For the setup itself, see the best Notion AI setup for law firms.
If something goes wrong
Stop the workflow, preserve what happened, assess what was exposed or what error was made, and follow your duties on correcting a tribunal or informing a client. Add the lesson to your policy. See the incident steps in the client data guide.
More: AI for lawyers, Notion AI and agents, AI in Notion and the legal AI prompt library.
Frequently asked questions
Is Notion AI safe for confidential legal work?
It can be used safely if you take reasonable steps. Notion states that it and its AI subprocessors do not use customer data to train models, and that for non-Enterprise plans providers retain data for 30 days or fewer, while Enterprise uses zero data retention. Whether that is enough depends on the client, the data and your regulator's guidance, so decide deliberately, by data tier, and record why.
Does Notion AI train on my data?
Notion states that it and its AI subprocessors do not use customer data to train any models, and that contracts with those subprocessors prohibit it. Read the current statement on Notion's AI security page before relying on it, as terms can change.
Do I need client consent to use AI on their matter?
It depends on your jurisdiction and the circumstances. ABA Formal Opinion 512 on generative AI discusses when informing a client, or obtaining informed consent, is needed, particularly where confidential information is input into a tool. Check your own regulator's guidance and any client outside-counsel rules, and see the consent template.
Can I rely on Notion AI's answers?
No, not without checking. AI can produce plausible but wrong text, including citations to cases that do not exist. A lawyer remains responsible for verifying anything used in advice or filed with a court.
What is the difference between Notion AI and an AI agent?
Broadly, an AI feature answers or drafts in response to a prompt, while an agent can carry out multi-step tasks across your workspace and connected tools. Agents raise additional questions about what they can access and do, so scope their reach more tightly.
Can an AI agent be tricked by content in my workspace?
Yes, this is a recognised risk called prompt injection: text inside a page, document or web content can contain instructions that an AI system may follow. Limit what agents can reach and do, do not let them act on untrusted content without review, and check any actions they take.
What should I never put through AI?
Anything a client or regulator has said must stay out of AI systems, matters you have decided are too sensitive, credentials, and anything you would not put in any cloud tool. Start with public or de-identified material.
Can I bill clients for AI-assisted work?
You must not bill for time you did not spend, and fees must be reasonable. Many lawyers reflect the value delivered under a fixed or value-based fee, and treat AI tool costs as overhead unless agreed otherwise. ABA Formal Opinion 512 discusses fees; check your own rules.
How often should we review our AI settings?
At least twice a year, and whenever Notion's AI features, packaging or terms change, a client adds special requirements, or your regulator issues new guidance.
Related guides