Notion A.I CyberSecurity Scoring
Notion
Company Information
Website:https://notion.com
Employees number:5,221
Number of followers:934,589
NAICS:5112
Industry Type:Software Development
Homepage:notion.com
Notion Risk Score (AI oriented)
Between 650 and 699
NotionSoftware Development
Updated:
04/05/2026
04/05/2026
693/1000
Weak
B
Notion Global Score (TPRM)
xxxx
NotionSoftware Development
Score locked

NotionWeak
Current Score
693B (WEAK)
01000
2 incidents
-47 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
697
MAY 2026
693
APRIL 2026
697
Vulnerability
22 Apr 2026 • Notion
Notion: Notion public pages found leaking user emails and profile pictures
Notion Privacy Leak Exposes User Metadata in Public Pages
693
CRITICAL-4
NOT1776839801
Notion Privacy Leak Exposes User Metadata in Public Pages
A recent investigation has revealed a privacy risk in Notion, the widely used productivity platform with tens of millions of users. Cybersecurity researchers found that publicly shared pages may inadvertently expose personal metadata of collaborators, including usernames, profile images, and email addresses.
The issue stems from Notion’s design when users publish pages without restrictions, the platform includes internal metadata alongside visible content. While this behavior is intentional, researchers argue that its privacy implications are often overlooked by users, who may not realize they are exposing sensitive details.
The vulnerability affects both individual users and organizations that rely on Notion for public documentation, knowledge bases, or shared repositories. Any unrestricted page could potentially leak contributor data, raising concerns about unintended exposure.
Notion initially defended its practices, stating that users were warned about metadata exposure during publishing. However, researchers demonstrated that these warnings were not consistently displayed in the interface. Following public backlash, the company acknowledged the issue, with spokesperson Max Schoening calling the current behavior "unacceptable." Notion is now exploring solutions, such as removing personal identifiers from public API responses or implementing email masking, similar to GitHub’s approach.
While the company works on a fix, the incident highlights the broader risks of metadata exposure in collaborative platforms.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
785
Breach
20 Mar 2026 • Notion
Notion, Slack, Google, Zoom, Nikkei and Workday: Your work apps are quietly handing 19 data points to someone
Workplace Apps Collect Extensive User Data, Raising Privacy and Security Concerns
695
CRITICAL-90
WORNOTGOOZOONIKTIN1777868873
Workplace Apps Collect Extensive User Data, Raising Privacy and Security Concerns
A recent study by Incogni, analyzing data from the Google Play Store as of March 20, 2026, reveals that ten widely used workplace apps including Gmail, Microsoft Teams, Zoom Workplace, Slack, and Notion collect an average of 19 data points per app, with some sharing sensitive information with third parties. These apps, cumulatively downloaded over 12.5 billion times, are integral to U.S. corporate operations but pose significant privacy and security risks.
Data Collection and Sharing Practices
Gmail leads in data harvesting, collecting 26 distinct data types, including approximate location, app interactions, and user IDs for advertising. Microsoft Teams and Zoom Workplace follow closely, with 25 and 23 data types, respectively both uniquely gathering precise location data. Six of the ten apps, including Slack, Notion, and Zoom Workplace, use collected data for marketing, with Slack, Todoist, and Notion specifically harvesting employee email addresses for this purpose.
Notion stands out for its outbound data flow, sharing eight data types such as email addresses, names, and device IDs with third parties, including advertising partners. The app’s privacy policy permits tracking tools on user browsers, raising concerns over the exposure of sensitive workspace content like HR records and client data. Regulatory scrutiny has intensified, particularly after the EU’s Data Protection Board tightened GDPR requirements in December 2024 regarding personal data use in AI training, directly impacting Notion’s third-party model integrations.
Security Vulnerabilities and Breach History
Most apps in the study have a history of breaches. In January 2026, a 96-gigabyte database containing 149 million login credentials 48 million tied to Gmail was exposed, attributed to infostealer malware on user devices. Slack suffered a November 2025 breach where attackers used stolen credentials to access accounts of over 17,000 Nikkei employees, exposing names, emails, and chat histories. Trello, Zoom, and Microsoft products have also faced incidents, with Trello data appearing for sale in January 2024.
Workday is the only app in the analysis without a user data deletion option, despite holding employment records and payroll details. In August 2025, the platform confirmed two breaches linked to its Salesforce CRM, where attackers obtained business contact information as part of a ShinyHunters social engineering campaign.
BYOD Risks and Platform Disparities
Many employees install these apps on personal devices, exposing contact details, financial data, and location information to advertising networks or corporate administrators. Slack, for example, lacks end-to-end encryption, allowing workspace owners to access direct messages and private channels. While the study focuses on Google Play data, Incogni notes that iOS disclosures may differ, though past comparisons suggest similar privacy practices across platforms.
The findings highlight the trade-offs between workplace productivity and data exposure, with recurring breaches and extensive tracking underscoring the risks of integrating these tools into daily operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
785
JANUARY 2026
785
DECEMBER 2025
785
NOVEMBER 2025
785
OCTOBER 2025
785
SEPTEMBER 2025
785
AUGUST 2025
785
JULY 2025
785
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Notion ??
What was Notion's A.I Rankiteo Cyber Score in May 2026 ??
What was Notion's A.I Rankiteo Cyber Score in April 2026 ??
What was Notion's A.I Rankiteo Cyber Score in March 2026 ??
What was Notion's A.I Rankiteo Cyber Score in February 2026 ??
What was Notion's A.I Rankiteo Cyber Score in January 2026 ??
What was Notion's A.I Rankiteo Cyber Score in December 2025 ??
What was Notion's A.I Rankiteo Cyber Score in November 2025 ??
What was Notion's A.I Rankiteo Cyber Score in October 2025 ??
What was Notion's A.I Rankiteo Cyber Score in September 2025 ??
What was Notion's A.I Rankiteo Cyber Score in August 2025 ??
What was Notion's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Notion's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Notion ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Notion's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?