Show HN: Personal CRM: Note taking, the way it should be
nat.app
nat.app
We're a bootstrapped team of 4 four and we've been building our personal crm app for over a year. As the original founder and CEO, I've been waiting for this day for a loooong time! I finally love my own app and use it on a daily basis (hopefully you will too).
We've already launched a long time ago but today we're launching a new feature: Note taking, straight from your inbox.
We email you before every meeting with all the notes you've taken about the person you're going to meet and you simply have to reply to the email to log a note! Making it the easiest way to build your database of notes about your contacts.
I know that there are tons of people who tried to build a personal CRM and that everyone has his opinion on how the "right" personal crm should work.
Personally, we've decided that: - it should be fully automated (sync with calendar and email) - super simple to use (no complex and clunky interface) - it should be magic (our app tells you who you're losing touch with based on your data)
And you? What are you looking for in a personal crm?
The note taking app within email is free and directly accessible, there are multiple calls to action on the page but here is a shortcut to get started: https://calendar.nat.app
Our paying/main app (the personal crm app that tells you who you're losing touch with) is on a request-only basis because it works with Gmail and we're limited in the number of users we can onboard for now.
Hope that clarifies things!
I strongly disagree with your tag line. I think the only way such note taking should be is open source and completely private, otherwise a) you're locked in and b) you risk sensitive info leaking.
We found that you have to look at those things like a scale: Open source <------> Ease of use
We've decided to focus on the ease of use but there are of course many other note takings apps focusing on the other side :)
https://news.ycombinator.com/showhn.html
I read it as referring to unfinished products that doesn't yet exist. What if you're making a Google Calendar extension? Wouldn't that be allowed as a Show HN?
Thanks!
Privacy and security. And your privacy assurances/policies are woefully insufficient.
> Your Gmail data is only used by machines. Our team won't read or access any of your email data unless you explicitly ask for it (for support for ex.)
"Won't" means nothing. The word you're looking for is "can't"
> By default, we don't share any data with third parties. The only exception to this rule is Mixpanel, our analytics apps, which receives information about how you use our app only.
Yeeaaaaah your privacy policy directly states that if you're acquired or go out of business, user data will be transferred or sold.
> As required by Google, the authentification tokens we use to retrieve your Gmail data are safely encrypted in our database.
"We do what is required" isn't convincing me you take privacy seriously, and...encrypted how? A password in the database server's config file?
> Access to production environments is limited to authorized team members only.
And....who are authorized team members? "Authorized team members" could mean "the entire engineering and QA teams, plus the marketing intern collecting demographic data reports."
Your statement doesn't distinguish between user data and the production environment as a whole, it doesn't commit to strictly keeping access to production AND user data to the bare minimum required.
> We use the industry-standard 256-bit encryption with SSL.
...like everyone else? This does not inspire faith that your company has exemplary network security if you think this is worth mentioning.
> Key passwords are updated on a quarterly basis to reduce risks.
You think quarterly password rotation is a noteworthy, or even effective, security practice? You're using passwords as your sole authentication for employees? O_o
You make no mention of your policies with regards to law enforcement. Do you commit to only releasing data when served with a warrant or subpoena, or can Officer Bob call you up and explain how he's investigating a Really Bad Person and you'll hand over their data? Seems the answer is yes, you will:
> "Nat discloses potentially personally-identifying and personally-identifying information only in response to a subpoena, court order or other governmental request, or when Nat believes in good faith that disclosure is reasonably necessary to protect the property or rights of Nat, third parties or the public at large."
What country is your organization incorporated in? What country is user data kept in and thus what laws is it subject to? Is the data stored in the cloud? A server in your uncle's basement?
You make no mention of systems to assure only a minimum number of designated employees have the access they need when they need it. IE a support team member cannot access a customer's data unless there is an open case verified as initiated by the customer.
You make no mention of how data or whether data is encrypted; it seems only gmail auth tokens are?
You should be using hardware token 2FA for critical employee access and 2FA everywhere else...not rotating passwords quarterly. You should be using vaults for every password used in production. All access should be logged and audited by an outside party.
We'll review your comment with the team this week and update our pages accordingly.
But really, we're not trying to pretend something and actually use data is a bad way.
We want to build a long term business that is totally based on trust and we really appreciate comments like yours that show that we still have a long way to go in the way we explain the use of our data.
Thanks again, I'll update this post once we've improved our /privacy page based on your comments.
When it comes to privacy, people actually want to know that YOU can't be exploited to giving information. If you can access something, what prevents someone from hacking your system and getting our data? That's the point, not your intent. It's that you are an attack vector now. What are you doing to mitigate this?
We're really doing everything we can to make sure the data you share with us is safe. Encrypting google access tokens, updating passwords regularly and using 2FA are a few examples.
But then, we're not un-hackable of course. Risk 0 does not exist and that's something every user is and should be aware of.
We don't have the same budget for security as big companies and even they get hacked.
I do not think that we host the kind of data that a hacker would like to acquire. Notes we take are usually pretty low-risk data. This is what protects us the most probably.
Please don't minimize this. You lose trust when you minimize a valid concern.
> Risk 0 does not exist
If someone is willing to educate you on the matter, they might already know such trivial things. Which is why I initially said 'what are you doing to minimize this'. You mentioned some above. I'd encourage you to look into more techniques to minimize it even further. This would build trust with whom you are asking to spend money with you.
"Usually".
The notes I take sometimes contain PII (personally identifying information) about other people, sometimes notes about things I'm investigating for someone that they would be distressed to find had ended up "on the internet", and sometimes commercial secrets (about jobs, clients etc that they share with me under NDA). And I'm just a lowly programmer and dogsbody doing random client work.
Now consider a therapist finds your product useful for their personal notes, and doesn't realise what they are getting into.
That would end up a small version of this awful incident: https://news.ycombinator.com/item?id=24886039
> I do not think that we host the kind of data that a hacker would like to acquire
Hackers don't tend to go for data they would find valuable themselves.
They go for data the author of the data finds valuable for themselves (which notes may be by definition), or just as likely, specifically don't want anyone else to read. An example of the former is all those ransomware attacks. An example of the latter is the above link to the private notes blackmail incident.
Trust on today's Internet? With regards to personal data? Facebook kinda poisoned the well for you there, /methinks.
Complete non-starter for me. So many reset flows go through email these days that your primary email is the keys to the kingdom.
I could set up a specific email account on my domain just for nat.app but the whole point of this CRM is that it's in the same flow as the rest of my email, isn't it?
We where discussing our main app, a personal crm that connects with Gmail.
The app we're sharing on HN today is our note taking app that only requires access to your calendar data of course!!
You only need to give us a read-only access to your calendar in order to use our note taking app inside of your Gmail. Hope that clarifies things!
Although good and constructive criticism, it is harsh on a team that is trying to launch something into this world, and scares off other users considering this service. I bet one could go through the privacy statement of a large co like youtube / facebook and nitpick similar issues. Of course it should be aligned, although i think it never is, a privacy statement is definitely not a reflection of how good a product’s security is.
Best of luck to you and your team!
I'm sure you wouldn't litter in a city park or dump motor oil into a lake, so please don't do the analogical things on HN.
What makes us special is that: - you can write notes from your inbox without having to open a web app or so - you get those notes in an email before your next meeting
If you care more about being able to draw/record, ... then evernote is a much better option.
That's why we've decided to focus on Gmail, GCAlendar, SMS and Phone calls :)
I am not working on the app now as I haven't figured out how to make money on it yet. However I will leave this idea here because I think that you guys should consider offering end-to-end encrypted notes (even just as an option for some selected notes).
I had a call with him about this and he clearly explained to me how hard it was to implement and all the compromises you have to make. In our case, as we want to offer the most effortless experience, end-to-end encryption is going to be hard, but we definitely want to get there at some point.
We're already encrypting some data though :)
What makes our note taking tool special is that we send you an email before every meeting with all the notes you've taken about the person you're about to meet. Then you can simply write a new note by replying to the email.
This is why the calendar integration is required. Hope that makes sense!
Edit: Keyloggers which send your data to a third party service.
The dismissiveness in your other comments on this post show, at best, a huge amount of naivety. If you're hiring, make sure your next technical hire is a (rational) security paranoiac.
>You don't need to open a new tab, just reply to the email to take notes.
Why reply to an email when I can just open a new tab in my editor? These both seem to be the same level of effort. Landing page doesn't explain why this solution is better.
> We'll send you an email before your meetings with all the notes you've taken about all the people that are present at the meeting. Automatically figure out who you're losing touch with and reconnect! We have built an algorithm that analyses your email and calendar data to figure this out.
These features seem to be your edge. Give them a spot light with a demo. Maybe a user-flow that showcases these features to give people an idea of why this note taking experience is better for them.
No. Mine.
This is flirting. Show me why I should be interested before I bare my soul.
2) um, what's the name? Is it personal CRM? (that doesn't appear in big font anywhere). nat.app? (I only see that in the url and email addresses). something else?
1) If your admin allows it you're fine. We work with G Suite as well. What concerns do you have? Please check out https://nat.app/privacy to understand how we treat your data, to summarize: - Your data is never accessed by a human - We don't share it with any third parties - Your data is safely stored and sent to you when needed (aka. before your next meeting). That's it.
If you're fine writing down notes into a web app, sending them per email is the same level of safety/security.
2) Its Nat indeed. We were previously called Nat Bot (initially we tried to build a chatbot, but pivoted a bit. Nat it is :)
Which seems to be a template text?
In the big enterprise world, you don't even get to ask your admin if it's fine. Every answer is a "no" by default unless you have an extremely compelling case. Sharing data outside of the network is a major no-no for certain industries (like mine, which is Financial Services)
> sending them per email is the same level of safety/security.
Not exactly. My company logs every e-mail I send / receive, but not every HTTP request. If we're ever sued, the e-mails may show up in court, but not HTTP.
And if you're ever sued, what happens to the data I e-mailed?
Thanks for sharing! That will definitely impact us if we want to sell to enterprise. But to be honest, we don't plan on going into that direction.
We're bootstrapped, so no big pressure on getting really big. We're super happy to just become a profitable business that our users enjoy, à la Basecamp.
A self-hosted option that the company can install on a VM somewhere would be the only option for 99.999% of meetings.
This is indicative of a broader trend in how software is distributed in the enterprise. Whereas software was traditionally purchased tops-down (i.e. CIO purchasing decision), today's software products are increasingly product-led & bottoms-up (i.e. end user purchasing). Classic examples include Dropbox, Slack and now Notion, Airtable, etc.
I realize the cloud is where all the sexy people try and make money today, but...I'm worn out by slight variations on the same old pitch: 'here's a database with a UI, and we'll host the database!'.
AKA - I learned how to make a CRUD app - pay me money (or your data) for it!
What I don't like are "personal productivity applications", because those seem like they are created by people without imagination. Making another TODO app with email remainders, quantified self, CRM's to manage connections with friends and family.
Those kind of apps that are created by "self improvement nerds" for people like them. Problem is those apps never solve any real world issues. Because people who are self improvement nerds would rather build their own system and people who don't care about it won't use it.
For me those apps are in category of self improvement books. Where for most of the people investment in self improvement system quickly goes above return on that investment. Just when you start tweaking your .vimrc and at the end of the day instead of doing work you just played with your settings.
Using such tools and tweaking those will quickly end up in using tool instead of actually living ones life. When you know your uncle Ted does not like you, using system that reminds you about his birthday is not going to change that. You are not going to become millionaire by using some system that "millionaires use". Using Elon Musk time management is not going to make you successful owner of multiple companies if you are working 9-5 drone job.
But to me at least, building a CRUD app that makes someone's life 10x better is worth a lot :) (even though our app is much more than just a crud app!)
The automatic reminders to read and type notes via emails solves a problem that I expect many people have with taking these kinds of notes: remembering to write them after meetings and remembering to read them before meetings.
Make one that saves everything to my Github account and then we'll talk.
This means we're far less likely to sell and regarding profitability, we're sharing our revenues transparently here: https://www.indiehackers.com/product/nat-bot.
Worst case scenario how long are you keeping this running at $34/mo+me revenue?
So while I appreciate you mentioning your business and financial aspirations, please remember the time when that, now famous, VR company had a kickstarter. Later - "journey thingie", "we have the same goals", "synergy" etc happened to them at Facebook.
In fact, in the case of WhatsApp a poor cofounder wasn't even able to see what Facebook planned to do with WhatsApp, something almost everybody was able to see with their eyes closed, when they took the billions (happy for them). He is now a respected billionaire born again privacy crusader. Nice guy.
On another note: personally I have been moving my notes to Standard Notes. nv -> nvAlt -> Apple Notes -> Simplenote -> Standard Notes (I wish these guys had native apps).
Bear is a solid app and I wanted to pay but they are not FOSS. I am also keeping an eye on https://github.com/glushchenko/fsnotes (native and promising).
https://github.com/serhii-londar/open-source-mac-os-apps#not... some more.
In order to sync across devices, I use Standard Notes, which also implements end to end encryption of your data.
There's a self-hosted open source version. And there's a paid version to host on their servers, which I've used for a few years now and have never had an issue with.
If you like the plain text format (with option to use Markdown), you might like it. For me, the benefit is when I have random things throughout the day I realize I need to do. I add it to my phone, and I then immediately have it on all of my Linux and Mac desktops and laptops. I also live in the mountains and frequently take notes while out of cell/wifi service and syncing has still been great.
But things like collaborative editing become impossible with this model. Or maybe i don't know enough.
I want to be able to access the notes. At all times. If I've got battery power, I should have my notes. Even Evernote screws this up sometimes if you're on a slow (not down) network
I've switched to Joplin myself because it just syncs every so often. My notes aren't hidden behind some bloated app that struggles with high latency and as a bonus my central storage is my NAS over WebDAV (and Tailscale to access it everywhere I have internet access)
Monica is fully manual. You have to add every interaction manually and open their web app if you want to add a note. We're much more integrated and proactive: you'll receive an email before every meeting with all the notes about the person you'll meet in that meeting for example.
Our main app also tells you who you're losing touch with based on your data. Monica is really a sexy database, we add some "magic" on top of that.
But 20k is a steep price :/ especially for a bootstrapped company like us.
Some might say Google is trying to prevent small companies to innovate upon Gmail...
Don't "wait". Do something about it.
P.S. Hate "waiting" mindset
Don't forget to budget in the fact that it's annual...
It's a valid concern and getting vetted by a security company will be a huge plus!
Especially given the privacy concerns raised by other comments.
Just to clarify for readers, to use our note taking app, you only need to sync your calendar. Syncing gmail is only requires to use our paying personal CRM app as we use this data to find out who you're losing touch with (but we only access metadata, we can't read your emails).
Either way - it's a huge chunk of change. Would be happier if it were on the lower end of that price range for sure.
1 - https://support.google.com/cloud/answer/9110914?hl=en#Securi...
Small typo in one of your images ( exec.png ) reads: "lastest notes about Marvin"
It's missing a definite logo with a name.
Nat App?
Personal CRM?
If I was to Google this? How would I find it?
Simply search for nat.app or "nat personal crm"
I have to Sync to get started? AI involved to reach out? No thank you! I prefer you not to mess with this information.
Our main personal crm syncs with Gmail and uses an AI in order to find out who you're losing touch if that's what you mean.
"be we can't" -> "but we can't"
- Take notes in markdown format
- Commit to a private Github/GHE repository