Skip to content

Privacy

Last updated: [date of publication]

This is a small service run by one person. This policy is short because the service collects little, and it is specific because a privacy policy that could describe any product describes nothing.

What this service does

You give it a link, a file, or a recording you make in the app. It turns the speech into text, separates the speakers, and — where somebody introduces themselves — names them. It gives you the text back. It does not summarise, analyse, translate or edit, and it does not do anything with your recordings except transcribe them.

What we hold about you

Your account. Your email address, your display name and your profile picture's web address, all of them from Google or Apple when you sign in. Nothing else. We do not ask for a password because we do not have one, we do not ask for a phone number, and we never see a payment detail because there is nothing to pay for.

Your transcripts. The text, the speaker separation, the timings, and — for a link — the title and address of what you transcribed. These are yours and we keep them until you delete them. There is no expiry and nothing removes them on its own.

Your audio. For as long as it takes to transcribe it, and then at most 24 hours longer. See the next section, which is the part of this policy that matters most.

A record of what the service did. How long each recording was, how long the work took, which machine did it, and what it cost. This is how the service is run and how a problem gets answered. It contains no part of what was said.

Your audio is deleted, and here is exactly what that means

When a transcript is finished, the original audio is scheduled for deletion 24 hours later. An automatic job deletes it and records that it did. If you delete a run or your account, the audio is deleted at once — and guaranteed within the hour, because the same job is the backstop.

This is enforced by a job that runs every hour, not by our intentions. The storage it deletes from keeps no previous versions, has no copies in other regions, and expires anything left behind after three days on its own. We check every day that no audio has outlived its deadline, and if any has, we are alerted.

When you delete your account, we do not mark it deleted until your audio is actually gone. If we cannot delete it, we tell you rather than showing you a screen that says it worked.

We do not keep a library of your recordings. There is no player, no archive, and no way — for you, for us, or for anyone else — to listen to something you transcribed last week.

Who can see what

Other users cannot see anything of yours. Accounts are separated by the database itself, not by a rule in our code that somebody might forget to write. There is no sharing, no team, and no public transcript.

The person who runs this service can read a transcript — to answer a support question, to investigate a failure, or when required to. Every time that happens it is recorded, permanently, in a log that cannot be edited or deleted by anyone, including him. If you ask what has been read, that log is the answer.

Where your audio and words go

Transcription happens on rented GPUs that start for your job and shut down when it finishes. Your audio is sent there, processed, and discarded with the machine.

Some accounts are set up to use the operator's own computer instead. Only accounts explicitly enabled for it, which by default means the operator's own. Your account screen tells you which applies to you, and if you were not told, it does not.

Naming speakers uses an outside model. If you ask for speakers to be named, the first few minutes of the transcript are sent to a language model provider to look for introductions. Nothing identifying you goes with it — not your name, not your email, not your account. The provider is contracted not to keep it or train on it. You can turn this off for any run with one checkbox, and then nothing you said leaves this service at all.

If you set up a destination, we send finished transcripts to it. That is an address you gave us, for a system you chose. We sign every delivery so the receiving system can tell it is really from us. We do not send anything to a destination somebody else registered — ever, for any reason.

That is the complete list. There is no analytics service, no advertising network, no tracking pixel, and no third party receiving anything about you that is not named above.

What we do not do

Cookies

One, plus two that exist for seconds while you sign in. The sign-in cookie cannot be read by JavaScript, is only sent over an encrypted connection, and is only sent to this site. It lasts 30 days, or 7 days for an administrator, and signing out deletes it immediately. There is no analytics cookie and no third-party cookie of any kind, so there is no consent banner to click, because there is nothing to consent to.

Your choices

After you delete your account, four things remain and none of them contains anything you said or any way to contact you: a record that the account existed, a record of how much the service was used, the log of what an operator did, and a receipt for each piece of audio that was deleted saying when. They exist so that our own records of what we did cannot quietly disappear along with the account, and they are kept indefinitely.

Security

Everything is encrypted in transit. Audio is encrypted where it is stored, and is deleted within 24 hours. Passwords do not exist. API keys and sign-in tokens are stored in a form we cannot reverse — if our database were stolen, no key or session in it would work.

If something goes wrong and your data is affected, we will tell you what happened, what was reached, and when — within 72 hours of knowing. That is a commitment, not an aspiration, and it holds whether or not any law requires it in your case.

Children

This service is not for people under 16 and we do not knowingly hold an account for one.

Where this happens

Your data is processed and stored in [region, once settled]. If you are outside it, using the service means your data is transferred there.

Changes

If this policy changes in a way that affects what happens to your data, you will be told before it takes effect — by email, not by a quietly updated date at the top of a page.

Contact

[contact address]. For a privacy question, a request for a copy, a deletion request you would rather not do yourself, a report about content, or anything else in this document.