ScribeFlash

Legal

ScribeFlash privacy policy

This policy explains how ScribeFlash handles personal information and Customer Content when providing interview transcription, evidence management, AI analysis, research reports, and subscriptions.

Effective
August 30, 2026
Last updated
August 30, 2026
  • You retain your rights in uploaded content and research outputs; we process them only to provide, secure, and improve the Service.
  • Interview materials may contain sensitive participant information. You must obtain required permissions and choose an appropriate retention period before uploading.
  • Product controls let you correct profile data, export data, set media retention, delete projects, and request account deletion.
  • We do not currently sell personal information or share it for cross-context behavioral advertising.

1. Scope and roles

This policy applies to the ScribeFlash website, accounts, research workspaces, interview transcription, evidence and report tools, subscriptions, and support (the “Service”). It does not cover independently operated third-party services.

The ScribeFlash service operator controls account, website, and operational data. For interviews, transcripts, participant details, and research content uploaded by a business customer, that customer generally determines the purposes and means of processing and ScribeFlash processes data on its instructions. The operator's legal name, registered address, and applicable contact details are stated on the Contact page or in your order or data processing agreement.

2. Participant data and your responsibilities

Do not upload recordings, media, or personal information unless you have authority to process them. You must give required notices and obtain valid permission for recording, transcription, AI analysis, international processing, and retention where applicable.

Interview data can reveal health, identity, financial, location, child, or other sensitive information. Minimize such data, use it only with an appropriate legal basis, and apply stronger controls. ScribeFlash does not create voiceprints or face templates for identity recognition; if that changes, we will provide separate notice and obtain consent where required.

3. Information we collect

Depending on how you use the Service, we collect:

  • Account and identity data, including name, email, securely hashed password, login method, account identifiers, language, and time zone. Google sign-in provides the identifiers and basic profile data you authorize.
  • Profile and organization data, such as first and last name, job title, company, working language, and notification preferences.
  • Customer Content, including project goals, research questions, participant labels, audio and video, source URLs, transcripts, speakers, timestamps, glossaries, notes, evidence, tags, AI suggestions, findings, counter-evidence, reports, exports, and edit history.
  • Usage and device data, such as access times, feature actions, processing status, quotas, browser and device type, IP address, request identifiers, errors, and security logs. We do not intentionally place access tokens, refresh tokens, or full OAuth credentials in client logs.
  • Transaction data, including plan, billing interval, order status, amount, currency, and payment-provider transaction identifiers. Payment providers normally process full card details directly; ScribeFlash does not store full card numbers.
  • Communications and support information you provide in feedback, troubleshooting, or rights requests.

4. Sources of information

We receive data directly from you, from the organization managing your account, automatically through use of the Service, or from services you choose to connect, such as Google sign-in and payment providers. Participant data in Customer Content is usually uploaded by a customer rather than the participant.

If you use an organization account, its administrators may manage your account, access workspace content, and set retention or deletion rules. Ask your organization about its own privacy practices.

5. Purposes and legal bases

We process information only where an applicable legal basis exists, including:

  • Contract: account creation, authentication, uploads, storage, transcription, evidence and report generation, exports, billing, support, and retention settings.
  • Consent: optional marketing, non-essential cookies, sensitive processing that requires separate consent, or another optional purpose we describe. Withdrawal does not affect earlier lawful processing.
  • Legal obligations: tax and accounting records, lawful requests, privacy-rights responses, and compliance with data-protection and consumer laws.
  • Legitimate interests or reasonable operational needs: security, fraud and abuse prevention, troubleshooting, aggregate usage measurement, reliability, and proportionate product improvement, balanced against individual rights.
  • Vital interests or establishing, exercising, and defending legal claims where permitted.

6. Transcription, AI, and automated processing

To perform requested transcription, summaries, topic extraction, evidence suggestions, cross-interview analysis, and report generation, we may send necessary audio, video, transcript text, research questions, and context to contracted transcription or AI providers.

AI output can be inaccurate, incomplete, or biased. ScribeFlash distinguishes suggestions from researcher-confirmed content and preserves source references for review. You must review output before relying on or sharing it. The Service does not use AI to make solely automated decisions with legal or similarly significant effects about individuals.

Unless we give clear notice and obtain authorization required by law, we do not use Customer Content to train general-purpose generative AI models offered to the public. Provider use is governed by our contracts, selected enterprise settings, and applicable provider terms.

7. Sharing and disclosure

We do not sell personal information. We disclose only what is reasonably necessary to:

  • Cloud hosting and object-storage providers, including Cloudflare R2 or equivalent infrastructure for media uploads and storage.
  • Transcription and AI providers that perform a task you request.
  • Authentication, email, support, monitoring, and security providers. Google handles Google sign-in interactions under its own policy.
  • Payment and subscription providers for checkout, renewal, refund, tax, and fraud prevention.
  • Your organization's administrators, authorized workspace members, or export recipients you choose.
  • Authorities, courts, regulators, or transaction counterparties where required by law, needed to protect rights and safety, or reasonably necessary for a merger, financing, reorganization, or asset transfer.

8. Cookies and similar technologies

We use strictly necessary cookies for authenticated and refreshed sessions and account security. These cookies are generally HttpOnly and sent over secure connections in production. Language can be determined by the URL or interface selection.

We currently do not deploy cookies for cross-site advertising profiles. A hosted login or checkout page may set cookies necessary for that third-party service. If we introduce non-essential analytics or marketing technologies, we will update this policy and provide choices where required.

9. International transfers

ScribeFlash and its providers may process information outside your country. We use contracts, access controls, encryption, and other lawful transfer mechanisms required by applicable law, and provide additional notice, consent, or assessments where required.

Organizations uploading data protected by China, EEA, UK, or other transfer rules must ensure they have a lawful transfer basis and may contact us for applicable processing arrangements.

10. Retention and deletion

We retain data for the shortest reasonable period needed for the purposes above, considering plan and project settings, contracts, security, disputes, and legal obligations. Account data and project structures, transcripts, evidence, and reports generally remain while the account is active unless deleted or otherwise agreed.

Current media-retention choices include deletion after processing or retention for 7, 30, 90, or 365 days; projects may have a separate policy. Available options can vary by plan. Project deletion first disables access and then queues cleanup of associated media, exports, cache, and content.

After account deletion or a valid erasure request, unnecessary data is deleted or de-identified. Isolated disaster-recovery backups expire through normal rotation. Limited tax, anti-fraud, dispute, or security records may be retained longer with restricted access and use.

11. Security and incident response

We apply safeguards proportionate to risk, such as encryption in transit, protected session cookies, least-privilege access, short-lived or signed upload URLs, server-side authorization, redacted logs, separation controls, and deletion workflows. No internet system is completely secure.

We assess, contain, document, and notify affected users or regulators of qualifying incidents as required by law. Use a strong password, protect your devices, and report suspicious access promptly.

12. Your privacy rights

Depending on location, you may have rights to notice, access, copy, correct, supplement, delete, restrict or object, withdraw consent, portability, information about automated processing, and complaint to a regulator. EEA and UK users may object to legitimate-interest processing where applicable; eligible US state residents may have access, correction, deletion, sale/share opt-out, and non-discrimination rights.

Use account settings to update a profile, request export, set media retention, or request deletion, or submit a request through the Contact page. We may verify identity, account ownership, and authorized-agent authority. Legal exceptions, other people's rights, trade secrets, and reasonable technical limits may apply.

Because ScribeFlash currently does not sell personal information or share it for cross-context behavioral advertising, no sale/share opt-out link is currently required. We will provide required notice and controls before that practice changes.

13. Children

The Service is for professional users able to contract and is not directed to children under 16. If research involves a minor, you must obtain guardian authorization and other required consent and use stricter minimization, access, and retention controls.

If you believe a child provided account information without proper authorization, contact us so we can verify and take reasonable deletion steps.

14. Changes and contact

We may update this policy as features, providers, or laws change. The date above will change, and material updates will receive reasonable notice through the site, product, or account email. We will request consent before effectiveness where required.

Use the ScribeFlash Contact page to exercise rights, ask about processing, or report a security concern. For participant requests involving an organization workspace, we may direct the request to the customer organization that determines the processing purposes.

Submit a request through our Contact page. We may verify your identity and authority before responding.

Go to Contact
Privacy Policy for Research Data | ScribeFlash