1. Scope and roles
This policy applies to the ScribeFlash website, accounts, research workspaces, interview transcription, evidence and report tools, subscriptions, and support (the “Service”). It does not cover independently operated third-party services.
The ScribeFlash service operator controls account, website, and operational data. For interviews, transcripts, participant details, and research content uploaded by a business customer, that customer generally determines the purposes and means of processing and ScribeFlash processes data on its instructions. The operator's legal name, registered address, and applicable contact details are stated on the Contact page or in your order or data processing agreement.
2. Participant data and your responsibilities
Do not upload recordings, media, or personal information unless you have authority to process them. You must give required notices and obtain valid permission for recording, transcription, AI analysis, international processing, and retention where applicable.
Interview data can reveal health, identity, financial, location, child, or other sensitive information. Minimize such data, use it only with an appropriate legal basis, and apply stronger controls. ScribeFlash does not create voiceprints or face templates for identity recognition; if that changes, we will provide separate notice and obtain consent where required.
3. Information we collect
Depending on how you use the Service, we collect:
- Account and identity data, including name, email, securely hashed password, login method, account identifiers, language, and time zone. Google sign-in provides the identifiers and basic profile data you authorize.
- Profile and organization data, such as first and last name, job title, company, working language, and notification preferences.
- Customer Content, including project goals, research questions, participant labels, audio and video, source URLs, transcripts, speakers, timestamps, glossaries, notes, evidence, tags, AI suggestions, findings, counter-evidence, reports, exports, and edit history.
- Usage and device data, such as access times, feature actions, processing status, quotas, browser and device type, IP address, request identifiers, errors, and security logs. We do not intentionally place access tokens, refresh tokens, or full OAuth credentials in client logs.
- Transaction data, including plan, billing interval, order status, amount, currency, and payment-provider transaction identifiers. Payment providers normally process full card details directly; ScribeFlash does not store full card numbers.
- Communications and support information you provide in feedback, troubleshooting, or rights requests.
4. Sources of information
We receive data directly from you, from the organization managing your account, automatically through use of the Service, or from services you choose to connect, such as Google sign-in and payment providers. Participant data in Customer Content is usually uploaded by a customer rather than the participant.
If you use an organization account, its administrators may manage your account, access workspace content, and set retention or deletion rules. Ask your organization about its own privacy practices.
5. Purposes and legal bases
We process information only where an applicable legal basis exists, including:
- Contract: account creation, authentication, uploads, storage, transcription, evidence and report generation, exports, billing, support, and retention settings.
- Consent: optional marketing, non-essential cookies, sensitive processing that requires separate consent, or another optional purpose we describe. Withdrawal does not affect earlier lawful processing.
- Legal obligations: tax and accounting records, lawful requests, privacy-rights responses, and compliance with data-protection and consumer laws.
- Legitimate interests or reasonable operational needs: security, fraud and abuse prevention, troubleshooting, aggregate usage measurement, reliability, and proportionate product improvement, balanced against individual rights.
- Vital interests or establishing, exercising, and defending legal claims where permitted.
6. Transcription, AI, and automated processing
To perform requested transcription, summaries, topic extraction, evidence suggestions, cross-interview analysis, and report generation, we may send necessary audio, video, transcript text, research questions, and context to contracted transcription or AI providers.
AI output can be inaccurate, incomplete, or biased. ScribeFlash distinguishes suggestions from researcher-confirmed content and preserves source references for review. You must review output before relying on or sharing it. The Service does not use AI to make solely automated decisions with legal or similarly significant effects about individuals.
Unless we give clear notice and obtain authorization required by law, we do not use Customer Content to train general-purpose generative AI models offered to the public. Provider use is governed by our contracts, selected enterprise settings, and applicable provider terms.
9. International transfers
ScribeFlash and its providers may process information outside your country. We use contracts, access controls, encryption, and other lawful transfer mechanisms required by applicable law, and provide additional notice, consent, or assessments where required.
Organizations uploading data protected by China, EEA, UK, or other transfer rules must ensure they have a lawful transfer basis and may contact us for applicable processing arrangements.
10. Retention and deletion
We retain data for the shortest reasonable period needed for the purposes above, considering plan and project settings, contracts, security, disputes, and legal obligations. Account data and project structures, transcripts, evidence, and reports generally remain while the account is active unless deleted or otherwise agreed.
Current media-retention choices include deletion after processing or retention for 7, 30, 90, or 365 days; projects may have a separate policy. Available options can vary by plan. Project deletion first disables access and then queues cleanup of associated media, exports, cache, and content.
After account deletion or a valid erasure request, unnecessary data is deleted or de-identified. Isolated disaster-recovery backups expire through normal rotation. Limited tax, anti-fraud, dispute, or security records may be retained longer with restricted access and use.
11. Security and incident response
We apply safeguards proportionate to risk, such as encryption in transit, protected session cookies, least-privilege access, short-lived or signed upload URLs, server-side authorization, redacted logs, separation controls, and deletion workflows. No internet system is completely secure.
We assess, contain, document, and notify affected users or regulators of qualifying incidents as required by law. Use a strong password, protect your devices, and report suspicious access promptly.
12. Your privacy rights
Depending on location, you may have rights to notice, access, copy, correct, supplement, delete, restrict or object, withdraw consent, portability, information about automated processing, and complaint to a regulator. EEA and UK users may object to legitimate-interest processing where applicable; eligible US state residents may have access, correction, deletion, sale/share opt-out, and non-discrimination rights.
Use account settings to update a profile, request export, set media retention, or request deletion, or submit a request through the Contact page. We may verify identity, account ownership, and authorized-agent authority. Legal exceptions, other people's rights, trade secrets, and reasonable technical limits may apply.
Because ScribeFlash currently does not sell personal information or share it for cross-context behavioral advertising, no sale/share opt-out link is currently required. We will provide required notice and controls before that practice changes.
13. Children
The Service is for professional users able to contract and is not directed to children under 16. If research involves a minor, you must obtain guardian authorization and other required consent and use stricter minimization, access, and retention controls.
If you believe a child provided account information without proper authorization, contact us so we can verify and take reasonable deletion steps.
14. Changes and contact
We may update this policy as features, providers, or laws change. The date above will change, and material updates will receive reasonable notice through the site, product, or account email. We will request consent before effectiveness where required.
Use the ScribeFlash Contact page to exercise rights, ask about processing, or report a security concern. For participant requests involving an organization workspace, we may direct the request to the customer organization that determines the processing purposes.
