Legal
Privacy Policy
Last updated September 15, 2026
No security guarantee. ScribeFlow does not encrypt your lectures, transcripts, or notes at rest, does not offer a professionally audited security program, and does not promise confidentiality. Operators, other processes on the same machine, and anyone who obtains the history file or this browser’s storage may be able to read your data. Do not upload information you are required by law or contract to keep secure.
This Privacy Policy explains what information ScribeFlow processes, why, and what choices you have. It applies to this instance of the ScribeFlow web application. By using ScribeFlow you acknowledge this Policy and the Terms of Service.
1. Who is responsible
The controller is the person or organization that operates this ScribeFlow instance. There is no separate privacy officer unless that operator names one. If you host ScribeFlow yourself, you are the controller for data on your machine.
2. Information we process
Account
If you sign in with Google, we receive an identifier (subject), and may receive your name, email address, and profile photo from Google. Local test sign-in stores a non-verified identifier in a cookie on this device.
Lecture material
Recordings or transcripts you upload, generated notes, quizzes, flashcards, file names, and timestamps. If you are signed in, this material may be saved in History on the ScribeFlow server (currently a local JSON store on the host, not a hardened database).
Device and session
Cookies and similar storage described in the Cookie Policy, including sign-in cookies and, if you allow functional storage, a draft of your last lecture in this browser’s localStorage.
Technical
Standard request logs that a host or reverse proxy may keep (IP address, user agent, URL, time). This application does not run its own advertising or analytics pixels.
3. How we use information
- to transcribe audio and draft study materials you request;
- to show History and restore a lecture when you are signed in;
- to keep you signed in and protect sign-in flows (CSRF, OAuth PKCE);
- to remember optional cookie preferences;
- to operate, debug, and (if the operator chooses) back up this instance.
Legal bases, where GDPR or similar law applies, include performing the contract (providing the tool you asked for), legitimate interests in running a working service, and consent for optional functional storage.
4. How we share information
We do not sell your personal information.
We share information with processors only as needed to run features you use:
- Model providers (when a live API key is configured): audio and/or transcript text are sent to generate transcripts and notes. Their privacy terms apply.
- Google (if you choose Google Sign-In): authentication is handled by Google. Google’s privacy policy applies to that flow.
- The instance operator and anyone with disk or admin access can read History files and server logs. Treat that as an intended limitation, not a bug we hide.
We may disclose information if required by law or to protect rights, safety, or the service.
5. Security — what we do not do
ScribeFlow is an experimental study tool. In particular we do not promise:
- encryption at rest for History or localStorage drafts;
- end-to-end encryption;
- role-based access control beyond “signed-in user sees their own rows”;
- penetration testing, SOC 2, ISO 27001, FERPA, HIPAA, or PIPEDA certification;
- guaranteed deletion from backups the operator may have made;
- secure transmission in every deployment (this copy may run on plain HTTP locally).
You are responsible for what you upload. If a recording includes other students, patients, or confidential workplace information, you must have the right to process it. If you need a secure system, do not use ScribeFlow.
6. Retention
Browser drafts remain until you clear site data or turn off functional storage. History remains until you delete an item or the operator deletes the store. Sign-in cookies last up to about 30 days for the local test cookie, or as configured for Google sessions. We do not run a scheduled purge.
7. Your choices and rights
- Sign out; delete History folders or versions in the app.
- Clear this site’s cookies and localStorage in your browser.
- Use cookie preferences to allow or refuse functional storage.
- Disconnect Google access in your Google account settings.
Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data, to withdraw consent, and to complain to a regulator (for example the Office of the Privacy Commissioner of Canada, or a European supervisory authority). Send requests to the operator of this instance. We may need to verify you and may refuse requests the law does not require us to honor.
8. Do not sell or share (US state privacy laws)
We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use targeted advertising cookies. If you still want to record a “do not sell or share” request, use cookie preferences (Essential only) and avoid Google Sign-In. This section is our notice under laws such as the CCPA/CPRA.
9. Children
ScribeFlow is not directed at children under 13. We do not knowingly collect personal information from them. If you believe a child under 13 used ScribeFlow, stop use and delete the data you control.
10. International transfers
If you use Google or a US-hosted model provider, data may be processed in the United States or other countries that may not have the same data-protection laws as your home. Local History stays on the machine that hosts this instance.
11. Automated decisions
Drafting notes and questions is automated. It is not a decision that produces legal effects about you (for example grading or admission). You can edit or discard output.
12. Changes
We may update this Policy. The “Last updated” date will change. Continued use after an update means you accept the revised Policy.
13. Contact
Contact the operator of this ScribeFlow instance. You can also delete in-app History, sign out, and clear browser site data.