Legal

Privacy Policy

Last updated: August 18, 2026

Template disclaimer — not legal advice

This page is a starting-point template describing our actual data practices as accurately as we can. It has not been reviewed by a lawyer, and it does not claim compliance with any specific law or regulation (e.g. GDPR, CCPA). If you have questions about your rights under a specific law, or need a policy that makes formal legal representations, please consult a qualified attorney.

Transcript ("we", "us", the "Service") turns a video URL (YouTube, TikTok, X, Instagram, Bilibili, Facebook, RedNote) or an uploaded audio file into a text transcript. This policy describes what information we collect when you use the website, the API, or the CLI, and what we do with it.

Information we collect

  • Account information. When you sign up, we collect your email address, and, if you sign in with Google, GitHub, or X (via Supabase Auth), the basic profile info that provider shares with us (name, avatar, email).
  • Content you submit. The video URLs you paste and the audio files you upload for transcription, plus the resulting transcript text.
  • Usage data. Minutes of video transcribed, request timestamps, API/CLI request counts, and rate-limit counters, so we can meter your plan and keep the Service reliable.
  • API keys. If you generate a product API key, we store only a one-way hash of it (SHA-256) — the plaintext key is shown to you once and is not retained by us afterward.
  • Billing information. Subscriptions are processed by Polar, our merchant of record. We receive your subscription tier and status, not your card number — Polar handles and stores payment details directly.
  • Analytics. Aggregate, privacy- oriented usage analytics (pages viewed, general performance) via Vercel Analytics.

How we use this information

  • To operate the Service: authenticate you, run transcription jobs, and return results.
  • To meter usage against your plan's monthly minutes and enforce fair-use rate limits.
  • To cache transcripts server-side, so a video that has already been transcribed can be served instantly to you (or another user requesting the same public content) without redoing the work.
  • To respond to support requests sent to the contact email below.
  • To detect, investigate, and prevent abuse, fraud, or violations of our Terms.
  • To improve reliability and performance of the Service.

Subprocessors

We rely on the following third parties to run the Service. Each processes the categories of data needed for its function:

  • Supabase — authentication, database, and storage for uploaded audio files.
  • Polar — subscription billing and payment processing (merchant of record).
  • Vercel — application hosting and aggregate analytics.
  • Upstash — Redis-backed caching and rate limiting.
  • OpenAI — audio transcription processing, used when a video has no native captions available and audio must be transcribed directly.

Cookies and analytics

We use a cookie set by Supabase Auth to keep you signed in — this is necessary for the Service to function and isn't used for advertising. Vercel Analytics collects aggregate, privacy-oriented usage metrics and does not use cross-site tracking cookies.

Data retention

We retain account information for as long as your account is active. Transcripts are cached server-side, as described above, and may persist after a single request completes so repeat requests for the same content are fast. Uploaded audio files are retained only as long as needed to produce your transcript and to support the caching behavior above. You can request deletion of your account and associated data at any time — see "Your rights" below.

Your rights

You can access or export your transcripts directly from the dashboard. To request a copy of your account data, request correction, or request deletion of your account and associated data, email us at support@transcript.land. We'll respond and act on verified requests in a reasonable time.

Security

We use reasonable technical measures to protect your data — traffic to the Service is encrypted in transit (TLS), and API keys are stored as one-way hashes rather than plaintext. No method of transmission or storage is perfectly secure, and we can't guarantee absolute security.

International data transfer

Our subprocessors (Supabase, Polar, Vercel, Upstash, OpenAI) operate infrastructure in the United States and other countries. If you use the Service from outside those countries, your information will be transferred to and processed in jurisdictions that may have different data protection rules than your own.

Children

The Service is not directed at children under 16, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this policy as the Service changes. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy or your data? Email support@transcript.land.