Legal
Privacy Policy
Data controller
TranscribeCat is operated by Klarweb in Oslo, Norway — a Norwegian-incorporated entity in the EEA. For GDPR purposes, Klarweb is the controller of personal data processed via transcribecat.com. Contact details are at the bottom of this page.
What we collect
Only what is needed to run the service:
- Account info — your email address and name, provided through Clerk when you sign up (Google sign-in or email).
- Audio and video files — the files you upload for transcription. You choose the retention period at upload time, from deletion the moment the transcript is ready up to 90 days; the default is 90 days. Files are then deleted automatically.
- Transcripts — the text output of your transcriptions, kept until you delete them.
- Payment info — handled entirely by Stripe. Card details never reach our servers and we do not store them.
- Your answer to the cookie banner — when you press Accept or Decline we record that a choice was made, which one it was, the page you were on and whether the screen was phone-sized, so we know how much of our own analytics is missing. It carries no identifier of any kind: no cookie is written or read, and the record is keyed to a random number generated for that one request and then discarded. Two answers from the same person cannot be linked, by us or by anyone. Legal basis: legitimate interest, Art. 6(1)(f) GDPR.
- Product analytics — only if you accept — pages visited, clicks and navigation, and a session replay with every input field masked, collected by PostHog in the EU. Nothing analytics-related runs in your browser until you accept the cookie banner. Legal basis: consent, Art. 6(1)(a) GDPR.
How we use your data
- To transcribe your audio and video files and deliver the results.
- To take payments and issue refunds.
- To send transactional email — a receipt from Stripe, and one message per file when a transcript is ready or has failed.
- To find and fix faults, and to see which parts of the product get used — but only for visitors who accepted analytics.
We do not sell your data. We do not share it for cross-context behavioural advertising (CCPA/CPRA terminology). We do not use your files or transcripts to train AI models, and we have granted no processor permission to do so.
Third-party processors
These are every third party that can process your personal data on our behalf. Our build fails if this list and the code disagree in either direction — a processor cannot be added to the product without appearing here, and one that stops being used cannot linger on this page.
- Clerk — Authentication, sign-in and account management. Your email address, your name, and sign-in metadata. Clerk, Inc., United States. Transfers are covered by the EU Standard Contractual Clauses in Clerk’s data processing addendum. Clerk privacy policy.
- Neon — PostgreSQL database hosting — your account record, your transcripts and their metadata. No audio is stored here. Email address, account settings, transcript text. EU — AWS eu-central-1 (Frankfurt). Neon privacy policy.
- Vercel — Application hosting, and Vercel Blob for the audio and video files you upload. Your uploaded files, plus the request metadata any web host sees (IP address, user agent). Split. The application runs in Vercel’s Frankfurt region (fra1) and your files are held in a private Vercel Blob store in the same region — but Vercel’s workflow infrastructure, which keeps the record that lets a transcription resume after a failure, runs only in the United States (iad1) and has no EU option today. Vercel Inc. is US-incorporated in any case; both that processing and any access from outside the EEA are covered by the EU Standard Contractual Clauses in its data processing addendum. Vercel privacy policy.
- Stripe — Payment processing and payment receipts. Your card details — which go to Stripe directly and never reach our servers — your email address, and the amount charged. United States and Ireland. Transfers are covered by the EU Standard Contractual Clauses in Stripe’s data processing agreement. Stripe is a PCI-DSS Level 1 service provider. Stripe privacy policy.
- Resend — Transactional email — one message per file when a transcript is ready or has failed, and account notices. Your email address and the contents of that message. Resend, Inc., United States. Transfers are covered by the EU Standard Contractual Clauses in Resend’s data processing agreement. Resend privacy policy.
- AssemblyAI — Speech-to-text transcription and speaker diarization. AssemblyAI fetches your file from a short-lived signed link, returns the transcript, and we store only the normalised text — never AssemblyAI’s raw response. The audio or video file you uploaded, and its transcript. United States. AssemblyAI’s own policy states that its services are “predominantly hosted and operated in the United States”; transfers are covered by the EU Standard Contractual Clauses in its data processing agreement. AssemblyAI privacy policy.
- PostHog — Product analytics, session replay and client-side error reporting — which pages people use, and what the screen looked like when something broke. Pages visited, clicks and navigation, a replay of the pages you viewed with every input field masked, and — if you are signed in — your Clerk user id. No email address, no file names, no transcript text. EU — eu.i.posthog.com. Loaded only if you accept the cookie banner. PostHog privacy policy.
Your files and transcripts are sent to AssemblyAI and stored with Vercel and Neon. They are not sent to PostHog: session replay masks every input, and no file name or transcript text is captured.
Stripe is the only processor that may be sent your IP address, and only ever for tax. Where sales tax or VAT is collected on a charge, the IP address of that one checkout request is given to Stripe so it can determine which jurisdiction’s rules apply to the sale. It is used for that and nothing else: we do not store it, we do not write it to a log, and it is not read at all for a charge on which no tax is collected. Our prices are tax-inclusive, so this decides what Stripe records about a payment, never the amount you pay.
How we record consent
Your cookie choice is stored on your own device in localStorage under the key tc-consent-v3, with a timestamp. We keep no server-side log of who consented when — the timestamp on your device is the record. Clearing your browser storage for transcribecat.com therefore resets the banner and we ask again. After 12 months we re-prompt automatically, in line with EDPB guidance on periodic re-confirmation.
An earlier consent record covered a different set of analytics tools. It could not stand in for consent to PostHog, so it is deleted rather than carried over, and everyone is asked again for the stack that is actually deployed.
International transfers
Most of your data stays in the EU. The application runs in Frankfurt, your files sit in an EU (Frankfurt) storage region, your account and transcripts sit in an EU (Frankfurt) database, and analytics stay in PostHog’s EU region.
Some of it does leave, and we would rather say so plainly than let four true sentences add up to a false impression. Clerk, Stripe, Resend and AssemblyAI process personal data in the United States. So does Vercel’s workflow infrastructure, which holds the orchestration record of each transcription job — the identifiers, timings and step outcomes that let a job resume after a failure. Your audio and your transcript text are not sent there. That record is stored in Virginia whatever region the rest of the application runs in, and Vercel offers no EU option for it today. Every one of these transfers relies on the EU Standard Contractual Clauses in that processor’s data processing agreement.
Analytics is the one transfer you control outright: decline the banner and PostHog is never started, so no request leaves your browser and no cookie is written.
Data retention
- Audio and video files — you choose at upload time how long the original is kept, from deletion the moment the transcript is ready up to 90 days. The default is 90 days, and 90 days from your last sign-in is also the ceiling: the file goes on whichever of the two falls first. The picker is on the upload page, next to the language selector, and on your profile page, where it sets the default for your next upload.
- Audio for a job that never finished — a transcription that never reaches “ready” or “failed” has no completion for your window to be measured from, so its audio is deleted on an absolute clock instead: 24 hours after upload if you chose deletion on completion, and 30 days after upload for every other choice.
- Transcripts — kept until you delete them, or until you delete your account.
- Account data — kept until you delete your account. Accounts inactive for 12 months get a 30-day deletion warning by email, then are deleted along with all transcripts and any remaining audio.
Your rights (EU/EEA and Norway)
Klarweb is established in Norway and processes data under the GDPR and the Norwegian Personopplysningsloven. You have the right to:
- Access — export your account data, transcripts and audio retention status from your profile page, or ask us for a copy.
- Rectification — correct inaccurate personal data from your profile, or by email.
- Erasure — delete individual transcriptions from your transcripts page, and your whole account from your profile page. In almost every case both finish the moment you confirm; if a step fails we say so in the response and the daily sweep finishes it within 24 hours. Our database backup is Neon point-in-time recovery and its window on this project is six hours, so a deleted record survives in a backup for at most six hours. The one exception is a manual database dump taken before a schema migration, held where only the operator who took it can read it and deleted within 30 days.
- Restriction and objection — ask us to stop a specific kind of processing. We review and respond within 30 days.
- Portability — the export above is machine-readable (JSON and plain text).
- Withdraw consent — use the “Manage cookies” link in the footer, which reopens the banner with your current choice. Withdrawing stops PostHog and removes its cookie. We send no marketing email, so there is nothing else to opt out of.
- Lodge a complaint — with the Norwegian Datatilsynet (datatilsynet.no) or your local supervisory authority, if you think we are handling your data improperly.
Security
All data is transmitted over HTTPS and database connections use SSL. Your uploaded files live in a private blob store and are reachable only through short-lived signed links scoped to your own account. Authentication is handled by Clerk. Card data is handled by PCI-DSS Level 1 Stripe infrastructure and never touches our servers.
Contact
For privacy questions and data-subject requests, email support.transcribecat@