Transcribe.so – Privacy Policy

Last updated: 10 September 2026

Transcribe.so is a product of Sunmoon.co Pte. Ltd. (UEN: 202432099D), a company registered in Singapore at 20A Tanjong Pagar Road, Singapore 088443 ("Transcribe.so," "we," "us," "our"). We are committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use and protect it, and what choices and rights you have regarding your personal information and content.

1. Overview

Transcribe.so is an AI-powered transcription service that processes audio and video content. We collect personal information to operate your account and process content data (audio, video, transcripts, AI-generated outputs) to provide our transcription services.

Important: We do not use your content or AI-generated outputs to train AI models unless you explicitly opt into a data sharing program.

2. Data We Collect

2.1 Account & Identity Data

| Data Type | Examples | Purpose | | --------- | -------- | ------- | | Account Information | Email address, name, password hash, user ID | Create and authenticate your account | | Profile Data | Display name, preferences, settings | Personalize your experience | | Authentication Tokens | Session tokens, OAuth tokens (if using Google/social login) | Keep you securely logged in | | Account Connection Credentials | YouTube/Google browser session cookie names, domains, expiry information, and encrypted cookie values that you voluntarily upload | Connect your account and retrieve, on your instruction, videos that require that account |

2.2 Payment & Billing Data

| Data Type | Examples | Purpose | | --------- | -------- | ------- | | Payment Information | Credit card last 4 digits, billing address (processed by Stripe) | Process subscription and wallet top‑up payments | | Subscription Data | Active plan tier (Free/Pro/Business/Enterprise), billing cycle dates, wallet credit balance, Stripe subscription ID | Manage your subscription and credit wallet | | Transaction Records | Purchase amounts, wallet credit balance, subscription invoices, transaction history | Manage your account credits and billing | | Wallet & Billing Data | Wallet top‑ups, credit holds, charges, refunds, plan credit deductions, wallet credit deductions | Track usage and billing across plan credits and wallet credits |

2.3 Content Data

| Data Type | Examples | Purpose | | --------- | -------- | ------- | | Input Content | YouTube URLs, uploaded audio/video files, original filenames | Process transcription requests | | Downloaded Media | Audio files extracted from YouTube via yt‑dlp through proxy infrastructure, or uploaded directly | Generate transcripts | | Processed Files | Audio files (.mp3), text files (.txt), metadata | Store your processed content | | Transcripts | Raw transcription text, timestamped utterances | Provide transcription service | | AI-Generated Outputs | Topics, chapters, summaries, embeddings, Q&A responses, entity extractions, speaker identifications | Provide enhanced features | | Metadata | Video titles, descriptions, channel names, durations, languages, timestamps | Organize and display your content |

2.4 Usage & Technical Data

| Data Type | Examples | Purpose | | --------- | -------- | ------- | | Usage Data | Pages visited, features used, transcription requests, search queries | Improve the Service, analytics | | Device Information | Browser type, operating system, device identifiers, screen resolution | Optimize performance, troubleshooting | | IP Address & Location | IP address, approximate geographic location | Security, fraud prevention, analytics | | Log Data | Access logs, error logs, performance metrics | Debugging, security monitoring | | Account Connection Data | Connected or expired status, last-use time, assigned fixed network address, retrieval result | Operate, secure, expire, and troubleshoot the optional YouTube Account Connection | | Feature Agreement Record | Account ID, agreement version, acceptance timestamp, IP address, user-agent information, and SHA-256 hash identifying the accepted text | Record affirmative acceptance, enforce the Terms, resolve disputes, and demonstrate compliance | | Cookies & Similar | Session cookies, local storage, preference cookies | Maintain sessions, remember preferences | | Free Tool Anti-Abuse Data | IP address, browser and device verification signals collected by Cloudflare Turnstile, an anonymous session cookie | Enforce daily limits on the no-signup free tools and prevent automated abuse |

2.5 AI Processing Data

| Data Type | Examples | Purpose | | --------- | -------- | ------- | | Embeddings | 2048-dimensional semantic vectors | Enable semantic search | | Search Queries | Text queries submitted to search/Q&A | Provide search and Q&A functionality | | Q&A History | Questions asked, answers generated, citations | Maintain Q&A history and improve accuracy | | Processing Metrics | API costs, token usage, processing times, model versions | Track costs, optimize performance |

3. Legal Bases for Processing

Depending on your jurisdiction, including the EU/EEA and UK, we rely on the following legal bases:

  • Contract Performance: We process account information, content, requested outputs, and optional Account Connection Credentials as necessary to provide features you choose to use. Storing and using Account Cookies to perform an authenticated retrieval you request is based on performance of our contract with you.
  • Legitimate Interests: We process proportionate usage, security, fraud-prevention, troubleshooting, and feature agreement records to protect the Service, establish or defend legal claims, and demonstrate acceptance. We balance these interests against your rights and minimize how long identifying network and device data are retained.
  • Consent: We rely on consent for optional marketing, optional data-sharing programs, and any other processing for which applicable law specifically requires consent. You may withdraw consent without affecting processing that occurred before withdrawal.
  • Legal Obligation: We process information where necessary to comply with tax, accounting, regulatory, court-order, or other legal requirements.

The YouTube Account Connection checkbox records contractual agreement and acknowledgement of the disclosed risks. It is not the GDPR legal basis for processing Account Cookies. Because the feature is optional, you may stop the related processing at any time by removing the connection, after which the stored Account Cookies are deleted as described in Section 8.

4. How We Use Your Data

4.1 Core Service Operations

  • Create, maintain, and secure your account
  • Process your transcription requests using AI models
  • Use Account Cookies, when you have enabled YouTube Account Connection, only to retrieve a requested video that requires the connected account
  • Maintain the connection's status and notify you when YouTube reports that the Account Cookies are invalid or expired
  • Store your content and outputs in encrypted cloud object storage (Cloudflare R2)
  • Generate transcripts, timestamps, topics, chapters, summaries, and embeddings
  • Provide search and Q&A functionality
  • Manage your credit balance and billing
  • Send service-related notifications (job completion, errors, billing updates)

4.2 Service Improvement

  • Analyze usage patterns to improve features and performance
  • Debug errors and optimize processing pipelines
  • Conduct aggregated analytics (anonymized where possible)
  • Test and develop new features

4.3 Security & Fraud Prevention

  • Detect and prevent fraudulent transactions
  • Monitor for abuse, spam, or violations of our Terms of Service
  • Protect against security threats and unauthorized access
  • Enforce usage limits on the anonymous free tools: we use your IP address, an anonymous session cookie, and browser/device verification signals from Cloudflare Turnstile to apply the daily limit and to block automated abuse. These signals are used only for abuse prevention and rate limiting, and the associated counters expire within 24 hours

4.4 Communications

  • Send transactional emails (account creation, password resets, billing)
  • Notify you of service updates or changes
  • Respond to your support requests
  • Send marketing communications (only if you've opted in; you can unsubscribe anytime)

4.5 Legal & Compliance

  • Comply with legal obligations (tax reporting, law enforcement requests)
  • Enforce our Terms of Service
  • Resolve disputes

5. Third-Party Services & Data Sharing

We do not sell your personal data or content. We share data with trusted third-party service providers who help us operate the Service:

5.1 AI Processing

Transcription, speaker identification, chapters, summaries, embeddings, search, and question‑and‑answer features run on AI models operated by Transcribe.so on infrastructure we operate. This infrastructure consists of GPU and cloud servers rented from hosting providers (listed in Section 5.2 as infrastructure subprocessors). Hosting providers supply the hardware only; they do not access, process, or receive your content as an AI service.

Your audio files, transcripts, and AI‑generated outputs are not sent to any third‑party AI provider.

Emergency service continuity. If a serious incident affects the availability of our AI infrastructure, we may temporarily enable a vetted backup cloud text‑processing provider to keep text features such as summaries and question‑and‑answer available. This backup is disabled by default and is used only for the duration of a declared service incident. If enabled, it receives transcript text and questions only, never your audio files, and Section 12 continues to apply: we do not authorize the provider to use your content to train AI models. The identity of any backup subprocessor is available on request through our support contact.

5.2 Infrastructure & Storage Subprocessors (Hardware & Hosting Only)

| Provider | Data Shared | Purpose | | -------- | ----------- | ------- | | Cloudflare (R2) | Audio files, text files, processed outputs, metadata | Encrypted cloud object storage for your content | | GPU & cloud server hosting providers | None as a service; your content is processed on servers we rent and operate | Supply the compute hardware for the AI processing described in Section 5.1 | | Supabase / PostgreSQL | Account data, metadata, transcription records, credits, billing records | Database hosting and management | | Redis Labs / Upstash | Cached data, session data, temporary processing data | Caching and performance optimization | | Proxy infrastructure providers | YouTube URLs, video metadata | Route yt‑dlp download requests on your behalf; your IP address is not forwarded to YouTube |

5.3 Payment Processors

| Provider | Data Shared | Purpose | | -------- | ----------- | ------- | | Stripe | Email, billing address, payment method details | Process credit purchases and payments |

5.4 Analytics & Monitoring

| Provider | Data Shared | Purpose | | -------- | ----------- | ------- | | Google Analytics 4 & Google Ads | Usage data, device info, page views, conversion events | Site analytics and ad conversion tracking | | PostHog | Usage data, device info, product events, session replays (when enabled) | Product analytics and usage insights | | Datafast | Page views, referrer and campaign data, device info | Web analytics and marketing attribution | | Sentry | Error reports, device info, IP address, session replays on errors | Error monitoring and performance | | Meta Pixel | Page views, conversion events, device info | Ad conversion tracking; only active during ad campaigns |

We also collect first-party usage analytics (events such as page views and feature usage, stored on our own servers) as part of providing and improving the Service.

5.5 Other Disclosures

We may share data when:

  • Required by law – Court orders, subpoenas, legal processes
  • Protecting rights – Investigating fraud, violations, or threats to safety
  • Business transfers – Mergers, acquisitions, or asset sales (you'll be notified)
  • With your consent – When you explicitly authorize sharing

6. Third‑Party Content & YouTube

When you submit a YouTube URL:

  • The Service uses yt‑dlp, an open‑source media downloader, routed through proxy infrastructure operated or contracted by Transcribe.so, to retrieve the audio track from the video you specify
  • The retrieval is performed at your direction and on your behalf
  • The URL and associated metadata, such as the video ID, title, channel, and duration, are processed and stored as part of your transcription record
  • Your own IP address is not forwarded to YouTube during the retrieval

Credentials you provide. If you choose to connect your YouTube/Google account, you upload browser session cookies for that account. Session cookies can permit account access and should be protected like a password. We accept only cookies associated with YouTube or Google domains and use them only when a video you request requires the connected account.

We encrypt Account Cookies at rest using AES‑256‑GCM with a per‑user authenticated binding. Encryption keys are kept in a secrets manager, and stored values are accessible only to the restricted service role. Cookie values are not displayed or returned to your browser. For a requested retrieval, we decrypt them only transiently in memory‑backed temporary storage in our processing environment and delete the plaintext copy after the retrieval.

Requests for a connected account use one fixed network address assigned to that account. Account Cookies are transmitted over an encrypted connection to YouTube or Google only to perform the requested retrieval. YouTube or Google receives and processes them under its own terms and privacy policy. We do not sell Account Cookies, disclose them to other users, use them for advertising, or authorize an infrastructure provider to use them for its own purposes.

You can view the connection status and replace or remove the connection in Settings. We delete stored Account Cookies when you remove the connection, after 90 days without use, or when you delete your Transcribe.so account. If YouTube reports them invalid or expired, we mark the connection expired and may send a service notification asking you to reconnect.

You remain responsible for determining whether you are authorized to retrieve and process a video. See Sections 5.2 and 5.6 of the Terms of Service and YouTube's Privacy Policy.

7. Data Storage & International Transfers

7.1 Storage Locations

Your data is stored on servers located in:

  • European Union – Primary application and database servers
  • Cloudflare's global network – Encrypted object storage operated by Cloudflare (R2)
  • European Union and other countries, including the United States – GPU servers that run the AI processing described in Section 5.1, rented from infrastructure providers as capacity requires (see Section 5.2). We rent this capacity where it is available, so the countries involved change over time.

7.2 Cross-Border Transfers

If you're located in the EU/EEA, UK, or other jurisdictions with data protection laws, your data may be transferred to countries that don't have equivalent data protection laws. We rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Your consent where required
  • Contractual necessity to provide the services you've requested

7.3 Data Security in Transit & At Rest

  • Internet transmissions use TLS/SSL encryption
  • Databases and Cloudflare R2 object storage use encryption at rest
  • Account Cookies use application-level AES‑256‑GCM encryption with a per‑user authenticated binding
  • Account Cookie encryption keys are held separately in a secrets manager
  • Stored Account Cookies are accessible only to the restricted service role and are not returned to a user's browser
  • Account Cookies are decrypted only transiently in memory‑backed temporary storage for a requested retrieval, after which the plaintext copy is deleted
  • AI processing runs on servers we operate, subject to the hosting disclosures in Sections 5.1 and 5.2
  • We use access controls, authentication, authorization, logging, monitoring, and incident-response procedures

8. Data Retention

| Data Type | Retention Period | Reason | |-----------|------------------|--------- | | Account data | While account is active + 30 days after deletion | Allow account recovery; legal requirements may extend retention | | Account Cookies | Until you remove the connection, 90 days pass without use, or you delete your account, whichever occurs first | Provide the optional connection only while it remains active; removed from active storage when the applicable event occurs | | Account connection status and last-use data | While the account is active + 30 days after deletion | Display and administer the connection, apply automatic expiry, and troubleshoot failures | | Feature agreement record | Deleted with your account, and earlier when you remove the connection (except where we must retain a record of your acceptance to resolve a dispute already notified to us) | Demonstrate affirmative agreement, enforce the Terms, and establish or defend legal claims | | Content & transcripts (successful) | While account is active + 30 days after deletion | Provide "forever access" as promised; deletion grace period | | Content & transcripts (failed) | 7 days after the failure | Failed transcriptions provide no value; deleted automatically. You can retry from the dashboard within the 7-day window to preserve the upload. | | Free tool uploads & transcripts (no account) | About 24 hours after processing finishes | The no-signup free tools are for one-off use; uploads and transcripts are deleted automatically. IP-based rate-limit counters for these tools expire within 24 hours. | | Backups | Up to 30 days after deletion | Disaster recovery | | Payment & tax records | 7 years after transaction | Legal and accounting requirements | | Usage logs & analytics | Up to 24 months, then aggregated or anonymized | Service improvement, security monitoring | | AI outputs (embeddings, summaries) | While account is active + 30 days after deletion | Linked to transcripts; deleted together | | Q&A history | While account is active + 30 days after deletion | Provide access to your Q&A records |

When you delete your account or individual transcripts:

  • Content files are marked for deletion and removed from active storage within 30 days
  • Stored Account Cookies are removed from active storage when you disconnect, after 90 days without use, or when the account is deleted
  • Inaccessible encrypted backup copies may persist for up to 30 additional days, are not used for retrieval, and are deleted through normal backup expiry
  • Feature agreement records are deleted with your account, and earlier when you remove the connection, except where we must retain a record of your acceptance to resolve a dispute already notified to us; they do not contain Account Cookie values
  • Some information may be retained longer where required by law or reasonably necessary for fraud prevention or an existing legal dispute

9. Your Privacy Rights

Depending on your location, you may have the following rights:

9.1 Access & Portability

  • Right to Access – Request a copy of your personal data
  • Right to Portability – Receive your data in a structured, machine-readable format (JSON, CSV)
  • You can download your transcripts and processed files directly from the Service

9.2 Correction & Deletion

  • Right to Rectify – Correct inaccurate personal data
  • Right to Delete ("Right to be Forgotten") – Request deletion of your personal data and content
  • You can delete individual transcripts or your entire account through the Service

9.3 Control & Objection

  • Right to Restrict – Limit how we process your data
  • Right to Object – Object to processing based on legitimate interests (e.g., marketing)
  • Right to Withdraw Consent – Withdraw consent at any time (where processing is based on consent)

9.4 Automated Decision-Making

  • We do not make solely automated decisions that significantly affect you without human involvement
  • AI-generated outputs are tools for your use; you retain control over how to use them

9.5 How to Exercise Your Rights

  • Email us at support@transcribe.so with your request
  • Through the Service – Use account settings to download, delete, or modify data
  • We may verify your identity before fulfilling requests
  • We will respond within the timeframe required by applicable law (typically 30 days)

10. Security Measures

We implement industry-standard security measures:

10.1 Technical Safeguards

  • Encryption in transit – TLS/SSL for all data transmission
  • Encryption at rest – Database and Cloudflare R2 object storage encryption
  • Credential encryption: Account Cookies are separately encrypted using AES‑256‑GCM with a per‑user authenticated binding and keys held in a secrets manager
  • Credential isolation: Stored Account Cookie values are available only to the restricted service role and are never displayed or returned through the user session
  • Transient decryption: Plaintext Account Cookies exist only in memory-backed temporary storage during a requested authenticated retrieval and are deleted afterwards
  • Access controls – Role-based access, authentication, authorization
  • Network security – Firewalls, intrusion detection, DDoS protection
  • Secure infrastructure – Hosting on trusted cloud providers (Cloudflare, Supabase, and vetted server hosting providers)

10.2 Operational Safeguards

  • Regular security audits and monitoring
  • Incident response procedures
  • Employee access restrictions and training
  • Vendor security assessments

10.3 Limitations

  • No security system is 100% secure
  • You are responsible for keeping your login credentials secure
  • Treat any cookies.txt export like a password. Do not email it, reuse it for another service, or give it to another person. Remove the connection immediately if you believe the file or connected account has been compromised.
  • Report security vulnerabilities to support@transcribe.so immediately

11. Cookies & Tracking Technologies

11.1 Types of Cookies

| Cookie Type | Purpose | Duration | |-------------|---------|----------| | Essential/Session | Keep you logged in, maintain session state | Session or up to 30 days | | Functional | Remember your preferences (theme, settings) | Up to 1 year | | Analytics | Understand usage patterns, page views | Up to 2 years | | Performance | Optimize loading times, caching | Varies | | Consent (ts_consent) | Remember your cookie consent choice | 180 days | | Region flag (ts_eea) | Remember whether the consent banner applies to your region | Session |

11.2 Your Choices

  • Browser settings: Most browsers allow you to block or delete cookies
  • Consent banner: If you visit from the EEA, UK, or Switzerland, a banner asks you to accept or decline analytics and advertising cookies before they are used. To change your choice later, delete the ts_consent cookie in your browser and the banner will appear again on your next visit.
  • Do Not Track: We currently do not respond to DNT signals (industry standard is unclear)

Note: Blocking essential cookies may prevent you from using certain features of the Service.

12. AI Training & Data Sharing

Default Policy: We do not use your content (audio, video, transcripts) or AI-generated outputs (summaries, embeddings, Q&A responses) to train AI models or share with third parties for their AI training purposes. Because AI processing runs on infrastructure we operate (see Section 5.1), your content is also not disclosed to third‑party AI providers.

Optional Data Sharing Program: We may offer an opt-in program where you can choose to contribute anonymized data to improve AI models. Participation is entirely voluntary, and you can opt out at any time.

13. Children's Privacy

The Service is not directed to individuals under 18 (or under 16 in the EU/EEA). We do not knowingly collect personal data from children.

  • If you are under 18, you must have parental or guardian consent to use the Service
  • If we discover we've collected data from a child without proper consent, we will delete it
  • Parents/guardians: if you believe your child has provided data, contact us at support@transcribe.so

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

14.1 Categories of Personal Information

During the preceding 12 months, we may have collected the following CCPA categories:

  • Identifiers, such as name, email address, account ID, IP address, and device identifiers
  • Customer-record information, such as account and billing details
  • Commercial information, such as subscription, credit, purchase, and transaction records
  • Internet or other electronic network activity, such as feature usage, browser information, logs, and YouTube URLs
  • Audio, visual, and content information, such as uploaded media, downloaded audio, and transcripts
  • Inferences and generated information, such as topics, summaries, embeddings, and account preferences
  • Sensitive personal information, specifically account-login information or credentials that can permit access to an account, including Account Cookies

We collect this information directly from you, automatically from your use of the Service, and from service providers involved in payments, security, and infrastructure. We use it for the purposes described in Sections 2 through 6. We disclose relevant categories to service providers for business purposes and, when you request an authenticated retrieval, transmit Account Cookies to YouTube or Google to carry out your instruction.

We do not sell Account Cookies or other personal information. We do not share them for cross-context behavioural advertising. We use sensitive Account Cookies only to provide and secure the optional feature and do not use them to infer characteristics about you.

14.2 Right to Know

You can request:

  • Categories of personal information we collect
  • Categories of sources from which we collect personal information
  • Our business or commercial purpose for collecting personal information
  • Categories of third parties with whom we share personal information
  • Specific pieces of personal information we've collected about you

14.3 Right to Delete

Request deletion of your personal information, subject to certain exceptions.

14.4 Right to Opt-Out of Sale or Sharing

We do not sell personal information as defined by the CCPA. We do not share personal information for cross-context behavioral advertising.

14.5 Right to Correct

Request correction of inaccurate personal information.

14.6 Right to Limit Use of Sensitive Personal Information

Account Cookies may constitute sensitive personal information because they can permit access to an account. We use and disclose them only as reasonably necessary to provide and secure the feature you request and do not use them to infer characteristics about you. We do not use sensitive personal information for purposes that require a right-to-limit notice under the CCPA/CPRA. If this practice changes, we will provide the required notice and control.

14.7 Non-Discrimination

We will not discriminate against you for exercising your CCPA rights.

14.8 How to Exercise Rights

Email support@transcribe.so or use our account settings. We will verify your identity and respond within 45 days (extendable by 45 days if necessary).

15. European Privacy Rights (GDPR)

If you are in the EU/EEA/UK, you have rights under the General Data Protection Regulation (GDPR):

15.1 Legal Bases

We process your data based on contract performance, consent, legitimate interests, or legal obligations (see Section 3).

15.2 Data Protection Officer

For GDPR-related inquiries, contact support@transcribe.so.

15.3 Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we've violated your privacy rights.

15.4 International Transfers

See Section 7.2 for information about cross-border data transfers and safeguards.

16. Changes to This Privacy Policy

16.1 Updates

We may update this Privacy Policy from time to time to reflect:

  • Changes in our practices
  • Changes in applicable laws
  • New features or services
  • User feedback

16.2 Notice of Changes

When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Post a notice on the Service
  • Send an email to the address associated with your account (for significant changes)
  • Provide at least 7 days' notice before changes take effect (for material changes that reduce your rights)

16.3 Your Acceptance

Continued use of the Service after the effective date constitutes acceptance of the updated policy. If you don't agree, you must stop using the Service and may delete your account.

17. Contact Us

Privacy Questions or Concerns

Email: support@transcribe.so

Data Subject Requests

To exercise your privacy rights (access, deletion, correction, etc.), email support@transcribe.so with:

  • Your name and email address associated with your account
  • The specific right you wish to exercise
  • Any additional information to help us verify your identity

Security Vulnerabilities

Report security issues to support@transcribe.so immediately.

Mailing Address

Sunmoon.co Pte. Ltd. 20A Tanjong Pagar Road, Singapore 088443

This Privacy Policy is effective as of the "Last Updated" date above and applies to all users of Transcribe.so.