Privacy Policy
What We Never Do
Data We Don’t Collect or Store
- ✗ Write your audio to our disks — ever
- ✗ Store your email address or name
- ✗ Log or store IP addresses (our network provider Cloudflare sees them in transit — see Third-Party Services)
- ✗ Use recordings to train AI models
- ✗ Share data with advertisers or brokers
- ✗ Track behaviour across apps or sessions
- ✗ Collect contacts, location, or biometric data
- ✗ Retain data after account deletion
What We Do Store
Data We Collect
Server-side (persistent until account deletion)
| Data | Purpose |
|---|---|
| Pseudonymous user ID (SHA-256 hash of your account ID) | Account identity — cannot be reversed |
| Pseudonymous device identifier (SHA-256 hash of device properties) | Abuse prevention — cannot be reversed |
| Account balance (USD) | Credit management |
| Free transcription minutes remaining | Welcome bonus tracking |
| Account creation and last update timestamps | Account management |
Per-job records (stored for each completed transcription):
| Data | Purpose |
|---|---|
| Audio duration (seconds) | Service analytics |
| File size (bytes) | Service analytics |
| Word count | Service analytics |
| Cost charged (USD) | Billing record |
| Processing timestamps | Service analytics |
Server-side (transient — deleted after processing)
| Data | When Deleted |
|---|---|
| Audio file | Immediately after transcription completes — 1-hour TTL failsafe if anything goes wrong |
| Transcript text | When you confirm receipt (acknowledgment) — 24-hour TTL failsafe if your device never acknowledges |
On your device (encrypted)
| Data | Retention |
|---|---|
| Transcripts (text, segments, metadata) | Until you delete them |
| Offline upload queue | Removed after successful upload |
| App settings and consent records | Until sign-out or account deletion |
| Encryption key | In iOS Keychain / Android Keystore — deleted with the app |
Optional (opt-in only)
| Data | Purpose |
|---|---|
| Crash reports | App stability via SafeScribe’s own crash reporting endpoint — all PII stripped before sending |
| Feedback & problem reports | Product improvement — a rating, bug report, complaint or suggestion you choose to send. Free text is PII-stripped server-side before storage; kept only with your pseudonymous user hash (no name, email, or IP). Retained up to 24 months, then auto-purged. |
Complete Deletion
Deleting the App vs. Deleting Your Account
These are two distinct actions with different outcomes:
| Action | What happens | Your balance |
|---|---|---|
| Delete the app | Local transcripts and encryption key removed from your device | Preserved on the server — reinstalling and signing in with the same account fully restores it |
| Delete your account | Every server-side record permanently erased — cannot be undone | Gone |
Account Deletion — Nothing Left That Identifies You
Deleting your account from Privacy Settings permanently removes every server-side record linked to your identity:
- ✓Pseudonymous user IDpermanently deleted
- ✓Credit balancepermanently deleted
- ✓Free minutes remainingpermanently deleted
- ✓Per-job statisticsanonymized immediately — re-labelled to a shared DELETED_USER tombstone, auto-purged after 2 years
- ✓Pseudonymous device identifierreduced to a salted one-way hash kept up to 2 years — blocks repeat welcome-credit abuse, cannot be reversed or tied to you
- ✓Daily backupthe daily-overwritten copy no longer contains your identifying data after the next backup cycle (within 24 hours); a separate point-in-time recovery snapshot taken at the moment of deletion is retained for disaster-recovery purposes and is not immediately purged
Every link to your identity is destroyed at the moment of deletion. Two narrow categories persist for a limited time without any identity link: financial records (purchase and usage amounts) are anonymized to the DELETED_USER tombstone and kept for 2 years under the ayıplı hizmet (defective service) statute of limitations (Turkish Consumer Protection Law, Art. 15-16), and a salted one-way device hash is kept up to 2 years to prevent repeated free-credit grants (GDPR Art. 6(1)(f) legitimate interest). Both are automatically purged from the live system when the window expires. The daily-overwritten backup no longer reflects deleted accounts within 24 hours; however, point-in-time recovery snapshots taken before a deletion are retained for disaster-recovery purposes and are not immediately purged.
Using the in-app deletion constitutes your formal exercise of the right to erasure under GDPR Art. 17 and KVKK Art. 11(e). If you cannot access your account, contact privacy@safescribe.dev to submit a deletion request by email.
Audio Processing
Zero Disk Policy
- ✓RAM-onlyaudio processed in volatile memory only
- ✓Never written to our disksnot even temporarily. (The app does write a temporary compressed copy to your device while recording; it is removed once the upload succeeds.)
- ✓No AI trainingyour audio is never used to improve models
- ✓Self-hosted AIno third-party AI service receives your audio
- ✓TTL failsafedata self-destructs even if deletion code fails
Authentication
Sign-In via Google or Apple
We use OpenID Connect (OIDC) via Google Sign-In and Sign in with Apple.
| What the provider sends us | What we do with it |
|---|---|
| Account ID | Hashed (SHA-256 + salt) — original discarded |
| Email address | Used for authentication only — not stored |
| Display name | Not stored |
We do not access your contacts, calendar, or any other account data.
Payments
Billing via App Stores
Payments are processed entirely by Apple App Store or Google Play Store. SafeScribe never receives, stores, or processes credit card numbers or payment details. We receive only a purchase receipt for balance verification.
Error Tracking
Crash Reports (Optional)
We send optional crash reports to SafeScribe’s own crash reporting endpoint. This is off by default and can be toggled from Privacy Settings at any time.
Before any report is transmitted, the following are automatically removed:
Redacted: email addresses · phone numbers · IP addresses · file paths · authentication tokens
Retained: error type and stack trace · device model · OS version · app version
Third Parties
Third-Party Services
We use the following services. No audio, transcript content, or personal information beyond what is noted is shared with any third party.
| Service | Purpose | Data shared | Privacy Policy |
|---|---|---|---|
| Cloudflare (Tunnel) | Keeps our servers off the public internet and absorbs denial-of-service attacks | Your request in transit — including your IP address and, because the shield works by decrypting and re-encrypting the connection at Cloudflare’s nearest edge, the audio while it passes through. Cloudflare does not transcribe, analyse, or store it. | cloudflare.com/privacypolicy |
| Cloudflare (R2) | Off-site backup of the billing ledger | Pseudonymous user hash, balance and usage figures — no audio, no transcripts | cloudflare.com/privacypolicy |
| Google Sign-In | Authentication | OIDC token only | policies.google.com/privacy |
| Apple Sign-In | Authentication | OIDC token only | apple.com/legal/privacy |
| Apple App Store | In-app purchases | Purchase receipt only | apple.com/legal/privacy |
| Google Play Store | In-app purchases | Purchase receipt only | policies.google.com/privacy |
| SafeScribe crash endpoint | Crash reporting (opt-in) | Anonymised error report — PII stripped | SafeScribe-operated, no third party |
Legal Basis
Legal Basis for Processing
| Processing activity | GDPR Basis | KVKK Basis (Turkey) | Required? |
|---|---|---|---|
| Audio transcription | Art. 6(1)(b) — Contract | Explicit consent | Required to use the service |
| Account & billing | Art. 6(1)(b) — Contract | Contract performance | Required to use the service |
| Authentication (OIDC) | Art. 6(1)(b) — Contract | Contract performance | Required to use the service |
| In-app purchases | Art. 6(1)(b) — Contract | Contract performance | Required to make purchases |
| Crash reporting | Art. 6(1)(a) — Consent | Explicit consent | Optional |
Providing data for transcription, authentication, and billing is required to use SafeScribe. Crash reporting is optional — the service operates fully without it.
Your Rights
What You Can Do
- ✓Accessview all your transcripts in the app at any time
- ✓Deleteremove individual transcripts or delete your entire account from Privacy Settings; account deletion leaves zero rows in any database
- ✓Exportshare or export transcripts, or request a full data export from Privacy Settings
- ✓Opt out of diagnosticsturn off crash reporting in Privacy Settings
- ✓Withdraw consentsign out and delete your account at any time
- ✓CCPA opt-outtoggle "Do Not Sell or Share" in Privacy Settings
- ✓No automated decisionswe never make automated decisions about you, including profiling with legal or similarly significant effects (GDPR Art. 22)
- ✓Lodge a complaintEU/EEA residents may contact their national supervisory authority (edpb.europa.eu); Turkey residents may contact KVKK (kvkk.gov.tr)
For any request you can’t complete in-app, contact privacy@safescribe.dev.
Legal
Additional Information
Data controller. SafeScribe is operated by an independent developer based in Turkey. Contact: privacy@safescribe.dev. No Data Protection Officer (DPO) has been appointed — processing is not carried out at large scale and no special-category data is systematically retained (audio is processed ephemerally in our server’s RAM only, never persisted to our disks).
Backups. A single daily backup of account records (pseudonymous ID, balance, usage statistics) is maintained for service continuity. Each backup overwrites the previous one. Data deleted by account deletion is removed from live systems immediately and from the backup within 24 hours.
International transfers. If you use SafeScribe from the EU/EEA, your audio and account data are processed on servers in Turkey, which does not hold an EU adequacy decision. Your upload goes straight from your own device to us, so there is no EU-based exporter and GDPR Chapter V (Arts. 44–49) does not apply to it — see EDPB Guidelines 05/2021 v2.0, Example 1. We are bound by the GDPR directly through Art. 3(2) because we offer the service to people in the EU, and the lawful basis for the processing itself is your consent under Art. 6. One onward step is a transfer: your connection reaches us through Cloudflare, whose nearest edge may sit outside Turkey — see Third-Party Services. For users in Turkey, cross-border transfer is authorised under KVKK Art. 9.
Children. SafeScribe is for adults. The app asks you to confirm you are 18 or older before you can use it, and the Terms of Service set the same requirement. We do not knowingly collect data from anyone under 18. The store content rating (4+) describes the absence of objectionable material, not the intended audience — the audience declared on Google Play is 18+.
Policy changes. We will update this page when our practices change. The “Last updated” date above reflects the most recent revision.
Contact
Get in Touch
| Topic | Contact |
|---|---|
| Privacy requests, data deletion, rights | privacy@safescribe.dev |
| Security vulnerabilities | security@safescribe.dev |
| General support | support@safescribe.dev |