Privacy Policy
Last Updated: December 11, 2025
Welcome to EchoScribe ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and safeguard your data when you use our iOS mobile application and services.
1. Information We Collect
We collect the following types of information to provide and improve our services:
- Account Information: Email address, name, and password (hashed) when you create an account. If you use "Sign in with Apple," we receive your Apple User ID and email (if shared).
- User Content: Audio recordings you upload or record within the app, and the resulting text transcripts (including word timings and paragraphs).
- Device & Usage Data: Partial IP address (with last segment masked for privacy), User-Agent, and account-based app usage metrics. We also collect API access logs for security monitoring, debugging, and service improvement. All internal identifiers use randomly generated UUIDs (Universally Unique Identifiers) which are not enumerable or guessable. We do not collect device identifiers or OS version as standalone fields.
- Payment Information: Subscription status (Free/Pro), expiration date, and product IDs. Payments are processed by Apple via the App Store; entitlement management is provided by Adapty. We do not store your credit card information.
- Notifications: We collect your Push Device Token (APNS) to send you service notifications.
2. How We Use Your Information
We use your information to:
- Provide AI-powered transcription services (converting speech to text).
- Manage your account, identity, and subscription entitlements.
- Send important service notifications (e.g., "Transcription Ready", password reset codes).
- Prevent fraud, bot attacks, and abuse of our free tier limits via security checks and account-based usage controls.
3. Third-Party Services
We use trusted third-party service providers to operate our app. Your data may be processed by:
- Deepgram: Processes audio data for transcription purposes. Audio is streamed or provided via a temporary URL; we do not request persistent storage on their end. Retention and processing are subject to Deepgramās policies.
- Cloudflare R2: Used for temporary secure storage of audio files during the transcription process. Files are promptly deleted after processing; failures are monitored and remediated.
- Adapty: Used for managing subscription entitlements and syncing subscription status. We do not store payment card information.
- Apple: Used for "Sign in with Apple" authentication and delivering Push Notifications (APNS).
- Brevo: Used as an SMTP relay to send transactional emails (e.g., password reset codes).
- Cloudflare Turnstile: Used to verify that requests are made by humans, not bots.
- Expo Notifications (client-side): Used to obtain device push tokens for delivery via APNS.
4. Data Retention & Deletion
- Audio Files (Transient): We employ a strict "Transient Data" architecture. Your audio files are promptly deleted from our cloud storage (Cloudflare R2) after the transcription process is complete, regardless of success or failure. Any deletion failures are monitored for remediation.
- Transcripts: Text transcripts are stored securely in our database to allow you to access them across devices. They remain until you delete them or delete your account.
- Account Deletion: You can delete your account at any time within the app settings. This action permanently removes your account and associated data (including transcripts and stored files) from our systems. Certain system audit logs that are not linked to your identity may remain for security and integrity purposes.
- Tokens: Refresh tokens and blacklisted tokens are purged on a schedule; password reset codes expire and are invalidated. Database rows may remain until cleanup.
5. Security
We implement industry-standard security measures, including encryption in transit (HTTPS/TLS) and appropriate controls for data at rest (e.g., server-side encryption in cloud storage where configured). We use pre-signed URLs with short expiration times for secure file uploads, IP verification (trusted proxies) and header validation, and rate limiting to protect our services.
6. Children's Privacy
Our service is not intended for children under the age of 13. We do not knowingly collect personal information from children.
7. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
[email protected]