Document

Privacy policy

Three separate places: your Mac, the recognition cloud and Scriptus servers. Here is what goes into each.

Draft for legal review. The data controller, jurisdiction and legal entity details will be stated after review.

Updated:

1. What stays on your Mac

Dictation history (only when retention is on), dictionary, snippets, settings and your Deepgram key are stored locally in the app. This data is never sent to Scriptus. You delete it yourself, in the app or by removing its data.

2. Speech recognition at Deepgram

During dictation, audio is streamed to Deepgram for recognition. Scriptus does not record audio on its servers and does not receive the recognised text.

  • Your own key: the app talks to Deepgram directly under your key. Processing follows Deepgram's terms and your agreement with Deepgram.
  • Scriptus access: the Scriptus server issues the app a short-lived token for one dictation; audio is still streamed directly to Deepgram. No permanent key is stored on your Mac.
  • Text cleanup by a model (if you enable it) runs under your own model provider key or locally; the text never passes through Scriptus servers.

3. What Scriptus stores

Scriptus servers exist only for the account and Scriptus access. We store:

  • Account: email address, user identifier, sign-in and account creation times.
  • Plan and invitations: which invite code was redeemed and when, the current plan and quota, including administrator overrides.
  • Usage metadata with Scriptus access: word count (as reported by the app, before cleanup), audio duration in seconds, timestamps, app version, session and token issuance identifiers, outcome (completed, cancelled, failed).
  • An administrator flag for accounts that manage invitations and quotas.
  • Access change history: administrator and user identifiers, action, access state before and after, timestamp and the reason entered by the administrator.

4. What Scriptus never stores

  • Dictated text and clipboard contents.
  • Audio or audio fragments.
  • Names of the apps and documents the text is pasted into.
  • Your Deepgram key and model keys.

5. Email and sign-in

Sign-in link emails are sent by the authentication provider (Supabase Auth) on behalf of Scriptus. The address is used for sign-in and support correspondence. There are no newsletters.

6. Website, cookies and analytics

The website loads no third-party scripts, fonts or trackers and sets no tracking cookies. Sign-in session data is stored in your browser and removed on sign-out.

7. Retention and deletion

Account data is kept while the account exists. Deleting the account from the account page removes the email address, plan, invite redemptions and usage metadata. The invitation's use counter remains as a number with no link to you. Local data on your Mac stays with you.

Access change history, including original identifiers and reasons, is not automatically removed with the account. Its retention period must be approved before public beta.

8. Your rights

You can request what data is stored, correct your email address or delete your account. Write to support from the account address, or delete the account from the account page.

Questions about data

Write to support@scriptus.online.