Scrieb
For IT, security and data protection teams

Data Protection & Security

Scrieb is built so that the sensitive part, your recordings and transcripts, never leaves your computer. A small backend handles accounts and billing and sees metadata only.

This page describes what is processed where, based on the current application and backend. It is a technical description, not legal advice and not a contract.

Request the security whitepaper

Two classes of data, kept apart

Stays on your device

  • Audio recordings (microphone and system audio)
  • Transcripts and timecodes
  • Summaries
  • Your edits and notes

Created, processed and stored locally. Not transmitted to Scrieb or to any third party.

Reaches the Scrieb backend

  • Email address (for the login link)
  • A random device ID, operating system, app language and version
  • Recording usage in seconds, a counter for plan limits
  • Product analytics events: names and metadata, never content
  • Payment and subscription data, handled by Stripe

What we can confirm about your content

These are the questions we get from lawyers, clinicians and researchers, answered directly. They apply to the current version of the app.

  1. Audio recordings stay on your computer. They are written to a folder you choose and are never uploaded.
  2. Transcription and speaker identification run locally. Both models execute on your CPU or GPU. No audio is sent anywhere for either step.
  3. Summaries are generated locally. The summarisation model also runs on your device.
  4. No content reaches our servers or any third party. Recordings, transcripts, summaries, edits and notes are not transmitted to Scrieb or to any other service.
  5. No content is used for AI training, analytics or telemetry. We do not train models; the models are downloaded, not trained by us. Analytics events carry event names and metadata only, never text or audio.

The app needs an internet connection for the login link, subscription checks, updates and the one-time model download. None of those requests carry conversation content.

AI runs on the device

Speech-to-text, speaker identification and summarisation use open-source AI models that run as local processes on your Mac or Windows PC. No audio or text is sent to a cloud AI service. Scrieb does not use OpenAI or any other hosted AI API for your content.

The model files are downloaded once during setup from a public model repository. That download carries no user content, only a standard file request. After it, transcription works with no internet connection at all.

Security measures

On the device

  • Optional database encryption with SQLCipher (256-bit key), enabled in Settings. The key is generated with a secure random generator and stored in the OS keychain.
  • Session tokens are stored in the macOS Keychain or Windows Credential Store.
  • Audio files are standard files on disk and rely on your disk encryption (FileVault, BitLocker).

In transit

  • All traffic between app and backend uses HTTPS/TLS with the system trust store.
  • Certificate validation is never disabled.

Authentication

  • Passwordless login: a one-time link by email, valid about one hour, single use.
  • API calls use signed session tokens (JWT).
  • Plan-limit values sent to the app are signed so tampering is detectable.

Backend access

  • Admin interfaces are bound to localhost and reachable only through an SSH tunnel plus an admin secret.
  • They are not exposed to the internet.

Subprocessors

Services involved in running the account and billing side. None of them receives recordings or transcripts.

ServicePurposePersonal dataLocation
DigitalOceanBackend hostingAccount and usage metadataFrankfurt, Germany
StripePayments and billing portalEmail, payment data, billing countryUS / global
ResendTransactional email (login links)Email addressUS / global
Hugging Face / CDNOne-time download of the open-source AI modelsNo user content; standard request metadata such as IP addressUS / global
Google reCAPTCHABot protection on a website form only, not in the appIP address, browser signalsUS / global

International transfers

Content data never leaves your device, so there is no international transfer of recordings, transcripts or summaries. The backend is hosted in Frankfurt, Germany. Account metadata such as your email and billing details is shared with the payment and email providers above, some of which are US-based or global, so limited transfers of that metadata outside the EU/EEA can occur through them.

Retention, deletion and your rights

Local content

  • Kept until you delete it. Deleting a recording removes its transcript, timecodes and notes, and optionally the audio file.
  • Uninstalling the app or deleting the storage folder removes everything.

Export and portability

  • Transcripts export to TXT, DOCX and PDF, locally, with no upload.

Account data

  • Account deletion, including subscription and usage records, is done on request by email.
  • Login-link tokens expire after about one hour and can be used once.

Data subject requests

  • Write to alex@scrieb.com. Requests concerning recordings cannot be handled by us, because we never hold them; they are answered by whoever operates the device.

Roles under GDPR

For recordings, transcripts and summaries, your organisation is the controller and Scrieb is not a processor: we never receive that content, so no processing on our side takes place. For the account and billing metadata listed above, Scrieb is the controller.

If your organisation deploys Scrieb to staff and your data protection officer requires an Article 28 agreement covering the account metadata, contact us.

Documentation for your review

Available on request, free of charge, for organisations evaluating Scrieb:

  • Data Protection & Security Whitepaper: architecture, data flows, security measures, current limitations.
  • Data Processing Summary: roles, categories of data, subprocessors, transfers, retention, in the structure a DPO expects.
Request the documents

Related pages

→ Privacy Policy→ Transcription for Lawyers→ GDPR Transcription→ Local Transcription→ Legal Notice