1. Scope
This policy applies to the AudioGist web app, API Worker, compute service, and related transactional emails. Third-party sites, hosted payment pages, and model providers are governed by their own policies.
2. Data we process
To provide the service, the system may process these categories:
- Account data: name, email, authentication methods, and session device information.
- User content: uploaded audio and video, YouTube source URLs, transcripts, summaries, action items, and edits.
- Service data: job state, processing duration, usage, error codes, request IDs, pseudonymous rate-limit keys, and allowlisted product events that exclude titles, transcript text, email, and URL query parameters.
- Billing data: local subscription projection, plan, and provider customer identifiers; the payment provider hosts complete card details.
3. Purposes and legal basis
Data is used to create and protect accounts, complete transcription jobs, generate requested AI results, enforce quotas and subscriptions, send transactional email, prevent abuse, diagnose failures, and meet legal obligations. The production operator must document applicable contractual, legitimate-interest, or consent-based legal grounds for each service region.
4. Media and AI processing
Source files are written to private object storage and processed by an isolated compute plane. The default configuration deletes source objects after successful processing; an authenticated user may instead retain sources for uploads and recordings created afterward, and transcript or account deletion still removes them. AudioGist's product policy is not to train models on customer content; before launch this section must identify the actual model providers, regions, retention periods, and data controls.
5. Retention
Different data follows different lifecycles:
- Source media: deleted after successful transcription by default; failed and orphaned uploads are handled by cleanup jobs.
- Transcripts and summaries: retained until the user deletes the project or account.
- Sessions, verification records, and rate limits: removed according to their security lifetime or cleanup schedule.
- First-party product events: deleted with the associated account; the production operator must also define a fixed retention window for aggregate analysis.
- Payment and provider records: retained as required for tax, dispute handling, and provider policies.
6. Sharing and subprocessors
Data is shared with cloud infrastructure, Cloudflare Web Analytics, email, payment, and model providers only as needed to deliver the service. AudioGist does not sell personal data. Before launch, the operator must publish the active subprocessors and cross-border transfer arrangements.
7. Security measures
The system uses HttpOnly session cookies, exact-origin CORS, Turnstile, pseudonymous rate limiting, single-use upload tokens, HMAC job signatures, user-level ownership checks, and secret isolation. No internet service can promise absolute security; suspected risks should be reported promptly.
8. User rights and deletion
Users can access and edit some account data, delete individual transcripts, revoke device sessions, or request account deletion after canceling an active subscription. Final deletion removes AudioGist-owned D1 and R2 data; records lawfully retained by third parties remain subject to their processes.
9. Contact and changes
Send privacy requests to [email protected]. Material changes should be announced in the product or by email and reflected in the date above.