Privacy Policy

Last Updated: March 22, 2025

Contents

1. Introduction

Grayscript ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered transcription and content generation service (the "Service").

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us:

  • First name and last name
  • Email address
  • Password (securely managed by our authentication provider)
  • Uploaded / Recorded audio and video files
  • Any other information you choose to provide

2.2 Automatically Collected Information

We automatically collect certain information when you use the Service:

  • Usage data and analytics
  • Log data and error information
  • Device information
  • IP address
  • Browser type and version
  • Time zone setting
  • Operating system and platform
  • Cookie data and local storage information

3. How We Use Your Information

We use the information we collect for various purposes:

  • To provide and maintain our Service
  • To improve and personalize user experience
  • To analyze and monitor usage patterns
  • To detect, prevent, and address technical issues
  • To communicate with you about Service-related matters
  • To comply with legal obligations
  • For marketing and promotional purposes
  • To enhance our services

4. Third-Party Service Providers

4.1 Authentication and User Management

4.2 Analytics and Performance Monitoring

  • PostHog for usage analytics
  • Sentry for error tracking and performance monitoring

4.3 Infrastructure and Database

  • Amazon Web Services (AWS) for hosting
  • Supabase for database services

4.4 Payment Processing

  • Stripe processes all payments and financial transactions
  • When you make a purchase, your payment information is collected and processed directly by Stripe
  • We do not store your credit card or payment information
  • For more information about how Stripe handles your data, please see Stripe's Privacy Policy

4.5 AI Processing

  • AssemblyAI for transcript generation
  • Anthropic's Claude and OpenAI's ChatGPT for content generation
  • Audio transcripts may be processed by either service to generate content

Our service providers have their own privacy policies. We encourage you to review the privacy policies of these third-party services for more detailed information about how they handle your data.

5. Data Storage and Security

We implement appropriate technical and organizational measures to maintain the security of your personal information, including:

  • Encryption of data in transit using HTTPS
  • Database encryption at rest
  • Secure authentication processes
  • Regular security updates and monitoring
  • Limited employee access to user data

6. Cookie Policy

We use cookies and similar tracking technologies to track activity on our Service and hold certain information. Cookies are files with small amount of data which may include an anonymous unique identifier. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

7. Data Retention

We retain your personal information indefinitely unless otherwise required by law. We maintain the right to:

  • Store all uploaded / recorded files
  • Store all generated transcripts and content
  • Retain user account information
  • Keep usage analytics and performance data

8. Your Privacy Rights

Residents of the European Economic Area and United Kingdom

Grayscript is considered the "data controller" of the "personal data" (as defined under the General Data Protection Regulation) we handle under this Policy. In other words, Grayscript is responsible for deciding how to collect, use, and disclose personal data, subject to applicable law. The laws of the European Economic Area and the United Kingdom require data controllers to tell you about the legal ground that they rely on for using, sharing, or disclosing your personal data. To the extent those laws apply, our legal grounds are as follows:

Contractual Commitments: We may use, share, or disclose personal data to honor our contractual commitments to you. For example, we will process your personal data to comply with our agreements with you, and to honor our commitments in any contracts that we have with you.

With Your Consent: Where required by law, and in some other cases, we use, share, or disclose personal data on the basis of your consent.

Legitimate Interests: In many cases, we use, share, or disclose personal data on the ground that it furthers our legitimate business interests in ways that are not overridden by the interests or fundamental rights and freedoms of the affected individuals, such as customer service, certain promotional activities, analyzing and improving our business, providing security for the Services, preventing fraud, and managing legal issues.

Legal Compliance: We need to use and disclose personal data in certain ways to comply with our legal obligations.

In addition to those rights described herein, you have the right to lodge a complaint with the relevant supervisory authority. However, we encourage you to contact us first, and we will do our very best to resolve your concern.

Residents of Nevada

If you are a resident of Nevada, you have the right to opt-out of the sale of certain personal information to unaffiliated parties. You can exercise this right by contacting us as described in the "Contact Us" section below with the subject line "Nevada Do Not Sell Request" and providing us with your name and the email address. We do not currently sell your personal information as sales are defined in Nevada Revised Statutes Chapter 603A.

Residents of California

Under the California Consumer Privacy Act ("CCPA"), we also have to provide you with the "categories" of personal information and sensitive personal information we collect and disclose for business or commercial purposes.

The categories of personal information are: identifiers, financial information (such as payment information), commercial or transactional information, internet or other electronic network activity information, general geolocation data, audio or video information (such as pictures and videos you submit), other information about you that you may provide to us voluntarily, such as through User Content, other information that may identify you, and inferences drawn from the information we collect.

We also collect the following categories of "sensitive personal information," as defined under the CCPA: (i) account log-in and password or other credentials that allow access to your account; and (ii) other sensitive personal information you may voluntarily provide to us in your capacity as an individual user of the Services.

We collect the categories of personal information identified above from the following sources: (1) directly from you; (2) through your use of the Services; and (3) other parties such as other users and through unaffiliated parties.

"Sale" and "sharing" of personal information

The CCPA sets forth certain obligations for businesses that "sell" or "share" personal information. Where we refer to "sell" or "share" (or their variants) in quotes, we are referring to those terms as uniquely defined in the CCPA.

We may use third-party analytics services and online advertising services that may result in the "sharing" of online identifiers (e.g., cookie data, IP addresses, device identifiers, general location information, and usage information) with advertising partners to advertise the Services on other websites.

We do not knowingly "sell" or "share" the personal information of children under 16.

Do-Not-Track disclosure

We do not respond to browser-initiated Do Not Track signals, as the Internet industry is currently still working on Do Not Track standards, implementations, and solutions.

CCPA rights

The CCPA also allows you to limit the use or disclosure of your "sensitive personal information" if your sensitive personal information is used for certain purposes. Please note that we do not use or disclose sensitive personal information other than for purposes for which you cannot opt out under the CCPA.

9. International Data Transfers

Our services are global and your information may be stored and processed in the United States and other countries outside the United States that may have data protection laws that differ from the laws in your country, and data may be accessible to law enforcement and national security authorities under certain circumstances.

By using the Services, or providing us with any information, you consent to the collection, processing, maintenance, and transfer of such information in and to the United States and other applicable countries in which the privacy laws may not be as comprehensive as, or equivalent to, those in the country where you reside and/or are a citizen.

10. Children's Privacy

Our Service is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us.

11. Changes to Privacy Policy

We reserve the right to update or change our Privacy Policy at any time. Your continued use of the Service after we post any modifications to the Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at support@grayscript.com.