1. Scope and who is responsible
This Privacy Policy applies to the ScriptGecko website, accounts, subscription features, and Instagram transcription service (the “Service”). ScriptGecko is the controller of personal information processed for operating the Service. This policy does not control the privacy practices of Instagram, Meta, or third-party websites you choose to visit.
Questions and privacy requests can be sent to legal@scriptgecko.com.
2. Information we process
Information you provide or authorize
- Account information. If you sign in with Google, we receive account identifiers and profile information you authorize Google to provide, such as your email address, name, and profile image. We do not receive your Google password.
- Instagram links and content. We process the public Instagram Reel, video, or post URL you submit and the associated audio needed to produce a transcript.
- Communications. If you contact us, we process the information included in your message so we can respond.
Information created when you use the Service
- Transcription data. The transcription provider processes temporary audio, transcript text, timestamps, detected language, and technical job identifiers. ScriptGecko returns the transcript to your browser but does not store transcript text in its application database.
- Usage and credit records. For paid accounts, we store job identifiers, duration, status, credits reserved or used, completion time, and limited failure information. For free use, a signed first-party cookie records the current UTC date and daily use count.
- Billing information. We store Stripe customer and subscription identifiers, plan, subscription status, billing-period dates, invoice identifiers, credit allocations, and limited payment-failure details. Stripe—not ScriptGecko—collects and stores your full payment-card details.
- Technical information. Our hosting and security providers may process IP address, browser and device information, request URLs, timestamps, referring pages, and diagnostic or security logs.
3. How and why we use information
We use information to:
- provide authentication, transcription, billing, subscription management, and account features;
- apply free-use limits and paid credit rules, including releasing credits when a transcription fails;
- secure the Service, prevent fraud and abuse, troubleshoot errors, and maintain reliability;
- respond to support, privacy, billing, and legal requests;
- comply with legal, tax, accounting, and regulatory obligations; and
- improve the Service using operational or aggregated information.
Where applicable law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and protecting the Service, compliance with legal obligations, and consent where we specifically ask for it. You can withdraw consent where consent is the basis, without affecting earlier lawful processing.
4. When we disclose information
We do not sell personal information or share it for cross-context behavioral advertising. We disclose only what is reasonably necessary to these categories of recipients:
- Supabase for authentication and application database services.
- Google when you choose Google sign-in.
- Stripe for checkout, recurring billing, invoices, payment security, and the customer portal.
- SocialKit to retrieve supported media from the public Instagram URL you submit.
- AssemblyAI to process audio and produce the transcript.
- Vercel for hosting, delivery, security, and technical logs.
The Footer contains badges hosted by There’s An AI For That. Loading those files or following those links may provide that service with your IP address, device details, referring page, and ordinary request information under its own practices.
We may also disclose information when required by law, to protect users or the Service, to investigate misuse, or as part of a merger, financing, acquisition, reorganization, or sale of assets. A successor must handle covered personal information consistently with this policy unless it provides legally required notice otherwise.
5. Cookies and similar technologies
ScriptGecko uses first-party cookies that are necessary for authentication, session continuity, security, and daily free-use limits. The daily quota cookie is HTTP-only and expires at the next UTC midnight. Authentication cookies may last longer so your session can continue securely.
We do not currently operate our own advertising or cross-site behavioral analytics cookies. Stripe, Google, and other third-party pages you intentionally open may use cookies under their own policies. You can clear cookies in your browser, but doing so may sign you out or prevent account and quota features from working correctly.
6. Data retention
- ScriptGecko does not store completed transcript text in its application database.
- Free-use quota cookies expire at the next UTC midnight.
- Account, subscription, credit, and job metadata is retained while needed to provide the Service, maintain accurate transaction records, resolve disputes, prevent abuse, and satisfy legal obligations.
- Third-party processors retain data according to our account settings, their agreements with us, and their published policies. Audio and transcript artifacts may remain with a processor for its configured operational retention period after a job completes.
- After a valid deletion request, we delete or de-identify information that is no longer needed, subject to legal, security, fraud-prevention, backup, accounting, and dispute-resolution exceptions.
7. International data transfers
ScriptGecko and its providers may process information in countries other than where you live, including the United States. Where required, providers may rely on adequacy decisions, contractual safeguards, or other lawful transfer mechanisms. Privacy and government-access laws may differ between countries.
8. Your privacy rights
Depending on where you live, you may have the right to request access, a copy, correction, deletion, restriction, portability, or an objection to certain processing. You may also have the right to withdraw consent, opt out of certain disclosures, and appeal a denied request. We do not discriminate against anyone for exercising a privacy right.
Send requests to legal@scriptgecko.com. State the email associated with your account and the request you want to make. We may ask for information needed to verify your identity and authority. You may also complain to your local data-protection authority.
9. Security
We use reasonable technical and organizational safeguards designed to protect information, including encrypted transport, restricted server credentials, signed webhooks, row-level database access controls, and payment processing through Stripe. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
11. Changes to this policy
We may update this policy when the Service, providers, or legal requirements change. We will post the revised version here and change the “Last updated” date. If a change is material, we will provide additional notice when required by law.
12. Contact
For privacy questions or requests, email legal@scriptgecko.com.