Privacy Policy

Last Updated: July 4, 2026

1. Overview

TerpScribe is built for professional consecutive interpreters handling confidential, privileged, or legally sensitive proceedings. This policy explains, in full, what data we collect, why, how it's protected, how long we keep it, and what rights you have over it.

The short version: your audio and transcripts never leave your Mac. The only data that reaches our servers is what's necessary to authenticate your account, enforce your subscription, and understand basic, non-identifying product usage.

2. Local Processing of Audio & Transcripts

  • Audio: All microphone and system-audio capture, voice activity detection, and speech recognition happen entirely in memory, on your local Mac, using the offline Qwen3-ASR (1.7B, 4-bit) speech model running via Apple's MLX framework. No audio is ever transmitted to, or stored on, our servers or any third party's servers.
  • Transcripts: Transcribed text is generated locally and displayed only in your local app instance. Transcript content is never uploaded, logged remotely, or included in any diagnostic or analytics data we collect (see Section 4).
  • Term Counts: Quick-reference terms, names, addresses, and any other content you view or copy from the transcript are never transmitted off your device as content — only anonymous counts (e.g., "a quick-reference term was added") are ever recorded, as detailed in Section 4.

3. Data We Collect and Store

To authenticate your account, enforce our one-device licensing terms, process payment, and maintain basic product analytics, we collect:

  • a) Account & Authentication Data: Email address and basic profile information, when you register or sign in via Google or email/password. This is managed through Google Firebase Authentication. Passwords, when used, are never visible to us in plaintext — Firebase handles credential storage and verification directly. Your session refresh token is stored locally on your Mac in the macOS Keychain (via the system's built-in secure credential storage), not in a plaintext file, and not on our servers.
  • b) Hardware Identifier: To enforce our single-device license terms and prevent account sharing/abuse, we generate a hardware identifier derived from your Mac's platform UUID and associate it with your account in our database. This identifier cannot be reverse-engineered to reveal any other information about your device or its contents.
  • c) Billing & Subscription Data: Subscription status, plan, and payment/invoice history are processed and stored by Paddle.com, Inc., our merchant of record. We do not receive, transmit, or store your credit card number, bank details, or other raw payment credentials — Paddle handles all such data directly and is PCI-DSS compliant.
  • d) Anonymous Product Analytics: We use Google Analytics 4 (via the Measurement Protocol) to understand aggregate product usage — for example, session length, which app features are used, and macOS version distribution. Analytics events are tied to a randomly generated installation identifier (a UUID stored locally in your app settings), not to your name, email, or account. This identifier cannot be used to re-identify you personally from our side, though Google's own privacy practices govern data once it's in their systems (see Section 4). No transcript content, quick-reference term content, or any other content you type, speak, or paste is ever included in analytics events — only counts, durations, and feature-usage flags, as documented in our own source code's analytics module. At this time, no user-facing toggle exists in the desktop application settings to disable anonymous analytics, but one is planned for a future update.

4. Third-Party Services

We rely on the following third parties to operate TerpScribe. Each is contractually and/or technically limited to the data described above:

  • Google Firebase (Authentication & Firestore): manages login credentials, session tokens, and subscription/licensing records. Firebase's own privacy practices are described at https://firebase.google.com/support/privacy.
  • Google Analytics 4: processes anonymous, installation-level usage analytics as described in Section 3(d). Google's privacy practices are described at https://policies.google.com/privacy.
  • Paddle.com, Inc.: acts as our merchant of record for all subscription billing, VAT/tax compliance, and invoicing. Paddle's privacy policy is available at https://www.paddle.com/legal/privacy.

We do not sell, rent, or share your personal data with any other third party for their own marketing or advertising purposes.

5. Recommended Third-Party Software (BlackHole)

TerpScribe's setup guide recommends BlackHole, a free, open-source virtual audio driver by Existential Audio Inc., to route videoconference audio for transcription. BlackHole is independent, third-party software that we do not develop, control, or distribute — installing it is entirely optional and at your discretion. BlackHole's own license (GPL-3.0) and any data practices are governed solely by Existential Audio Inc., not by TerpScribe. Please review BlackHole's own documentation at https://github.com/ExistentialAudio/BlackHole before installing it.

6. Data Retention & Deletion

  • Account and billing data is retained for as long as your account remains active, plus a limited period afterward as required for tax, accounting, and fraud-prevention obligations.
  • You may request deletion of your account and associated data (email, hardware identifier, and Firestore subscription records) at any time by submitting a request via our contact form with the subject "Account Deletion Request." We will process deletion requests within 30 days, except where retention is legally required (e.g. billing records needed for tax compliance).
  • Locally stored data — settings, cached transcripts if any are saved locally, and the Keychain-stored session token — can be removed at any time by signing out of the app and/or deleting the app itself; this data never reaches our servers in the first place.
  • Anonymous analytics data tied to your installation UUID is retained by Google Analytics per Google's standard retention settings and is not linked to your identity on our end, so it cannot be individually deleted upon request in the same way account data can.

7. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

For users in the European Economic Area, UK, and Switzerland (GDPR): the right to access, correct, delete, or port your data; the right to restrict or object to processing; and the right to lodge a complaint with your local data protection authority.

For California residents (CCPA/CPRA): the right to know what personal information we collect and why; the right to delete it; the right to correct inaccurate information; and the right to opt out of the sale or sharing of personal information — though we do not sell or share your personal information with third parties for monetary or other valuable consideration.

To exercise any of these rights, contact us via our contact form. We will respond within the timeframe required by applicable law.

8. Children's Privacy

TerpScribe is intended for use by professional interpreters and other adult professionals. It is not directed at, marketed to, or knowingly used by children under 13 (or the relevant minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us via our contact form and we will delete it promptly.

9. International Data Transfers

Because our service providers (Google Firebase, Google Analytics, Paddle) operate data centers in multiple countries, your account and billing data may be processed or stored outside your country of residence, including in the United States. These providers maintain their own safeguards for international transfers (e.g. Standard Contractual Clauses where applicable under GDPR).

10. Security

We rely on industry-standard security practices, including:

  • TLS/SSL-encrypted connections (verified via certificate validation, never disabled) for all communication with Firebase and Paddle.
  • Storage of session credentials in the macOS Keychain rather than in plaintext files on disk.
  • No storage of audio or transcript content on any server, by design — the most effective security measure for that data is that it never leaves your device.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work to protect your data using practices appropriate to its sensitivity.

11. Cookies & Website Tracking

Our website (terpscribe.com) may use minimal, privacy-respecting analytics to understand site traffic. At this time, our website does not use tracking cookies or third-party advertising scripts.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date above and, for significant changes, notify active users via email or an in-app notice. Continued use of TerpScribe after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

Questions about this Privacy Policy or your data can be directed to us via our contact form.
Address: [insert business name / address if applicable for legal notices]