Privacy Policy

How RiverScript collects, uses, and protects your personal information.

Last updated: August 22, 2026

RiverScript is operated by Lex Valo (Business ID: 3617726-2), a business registered in Finland ("we", "us", "our"). This policy explains what personal data we handle, why, and your rights under the General Data Protection Regulation (GDPR).

Contact for all privacy matters: Lex Valo (Business ID: 3617726-2), Finland — [email protected]


Our Two Roles

RiverScript handles two very different kinds of data, and our legal role is different for each. This distinction matters, so we state it up front.

DataOur GDPR roleWho decides why it is processed
Account data (email address, settings, balance, subscription status)ControllerUs
Billing and payment recordsControllerUs (with Polar as Merchant of Record)
Security, anti-abuse and error diagnostics dataControllerUs
Anonymous analyticsControllerUs
Your content — audio and video you upload or record, and the transcripts, translations, and AI outputs derived from itProcessorYou

You decide what to record, whom to record, and why. We never choose the purpose of your content — we only do what you instruct us to do with it: transcribe it, translate it, summarize it, store it until you delete it. That makes you the controller of that content and us your processor.

Where you use RiverScript in a professional, employment, or business capacity and your content contains other people's personal data, you (or the organization you act for) are the controller, we are your processor, and our Data Processing Terms apply automatically — you do not need to sign anything.

Where you use RiverScript purely for personal or household purposes, GDPR does not impose controller obligations on you (Art. 2(2)(c)). We apply the same protections to your content either way.

Recording rules differ from one country to another, and sometimes between regions of the same country. We recommend that you familiarize yourself with the rules that apply where you are and follow them — including asking everyone involved for their agreement before you record, where that is what your local rules expect. Because you are the one who decides what to record and why, that assessment rests with you. See Recording Responsibly for a plain-language overview.


What We Collect

Account data. When you sign up, we collect your email address — either directly via email registration, or through Google or Microsoft sign-in, which also gives us the display name held by that account. We store your interface preferences and settings.

Your content. Audio and video files you upload, and audio you record through the Desktop client's microphone or system audio capture and then submit for transcription. Every audio and video file that reaches our servers is automatically and permanently deleted 7 days after upload, regardless of whether your account remains active. What is produced from it — transcripts, translations, summaries, and AI chat conversations — stays in your account until you delete it, as described in the next item.

Files on your own device. The Desktop client keeps your recordings, and converted copies of files you work with, in a folder on your own computer, so you can trim them, re-use them, or submit them again later. Those files stay there until you delete them yourself — whether or not you ever sent them to us. They are your files in your folder, and we have no access to them.

Transcripts and derived output. Transcripts, translations, summaries, and AI chat output generated from your content, stored in your account until you delete them or close your account.

Usage data. Account-level operational data: transcription count, remaining balance, subscription status, and the technical metadata needed to run a job (file size, duration, chosen model and language).

Security and anti-abuse data. The IP address you registered from, stored with your account record, and the approximate country it resolves to. Server logs record IP addresses and request metadata for a short period. We also keep a record of IP addresses linked to confirmed abuse so that we can block them. We use this data only to keep the service secure and available — to stop fraudulent sign-ups, credential attacks, and automated scanning of our servers.

Error diagnostics. When something breaks, our error tracker (Sentry, hosted in the EU) records the technical details of the failure, which can include your account identifier, IP address, and the page or action involved. It never receives your audio or video.

For a small sample of sessions, and for sessions in which an error occurs, Sentry also records a masked replay of the interface. Text and input values are masked out inside your browser before anything is sent, and media is blocked, so a replay shows layout and interactions — which button was clicked, where the interface froze — not the content of your transcript.

Support communications. If you email us or use the in-app feedback and support buttons, we keep your message and our reply.

Analytics. We use two privacy-first analytics tools. Umami is self-hosted on our own infrastructure and collects only anonymous, aggregated page view data — no personal data, no cookies, no cross-site tracking. PostHog is configured with memory-only persistence, meaning it collects session-level product usage (such as which features are used) but stores nothing in cookies or local storage. Data is not retained between sessions.


What We Never Do With Your Content

This is a commitment, not a preference:

  • We do not train on it. Your audio, video, transcripts, and AI outputs are never used to train, fine-tune, evaluate, or benchmark any model — ours or anyone else's. We contractually require the same from every AI provider we send content to.
  • We do not sell, rent, or share it. Not for marketing, not for data brokerage, not for any purpose outside delivering the feature you asked for.
  • We do not use it for advertising or profiling. We run no advertising network and build no behavioral profiles.
  • We do not keep it to build datasets. Source audio is deleted after 7 days. Transcripts exist because you want them, and disappear when you delete them.

We do not read or listen to your content. There are three narrow exceptions, and nothing else:

  1. You ask us to — for example, you contact support about a specific transcript and ask us to investigate it.
  2. A technical fault cannot be diagnosed any other way — and then only to the minimum extent needed to fix it.
  3. We receive a specific, substantiated report that a piece of content is illegal or breaches our Terms of Service, or we are required to act by law.

Access is limited to the person who operates RiverScript and is kept to the minimum necessary in every case.


Recordings You Create

RiverScript's Desktop client can record your microphone and your computer's system audio. How that works matters for your privacy:

  • Recording happens locally, on your device, and only when you start it yourself. There is no remote activation, no hidden mode, and no way for us to start a recording on your machine. The app shows a visible recording state while it is capturing.
  • We receive only what you choose to submit. A recording you keep or discard locally never reaches our servers.
  • On macOS, system audio capture requires the operating system's Screen Recording permission, which only you can grant, and which you can revoke at any time in System Settings.
  • The rules about recording depend on where you are. They vary by country, and often by state or region. We recommend reading up on the rules that apply to you and following them — see Recording Responsibly.

Where we act as controller:

Processing activityLegal basis (GDPR Art. 6)
Account creation and authenticationContract performance — Art. 6(1)(b)
Operating the service you paid forContract performance — Art. 6(1)(b)
Subscription billingContract performance — Art. 6(1)(b)
Transactional emailContract performance — Art. 6(1)(b)
Support correspondenceContract performance — Art. 6(1)(b)
Anonymous analyticsLegitimate interests — Art. 6(1)(f)
Fraud, abuse and account-farming preventionLegitimate interests — Art. 6(1)(f)
Error diagnostics and service reliabilityLegitimate interests — Art. 6(1)(f)
Retaining records required by tax and accounting lawLegal obligation — Art. 6(1)(c)

Where we act as processor — that is, for your content and everything derived from it — we process only on your documented instructions, which are given by your use of the Services and by our Data Processing Terms. The legal basis for the underlying content, including any consent required from people appearing in a recording, is yours to establish as controller.

Special category data. Recordings can contain health, biometric, political, religious, or other sensitive information (GDPR Art. 9). RiverScript is a general-purpose transcription tool and is not designed or certified for regulated categories of data — see the "Our Services" section of the Terms of Service. If your content includes special category data, establishing an Art. 9 condition for it is your responsibility as controller.


Automated Decisions

We apply automated abuse checks to new account creation. If one of them stops you from signing up, email [email protected] and a person will review it. Beyond that, we do not carry out profiling or automated decision-making that produces legal or similarly significant effects concerning you.


Data Retention

DataRetention period
Source audio/video files7 days from upload, then permanently deleted
Transcripts and derived outputUntil you delete them or close your account
Account data (email address, preferences)Until you close your account
Registration IP addressStored with your account record; deleted when you delete your account
Blocked IP addressesUntil removed by us
Error diagnosticsSentry's standard event retention (currently up to 90 days)
Support correspondenceAs long as needed to handle your request and to keep a record of it
AnalyticsUmami: anonymous aggregates only. PostHog: memory-only, cleared at session end.
Payment recordsRetained by Polar in accordance with their privacy policy and applicable law
Database backupsDeleted data may persist in encrypted backups for up to 7 days, then rolls out of the cycle

Subprocessors

To provide RiverScript, we share data with third-party processors. Your audio files are sent to AI transcription providers solely to perform the transcription you requested; we do not permit these providers to use your data for any other purpose. A full list, including what each one processes and where, is on the Subprocessors page.

We keep that page current and give notice before a new subprocessor starts processing content, so that business customers can object. See the Data Processing Terms for how that works.


International Transfers

Several subprocessors are located in the United States. These transfers are conducted under Standard Contractual Clauses (SCCs) adopted by the European Commission, or under the EU-US Data Privacy Framework where the provider is certified. Core infrastructure (servers and database) is located within the EU.


Your Rights

Under the GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — delete your account and all associated data at any time from Settings → Privacy
  • Portability — receive your data in a structured, machine-readable format, or export any transcript yourself from the editor in any of the formats offered there
  • Object — object to processing based on legitimate interests
  • Restriction — request that we limit processing in certain circumstances

Most of these you can exercise yourself, immediately, from Settings — no request needed. To exercise any right, contact us at [email protected]. We respond within 30 days.

You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) tietosuoja.fi


If You Appear in Someone Else's Recording

If you believe a recording or transcript containing your voice or personal data was processed through RiverScript, please note that we are the processor for that content, not the controller. The person or organization who made the recording decides why it exists and what happens to it, and your rights of access, correction, and erasure are exercised against them.

We cannot identify who appears in a recording, and we do not search user content to look for individuals. If you contact us at [email protected] with enough information to identify the specific content, we will pass your request on to the account holder responsible and act on their instructions, as GDPR requires of a processor.

If the content is illegal rather than merely unwanted, use the reporting route in the "Reporting Illegal Content" section of our Terms of Service. That one we act on ourselves.


Cookies

We do not use tracking cookies.

We built RiverScript without advertising networks, retargeting pixels, or any form of cross-site tracking. The only cookies RiverScript sets are:

  • Session cookie (authjs.session-token) — keeps you logged in. This is a strictly necessary functional cookie required for the service to work.
  • Referral code — a temporary cookie (expires after 1 hour) set only when you arrive via a referral link. It contains no personal data and is deleted automatically after your account is created.

No advertising cookies. No social network trackers. No third-party cookies of any kind.


Data Security

Your data is stored on servers in the European Union (Hetzner Cloud, Helsinki, Finland). We use HTTPS/TLS for all data in transit, encrypted database connections, and access controls that limit who can reach production systems. Source audio files are automatically deleted after 7 days. Full details are on the Security page.

If a personal data breach occurs, we notify the Finnish Data Protection Ombudsman within 72 hours where the breach is notifiable, and we notify affected users without undue delay where the breach is likely to result in a high risk to their rights. Where we act as your processor, we notify you without undue delay after becoming aware, so that you can meet your own obligations as controller.


Sharing a Transcript

Transcripts are private by default and visible only to you. If you choose to share one, RiverScript generates a public link — anyone holding that link can read it. Search engine indexing of shared transcripts is disabled by default and can be enabled by you in Settings. You can stop sharing at any time from the Shared & Referrals page. Deciding whether a transcript is appropriate to publish, including any personal data it contains about other people, is your decision as controller.


Optional Integrations You Connect

RiverScript can send a transcript to another service you use, such as Notion, when you connect that service yourself and ask us to push a specific transcript to it. In that case we transmit the content to the destination you chose, on your instruction, and we store the access token you granted so the connection keeps working. Once the content arrives there, it is governed by that service's own terms and privacy policy, not ours. You can revoke RiverScript's access at any time from your account settings on that service.


Children

RiverScript is not directed at children under 16. We do not knowingly collect personal data from children.


Changes to This Policy

We may update this policy from time to time. If changes are material, we will notify registered users by email. The date at the top of this page always reflects the most recent update.


Contact

Lex Valo (Business ID: 3617726-2) Finland [email protected]