Security

How RiverScript protects your data and what controls you have over it.

Infrastructure

RiverScript runs on servers located in the European Union — specifically Hetzner Cloud data centers in Helsinki, Finland. Your transcripts and account data never leave the EU.

Audio files are stored on Cloudflare R2 and are accessible only via authenticated, time-limited URLs. Audio files are automatically and permanently deleted 7 days after upload.

Data in Transit and at Rest

All communication between your browser or Desktop Client and RiverScript is encrypted over HTTPS/TLS. Database connections are encrypted. Access to production systems is restricted to authorized personnel only.

Who Can Access Your Content

Within the application, your transcripts are visible only to your account, and to anyone holding a share link you generated yourself.

On our side, we do not read or listen to your content. There are three narrow exceptions: when you ask us to look at something specific, when a technical fault cannot be diagnosed any other way, and when we receive a substantiated report of illegal content or a breach of our Terms — or where the law requires it. In every case access is limited to the person who operates RiverScript and kept to the minimum necessary. The full statement is in the Privacy Policy.

We never use your content for model training, advertising, or any purpose of our own, and we require the same of every provider we send content to.

Your Data Controls

You have full control over your data directly from the RiverScript interface:

  • Delete individual transcripts — remove any transcript from your account at any time from the transcript list.
  • Delete all your files — permanently delete all transcripts and files in your account at once, without deleting the account itself. Available in Settings → Privacy.
  • Delete your account — permanently deletes your account and all associated data, including transcripts and account settings. Available in Settings → Privacy. Source audio files are deleted on their normal 7-day schedule if not already gone.
  • Export your transcripts — download any transcript from the editor in any of the formats offered there, at any time.

No need to contact support for any of the above — these controls are available to you directly.

Audio File Retention

Source audio and video files are automatically deleted from our storage 7 days after upload. This happens regardless of whether your account is active or not. Transcripts generated from those files are retained separately until you delete them.

Deleted data may persist in our database backups for up to 7 days before it rolls out of the backup cycle.

Security Incidents

If a personal data breach occurs, we notify the Finnish Data Protection Ombudsman within 72 hours where the breach is notifiable, and we notify affected users without undue delay where the breach is likely to result in a high risk to their rights.

Where we act as a processor for business customers, we notify the customer without undue delay after becoming aware, with the information they need to meet their own obligations. See the Data Processing Terms.

Reporting a Security Issue

If you discover a security vulnerability in RiverScript, please contact us at [email protected]. We take all reports seriously and will respond promptly.

Please give us a reasonable opportunity to fix an issue before disclosing it publicly. We will not pursue action against anyone who reports a vulnerability in good faith, without accessing or modifying other people's data, and without degrading the service for others.