Start
Privacy and data handling
What leaves your device, what Scribiz keeps and for how long, what Google sees, and how to delete a result.
On this page
This page describes what happens to your media and your results. The privacy policy is the legal text. This page is the plain version.
What leaves your device
It depends on where you run Scribiz.
| You run | What is sent | To whom |
|---|---|---|
| Web, with a YouTube link | The link. YouTube blocks our server from downloading the video, so Google's model reads the public video from the link. No copy of the video is made. | Scribiz, then Google |
| Web, with another site's link or a direct media link | The link. Our server then downloads the audio, and for Watch a low-resolution copy, from the site. | Scribiz, then Google |
| Web, with a file | The audio. For a video file your browser extracts the audio first. | Scribiz |
| MCP server, with or without a key, a YouTube link | The link and your questions. Google's model reads the public video from the link. | Scribiz, then Google |
| CLI with your own Gemini key, Listen | The audio, as short 16 kHz mono chunks. Never the whole video. | Google (your key) |
| CLI with your own Gemini key, Watch or Both | A low-resolution copy of the video, built on your machine. | Google (your key) |
| CLI with your own Gemini key, a public YouTube link read through Gemini | The link. Google's model reads the video from YouTube. | Google (your key) |
| CLI signed in to Scribiz, Listen | The audio, as short chunks. Never the whole video. | Scribiz, then Google |
| CLI signed in to Scribiz, Watch or Both | A low-resolution copy of the video, built on your machine. | Scribiz, then Google |
| CLI with browser cookies for a site | Nothing. Cookies are read locally and used by the local downloader. | Nobody |
The Mac app is not out yet. It will run the CLI inside, so it will send the same things.
Scribiz never uploads a whole local video. For audio the file is cut into chunks on your machine. For video a small copy is made first.
For a public YouTube link on the hosted service, Auto mode uses its captions first. YouTube blocks the download from our server, so to listen, Scribiz passes the link to Google and Google's model reads the public video. For other sites and direct media links, our server downloads the audio (and for Watch a low-resolution copy of the picture), sends it to Gemini and deletes it when the job ends. The transcript from a YouTube link read this way has approximate timing and no speaker labels.
What the hosted service keeps
- Media. Audio chunks and low-resolution copies are deleted from Google's file store when the run ends, success or failure. As a backstop, Scribiz removes any it missed after two hours, and Google expires files after at most 48 hours. A file you upload to the API is removed when its job succeeds. After a failure it is kept until its one hour is up, so a retry needs no second upload.
- Results. A result is kept so that you can come back to it. Results are kept for 24 hours, or for 30 days when you are signed in. You can delete one sooner.
- Private links. A result lives at an unguessable address. It is not indexed by search engines and it is not in the sitemap. There are no public transcript pages.
- A reuse cache. To avoid paying twice for the same public video, Scribiz can reuse a stored result when someone else asks for the same video. The cache holds derived text, never media, and only for videos of a platform such as YouTube: never an upload and never a direct media link. Video details are kept for 24 hours, captions for 30 days and generated text for 90 days, and the cache is capped at 1 GB. It is never shown as a public page. On a takedown request it is purged.
What Google sees
Processing uses Google's Gemini API.
- The hosted service uses a paid-tier Gemini API account. Google's Gemini API terms say that content sent on the paid tier is not used to improve Google's products. Read the terms for the exact wording.
- When you use your own key, Google's rules for that key apply. Free-tier keys may let Google use your content to improve its products. Turn on billing for the key to opt out.
Your keys and cookies
- A Gemini key goes to Google only. The CLI stores it in
~/.scribiz/config.jsonwith mode 0600, and takes it from the environment if you setGEMINI_API_KEY. - The Scribiz key that
scribiz loginmakes goes to Scribiz only, and is stored in the same file with the same mode.scribiz logoutremoves it from that machine. It does not revoke it: revoke it in the dashboard. No flag takes a key, sopscannot show one. The Mac app, once it is out, will keep it in the Keychain. - Scribiz API keys are stored as a hash. Revoke a key in the dashboard and it stops working within about a minute.
- Browser cookies are used by the local downloader and are never sent to Scribiz. A hosted request for a site that needs a login fails and tells you to download the file and upload it.
Waitlists and website analytics
- Waitlists. If you join a waitlist (the Mac app, Mac Lifetime or Pro), Scribiz stores your email address, which list you chose, the page you joined from, the
?ref=tag of the link that brought you, and your country when it is known. It uses the address to send you one email when the thing ships. Nobody proves an address is theirs when they join, so before any email is sent, Scribiz will ask each address to confirm, and the one email goes only to addresses that did. The links in that email open a page with a button, and only pressing the button confirms or removes the address. If you remove an address with that link, Scribiz keeps a one-way code made from it (not the address) for 180 days, and a new sign-up with that address stores nothing and sends no email. To be removed from every list, use the form in the privacy policy. Deleting your account also deletes entries for your email address. - Analytics. The privacy policy says whether the website uses analytics, what it records and which cookies it sets. It is the source of truth for that.
Delete things
| What | How |
|---|---|
| One result | Press Delete on the result page, or send DELETE /v1/jobs/:id for a finished job |
| Everything in your account | Delete the account in the dashboard, or send DELETE /v1/account from a signed-in session. Results, keys and any remaining files at Google are removed. |
| A local cache | Delete the folder ~/.scribiz/cache. The CLI caches text, never media. |
| Your waitlist entry | Use the form in the privacy policy |
| A video you own, from the public cache | Send a takedown request. See the DMCA page at /dmca. |
Content you submit
You are responsible for having the right to process what you submit. Scribiz is for personal study, accessibility and your own content. It does not offer downloads of other people's videos. It returns transcripts and subtitles.
Not affiliated
Scribiz is not affiliated with YouTube, TikTok or Instagram.