Skip to content
Try it free

Last updated 5 October 2026

Privacy Policy

Scribiz turns a video or an audio file into a transcript, the text and scenes shown on screen, a summary and chapters. This policy covers the website, the MCP server, the API and the command-line tool, and the Mac app once it is out. If something here is unclear, ask through the contact form.

Who we are

Scribiz is a service run from scribiz.com by Superleuk LLC, 500 Westover Dr #32164, Sanford, NC 27330, United States, and made by Ilias Ism (il.ly). In this policy, we means Superleuk LLC. Questions and privacy requests go through the contact form. Copyright notices and abuse reports go through the same form.

What we collect

  • What you submit. Links, and audio from files you upload on the web or that the Mac app or the CLI sends for hosted processing. A video file is never uploaded whole. The Mac app and the CLI send audio, and for Watch a small low-resolution copy of the picture with no sound.
  • What we make from it. The transcript, the on-screen text and scene notes, the summary and the chapters, and the private page that shows them.
  • Account details. If you sign in, your email address and name from Google or from the email you give us, your plan, the minutes you have used and the API keys you create. Keys are stored as hashes, so we cannot read them back.
  • Usage records. For each job: the mode, where it came from (web, Mac, CLI, MCP or API), how many minutes it used and whether it worked. We use them for limits, billing and finding faults.
  • Technical data. Your IP address and basic request details, used for rate limits and to stop abuse. For the limits that apply without an account, we turn your IP address into a code that changes every day, so the same person has a different code tomorrow and our usage records do not hold the address. Before Listen or Watch without an account we may ask Cloudflare Turnstile to check that you are not a script. Cloudflare runs that check under its own privacy terms.
  • Waitlists. If you join one, what it stores is listed in Waitlists below.
  • Messages. Anything you send through the contact form: the topic, the address you give so we can answer, and your text. We keep it for as long as it takes to deal with it, and you can ask us to delete it.

What stays on your device

With the CLI a local file is never uploaded whole. The audio is read on your computer. With your own Gemini key it goes from your computer to Google and not through Scribiz. The CLI keeps your key in ~/.scribiz/config.json, readable by you only, and the transcripts and summaries it makes as text in ~/.scribiz/cache. --no-cache turns that off. The Mac app, once it is out, keeps history and results in the app's folder on your Mac and your keys in the macOS Keychain.

On the website, your browser reads the audio out of the file you choose and uploads only that, and only after you press the button. If the browser cannot read the audio, the upload is refused. We never fall back to sending the video.

Cookies and browser storage

When you sign in, Scribiz sets cookies that keep you signed in. Scribiz sets no other cookies of its own.

Your browser also keeps a few things in its local storage, on your device only, and never sends them to us on their own:

  • Your light or dark theme choice.
  • The ref tag of the link that first brought you here, if it had one. It is sent with a waitlist sign-up so we know which link worked.
  • A list of the results you opened in this browser, so the dashboard can show your history.
  • Speaker names you typed on a result, and the tab you chose in the docs.

You can clear these in your browser settings at any time.

Waitlists

If you join a waitlist (the Mac app, Mac Lifetime or Pro), we store your email address, which list you joined, the ref tag and the page you came from, and your country when it is known. We use it to send you one email when the thing you joined for ships, and to confirm the address first (see below). We do not use it for anything else, and we do not write the address to our logs. A list for the command-line tool is no longer offered, because the tool is on npm. An address that joined it earlier is covered by the same rules.

Anyone can type any address into the form. When we send a confirmation email, the form says “Check your inbox to confirm.” We send one email to an address that joined, with a link to confirm it and a link to leave, and no more than one a day for each list. Each link opens a page with a button, and only pressing the button confirms the address or takes it off the list. Only confirmed addresses get the launch email. The form tells nobody whether an address is already on a list.

If you take an address off a list with the link in a confirmation email, we keep a one-way code made from that address (not the address itself) for 180 days. While it is kept, a new sign-up with that address stores nothing and sends no email. If you pressed it by mistake, write to us through the contact form and we will take the code away.

To be taken off, use this form. It removes the address from every list, and it answers the same whether or not the address was on one. If you delete your account, entries for your email address are deleted with it.

Analytics

This site counts visits with Plausible Analytics, running on a server of our own (p.il.ly), so the numbers go to no other company. Plausible sets no cookies and keeps nothing in your browser. It records the page you open, the page or link you came from (including a ref or UTM tag), your browser, operating system and device type, and your country, worked out from your IP address. The IP address itself is not stored. To count a visitor once a day it makes a code from the IP address and the browser, with a secret that changes every day, so yesterday's code cannot be matched with today's. It also records a few named events, such as a job starting, finishing or failing, a format being downloaded, a waitlist sign-up, a click on the Mac download or a pricing button, a checkout starting or completing, and an MCP snippet being copied. The events do not include the link you paste or the file you drop. The address of a result page (one that starts with /r/) is never recorded, because that address is the private link to the result.

What leaves your device, and where it goes

  • Links and audio sent for hosted processing go to our servers, and from there to the Gemini API from Google for transcription and analysis. For a public YouTube link, Auto mode uses its captions first. YouTube blocks the download from our server, so to listen we pass the link to Google, whose model reads the public video. We send Google the link, and we make no copy of the video. For other sites and direct media links, our server downloads the audio (and for Watch a low-resolution copy of the picture), sends it to Gemini and deletes it when the job ends.
  • What Google may do with what we send it depends on its terms for the kind of key used: its terms for paid use say it does not use prompts and responses to improve its products, and its terms for free-tier use say it may. Those are Google’s terms and they can change, so read the current Gemini API terms if this matters to you.
  • The result page for a YouTube video shows it in an embedded YouTube player. Opening the page loads Google’s player script and the player, and Google then receives your IP address and the video’s id, under Google’s own privacy policy.
  • When you sign in to Scribiz from the CLI (scribiz login), the CLI and the local MCP server send audio from your computer to our servers, and from there to the Gemini API from Google, as for hosted processing. With your own Gemini key, in the CLI or the local MCP server (and in the Mac app, once it is out), audio goes from your computer straight to Google under your key’s terms. For a public YouTube link that the CLI reads through Gemini, only the link goes to Google, and Google reads the video from YouTube. A free-tier key may let Google use your content to improve its products. Turn on billing for the key to opt out.
  • Files we upload to Google for a job are deleted when the job ends. If a delete ever fails, Google removes uploaded files itself within 48 hours.
  • We use a small number of service providers for hosting, sending emails (sign-in links, waitlist confirmations and our own copy of a contact message), error reports (when something fails on our servers, a short record goes to Sentry: the error and the id of the job or account it happened to, never your files or results) and bot protection. They handle data only to do that job. We do not sell your data, and Scribiz does not use your videos, audio or transcripts to train models of its own.

How long we keep things

  • Media. Uploaded audio and any temporary copy are deleted when the job ends.
  • Results. Without an account, a result is a private link that is kept for 24 hours and then deleted. A result kept by an account lasts 30 days, unless you delete it sooner.
  • Cache. To avoid doing the same work twice we keep a cache, keyed by the video’s identifier on the site it came from. It holds text, never media, and only for videos of a platform such as YouTube, never an upload or a direct media link. Video details are kept for 24 hours, captions for up to 30 days and generated text (transcript, scene notes, summary and chapters) for up to 90 days. It is used only when someone asks for that same video. It is never shown as a public page, and we purge it when a takedown notice requires.
  • Account and usage records. Until you delete your account. Billing records, once payments exist, for as long as the law requires.
  • Server logs. Kept briefly, and used only for security and debugging.

Results are private

A result lives at an address with a long random identifier. Search engines are told not to index it, and we never publish a result as a public page. Anyone who has the link can open it until it expires or you delete it, so sharing the link shares the transcript. We do not list results anywhere.

Payments

Payments are taken by Stripe, on Stripe's own page. Stripe handles card details, and we do not see or store card numbers. We keep your plan and the status of each purchase. Stripe keeps its own payment records, also after you delete your account, under its own privacy policy. We keep a record of each payment (what was bought, the amount and the date) without your name or email, so that refunds and our accounts stay right.

Your choices and rights

You can delete a result from its page whenever you like, and ask us to delete your account and everything tied to it. You can ask for a copy of your data, ask us to correct it, or object to how we use it. Where the law gives you more, for example in the EU, the UK or California, you have those rights too, including the right to complain to your data protection authority.

Use the contact form. We will answer within 30 days, by email, at the address you give. To report a copyright problem, see the takedown page.

Children

Scribiz is not meant for children under 13, and we do not knowingly collect their data.

Security

We use HTTPS, store API keys as hashes and limit who can reach our systems. No service is perfectly secure, so do not submit anything you could not bear to see leak.

Where data is processed

Our service providers and Google may process data in countries other than yours. Where the law requires a transfer mechanism, we rely on one.

Changes

When we change this policy we change the date at the top. If a change affects what we do with your data in a way you would not expect, we will say so on the site before it takes effect.