Version: 2.2
Last updated: 18 August, 2026
Effective Date: 18 August, 2026
1. Controller
The controller responsible for processing personal data in connection with ScripTea (the "service") is:
Levente-László Bagi
Stendaler Str. 77
12627 Berlin
Germany
levente@scriptea.app
ScripTea is operated by a solo self-employed developer.
2. Scope of this Policy
This Privacy Policy explains how personal data is processed when you use the ScripTea website, web application, account features, billing features, contact form, and related services.
3. Categories of Personal Data
Depending on how you use the service, we may process the following categories of personal data:
- account data, such as your email address, login and verification records, and session information
- legal acceptance data, such as accepted Terms of Service version, accepted Privacy Policy version, and acceptance timestamps
- contact data, such as your name, email address, and message content when you contact us
- billing data, such as billing name, billing address, country, buyer type, VAT or tax ID, invoice identifiers, payment status, and transaction metadata
- usage metering data, such as records of each transcription, translation, or dictionary lookup, including the affected recording or track identifier and name, time range, language pair, looked-up word, amount consumed, and the processing provider used
- user content, such as uploaded audio files, recordings, transcripts, translations, and related metadata
- usage and technical data, such as IP address, server logs, security events, browser metadata, and error reports
- analytics data, such as page views and event data collected for privacy-friendly reach measurement
4. Purposes and Legal Bases
We process personal data only where a legal basis under the GDPR applies. In particular, we process data for the following purposes:
- to provide the service, create and manage accounts, authenticate users, store user content, and enable requested features under Article 6(1)(b) GDPR
- to process payments, generate invoices, manage credit topups, and comply with tax and accounting obligations under Article 6(1)(b) and Article 6(1)(c) GDPR
- to respond to contact requests and support inquiries under Article 6(1)(b) GDPR or Article 6(1)(f) GDPR where no contractual relationship exists
- to maintain IT security, prevent abuse, detect misuse, and investigate incidents under Article 6(1)(f) GDPR
- to document legal acceptances and comply with legal obligations under Article 6(1)(c) GDPR
- to improve reliability, diagnose errors, and measure product usage in a privacy-conscious way under Article 6(1)(f) GDPR
Our legitimate interests include operating a secure and reliable service, preventing misuse, troubleshooting errors, improving usability, and managing our business efficiently.
5. Account, Login, and Session Data
If you create or use an account, we process your email address and the data necessary to authenticate you and maintain your session. We also store verification tokens, session records, and related timestamps.
This processing is necessary to provide account-based features and to protect account security.
6. User Content and Service Data
When you use ScripTea, we process the content required to provide the requested functionality. This may include podcast subscriptions, uploaded recordings, audio files, transcripts, translations, playback-related data, and associated metadata.
Some data may also be stored locally in your browser or device to support core app functionality, session continuity, legal acceptance prompts, analytics opt-out preferences, and other necessary product behavior.
7. Contact Requests
If you contact us through the contact form or by email, we process the information you provide, including your name, email address, and message, in order to respond to your request and handle follow-up communication.
8. Billing, Payments, and Invoicing
If you purchase paid services, top up your account, or request an invoice, we process the billing and transaction data required to complete the purchase, document payment, validate tax treatment, and comply with legal obligations.
This may include your billing name, postal address, country, buyer type, VAT or tax ID, email address, transaction identifiers, invoice identifiers, invoice data, and topup status.
9. Usage Metering
Each transcription, translation, or dictionary lookup creates a usage record. We use these records to meter consumption, enforce free usage limits, calculate charges against your credit balance, and show you your own usage history in your account.
A usage record includes the type of operation, the recording or track identifier and name, the processed time range or character count, the language pair, the word looked up in the case of a dictionary lookup, the processing provider used, and the resulting credit amount.
10. Security Logs and Error Reporting
We process technical and log data, including IP addresses and error information, to maintain service security, detect abuse, investigate incidents, monitor stability, and fix problems.
11. Bot Protection on the Login Form
To protect the login form against automated sign-in attempts and spam, we use Cloudflare Turnstile. When the login page is loaded, a challenge widget is embedded from Cloudflare, and when the form is submitted, the resulting challenge token is validated by our server with Cloudflare.
In this process, Cloudflare receives your IP address, browser and device metadata, and information about your interaction with the challenge. Cloudflare Turnstile does not use this data for advertising or cross-site tracking.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest is to protect accounts and the service from automated abuse.
12. Analytics and Similar Technologies
ScripTea uses privacy-conscious analytics to understand how the service is used and to improve the product. The web application also uses local browser storage for technically necessary functions, such as storing legal acceptance state or analytics opt-out preferences.
ScripTea does not use third-party advertising cookies.
13. Recipients and Processors
We use service providers that process personal data on our behalf or receive data as part of providing the service. In particular, these may include:
- Hetzner Online GmbH, Germany, for hosting and server infrastructure
- Scaleway S.A.S., France, for email services, contact form handling, and authentication emails
- Plausible Insights OÜ, Estonia, with data infrastructure based in Germany, for privacy-focused analytics
- Deepgram, Inc., using their EU-hosted service for speech-to-text transcription
- DeepL SE, Germany, for machine translation
- Google Cloud, using their EU-hosted service for machine translation
- Stripe, Inc., United States, for payment processing and billing management
- OpenAI, L.L.C., United States, for machine transcription and translating individual words
- Cloudflare, Inc., United States, for bot protection on the login form
We may also disclose personal data where required by law or where necessary to establish, exercise, or defend legal claims.
14. International Transfers
We aim to process and store personal data within the European Union where reasonably possible. This includes using EU-based infrastructure and, where available, provider configurations that keep processing in the EU.
If a provider or legal requirement makes a transfer outside the EU or EEA necessary, we will only do so on a lawful basis and with appropriate safeguards under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
15. Retention Periods
We keep personal data only for as long as necessary for the relevant purpose, unless a longer retention period is required or permitted by law.
In particular:
- account and service data is retained for as long as needed to provide the service and for a reasonable period thereafter to handle security, support, and legal matters
- contact requests are retained for as long as necessary to handle the request and any related follow-up
- billing, payment, tax, and invoice records are retained for the statutory retention period applicable under German law, which may generally be 6 or 10 years
- usage metering records are retained for as long as needed to operate the credit system and to substantiate charges; where such a record forms part of an accounting or tax record, the statutory retention period applies
- security and technical logs are retained for as long as needed for security, troubleshooting, and abuse prevention
16. Your Rights
Under the GDPR, you may have the right to:
- request access to your personal data
- request rectification of inaccurate personal data
- request erasure of your personal data
- request restriction of processing
- object to processing based on Article 6(1)(f) GDPR
- receive your data in a portable format where applicable
- withdraw consent at any time, where processing is based on consent
- lodge a complaint with a supervisory authority
If you are in Berlin or ScripTea's processing falls under Berlin supervision, you may contact the Berliner Beauftragte fur Datenschutz und Informationsfreiheit. You may also contact any other competent supervisory authority in Germany or in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
17. No Automated Decision-Making
ScripTea does not use automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example to reflect legal, technical, or business changes. The current version will always be published within the service together with its version number and effective date.
19. Contact
If you have questions about this Privacy Policy or about the processing of your personal data, please contact:
Levente-László Bagi
Stendaler Str. 77
12627 Berlin
Germany
levente@scriptea.app