Privacy Policy
Effective date: 2026-07-15 Last updated: 2026-09-11
SummitScribe ("we", "us", "our") provides an AI-powered meeting intelligence platform that records audio, transcribes it, and produces structured notes for the recorded user. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have over your data. The public Help Center describes how to use each feature.
Your use of the service is also governed by our Terms of Service, which incorporate this policy by reference.
For privacy inquiries, contact us at info@summitscribe.app.
1. Scope
This policy applies to:
- Individual users who create a SummitScribe account for personal use.
- Business and team customers whose organization provides them with a SummitScribe account as part of a team or enterprise plan.
If your organization is the one that gave you access to SummitScribe, that organization is the data controller for content you create in the service, and SummitScribe acts as the data processor on its behalf (see §6).
2. Data We Collect
We collect the following categories of data:
- Account identity — email address and display name, provided by you at sign-up or received from your sign-in provider (Apple, Google). If you use Continue with Apple and Hide My Email, we receive an Apple private-relay address (
…@privaterelay.appleid.com) instead of your personal inbox. - Audio recordings — meeting audio you record in the browser, on the Android or iOS app, with the Windows, macOS, or Linux desktop capture agent, or upload from your device.
- On the Android app, if you turn on Include system / meeting audio, we also capture audio playing on the device (for example a speaker, a podcast, or some apps) after Android’s system consent dialog. We do not record your screen. Some apps block playback capture; in that case we keep your microphone only.
- On the iOS app, if you turn on Include system / meeting audio, iPhone asks to start Screen Recording so we can hear other apps. We do not save or upload video. A red recording indicator stays on while this is included. Some apps block capture; then we keep your microphone only.
- On Windows, macOS, and Linux, the local capture agent records microphone and (when available) system/meeting audio on your computer, then uploads it to your account.
- Transcripts and notes — text transcripts, structured notes, action items, and other AI output generated from your recordings (including study flashcards, mind maps, role views, and optional artifacts such as an email draft).
- User Notes and photos — rich text and images you add (whiteboards, slides, paper notes). Photos may be analyzed with vision models to extract text and link them to the transcript.
- Memory and search — indexes of your meetings so you can search and chat across them. Evidence used in chat is drawn from meetings you already own.
- Share links and clips — if you create a share link or a named audio clip, the token and the shared content are stored so the public URL can work until you revoke it.
- Note destinations — if you connect Notion or Microsoft OneNote, we store encrypted OAuth tokens and the destination you pick so we can send pages you request (or auto-push after AI finishes). We send a copy of the selected notes to that service; your SummitScribe copy stays in your account.
- Offline copies — if you use Keep offline, notes, photos, AI details, and (optionally) audio are stored on that device in the app’s private storage. Desktop capture may also keep audio and draft notes on disk until they upload.
- Service telemetry — request metadata, error logs, and aggregate feature usage necessary to operate and improve the service.
- Billing records — only if you are on a paid plan. On the website (summitscribe.app) and on Windows or Mac, payment is handled by Stripe. On the Android app, paid Starter, Pro, Ridge, and Ultimate plans are sold through Google Play Billing. iOS in-app subscriptions are not offered in this version. Stripe does not share full card numbers with us; we receive only the payment-method brand (e.g. Visa), the last 4 digits, the card expiration, and the billing email and postal country associated with your Stripe customer record. Google Play does not share full card numbers with us; we receive the Play product id, purchase token, obfuscated account id, and subscription status needed to keep your SummitScribe hours in sync. Complimentary plans granted by an operator have no payment-processor charge.
- Device notifications — on the Android app, while you are recording a meeting, we show an ongoing recording notification (a microphone foreground service) so capture can continue when the screen is off. You can stop from that notification. On the iOS app, a Stop notification stays available while capture is live. If you opt in, we may also show a local “AI ready” notification when processing finishes. We do not use notifications for advertising.
We do not collect your contacts, your calendar, your location, or any background data from other apps on your device.
3. How We Use Your Data
We use your data for the following purposes:
- To provide the core SummitScribe service (recordings, transcripts, notes, search, destinations you connect, and share links you create).
- To run AI processing only on content you submit to the app — we do not train any AI model on your data (see §4).
- To secure your account, prevent abuse, and respond to support requests.
- To bill you if you are on a paid plan, using the store that sold the plan (Stripe or Google Play).
- To comply with legal obligations.
4. AI Processing Disclosure
When you start a meeting or upload audio, we send that data to trusted sub-processors for the following purposes:
- Speech-to-text and speaker diarization — your audio is sent to AssemblyAI. AssemblyAI processes the audio and returns a transcript with speaker labels. AssemblyAI does not retain or use your audio to train its models.
- Structured notes, vision, and action items — the transcript and section chunks are sent to xAI (Grok) to generate structured notes, identify themes across sections, run vision analysis on images you add, and (when you ask) produce study cards, role views, or artifacts. xAI does not train on your data per its published policy.
SummitScribe does not train any model (our own or third-party) on your recordings, transcripts, notes, or photos.
5. Sub-Processors
We share your data with the following trusted sub-processors, each bound by their own privacy commitments:
| Vendor | Purpose | Data shared with them | Privacy policy |
|---|---|---|---|
| Supabase | Authentication, database, file storage | Account identity, recordings, transcripts, notes | https://supabase.com/privacy |
| Vercel | Web application hosting | HTTP requests, rendered pages | https://vercel.com/legal/privacy-policy |
| Railway | Background AI pipeline worker | Encrypted audio + transcript payloads | https://railway.com/legal/privacy |
| AssemblyAI | Speech-to-text, speaker diarization | Audio recordings | https://www.assemblyai.com/legal/privacy-policy |
| xAI / Grok | Structured notes + vision | Transcript text, section chunks, embedded note images | https://x.ai/legal/privacy-policy |
| Stripe | Payment processing + subscription management (website and Windows paid plans) | Billing email, billing postal country, payment-method brand/last4/expiration, subscription tier and status, invoice history | https://stripe.com/privacy |
| Google Play | Payment processing + subscription management (Android paid plans via Google Play Billing) | Play account identity, purchase token, product id, obfuscated account id, subscription status | https://policies.google.com/privacy |
| Apple | Sign-in (when you use "Continue with Apple") | Apple-issued identity token; Hide My Email may provide a private-relay address | https://www.apple.com/legal/privacy/ |
| Sign-in (when you use "Continue with Google") | Google-issued identity token | https://policies.google.com/privacy | |
| Notion | Optional note destination (when you connect and send) | OAuth tokens (stored encrypted), meeting notes you choose to send | https://www.notion.com/privacy |
| Microsoft | Optional OneNote destination (when you connect and send) | OAuth tokens (stored encrypted), meeting notes you choose to send, Microsoft account identifiers needed for Graph | https://privacy.microsoft.com/privacystatement |
We update this table when we add or change a sub-processor.
6. Business Customers and Processor Role
If you use SummitScribe through an organization (a team or enterprise plan), your organization is the data controller for content you create in the service and SummitScribe is the data processor. SummitScribe processes that content only on the organization's documented instructions and only to provide the service.
A Data Processing Addendum (DPA) is available to organizations on request to info@summitscribe.app.
7. International Data Transfers
SummitScribe and its sub-processors operate primarily in the United States. For users in the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) and supplementary technical and organizational safeguards to transfer your data outside your jurisdiction. Contact info@summitscribe.app for a copy of our SCC commitments.
8. Your Rights
Depending on where you live, you may have some or all of the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate personal data.
- Erasure — request that we delete your personal data.
- Restriction — limit how we process your personal data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Complain to a supervisory authority — lodge a complaint with your local data protection authority.
If you are a California resident, you also have the right to know, delete, correct, and limit the use of sensitive personal information under the California Consumer Privacy Act (CCPA).
To exercise any of these rights, contact info@summitscribe.app. We acknowledge deletion and access requests within 30 days.
9. Data Retention
- While your account is active, we retain your recordings, transcripts, notes, and photos so the service works for you.
- Audio recordings remain available until you delete the meeting yourself.
- When you close your account, we delete your personal data within 30 days, except where retention is required by law (for example, tax records). You can delete your account in Account settings → Danger zone, or email info@summitscribe.app. Step-by-step instructions (including deleting a meeting without closing the account) are at summitscribe.app/delete-data.
- Backups are rotated on their normal cycle; data in backups is deleted at the end of the backup lifecycle.
10. Security
We protect your data with industry-standard safeguards:
- TLS in transit (HTTPS).
- AES-256 encryption at rest (provided by our infrastructure sub-processors).
- Service-role credentials isolated to backend server actions and the background worker — never shipped to the browser.
- No third-party analytics SDKs on the client.
- No plain-text storage of authentication secrets in any code repository.
No system is perfectly secure, but we work continuously to keep yours safe.
11. Children's Privacy
SummitScribe is not directed to children under 13 (COPPA) or under 16 (GDPR). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact info@summitscribe.app and we will delete it.
12. Changes to This Policy
If we make a material change to this policy, we will notify you by email and show a banner in the product before the change takes effect. Non-material changes (typo fixes, clarifications) are reflected in the "Last updated" date at the top of this page.
13. Contact
Privacy inquiries, including all data-subject requests:
- Email: info@summitscribe.app
- Legal entity: SummitScribe