Privacy
This page describes exactly what Skribia stores, where it is processed and how long it is kept. It is written from the code that runs the service, so every period below is a real setting rather than a promise made in the abstract.
Last updated 26 July 2026
Cette page n’est disponible qu’en anglais. Si une traduction du site s’en écarte, c’est le texte anglais qui fait foi.
This page is not finished: the operator’s name, address and contact address are still placeholders. Fill them in web/lib/legal.ts before taking real payments.
Who is responsible
Skribia is operated by FYLL I: ditt namn eller ditt bolags namn, FYLL I: gatuadress, postnummer, ort, Sweden. We are the data controller for everything described here. Write to FYLL I: en adress som du läser about anything on this page, including deletion of your account.
Where your audio is processed
On our own hardware in Sweden. Transcription runs on a speech model we host ourselves, on a machine we own. Your recordings are never sent to OpenAI, Google, Amazon or any other transcription service, and they are never used to train anything — not by us and not by anyone else.
This is the single most important sentence on the page, so it is worth being blunt about the exception: if you paste a link instead of uploading a file, our server visits that link to fetch the media. That site then sees a request from our server, not from you.
What we store
- Your account
- Your email address, and your password stored as a scrypt hash. We cannot read your password, and neither can anyone who steals the database. Six-digit codes for confirming your address or resetting your password are stored until used or expired.
- What you send us
- The audio or video you upload, or the media we fetch from a link you paste, together with the file name and the transcript produced from it. If you rename or edit a transcript, we store the edited version.
- Payment
- Stripe handles the payment itself and we never see your card. We store the identifiers Stripe gives us for your customer and subscription, which plan you are on, when the period renews, and how many seconds of audio you have transcribed in the current month.
- Technical records
- The IP address the job came from, stored with the job, and short-lived counters per IP address used to stop one visitor from taking the whole machine. Failed sign-in attempts are counted per email address so that guessing can be slowed down.
- One cookie
- A single cookie named skribia_session, set only when you sign in. It cannot be read by scripts and lasts 60 days. There is no analytics, no advertising and no tracking on this site, which is why you were not asked to accept anything.
How long we keep it
- Uploaded media
- Deleted automatically 7 days after the job. You can delete it sooner from your library, or press keep to give it another 7 days, as many times as you like.
- Transcripts
- Kept until you delete them. They are text and cost us almost nothing to store, so the choice is yours rather than ours.
- Per-IP counters
- 3 days, then deleted.
- Your account
- Until you ask us to delete it. Deleting the account deletes the transcripts with it.
- Backups
- The database is copied to a second machine of ours every night and kept for 30 days. Uploaded audio is never included in a backup, so a deleted recording is gone for good rather than living on in a copy.
Who else is involved
Four companies handle parts of the service. None of them receives your audio or your transcripts.
- Vercel
- Serves the website. Sees the requests your browser makes to skribia.com.
- Cloudflare
- Provides the domain and the encrypted tunnel that carries uploads to our machine. Sees connection data, not content in readable form.
- Brevo
- Sends the confirmation and password emails. Receives your email address and the text of those messages.
- Stripe
- Takes the payment and stores the card details. Receives your email address and your payment information.
Vercel, Cloudflare and Stripe are American companies and some of this data is processed outside the EU under the European Commission’s standard contractual clauses. Your recordings stay in Sweden regardless.
Why we are allowed to hold it
To perform the contract you entered into when you created an account: your address, your password, your files and your transcripts. Because we have a legitimate interest in the service continuing to work for everyone: the IP records and the abuse limits. Because the law requires it: payment records kept for accounting purposes.
What you can ask for
A copy of everything we hold about you, a correction, or deletion. You can already export any transcript as text, subtitles or a timed file, and delete any transcript or recording yourself from your library. For anything beyond that, write to us and we will answer within a month.
If you think we are handling your data badly, you can complain to the Swedish Authority for Privacy Protection (IMY), and we would rather you told us first so we can fix it.
How it is protected
Passwords are hashed with scrypt. Every transcript is checked against its owner before it is handed out, so knowing a link is not enough. The session cookie cannot be read by scripts. Traffic is encrypted end to end, and the machine holding the recordings is not reachable from the open internet.
Setting a new password signs out every other session on your account, which is the point of the feature rather than a side effect. If a breach ever affects your data, we will tell you and the authority, and we would rather explain an embarrassing mistake than quietly hope nobody noticed.
Age
Skribia is not for children. You need to be at least 16 to have an account, or to have a parent or guardian agree on your behalf.
Changes
If this page changes in a way that affects you, we will say so by email before it takes effect. The date at the top always shows when it was last edited.
FYLL I: ditt namn eller ditt bolags namn
FYLL I: gatuadress, postnummer, ort · Sweden