Privacy Policy
Effective October 1, 2026
We keep your recordings, transcripts and translations until you ask us to delete them, and use them only to run the jobs you ask for. We do not sell data, show ads, or track you. The only cookie keeps you signed in. To have everything deleted, email support@verbatim.sh.
Who is responsible
Verbatim is operated by Lukus Reindl, a sole proprietor based in Iowa, USA. Contact: support@verbatim.sh.
We hold two kinds of data, in two different roles:
- Your account data (your email address, sign-in, credit and payments): we decide what is collected and why. In GDPR terms, we are the controller.
- Your recordings and what is made from them (audio, transcripts, translations): we process them only to deliver the jobs you ask for. In GDPR terms, we are your processor.
If you are recorded in someone else’s audio, the person who submitted it decides what happens to it. Ask them first. You can also write to us, and we will pass the request on.
What we collect
- Account: your email address. If you sign in with GitHub, the identity and verified email GitHub returns.
- Recordings: audio you upload, or the link to audio you submit; the transcripts and translations made from them; and each job’s settings, length, price and status.
- Credit: your balance and the record of each top-up, refund and job charge. Your card details go to Stripe and Link, never to us.
- Sign-in: a session cookie that keeps you signed in. It is the only cookie we set. At sign-in, Cloudflare checks for bots using your IP address and browser signals.
- Errors: when something breaks, ids and error details. Never content or your email address.
- Mail you send us at support@verbatim.sh.
How we use it
- To run the jobs you submit, and show you the results.
- To keep your balance: quotes, charges, refunds.
- To sign you in and keep the service secure.
- To answer you when you write to us.
We do not sell your data. We do not show ads, use analytics, or track you across sites. Verbatim itself does not use your recordings, transcripts or translations to train any model. What the providers that process them may do is set out under who processes it.
Who processes it
These companies process data for Verbatim. Each one is used for the purpose shown.
| Company | What for | What it receives | Where |
|---|---|---|---|
| AssemblyAI | Transcribes audio. | Your audio (it fetches it from a link we give it) and the resulting transcript. | United States |
| Anthropic | Translates transcripts, only when you ask for a translation. | The transcript text being translated. | Stored in the United States; may be processed in other countries |
| Supabase | Our database and sign-in. | Your account, your jobs, transcripts and translations. | United States |
| Vercel | Hosts the website and stores uploaded audio. | Every web request, and the audio files you upload. | United States |
| Railway | Runs the connection AI assistants use. | Requests and results passing between your assistant and Verbatim. It stores none of them. | United States |
| Stripe and Link | Sells you credit, as merchant of record. | Your payment details and purchase. Verbatim never sees your card. | Worldwide |
| Resend | Sends sign-in emails. | Your email address and the sign-in link or code. | United States |
| Cloudflare | Checks sign-ins for bots, and forwards mail sent to our support address. | Your IP address and browser signals at sign-in; your email if you write to us. | Not stated by Cloudflare |
| GitHub | Sign-in, only if you choose it. | That you authorised Verbatim; it returns your verified email to us. | Worldwide |
| Sentry | Records errors so we can fix them. | Error details and ids only. Never your recordings, transcripts or email address. | United States |
| Better Stack | Checks that the service is up. | Nothing about you. It requests public pages. | European Union |
What the two that see your content do with it:
- AssemblyAI keeps a transcript for up to 30 days unless it is deleted sooner, and keeps some logging and billing records. Once a transcript is stored with us, we delete it at AssemblyAI. If a job fails, AssemblyAI’s copy is left to its own 30-day deletion. Verbatim has opted out of AssemblyAI using its customers' data to train its models, for requests since October 1, 2026.
- Anthropic receives a transcript only when you ask for a translation. It does not train on it, and deletes it within 30 days. It may keep content its systems flag for a policy violation for up to 2 years. We cannot delete it there sooner.
Stripe and Link control your payment data under their own privacy policies, as do GitHub and Cloudflare for the signals they collect. Resend keeps sign-in email data for 30 days.
How long we keep it
- Recordings, transcripts and translations are kept until you ask us to delete them.
- Each account can store up to 1 GB of uploaded audio.
- Your account is kept until you ask us to close it.
- Error records are kept for 30 days.
Deleting your data
To delete your account and everything in it, email support@verbatim.sh from the address you sign in with. We delete it within 30 days and reply when it is done. There is no self-serve delete button yet.
Deletion removes your uploaded audio, your transcripts and translations, your jobs and your account. Two things survive it:
- Payment records held by Stripe and Link, who sold you the credit and keep their own records under their own policies.
- Our accounting entries for your credit: each keeps an amount, a date and the Stripe payment id, but no longer points to you.
Ask for a refund of unused credit before you ask for deletion; see Refunds.
Your rights
You can ask us for a copy of your data, to correct it, or to delete it, by emailing support@verbatim.sh. We may ask you to confirm the request from the address you sign in with. Depending on where you live, you may have further rights under laws such as the GDPR or the CCPA, and the right to complain to your data protection authority.
Security
Data travels encrypted. Uploaded audio is stored privately and fetched through links that expire. Access to your jobs is limited to your account. No system is perfectly secure.
Children
Verbatim is for adults. You must be 18 or older to use it, and we do not knowingly hold an account for anyone younger.
Changes to this policy
When this policy changes materially, we email accounts with a balance or recent jobs at least 14 days before the change takes effect. The effective date at the top shows which version is in force.
Questions about this document: support@verbatim.sh.