Privacy Policy
This document explains what personal data we process in skryba.ai, on what legal basis, who we entrust it to and how long we keep it. It also explains how to exercise your rights. If anything is unclear, write to hello@wondel.ai.
Data controller
The controller of your personal data is Wondel.ai sp. z o.o., registered in Warsaw, Poland, ul. Twarda 18, 00-105 Warszawa, KRS 0001029516, NIP (VAT) 5252951298, REGON 524989057. Contact for data protection matters: hello@wondel.ai.
We have not appointed a data protection officer, as we are not required to. All data protection matters are handled at the address above.
What data we process
- Account data: your email address and the name you provide. We store no passwords — you sign in with a one-time code emailed to you or with your Google account.
- Audio files you upload, together with metadata: file name, size, type, duration and the selected language.
- Transcripts: full text, segmentation, speaker labels, detected language and any manual corrections you make.
- Billing data: your trial period, active subscription and consumed transcription hours. We never see or store your card details — Stripe handles them.
- Email addresses of share recipients that you enter yourself in order to send someone a link to a transcript.
- The email address entered in Stripe's payment form when buying one-off access without an account — we store it at purchase time so that, after payment, we can offer to sign you in as that address and attach the purchase to your account.
- Feedback you choose to give: a transcript rating with optional remarks, feature suggestions, and the reason you decided not to buy with an optional comment. Only the category or the star count ever reaches analytics tools — never the text.
- Consents: which version of the Terms of Service and Privacy Policy you accepted, and when.
- Technical data: IP address and browser information processed for anti-abuse verification, in server logs and — to the extent described under analytics below — transmitted to the analytics provider, which derives a country and a daily hash from them without storing the address itself. To enforce the daily limit on free transcriptions without an account we store only a cryptographic hash of the IP address, computed with a key known only to our server and combined with the current date — never the address itself, the hash cannot be reversed without that key, and hashes from different days are unlinkable, so no record of visits is created. Hashes are deleted after 3 days.
- Analytics events: which screens you visit and which actions you take in the app (for example starting an upload, downloading a transcript), together with your device and browser type. We collect them before you answer the consent question too — cookielessly then, with nothing written to your browser, and with a visitor recognised only by the daily hash described below. A persistent pseudonymous identifier, the one that links your consecutive visits, is created only after you consent to analytics. Never the content of recordings or transcripts, and never file names.
- Ad-measurement data — only if you consent to the marketing category: the ad-click identifier (e.g. gclid) with which you arrive from a Google search ad, and the fact that an action such as a registration or a purchase took place. We store the click identifier alongside the recording whose upload it begins, and delete it together with that recording. If you buy access without creating an account, we additionally send Google an irreversible hash (SHA-256) of the email address entered in the payment form, solely to attribute that purchase to the ad — Google never receives the address itself from us, and for signed-in customers we send it in no form at all. Never the content of recordings or transcripts, and never file names.
You can use the transcript preview without an account. In that mode we ask for no personal data beyond whatever the recording itself contains, and the file, together with its transcript, is deleted automatically after 30 days — that is how long you have to come back for your recording before it is gone. If you buy one-off access without an account, Stripe asks for an email address to process the payment (see above), and the paid recording is kept for at least 30 days.
Purposes and legal bases
- Providing the transcription service, maintaining your account, running the trial and paid plans — art. 6(1)(b) GDPR (performance of a contract).
- Sending messages necessary for the service: the one-time sign-in code, share notification, the notice before the card is charged at the end of a trial, failed-transcription notice — art. 6(1)(b) and (f) GDPR.
- Security and abuse prevention: Cloudflare Turnstile verification, request rate limits, technical logs — art. 6(1)(f) GDPR (our legitimate interest in protecting the service and its costs).
- Sending news and offers if you give separate consent — art. 6(1)(a) GDPR. You can withdraw it at any time in your account settings, without affecting the lawfulness of prior processing.
- Product analytics in your browser, in its cookieless form: we record events about your use of the app so we can see which steps cause trouble and what to fix, without storing or reading anything on your device — art. 6(1)(f) GDPR (legitimate interest in developing and maintaining the quality of the service). Because nothing is written to browser storage, art. 399 of the Polish Electronic Communications Law does not require consent for it. Visitors are counted with an identifier created by the provider as an irreversible hash of the IP address, browser name and site address, combined with a random value that changes daily and is deleted at the end of that day — which is why visits on different days are unlinkable. You may object to this processing at any time (art. 21 GDPR) by choosing “Essential only” in the “Privacy settings” dialog; that switches analytics off entirely.
- Product analytics with browser storage: if you consent to the analytics category, the same mechanism starts using browser storage and a persistent identifier, which lets consecutive visits be read as one history — art. 6(1)(a) GDPR in conjunction with art. 399 of the Polish Electronic Communications Law. You can withdraw it at any time through the “Privacy settings” link in the footer, without affecting the lawfulness of prior processing.
- Ad-effectiveness measurement: if you consent to the marketing category, we pass to Google the information that a click on our ad led to a registration or another action in the service — art. 6(1)(a) GDPR in conjunction with art. 399 of the Polish Electronic Communications Law. You can withdraw the consent at any time through the same “Privacy settings” link, without affecting the lawfulness of prior processing.
- Server-side service reliability statistics: we count how many transcriptions succeeded, how many failed and why. These events are not linked to your account or profile — art. 6(1)(f) GDPR (legitimate interest in maintaining service quality). You may object to them.
- Tax and accounting obligations — art. 6(1)(c) GDPR (legal obligation).
- Establishing, pursuing and defending claims — art. 6(1)(f) GDPR.
Providing data is voluntary, but without an email address we cannot create an account, and without an audio file we cannot produce a transcript.
Who we share data with
We use external providers that process data only on our instructions, under data processing agreements:
- Cloudflare, Inc. — application hosting, audio and database storage, abuse protection (Turnstile) and fallback speech recognition (the Deepgram Nova-3 model running on Cloudflare Workers AI infrastructure — in this mode the recording is not passed to Deepgram, Inc.). Data is stored in the European region; Cloudflare is a US company and transfers rely on Standard Contractual Clauses and the EU–U.S. Data Privacy Framework.
- ElevenLabs, Inc. — speech recognition. It receives your audio file through a temporary, expiring link and returns the transcript. A US company; transfers rely on Standard Contractual Clauses. If you do not want a recording to leave European infrastructure, contact us before uploading it.
- Anthropic PBC — preparation of the cleaned-up version of a transcript (removal of fillers and stammers), only at your request and only for the recording you choose. It then receives the transcript text; the audio file is never sent. The provider retains the submitted text as a rule for 30 days and does not use it to train models; longer retention may follow from its legal obligations or safety procedures. A US company; transfers rely on Standard Contractual Clauses. If you never start this feature, no part of your transcript is sent there.
- Stripe Payments Europe, Ltd. and Stripe, Inc. — payment processing and invoicing. Stripe acts as an independent controller for payment data and retains billing records under its own legal obligations. If you grant the marketing consent, we attach the identifier of the ad click that brought you to the service to the payment session metadata — used solely to measure the effectiveness of our own ads.
- Resend, Inc. — email delivery. We configured sending in the European region; the company is based in the US and transfers rely on Standard Contractual Clauses.
- Functional Software, Inc. (Sentry) — application error reporting, so faults can be fixed. It receives technical data about the error: the page address, the message and a stack trace. Recording or transcript content is never sent, and page addresses containing one-time links (transcript shares) are stripped beforehand. A US company; transfers rely on Standard Contractual Clauses.
- Google Ireland Limited and Google LLC — only if you choose to sign in with the “Continue with Google” button. Google confirms your identity to us and passes on your email address, name and Google account identifier; we never receive your password. For this purpose Google acts as an independent controller and processes the data under its own privacy policy. An affiliated US company; transfers rely on Standard Contractual Clauses and the EU–U.S. Data Privacy Framework. If you would rather not use this route, sign in with a one-time code sent to your email.
- PostHog, Inc. — product analytics. It receives events about your use of the app together with a pseudonymous identifier, your device and browser type, and your IP address, from which it derives an approximate location (country) and the daily visitor hash described above. Our project has IP discarding switched on, so the address itself is not stored there. Recording content, transcripts and file names are never sent. Data is stored in the European region (Frankfurt); the company is based in the US and transfers rely on Standard Contractual Clauses. If you object by choosing “Essential only”, we stop collecting and clear the tool’s entries from your browser, and on later visits it is not loaded at all.
- Google Ireland Limited — Google Ads conversion measurement, started only after you consent to the marketing category. Google then receives the ad-click identifier and the information that an action such as registration took place — never the content of recordings or transcripts, and never file names. For this purpose Google acts as an independent controller; an affiliated US company, transfers rely on Standard Contractual Clauses and the EU–U.S. Data Privacy Framework. Without that consent the Google script is never loaded at all.
- Accounting and legal service providers — to the extent necessary for settlements and defence of claims.
We do not sell personal data. The only tools that process data about your use of the service — product analytics and ad-conversion measurement — are described above. Conversion measurement runs solely with your separate consent, and so does analytics in the form that writes anything to your browser; without consent analytics runs cookielessly only, on our legitimate interest and until you object. Conversion measurement tells Google whether our own ads worked; we do not track you across other websites and we build no advertising profiles ourselves.
How long we keep data
- Recordings uploaded without an account: deleted automatically after 30 days, together with the transcript. That is the window in which you can come back for your recording, unlock it or attach it to an account; you can delete it yourself sooner at any time. A recording whose one-off access was bought without an account is kept for the same period counted from the purchase.
- Feedback, ratings and feature suggestions: until you delete your account; given without an account — up to 24 months.
- The email address given when buying without an account: until the purchase is attached to an account, and at most 12 months from the purchase — then we delete it, keeping only the accounting record of the transaction.
- Audio files on an account: kept for as long as you decide. In settings you can choose automatic deletion after 1, 7 or 30 days; by default it is off ("Never"), so the file stays on your account until you delete it yourself. The transcript remains available regardless of that choice.
- Transcripts: until you delete the recording or your account.
- Account and settings: until you delete your account.
- Share links, including the recipient's email address: 30 days from creation, or until you delete the link earlier.
- Login sessions: 30 days. One-time sign-in codes: 10 minutes, and the record that one was sent is deleted after an hour.
- Consent records: for the lifetime of the account and the limitation period for claims.
- Billing documents: 5 years from the end of the tax year in which the tax obligation arose.
- Technical logs: up to 7 days.
- Analytics events: 12 months.
- Ad-click identifiers stored in your browser after the marketing consent: up to 90 days. A copy attached — likewise only after that consent — to the payment session metadata is retained by Stripe together with the transaction records, for the periods described under billing documents.
- Text sent for preparing the cleaned-up version: as a rule 30 days on Anthropic's side. This is the provider's own retention period, independent of how long we keep the transcript; the provider may keep it longer where its legal obligations or safety procedures require. If you never start the feature, nothing is sent there.
Your rights
- The right of access and to receive a copy — you can download all of your data as JSON in your account settings.
- The right to rectification — you can edit transcript text yourself; we will correct other data on request.
- The right to erasure — you can delete a single recording or your whole account in settings. Account deletion is irreversible and covers audio files, transcripts and shares.
- The right to restriction of processing and the right to object to processing based on our legitimate interest.
- The right to data portability — the export in your account settings is machine-readable.
- The right to withdraw marketing consent at any time, without giving a reason.
- The right to withdraw the analytics or ad-measurement consent at any time — through the “Privacy settings” link in the footer of the service. Withdrawal takes effect immediately: that tool stops loading and its browser storage is cleared.
We respond to requests within one month of receipt. Requests can be sent to hello@wondel.ai.
Complaint to the supervisory authority
If you believe we process your data unlawfully, you have the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl).
Automated processing and AI
Transcripts are produced fully automatically using speech-recognition models. We do not make decisions about you based solely on automated processing that would produce legal effects within the meaning of art. 22 GDPR.
Transcripts are produced using artificial-intelligence systems within the meaning of Regulation (EU) 2024/1689 (the AI Act): the ElevenLabs Scribe speech-recognition model, with the Deepgram Nova-3 model running on Cloudflare Workers AI infrastructure as a fallback. If you start the cleaned-up version of a transcript, the text is additionally processed by Anthropic's Claude language model. Details — including how we mark AI-generated content — are described at https://app.skryba.ai/en/ai.
Model output contains errors — especially with poor recording quality, overlapping voices, dialect, specialist terminology or proper names. Speaker identification is approximate. Verify a transcript against the recording before using it in official, court or medical matters.
We do not use your recordings or transcripts to train models, and we require the same of our speech-recognition provider.
Recordings involving other people
If you upload a recording that captures other people, you decide the purpose and means of processing their data — you are the controller in that respect and we process the data on your instructions. You are responsible for having a legal basis to record and process those statements, and for informing those people where the law requires it.
If you enter the email address of someone you share a transcript with, we send them a single notification containing the link, the source of their data and their rights. We delete the address when the share expires or is removed.
Security
- We store no passwords. Session identifiers, share links and one-time sign-in codes are kept only as cryptographic hashes (SHA-256), so a copy of the database yields no working credentials.
- Session, share and anonymous-access tokens are stored only as SHA-256 hashes — the token itself cannot be reconstructed from the database.
- Audio files go to private object storage and are served only through an authenticated endpoint or a temporary, expiring link for the speech-recognition provider.
- All traffic uses HTTPS with HSTS enabled and a restrictive Content-Security-Policy.
Changes to this policy
Every version of this policy carries a version number and effective date, shown at the top of this page. We will notify you by email or an in-app message about material changes before they take effect.