Privacy Policy
Last updated: August 24, 2026
This Privacy Policy describes how transcrevo ("transcrevo", "we", "us") collects, uses, shares, and protects personal data on transcrevo.com, in the dashboard, and in the transcription API (together, the "Service"), in compliance with the Brazilian General Data Protection Law (Law No. 13,709/2018, "LGPD"). "Personal data" is any information relating to an identified or identifiable natural person. This policy does not cover the practices of third-party sites or services we do not control.
1. Our roles: controller and processor
For your account, billing, Service usage, and website browsing data, we are the controller: we decide how and why that data is processed, as described in this policy.
For personal data contained in the audio you submit through the API and in the transcripts generated from it ("Customer Content"), we are the processor: we handle that data exclusively on your instructions and to provide the Service. In that case you are the controller, responsible for ensuring a legal basis to record and process the audio, including when it contains the voice and data of third parties, for informing data subjects, and for responding to their requests.
If this policy conflicts with specific contractual commitments made to you regarding Customer Content, whichever gives the data more protection prevails.
2. Data we collect
We collect the following categories of data:
- Account data: name, email, and password (stored only as a cryptographic hash; never in plain text).
- Billing data: history of Credit purchases, auto-recharges, amounts, dates, payment status, and partial card identification (brand and last digits) provided by Stripe. The payment itself is processed by Stripe; we do not store your full card number.
- Service usage data: transcription metadata (duration, language, cost, status, dates), API call history, and Credit consumption.
- Technical and security data: IP address, access date and time, request identifiers, and authentication logs, used for security, fraud prevention, and abuse limiting.
- Communications: messages you send us (for example, to contato@transcrevo.com) and our support records.
- Customer Content: the audio you submit and the transcripts, summaries, and metadata generated, handled in our capacity as processor, per section 1.
3. Sources of data
Data comes from three sources: from you, when you create an account, configure billing, use the API, or write to us; automatically, when you browse the site or call the API (technical logs); and from third parties acting on our behalf, such as Stripe, which returns payment status and partial card identification to us.
4. Purposes and legal bases
We process personal data for the purposes below, under the corresponding legal bases of Article 7 of the LGPD:
- Providing the Service, processing audio, generating transcripts, maintaining your account, dashboard, and history (performance of a contract, Art. 7, V).
- Billing, debiting Credits, processing payments and auto-recharges via Stripe, issuing receipts (performance of a contract, Art. 7, V, and compliance with legal obligations, Art. 7, II).
- Security and fraud prevention, authentication, access logs, rate limiting, abuse detection (legitimate interest, Art. 7, IX, and compliance with the log-retention obligations of the Brazilian Internet Civil Framework, Art. 7, II).
- Operational communications, notices about your account, billing, security, and changes to the Service or to these documents (performance of a contract, Art. 7, V).
- Service improvement, usage metrics and statistics in aggregated form that do not identify you (legitimate interest, Art. 7, IX).
- Compliance with legal and regulatory obligations, retention of tax and access records, responding to authorities (Art. 7, II and VI).
We do not use your audio or your transcripts to train our models or anyone else's. We do not sell personal data. We do not use your data for targeted advertising and do not send marketing without your consent; if we ever send promotional communications with your consent, every message will include an unsubscribe option.
5. Audio and transcripts
Submitted audio is stored only for as long as needed to process the transcription and make the result available, and is discarded afterwards. Transcripts and their metadata remain available in your account until you delete them through the API or close your account.
You can delete individual transcripts at any time through the API. When you close your account, we delete Customer Content within 30 days, except where retention is legally required.
Internal access to Customer Content is restricted to what is strictly necessary to operate the Service, investigate security incidents, or comply with the law, always with access control and logging.
6. Cookies and similar technologies
We use only essential cookies: an httpOnly, secure session cookie to keep you signed in to the dashboard. It is indispensable to the operation of the Service and therefore does not depend on consent.
We do not use advertising cookies, tracking pixels, session replay, or third-party tracking technologies. Since we do not track you across sites, signals such as "Do Not Track" do not change our behavior, we already do not track by default.
7. Who we share with
We share personal data only in the following situations:
- Processors and sub-processors acting under contract and only on our instructions: Oracle Cloud Infrastructure (application and database servers), Cloudflare (network, attack protection, and storage of uploaded audio, encrypted), Vast.ai (GPU machines that run the transcription: this is where audio is decoded and processed), Stripe (payment processing and fraud prevention), and Google (identity verification only, for people who choose to sign in with a Google account).
- Public authorities, when required by law, court order, or a request from a competent authority, limiting disclosure to what is strictly required and, when permitted, notifying you.
- Protection of rights: when necessary to exercise or defend rights in judicial, administrative, or arbitral proceedings, or to protect the security of the Service, of us, of you, or of third parties.
- Corporate transactions: in a merger, acquisition, reorganization, or sale of assets, data may be transferred to the successor, which will be bound by this policy; we will notify you of relevant changes of control.
We may create and use aggregated, anonymized, or statistical data that does not identify you, including disclosing it (for example, public metrics of processed volume), and we commit not to attempt to re-identify it.
We will keep this policy updated if new sub-processors start processing personal data on our behalf.
8. International transfers
Our infrastructure, including Oracle Cloud, Cloudflare, Vast.ai, and Stripe, processes and stores data outside Brazil, especially in the United States and in other regions where those providers operate. These transfers rely on Article 33 of the LGPD, through contractual clauses and safeguards that ensure the data a level of protection equivalent to that required by Brazilian law and provided in this policy.
9. Retention
We keep each category of data only for as long as its purpose requires:
- Submitted audio: only during processing (section 5).
- Transcripts and metadata: until you delete them or close your account (and then for up to 30 days, except where legally required).
- Account data: for as long as the account exists and, afterwards, for the period needed to meet legal obligations and to exercise rights in potential proceedings.
- Billing data: for the periods required by tax and accounting legislation.
- Technical access logs: for the minimum 6-month period set by Article 15 of the Brazilian Internet Civil Framework (Law No. 12,965/2014), and for the additional period needed for security and incident investigation.
- Anonymized or aggregated data: may be kept indefinitely, as it does not identify you.
10. Security
We adopt technical and organizational measures appropriate to the nature of the data processed: encryption in transit (TLS) and at rest, hashed passwords, protected storage of API keys, httpOnly/secure cookies, least-privilege access control, activity logging, input validation, and rate limiting against abuse.
No method of transmission or storage is completely secure. If a security incident occurs that may create relevant risk or harm to you, we will notify you and the Brazilian National Data Protection Authority (ANPD) under Article 48 of the LGPD.
You also play a role in security: protect your password and API keys, do not reuse them, and sign out on shared devices.
11. Your rights as a data subject
Under Article 18 of the LGPD, you may request at any time: confirmation that processing exists; access to the data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data or data processed in non-compliance; portability; deletion of data processed with consent; information about sharing with third parties; information about the option of not consenting and its consequences; withdrawal of consent; and review of automated decisions.
Much of this is available directly in the dashboard: you can correct your name, manage API keys, change your password, and delete transcripts through the API. For other requests, write to contato@transcrevo.com; we may ask for information to confirm your identity and will respond within the deadlines of the LGPD.
If you believe processing violates the law, you may also lodge a complaint with the ANPD.
If your data appears in audio submitted by one of our customers, direct your request to that customer, who is the controller of that data; we will provide them the technical support needed to serve you.
12. Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects on you, and we do not build behavioral profiles for advertising. Automated security mechanisms (such as rate limiting and blocking on suspicion of fraud) may temporarily restrict access; in those cases you may contact us for human review.
13. Children and adolescents
The Service is not intended for people under 18, and we do not knowingly collect data from minors. If we learn that we have collected data from a minor without the consent required by law, we will delete it as quickly as possible. If you believe this has happened, contact contato@transcrevo.com.
14. Changes to this policy
We may update this policy from time to time to reflect changes in the Service or in the law. Material changes will be communicated with reasonable advance notice by email or a notice in the dashboard. The date at the top indicates the current version; using the Service after it takes effect constitutes awareness of the new version.
15. Contact and DPO
transcrevo's Data Protection Officer (DPO) can be reached at contato@transcrevo.com. Use this channel to exercise your rights, ask questions about this policy, or report privacy concerns. We will respond as promptly as possible, within the legal deadlines.