OpenTranscription
OpenTranscription
RankerModelsPlayground
OpenTranscription
OpenTranscription

One API to every speech-to-text model worth using. Compare them on your audio, route to the best one, pay per second.

Platform status

Product

RankerModelsTranscriptionsPlaygroundBlog

Developers

DocumentationReliabilityAPI VersioningStatus

Legal

Privacy PolicyTerms of ServiceSupport
© 2026 OpenTranscription

Privacy Policy

Last updated: 2026-08-31

1. Introduction

OpenTranscription ("we", "our", "us") is a service operated by ReadychatAI LLC, located at Chicago, Illinois, United States. We operate the opentranscription.io platform. This Privacy Policy explains how we collect, use, and protect your information when you use our speech-to-text transcription service. The data controller for the purposes of the EU General Data Protection Regulation (GDPR) is ReadychatAI LLC.

2. Data We Collect

We collect the following types of information when you use our service:

  • Account information: email address, name, and authentication data (via email, Google, or GitHub OAuth)
  • Audio files: files you upload for transcription, stored in encrypted cloud storage
  • Transcripts: the text output generated from your audio files
  • Payment information: processed by Stripe — we never store your card details directly
  • Usage data: transcription jobs, model selections, credit usage, and feature interactions; and, where you have allowed analytics cookies, consent-gated session replay records of your interactions with public marketing pages
  • Email send records: a log of the emails we send you — which account received it, whether it was a service message or part of an onboarding or re-engagement sequence, and for those the sequence, step, delivery status and timestamp. We do not log the message body.
  • API keys (BYOK): if you provide your own provider API keys, they are encrypted at rest using AES-256-GCM
  • Advertising attribution data: if you arrive from an ad, the click identifier the ad platform appended to the link (for example Google's gclid, Meta's fbclid, or TikTok's ttclid), the campaign tags on that link, the page you landed on and the referring site, and — only if you accept marketing cookies — the matching identifiers set by the Meta and TikTok pixels; if you accept analytics cookies, the Google Analytics client and session identifiers from your browser; the two-letter country your network address resolves to, used only to decide which consent rules apply to advertising measurement as described below — a country code only, never a precise location; and a one-way hash of your account identifier used to match conversions.

3. How We Use Your Data

  • Process your transcription requests
  • Manage your account and billing
  • Improve our service through aggregated, anonymized usage analytics
  • Understand how visitors use our public pages through consent-gated session replay (Microsoft Clarity) of public marketing pages only — never signed-in product pages
  • Communicate service updates and respond to support requests
  • Measure advertising: if you accepted marketing cookies, we report your signup (and, if you buy credits, your purchase) to the advertising platform whose ad brought you, so we can tell which ads work. For Meta specifically: if you are in the European Economic Area, the United Kingdom, or Switzerland, that reporting still depends on your marketing-cookie consent; everywhere else, we report those conversions regardless of your cookie choice, using the click identifier from the ad link and a hash of your email address in place of pixel-set identifiers, and flag the data for Meta's Limited Data Use if you are in the United States. The Meta pixel itself still never loads without your consent.

4. Sub-Processors

To process transcriptions, your audio files are sent to third-party speech-to-text providers based on the model you select:

Transcription provider sub-processors (a request may be routed to one based on the model you select):

  • Amazon Web Services (Transcribe) — United States
  • Microsoft Azure (Speech Services) — United States
  • Google Cloud (Speech-to-Text) — United States
  • OpenAI (Whisper API) — United States
  • Deepgram — United States
  • AssemblyAI — United States
  • ElevenLabs — United States
  • Cartesia — United States
  • Groq (Whisper API) — United States
  • Alibaba (Qwen ASR) — Singapore
  • Mistral (Voxtral) — European Union
  • Soniox — United States
  • Gladia (Solaria) — European Union
  • Rev AI (Reverb) — United States
  • Speechmatics — European Union

We also use the following infrastructure sub-processors:

  • Supabase: database, authentication, and file storage (hosted in the United States)
  • Stripe: payment processing (PCI DSS Level 1)
  • Vercel: application hosting and content delivery
  • Inngest: background job processing
  • Upstash: distributed rate limiting (Redis)
  • Sentry: error monitoring and performance tracking

Advertising platforms. If you accepted marketing cookies and arrived from an ad, we report signup and purchase conversion events — with the click and browser identifiers described in Section 2 — to the platform that showed you the ad. For Meta, that reporting does not always depend on your cookie choice — see below. Unlike the sub-processors above, these platforms use that data as independent controllers under their own privacy policies:

  • Meta Platforms (Facebook/Instagram ads): conversion measurement via the Meta Pixel and Conversions API. Conversions (signup, first transcription, checkout, purchase) are also reported server-side and carry a hash of your email address, a hash of your account identifier, and, when the action happens in your browser session, your IP address and browser user agent. If you are in the European Economic Area, the United Kingdom, or Switzerland, none of this server-side reporting happens unless you accepted marketing cookies. Elsewhere, we report it regardless of your cookie choice, using the click identifier from the ad link in place of the identifiers a pixel would otherwise set, and — if you are in the United States — flagged for Meta's Limited Data Use, a setting Meta uses to restrict how it processes the data. The Meta Pixel itself never loads without your consent.
  • Google (Google Ads): conversion measurement for Google ad campaigns
  • TikTok: conversion measurement via the TikTok Pixel and Events API. Conversions (signup, first transcription, checkout, purchase) are also reported server-side and carry a hash of your email address, a hash of your account identifier, and, when the action happens in your browser session, your IP address and browser user agent. Nothing is sent unless you accepted marketing cookies.

Product analytics. Where you have allowed analytics cookies:

  • Microsoft Clarity: session replay and heatmaps of public marketing pages — never on signed-in product pages where transcripts or account details are rendered

Each sub-processor is subject to its own Data Processing Agreement or equivalent contractual commitments. The groups above work differently. Infrastructure sub-processors process your data by default; product-analytics tools do so only where you have allowed analytics cookies above. We publish any addition or replacement to either list before it takes effect, and you can object to one on data-protection grounds. A transcription provider only ever receives your audio if you route a job to it — the model you choose is what authorizes it — so we add providers to the catalogue without advance notice. If you would rather have a fixed set, you can restrict routing to specific providers in your organization's settings, and later additions will not apply to you.

5. Bring Your Own Key (BYOK)

If you bring your own API keys (BYOK), they are encrypted at rest using AES-256-GCM and are never shared with other users or used for any purpose other than processing your transcription requests. You can delete your stored keys at any time from your account settings, and deletion is immediate and permanent.

6. Data Retention & Deletion

We retain different data classes for different periods, consistent with GDPR Article 5(1)(e) storage-limitation principles:

  • Audio files: retained according to your organization's retention settings. Audio uploaded through the web app defaults to indefinite retention; audio submitted via our API defaults to 7-day retention. You can change both defaults in Settings → Privacy. API consumers can additionally override retention on a per-request basis, including immediate deletion on completion.
  • Transcripts: retained indefinitely until you delete them — you own the output and control its lifetime
  • Account data (profile, organization, billing records): retained while your account is active; purged 30 days after account deletion
  • Billing transactions and usage logs: retained for 24 months to satisfy tax, audit, and anti-fraud obligations
  • Email send records: we keep a log of the emails we send you — which account, whether the message was a service message or part of an onboarding or re-engagement sequence, and for those the sequence, step, delivery status and timestamp. We do not store the message body. Service-message records are deleted on a weekly sweep once they are more than 35 days old. Records of sequence emails are kept for the life of the account, because that record is what stops us sending you the same message twice; both kinds are erased with your account.
  • BYOK provider keys: deleted immediately and permanently when you remove them from your account
  • Realtime streaming transcript chunks: purged after the final transcript is assembled (typically within seconds of session completion)
  • Session-replay data: Microsoft Clarity retains playback recordings for 30 days. After that, it automatically retains 1% of recordings or 10 recordings per day, whichever is higher, for up to 9 months; labeled or favorited sessions and aggregate heatmap and click data may also be retained for up to 9 months. Clarity deletes its data, including backups, after the applicable retention period.

You can request full account deletion at any time. Upon request, we soft-delete your account within 24 hours and permanently erase your data after the 30-day grace period, except for records we are legally required to keep (for example, billing invoices for tax reporting).

7. Cookies

We use a small number of cookies the Service cannot work without, and we set them without asking: Supabase authentication session cookies that keep you signed in, your light or dark theme, your language, the record of the cookie choices you made, and a first-party visitor identifier set when you arrive so that a later signup can be attributed to the page or campaign that brought you. We also load Google Analytics on every page where it is configured. Under Google Consent Mode v2 it starts with analytics and advertising storage denied, so it stores nothing on your device and sets no analytics or advertising cookies unless you allow them; in the European Economic Area, the United Kingdom, and Switzerland advertising measurement works the same way, off unless you turn it on, while everywhere else the optional categories start on by default, as described below. Our server-side reporting of signup and purchase conversions to Meta is the one exception even to that default: it follows the region-based rule described in Section 3, firing regardless of your cookie choice outside the European Economic Area, the United Kingdom, and Switzerland. If you accept analytics cookies, we additionally send certain events (such as signup and purchase) to Google Analytics directly from our servers, using the same client and session identifiers your browser already set; nothing is sent server-side if you have not accepted analytics cookies. If you accept marketing cookies, we additionally load the Meta and TikTok advertising pixels, which set their own matching identifiers (_fbp and _fbc for Meta, _ttp for TikTok) used to connect your signup or purchase to the ad that brought you; until you accept, neither pixel loads and none of those identifiers are set. If you accept analytics cookies, we also load Microsoft Clarity, a session-replay and heatmap tool that records how public marketing pages are used (scrolls, clicks, cursor movement); Clarity sets its own _clck and _clsk identifiers and may also receive Microsoft identifiers such as MUID, and does not load until you allow analytics. In the European Economic Area, the United Kingdom, and Switzerland, you choose when you first arrive: accept all, reject all, or per category. Everywhere else, the optional categories start on by default. Wherever you are, "Cookie Preferences" in the page footer reopens these choices at any time, and your choice is stored in a cookie named ot_consent.

8. Your Rights

You have the following rights regarding your data:

  • Access: request a copy of the personal data we hold about you
  • Portability: download your transcripts and account data in a machine-readable format at any time
  • Erasure: request deletion of your account and associated data
  • Rectification: update your profile information at any time through your settings
  • Object: object to or restrict certain types of processing where we rely on legitimate interests
  • Complaint: lodge a complaint with your local data protection authority

To exercise any of these rights, email privacy@opentranscription.io. We respond within 30 days, and typically within 7 business days.

9. International Data Transfers

OpenTranscription is operated from the United States. When you use the Service, your information (including audio files and transcripts) is transferred to and processed in the United States. For transfers of personal data of EU, UK, or Swiss residents, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914 Module Two), supplemented by the UK Addendum where applicable, incorporated by reference into our Data Processing Agreement at /dpa. Customers subject to GDPR or equivalent laws should review our Data Processing Agreement for the full transfer mechanism.

10. Legal Basis for Processing

Under the EU GDPR, we rely on the following legal bases for processing your personal data:

  • Performance of a contract: processing transcriptions, managing your account, and handling billing — necessary to deliver the service you requested
  • Legitimate interests: aggregated analytics to improve the service, fraud prevention, and security monitoring — balanced against your rights and interests
  • Legal obligations: retention of billing records for tax and audit purposes
  • Consent: for advertising cookies, and for the advertising measurement described in Sections 4 and 7 — the Meta and TikTok pixels, and (for visitors in the European Economic Area, the United Kingdom, and Switzerland) the conversion reporting to advertising platforms — and for any other optional processing (for example, marketing communications). Outside those regions, our server-side reporting of signup and purchase conversions to Meta described in Section 4 does not rely on this consent. Consent can be withdrawn at any time

11. Children's Privacy

The service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact privacy@opentranscription.io and we will delete it promptly.

12. Security

We protect your data with industry-standard technical and organizational measures: TLS 1.2+ encryption for all data in transit, encryption at rest for audio files and transcripts (managed by our storage provider), AES-256-GCM encryption for BYOK provider keys, row-level security (RLS) policies in our database to enforce tenant isolation, and least-privilege access controls. No security program is perfect — if we discover a breach that affects you, we will notify you without undue delay, consistent with GDPR Articles 33 and 34 and applicable state data-breach laws.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Every change is reflected in the "last updated" date at the top. For material changes — for example, a new class of data collected, or a change to a retention period — we will also display a notice in the application. Changes to the sub-processor lists are handled differently and are governed by Sub-Processors above.

14. Contact

Questions about this Privacy Policy or your data? Contact us:

ReadychatAI LLC

Chicago, Illinois, United States

Data requests: privacy@opentranscription.io

General legal inquiries: legal@opentranscription.io