Skip to content
PrivacyVersion 1.2 - January 2026

Privacy Policy

Data Controller: Johan Thorén (Philippines)

Your privacy matters. ParrotScribe processes audio entirely on your device - we never hear your conversations. This policy explains what little data we do collect.

The App

Audio is processed entirely on your device using Apple's Neural Engine. Your recordings and transcripts are never sent to our servers.

On-Device Processing

ParrotScribe uses Apple's built-in speech recognition, which runs locally on your Mac. Your audio never leaves your device for transcription purposes.

Local Storage

Transcripts are stored locally on your Mac, by default in ~/Documents/ParrotScribe. You can configure this location in the app settings.

iCloud Note: If your Documents folder syncs with iCloud (based on your macOS settings), your transcripts may be transmitted to and stored by Apple. This is controlled by your system preferences, not by ParrotScribe. See Apple's Privacy Policy for details.

License Key Storage

Your license key is stored securely in the macOS Keychain, which provides hardware-backed encryption on Apple Silicon Macs.

Telemetry

The app collects anonymous usage data:

  • Device model
  • Operating system version
  • Application version

This data contains no personally identifiable information.

License & Activation Data

The app requires periodic online validation. When you activate ParrotScribe, we store the following data:

DataPurposeProtection
Email addressLicense recovery, purchase confirmationAES-256 encrypted
License keyVerify your license is validBcrypt hashed
Device identifiersTrack activations against device limitSHA-256 hashed
Activation timestampsLicense managementStandard
Device countEnforce device limit per license tierStandard

This data is stored on Supabase servers in the European Union (Frankfurt, Germany).

Payment Processing

Payments are processed by Paddle.com (Paddle.com Market Limited, UK), who acts as the Merchant of Record for all purchases.

What Paddle Collects

Paddle collects and processes:

  • Payment details (card number, billing address)
  • Email address
  • Name
  • Transaction history
  • IP address and device information

We do not have access to your full payment details. We only receive confirmation of successful purchases and your email address to issue your license. See Paddle's Privacy Policy for full details.

Website

Hosting

This website is hosted on Cloudflare Pages. Cloudflare may collect standard web server logs including IP addresses, browser type, and pages visited. See Cloudflare's Privacy Policy.

Cookies

We use local storage for:

  • Essential preferences: Storing your theme preference (light/dark mode).

We do not use any tracking or advertising cookies.

Analytics

We use Plausible Analytics to understand website traffic. Plausible is a privacy-first analytics tool that:

  • Does not use cookies
  • Does not collect any personal data
  • Does not track you across websites or devices
  • Processes all data anonymously and in aggregate

All data is hosted on European-owned, EU-based infrastructure.

Data Security

We implement multiple layers of security to protect your data:

Encryption at Rest

All data stored in our database is encrypted using AES-256 encryption. Sensitive fields (email, license key, device ID) have additional application-level encryption or hashing.

Encryption in Transit

All data transmitted between your device and our servers uses TLS (Transport Layer Security) encryption.

Hashing

License keys and device identifiers are hashed using industry-standard algorithms (bcrypt, SHA-256). Even if our database were compromised, these values cannot be reversed.

Infrastructure

Our license backend runs on Supabase, which maintains SOC 2 Type 2 certification and undergoes regular security audits.

International Data Transfers

Johan Thorén operates from the Philippines. Your data may be processed in the following locations:

ServiceDataLocationSafeguards
SupabaseLicense dataEU (Frankfurt)GDPR compliant
PaddlePayment dataUnited KingdomUK GDPR, EU adequacy
PlausibleAnonymous analyticsEU (Estonia)GDPR compliant
CloudflareWebsite logsGlobal CDN (US company)EU-U.S. DPF, SCCs

For transfers from the EU/UK, our service providers rely on Standard Contractual Clauses (SCCs) and/or the EU-U.S. Data Privacy Framework where applicable.

Your Rights

Under the Philippine Data Privacy Act and GDPR (for EU residents), you have the following rights:

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate personal data.

Erasure

Request deletion of your personal data (subject to legal retention requirements).

Portability

Request your data in a structured, machine-readable format.

Objection

Object to processing of your personal data for certain purposes.

Restriction

Request that we limit how we use your data.

To exercise any of these rights, contact us at support@parrotscribe.com. We will respond within 30 days.

Data Retention

  • License data: Retained for the duration of your license plus any period required by law for tax and accounting purposes.
  • Payment records: Retained by Paddle per their retention policy and legal requirements.
  • Website logs: Retained by Cloudflare per their data retention policy.
  • Your transcripts: Stored only on your device. We never have access to them.

Contact & Supervisory Authorities

Contact Us

For privacy-related questions or to exercise your rights, contact: support@parrotscribe.com

Supervisory Authorities

If you believe your privacy rights have been violated, you have the right to lodge a complaint with a supervisory authority:

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website. The “Version” date at the top indicates when this policy was last updated.