Privacy Policy
Data Controller: Johan Thorén (Philippines)
Your privacy matters. ParrotScribe processes audio entirely on your device - we never hear your conversations. This policy explains what little data we do collect.

The App
Audio is processed entirely on your device using Apple's Neural Engine. Your recordings and transcripts are never sent to our servers.
On-Device Processing
ParrotScribe uses Apple's built-in speech recognition, which runs locally on your Mac. Your audio never leaves your device for transcription purposes.
Local Storage
Transcripts are stored locally on your Mac, by default in ~/Documents/ParrotScribe. You can configure this location in the app settings.
iCloud Note: If your Documents folder syncs with iCloud (based on your macOS settings), your transcripts may be transmitted to and stored by Apple. This is controlled by your system preferences, not by ParrotScribe. See Apple's Privacy Policy for details.
License Key Storage
Your license key is stored securely in the macOS Keychain, which provides hardware-backed encryption on Apple Silicon Macs.
Telemetry
The app collects anonymous usage data:
- Device model
- Operating system version
- Application version
This data contains no personally identifiable information.
License & Activation Data
The app requires periodic online validation. When you activate ParrotScribe, we store the following data:
| Data | Purpose | Protection |
|---|---|---|
| Email address | License recovery, purchase confirmation | AES-256 encrypted |
| License key | Verify your license is valid | Bcrypt hashed |
| Device identifiers | Track activations against device limit | SHA-256 hashed |
| Activation timestamps | License management | Standard |
| Device count | Enforce device limit per license tier | Standard |
This data is stored on Supabase servers in the European Union (Frankfurt, Germany).
Payment Processing
Payments are processed by Paddle.com (Paddle.com Market Limited, UK), who acts as the Merchant of Record for all purchases.
What Paddle Collects
Paddle collects and processes:
- Payment details (card number, billing address)
- Email address
- Name
- Transaction history
- IP address and device information
We do not have access to your full payment details. We only receive confirmation of successful purchases and your email address to issue your license. See Paddle's Privacy Policy for full details.
Website
Hosting
This website is hosted on Cloudflare Pages. Cloudflare may collect standard web server logs including IP addresses, browser type, and pages visited. See Cloudflare's Privacy Policy.
Cookies
We use local storage for:
- Essential preferences: Storing your theme preference (light/dark mode).
We do not use any tracking or advertising cookies.
Analytics
We use Plausible Analytics to understand website traffic. Plausible is a privacy-first analytics tool that:
- Does not use cookies
- Does not collect any personal data
- Does not track you across websites or devices
- Processes all data anonymously and in aggregate
All data is hosted on European-owned, EU-based infrastructure.
Data Security
We implement multiple layers of security to protect your data:
Encryption at Rest
All data stored in our database is encrypted using AES-256 encryption. Sensitive fields (email, license key, device ID) have additional application-level encryption or hashing.
Encryption in Transit
All data transmitted between your device and our servers uses TLS (Transport Layer Security) encryption.
Hashing
License keys and device identifiers are hashed using industry-standard algorithms (bcrypt, SHA-256). Even if our database were compromised, these values cannot be reversed.
Infrastructure
Our license backend runs on Supabase, which maintains SOC 2 Type 2 certification and undergoes regular security audits.
International Data Transfers
Johan Thorén operates from the Philippines. Your data may be processed in the following locations:
| Service | Data | Location | Safeguards |
|---|---|---|---|
| Supabase | License data | EU (Frankfurt) | GDPR compliant |
| Paddle | Payment data | United Kingdom | UK GDPR, EU adequacy |
| Plausible | Anonymous analytics | EU (Estonia) | GDPR compliant |
| Cloudflare | Website logs | Global CDN (US company) | EU-U.S. DPF, SCCs |
For transfers from the EU/UK, our service providers rely on Standard Contractual Clauses (SCCs) and/or the EU-U.S. Data Privacy Framework where applicable.
Your Rights
Under the Philippine Data Privacy Act and GDPR (for EU residents), you have the following rights:
Access
Request a copy of the personal data we hold about you.
Rectification
Request correction of inaccurate personal data.
Erasure
Request deletion of your personal data (subject to legal retention requirements).
Portability
Request your data in a structured, machine-readable format.
Objection
Object to processing of your personal data for certain purposes.
Restriction
Request that we limit how we use your data.
To exercise any of these rights, contact us at support@parrotscribe.com. We will respond within 30 days.
Data Retention
- License data: Retained for the duration of your license plus any period required by law for tax and accounting purposes.
- Payment records: Retained by Paddle per their retention policy and legal requirements.
- Website logs: Retained by Cloudflare per their data retention policy.
- Your transcripts: Stored only on your device. We never have access to them.
Contact & Supervisory Authorities
Contact Us
For privacy-related questions or to exercise your rights, contact: support@parrotscribe.com
Supervisory Authorities
If you believe your privacy rights have been violated, you have the right to lodge a complaint with a supervisory authority:
- Philippines: National Privacy Commission
- European Union: Your local Data Protection Authority. See list of EU DPAs.
- United Kingdom: Information Commissioner's Office (ICO)
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website. The “Version” date at the top indicates when this policy was last updated.