Legal
Privacy Policy
Effective 31 July 2026 · Last updated 7 September 2026
Scriben records meetings and turns them into notes, action items and a morning brief. That means we handle some of the most sensitive material you own — what you said, and who you said it to. This page explains exactly what we collect, what we do with it, and how to get rid of it.
The short version
- We collect what you record and what you explicitly connect. Nothing else.
- Your recordings, transcripts and notes belong to you.
- We do not sell your data, we do not serve advertising, and your recordings are never used to train AI models — ours or our providers’. Section 5 says how that is enforced.
- Where Scriben is used for patient consultations we act as a HIPAA business associate, and we will sign a Business Associate Agreement.
- Calendar and mail content is read at the moment your brief is generated and is not saved to our database.
- You can disconnect any integration, or delete your account outright, at any time.
1Who we are
Scriben (“Scriben”, “we”, “us”) provides the Scriben smart pen, the Scriben mobile app and the Scriben web app. This policy covers all three.
Questions, requests or complaints: emma@scriben.ai.
2What we collect
Account information
When you sign in with Google we receive your name, email address and profile picture. Sign
in requests only the basic openid email profile permissions — signing in
alone gives us no access to your mail or calendar.
Recordings and what we derive from them
- Audio you record with the Scriben pen or in the app.
- Transcripts generated from that audio, including speaker labels.
- Notes, summaries, action items and follow-ups written from the transcript.
- Memory entries — durable facts Vera extracts from your recordings so later notes have context.
Biometric data
Scriben does not collect, store or process biometric identifiers or biometric information. We do not create voiceprints or voice embeddings, we do not perform facial or fingerprint recognition, and we do not use your voice to identify you. Speaker labels in a transcript are derived from the recording itself and are not retained as a biometric identifier.
Data from services you connect
Only if you connect them, and only the categories described in section 3. Connecting is always a separate, explicit step from signing in.
Technical data
A session cookie to keep you signed in, plus standard server logs (IP address, timestamps, error traces) used to keep the service running and secure.
3Google user data
Scriben requests the narrowest set of Google permissions that will deliver the features you turn on. Signing in and connecting are deliberately separated, so you are never asked for calendar or mail access just to create an account.
| Permission | Why Scriben asks |
|---|---|
openid email profile |
Sign you in and show your name and picture in the app. |
calendar.events |
Read your events so your Morning Brief knows what your day looks like, and create an event only after you approve it. |
gmail.readonly |
Read recent mail to surface the replies you owe in your brief. Requested only if you choose to connect mail. |
gmail.compose |
Create drafts for you to review. Scriben never sends mail on its own. Requested only if you choose to connect mail. |
contacts.other.readonly |
Resolve a name mentioned in a meeting to the right email address, so a follow-up goes to the correct person. Requested only if you choose to connect mail. |
Limited Use
Scriben’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and without exception:
- We do not use Google user data for advertising of any kind.
- We do not sell or rent Google user data.
- We do not use Google user data to train generalized AI or ML models.
- No human at Scriben reads your Google user data, except with your explicit permission (for example, if you ask us to investigate a problem), where necessary for security, or where the law requires it.
What we keep, and what we do not
Calendar events and mail messages are fetched at the moment Vera generates your brief and are not written to our database. Recently fetched drafts may be held in server memory for up to sixty seconds so the interface does not re-request the same data, after which they are discarded. What is saved to your account is the brief Vera writes — not the mailbox it was written from.
If you have not connected mail, Scriben still drafts your follow-ups; the draft simply opens in your own mail app instead, and your mailbox is never touched.
4How we use your information
- To transcribe your recordings and write notes, summaries and action items.
- To assemble your Morning Brief and suggest follow-ups you can approve or dismiss.
- To carry out actions you explicitly approve, such as creating a calendar event.
- To keep the service running, diagnose faults and prevent abuse.
We do not build advertising profiles, and we do not use your content to train general-purpose models.
5Who we share it with
We do not sell your data. We share it only with the service providers needed to make Scriben work, each handling it on our instructions:
- Google Cloud — hosting, database and file storage for the service.
- Deepgram — speech-to-text. The audio of the recordings you make, and of voice notes you send in chat, is sent to Deepgram to be converted into text.
- OpenAI — the language models behind the assistant. Transcripts, note content and your chat messages are sent to OpenAI to write summaries and answer your questions. Where you have connected Gmail, Calendar or another service, the content Scriben reads there is included when it is needed to answer you.
- Google Cloud (Vertex AI) — the language models that write summaries, and speech-to-text if the primary service is unavailable. Transcripts, and in that fallback case audio, are sent to Vertex AI, which sits inside our Google Cloud agreement.
- Firebase (Google) — sign-in and push notifications. Your email address, your account identifier and your device's notification token. Not your recordings, transcripts or notes.
- Sentry — crash and error reports, so we can find and fix faults. Technical detail about the failure, together with your account identifier and email address so we can tell whose report it is and follow it up. Not your recordings, transcripts or note content, and not your IP address.
- Services you connect yourself — such as Slack, GitHub, Linear or Jira. Data flows to these only when you connect them and only for the actions you approve.
Each of these providers is bound by a written agreement that requires them to protect your information to a standard equal to our own, to process it only to provide the service to you and on our instructions, and not to use your content to train their models. None of them may sell it, and none of them receives it for advertising.
That last commitment is enforced in the request itself, not only on paper. Every call to
Deepgram carries mip_opt_out, which excludes your audio from their Model
Improvement Program — a setting separate from the agreement, and one we send on
every request, on both of the paths that transcribe audio. Our OpenAI organisation runs
under Modified Retention, so transcripts are not used for training and are not read by
OpenAI staff.
Healthcare customers and HIPAA
Where Scriben is used to record patient consultations we act as a business associate under HIPAA, and we will enter into a Business Associate Agreement with the covered entity. Every subcontractor that can receive protected health information has an executed agreement with us covering it — Google Cloud, Deepgram and OpenAI. Sentry receives error diagnostics only, and is configured so that recordings, transcripts and note content never reach it.
HIPAA has no certificate and no certifying body, so no company can truthfully claim to be “HIPAA certified”. What we can show you is the agreements themselves, the controls behind them and the monitoring that keeps them honest. Ask and we will share them.
We may also disclose information where we are legally required to, or where necessary to protect the safety and rights of users.
6How long we keep it
- Recordings, transcripts, notes and memories — kept in your account until you delete them or delete your account.
- Large uploads in transit — a long recording is uploaded to temporary storage so it can be processed. Those files are deleted after processing, and in any case automatically removed within one day.
- Calendar and mail content — not stored (see section 3).
- Connected-account tokens — kept until you disconnect that service or delete your account.
7Your choices
Delete individual recordings
Any recording, and everything derived from it, can be deleted from the app.
Disconnect a service
Disconnecting from Scriben’s Integrations screen deletes the access tokens we hold, which ends our access immediately. You can additionally revoke Scriben’s access from your Google account at myaccount.google.com/permissions.
Delete your account
In the Scriben iOS app, open Settings → Delete account. This removes your account and its content. You can also email emma@scriben.ai and we will do it for you.
Access and correction
Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold, and to object to certain processing. Write to emma@scriben.ai and we will respond.
8Security
Traffic between your devices and Scriben is encrypted in transit using TLS. Data is stored on Google Cloud infrastructure, and access to production systems is limited to the people who need it to operate the service. Each account’s data is isolated: requests are scoped to the signed-in user, and integration tokens are stored per user.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you without undue delay, and we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires that.
9Recording other people
Scriben records conversations, and the law on recording others varies by country and by state — in many places every participant must consent. You are responsible for obtaining whatever consent is required before you record. Please tell people they are being recorded.
10Children
Scriben is not intended for anyone under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
11California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to access a copy of it, to correct it, to delete it, and to be free from discrimination for exercising any of these rights. Exercise them by writing to emma@scriben.ai; we will verify your request against the account it concerns before acting on it, and you may use an authorised agent.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and we do not sell or share the personal information of minors.
The categories we collect are identifiers (name, email address), audio and its transcriptions, and internet activity necessary to operate the service; the sources, purposes and recipients are described in sections 2, 4 and 5. Recordings and transcripts may contain sensitive personal information — we use it only to provide the service you asked for and never to infer characteristics about you, which are the purposes permitted without a right to limit under the CPRA.
12European and UK privacy rights
If the GDPR or UK GDPR applies to you, Scriben is the controller of the personal data described in this policy. Our legal bases are: performance of a contract for recording, transcribing and generating your notes and brief; consent for connecting an optional service such as Google Calendar or Gmail, which you may withdraw at any time by disconnecting it; and our legitimate interests in keeping the service secure, diagnosing faults and preventing abuse.
You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and to receive it in a portable form. Withdrawing consent does not affect processing carried out before you withdrew it. You may also lodge a complaint with your local supervisory authority. Write to emma@scriben.ai and we will respond within the period the law allows.
13International transfers
Scriben is operated from the United States and our providers process data there. If you use Scriben from elsewhere, your information will be transferred to and processed in the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) as the transfer safeguard, together with the technical and organisational measures described in section 8.
14Changes to this policy
If we make a material change we will update the date at the top of this page and, where the change meaningfully affects you, notify you in the app. Continuing to use Scriben after a change means you accept the updated policy.