Last updated:
This Privacy Policy explains how Subbix collects, uses, stores, and protects your personal data when you use our AI-powered transcription platform. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and Google API Services User Data Policy.
The personal data collected on Subbix is processed by:
For any questions about this privacy policy or to exercise your rights, please contact us at the email address above.
When you choose to sign in with Google, we access the following data from your Google account:
We only request the minimum necessary permissions (email and basic profile). We do not access your Google Drive, Gmail, Calendar, or any other Google services.
Your Google account data (email, name, profile picture) is retained until you delete your Subbix account. You can disconnect your Google account at any time from your account settings.
Your Google account data is never sold or shared with third parties for advertising or marketing purposes. It is only used within our platform for the purposes described above.
We collect the following types of personal data:
⚠️ Media files are automatically deleted from our servers 24 hours after upload
We process your personal data for the following purposes:
We share your data with the following third-party service providers:
Purpose: Store account data, transcripts, and media files
Location: EU and USA servers
Security: SOC 2 Type II certified, GDPR compliant
Privacy Policy →Purpose: Process subscription payments and manage billing
Location: USA (PCI-DSS Level 1 certified)
Security: Industry-leading payment security, GDPR compliant
Privacy Policy →Purpose: Process video/audio files for transcription and transcript enhancement
Data Shared: Your uploaded media files and transcripts are sent to Replicate's AI models
Retention: Replicate does not retain your data after processing
Location: USA
Privacy Policy →We do not sell, rent, or trade your personal data to third parties for advertising or marketing purposes.
We may disclose your data if required by law, court order, or to protect our rights, property, or safety.
We implement industry-standard security measures to protect your data:
While we implement strong security measures, no system is 100% secure. Please use a strong, unique password and enable two-factor authentication when available.
We retain your data for different periods depending on the type:
24 hours after upload
Automatically deleted from our storage to save costs and protect your privacy
Retained indefinitely until you delete them
You can delete individual transcripts or your entire account at any time
Retained until you delete your account
Upon account deletion, all your data (transcripts, usage logs) is permanently deleted within 30 days
1 year
Retained for billing, support, and regulatory compliance purposes
7 days
Automated backups are retained for disaster recovery, then permanently deleted
Under the GDPR, you have the following rights regarding your personal data:
Request a copy of all personal data we hold about you
Correct inaccurate or incomplete personal data
Request deletion of your personal data (account deletion)
Receive your data in a structured, machine-readable format (JSON export)
Limit how we use your data in certain circumstances
Object to processing based on legitimate interest or direct marketing
Withdraw consent for data processing (e.g., disconnect Google Sign-In)
File a complaint with your national data protection authority if you believe your rights have been violated
Your data may be processed in countries outside the European Economic Area (EEA):
Provider: Supabase (primary database and storage)
Data primarily stored in EU data centers
Providers: Stripe (payments), Replicate (AI processing), Vercel (hosting)
Safeguards: These providers comply with GDPR through Standard Contractual Clauses (SCCs) and adequate security measures
We only transfer data to countries with adequate data protection standards or use approved safeguards (SCCs, Privacy Shield frameworks where applicable).
We use cookies for essential functionality only:
Purpose: Maintain your login session
Duration: Session-based (deleted when you close your browser)
Strictly necessary for the service to function
Purpose: Remember your language preference
Duration: 1 year
Optional but improve user experience
We do not use cookies for advertising, analytics, or third-party tracking. We respect your privacy.
Our service is not intended for children under 16 years old.
We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact us immediately at support@subbix.io, and we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
We recommend reviewing this policy periodically to stay informed about how we protect your data.
For any questions, concerns, or requests regarding this Privacy Policy or your personal data:
Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données)
https://www.autoriteprotectiondonnees.be/
You have the right to lodge a complaint with this authority if you believe your data protection rights have been violated.