Privacy & GDPR
Your privacy is fundamental to how we built SenScript. We process only what's necessary to create your CheatCards, and you maintain full control of your data.
SOC 2 Compliant
Enterprise-grade security standards for data protection and privacy
Local Processing
Audio processing happens on your device when possible - no server uploads
No Permanent Storage
Audio files are never stored permanently - deleted after processing
End-to-End Encryption
All data transmissions are encrypted using industry standards
What Data We Process
SenScript follows data minimization - we only process what's essential for CheatCard generation
Audio Data
Temporary audio for transcription only
Retention
Deleted immediately after processing
Purpose
Generate transcriptions for CheatCard creation
Transcribed Text
Text extracted from your conversations
Retention
Stored locally or encrypted in cloud
Purpose
Create flashcards and study materials
Generated Cards
AI-created flashcards and CheatCards
Retention
Until you delete them
Purpose
Your personal study and learning materials
Account Information
Email, name, subscription details
Retention
Until account deletion
Purpose
Service delivery and billing
Transcription-Only Audio Policy
No Audio Storage
SenScript never stores your audio files permanently. Audio is processed in real-time for transcription purposes only and immediately deleted after text extraction.
Local-First Processing
When possible, audio transcription happens locally on your device using Web Speech API. This means your conversations never leave your computer.
Encrypted Transmission
When cloud processing is used (for accuracy or language support), audio is transmitted using TLS 1.3 encryption and processed by GDPR-compliant AI providers.
Your Consent Controls
Your GDPR Rights
You have full control over your personal data and how it's processed
Legal Bases for Processing
Consent (Article 6(1)(a))
For: Audio processing, AI analysis, cloud storage
You explicitly consent to audio processing for CheatCard generation. You can withdraw consent at any time in your settings.
Contract Performance (Article 6(1)(b))
For: Account management, billing, service delivery
Processing necessary to provide SenScript services as described in our terms of service.
Legitimate Interests (Article 6(1)(f))
For: Security monitoring, fraud prevention, service improvement
We have legitimate interests in protecting our service and improving user experience, balanced against your privacy rights.
International Data Transfers
EU Data Processing
SenScript servers are located in the EU. When using our fallback API keys, processing happens within GDPR jurisdiction.
Your API Keys
When you use your own API keys (OpenAI, Anthropic, DeepSeek), data transfers are governed by your direct relationship with those providers.
Safeguards for Non-EU Processing
- • Standard Contractual Clauses (SCCs) with all third-party processors
- • Privacy Shield certified providers where applicable
- • Encryption in transit and at rest
- • Regular adequacy assessments
Questions About Privacy?
Our Data Protection Officer is here to help with any privacy concerns
Data Protection Officer
For all privacy and GDPR-related questions, contact our dedicated DPO team.
Contact DPOLast updated: August 23, 2025 •Report Privacy Issue