Security at a glance
| In transit | Encrypted with TLS |
|---|---|
| At rest | Provider-dependent (see below) — do not assume a specific standard |
| Retention | You choose the window; delete anytime; guest files auto-removed (~2 h) |
| AI training | Your content is not used to train AI models |
| Privacy law | GDPR-aligned; data-subject rights supported |
| Certifications | No SOC 2 report or HIPAA BAA is published — see below |
Encryption
Uploads and downloads are encrypted in transit using TLS, so your audio is protected while it moves between your device and the service.
Retention and deletion
You control how long your recordings and transcripts are kept. Account holders set a retention window, delete any file at any time, and files uploaded without an account are removed automatically within a couple of hours. Deleted files are permanently purged after roughly 30 days.
See the Data Retention page for the details, options, and defaults.
No AI training on your content
Your recordings and transcripts are not used to train AI models. Where processing is handled by third-party AI providers, that processing operates under their no-training API terms.
Privacy and your rights
Data handling is GDPR-aligned and supports data-subject rights such as access and deletion. The Privacy Policy describes what is collected, how it is used, the processors involved, and how to exercise your rights.
Compliance: what we do and do not claim
We keep compliance claims honest. The measures above (TLS in transit, configurable retention, deletion, no-training, GDPR-aligned handling) are in place today.
Frequently Asked Questions
Is my audio encrypted?
Yes, in transit with TLS. At-rest encryption depends on the storage backend; ask us if a specific standard is required.
Do you train AI on my recordings?
No. Your content is not used to train AI models, and processing partners operate under no-training terms.
How long do you keep my data?
You choose the retention window and can delete files at any time; guest uploads are auto-removed within a couple of hours. See the Data Retention page.
Are you SOC 2 certified or HIPAA compliant?
We do not currently publish a SOC 2 report or offer a HIPAA BAA. Contact us before relying on TranscribeThis for workflows that require them.
Is TranscribeThis GDPR-aligned?
Yes — data handling is GDPR-aligned and supports data-subject rights. See the Privacy Policy.
Related resources
Reviewed by the TranscribeThis product team · Last updated: July 2026
