Security and Data Handling

TranscribeThis encrypts your uploads in transit (TLS), lets you control how long files are kept and delete them at any time, and does not use your content to train AI models. Data handling is GDPR-aligned. This page describes what is actually in place — it is a practical summary, and the Privacy Policy holds the full terms.

Transcribe a file securely
or drag & drop it here
Encrypted in transit · you control retention · first 5 min free
Up to 99% Accurate90+ Languages1-Hour Audio in 2 Min30+ File Formats
4.8 ratingTrustpilotG2SOC 2GDPRSSL

Security at a glance

In transitEncrypted with TLS
At restProvider-dependent (see below) — do not assume a specific standard
RetentionYou choose the window; delete anytime; guest files auto-removed (~2 h)
AI trainingYour content is not used to train AI models
Privacy lawGDPR-aligned; data-subject rights supported
CertificationsNo SOC 2 report or HIPAA BAA is published — see below

Encryption

Uploads and downloads are encrypted in transit using TLS, so your audio is protected while it moves between your device and the service.

Honest note on at-rest encryption
Encryption of stored files depends on the storage backend in use and is not something we overstate. Do not assume a specific at-rest standard (for example AES-256) applies universally. If at-rest encryption to a named standard is a hard requirement for your organization, contact us before relying on it.

Retention and deletion

You control how long your recordings and transcripts are kept. Account holders set a retention window, delete any file at any time, and files uploaded without an account are removed automatically within a couple of hours. Deleted files are permanently purged after roughly 30 days.

See the Data Retention page for the details, options, and defaults.

No AI training on your content

Your recordings and transcripts are not used to train AI models. Where processing is handled by third-party AI providers, that processing operates under their no-training API terms.

Privacy and your rights

Data handling is GDPR-aligned and supports data-subject rights such as access and deletion. The Privacy Policy describes what is collected, how it is used, the processors involved, and how to exercise your rights.

Compliance: what we do and do not claim

We keep compliance claims honest. The measures above (TLS in transit, configurable retention, deletion, no-training, GDPR-aligned handling) are in place today.

Important
TranscribeThis does not currently publish a SOC 2 report and does not offer a HIPAA Business Associate Agreement. If your workflow legally requires SOC 2, HIPAA, or a signed DPA, do not assume coverage — contact us first to confirm what can be provided.

Frequently Asked Questions

Is my audio encrypted?

Yes, in transit with TLS. At-rest encryption depends on the storage backend; ask us if a specific standard is required.

Do you train AI on my recordings?

No. Your content is not used to train AI models, and processing partners operate under no-training terms.

How long do you keep my data?

You choose the retention window and can delete files at any time; guest uploads are auto-removed within a couple of hours. See the Data Retention page.

Are you SOC 2 certified or HIPAA compliant?

We do not currently publish a SOC 2 report or offer a HIPAA BAA. Contact us before relying on TranscribeThis for workflows that require them.

Is TranscribeThis GDPR-aligned?

Yes — data handling is GDPR-aligned and supports data-subject rights. See the Privacy Policy.

Related resources

Reviewed by the TranscribeThis product team · Last updated: July 2026