Scriben

Legal

Privacy Policy

Effective 31 July 2026 · Last updated 7 September 2026

Scriben records meetings and turns them into notes, action items and a morning brief. That means we handle some of the most sensitive material you own — what you said, and who you said it to. This page explains exactly what we collect, what we do with it, and how to get rid of it.

The short version

1Who we are

Scriben (“Scriben”, “we”, “us”) provides the Scriben smart pen, the Scriben mobile app and the Scriben web app. This policy covers all three.

Questions, requests or complaints: emma@scriben.ai.

2What we collect

Account information

When you sign in with Google we receive your name, email address and profile picture. Sign in requests only the basic openid email profile permissions — signing in alone gives us no access to your mail or calendar.

Recordings and what we derive from them

Biometric data

Scriben does not collect, store or process biometric identifiers or biometric information. We do not create voiceprints or voice embeddings, we do not perform facial or fingerprint recognition, and we do not use your voice to identify you. Speaker labels in a transcript are derived from the recording itself and are not retained as a biometric identifier.

Data from services you connect

Only if you connect them, and only the categories described in section 3. Connecting is always a separate, explicit step from signing in.

Technical data

A session cookie to keep you signed in, plus standard server logs (IP address, timestamps, error traces) used to keep the service running and secure.

3Google user data

Scriben requests the narrowest set of Google permissions that will deliver the features you turn on. Signing in and connecting are deliberately separated, so you are never asked for calendar or mail access just to create an account.

Permission Why Scriben asks
openid email profile Sign you in and show your name and picture in the app.
calendar.events Read your events so your Morning Brief knows what your day looks like, and create an event only after you approve it.
gmail.readonly Read recent mail to surface the replies you owe in your brief. Requested only if you choose to connect mail.
gmail.compose Create drafts for you to review. Scriben never sends mail on its own. Requested only if you choose to connect mail.
contacts.other.readonly Resolve a name mentioned in a meeting to the right email address, so a follow-up goes to the correct person. Requested only if you choose to connect mail.

Limited Use

Scriben’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, and without exception:

What we keep, and what we do not

Calendar events and mail messages are fetched at the moment Vera generates your brief and are not written to our database. Recently fetched drafts may be held in server memory for up to sixty seconds so the interface does not re-request the same data, after which they are discarded. What is saved to your account is the brief Vera writes — not the mailbox it was written from.

If you have not connected mail, Scriben still drafts your follow-ups; the draft simply opens in your own mail app instead, and your mailbox is never touched.

4How we use your information

We do not build advertising profiles, and we do not use your content to train general-purpose models.

5Who we share it with

We do not sell your data. We share it only with the service providers needed to make Scriben work, each handling it on our instructions:

Each of these providers is bound by a written agreement that requires them to protect your information to a standard equal to our own, to process it only to provide the service to you and on our instructions, and not to use your content to train their models. None of them may sell it, and none of them receives it for advertising.

That last commitment is enforced in the request itself, not only on paper. Every call to Deepgram carries mip_opt_out, which excludes your audio from their Model Improvement Program — a setting separate from the agreement, and one we send on every request, on both of the paths that transcribe audio. Our OpenAI organisation runs under Modified Retention, so transcripts are not used for training and are not read by OpenAI staff.

Healthcare customers and HIPAA

Where Scriben is used to record patient consultations we act as a business associate under HIPAA, and we will enter into a Business Associate Agreement with the covered entity. Every subcontractor that can receive protected health information has an executed agreement with us covering it — Google Cloud, Deepgram and OpenAI. Sentry receives error diagnostics only, and is configured so that recordings, transcripts and note content never reach it.

HIPAA has no certificate and no certifying body, so no company can truthfully claim to be “HIPAA certified”. What we can show you is the agreements themselves, the controls behind them and the monitoring that keeps them honest. Ask and we will share them.

We may also disclose information where we are legally required to, or where necessary to protect the safety and rights of users.

6How long we keep it

7Your choices

Delete individual recordings

Any recording, and everything derived from it, can be deleted from the app.

Disconnect a service

Disconnecting from Scriben’s Integrations screen deletes the access tokens we hold, which ends our access immediately. You can additionally revoke Scriben’s access from your Google account at myaccount.google.com/permissions.

Delete your account

In the Scriben iOS app, open Settings → Delete account. This removes your account and its content. You can also email emma@scriben.ai and we will do it for you.

Access and correction

Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold, and to object to certain processing. Write to emma@scriben.ai and we will respond.

8Security

Traffic between your devices and Scriben is encrypted in transit using TLS. Data is stored on Google Cloud infrastructure, and access to production systems is limited to the people who need it to operate the service. Each account’s data is isolated: requests are scoped to the signed-in user, and integration tokens are stored per user.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify you without undue delay, and we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires that.

9Recording other people

Scriben records conversations, and the law on recording others varies by country and by state — in many places every participant must consent. You are responsible for obtaining whatever consent is required before you record. Please tell people they are being recorded.

10Children

Scriben is not intended for anyone under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

11California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to access a copy of it, to correct it, to delete it, and to be free from discrimination for exercising any of these rights. Exercise them by writing to emma@scriben.ai; we will verify your request against the account it concerns before acting on it, and you may use an authorised agent.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and we do not sell or share the personal information of minors.

The categories we collect are identifiers (name, email address), audio and its transcriptions, and internet activity necessary to operate the service; the sources, purposes and recipients are described in sections 2, 4 and 5. Recordings and transcripts may contain sensitive personal information — we use it only to provide the service you asked for and never to infer characteristics about you, which are the purposes permitted without a right to limit under the CPRA.

12European and UK privacy rights

If the GDPR or UK GDPR applies to you, Scriben is the controller of the personal data described in this policy. Our legal bases are: performance of a contract for recording, transcribing and generating your notes and brief; consent for connecting an optional service such as Google Calendar or Gmail, which you may withdraw at any time by disconnecting it; and our legitimate interests in keeping the service secure, diagnosing faults and preventing abuse.

You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and to receive it in a portable form. Withdrawing consent does not affect processing carried out before you withdrew it. You may also lodge a complaint with your local supervisory authority. Write to emma@scriben.ai and we will respond within the period the law allows.

13International transfers

Scriben is operated from the United States and our providers process data there. If you use Scriben from elsewhere, your information will be transferred to and processed in the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) as the transfer safeguard, together with the technical and organisational measures described in section 8.

14Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change meaningfully affects you, notify you in the app. Continuing to use Scriben after a change means you accept the updated policy.

15Contact

emma@scriben.ai