BossyScript

Privacy Policy

BossyScript is built around private transcripts, short retention, and user-controlled deletion.

What we collect

Account: Google subject, email, name, optional avatar, locale, timezone, and versioned consent to these documents.

Jobs: title, source type, platform, file name/size or source URL, status, duration, language, timestamps, and a short preview used in your own history. The full transcript lives in private object storage, not in ordinary database fields.

Payments: Paddle customer and subscription identifiers, interval, and status. We do not store card numbers.

Support: subject and message you send. Do not paste transcripts into tickets.

Where it lives

Structured account, job, billing, support, and audit metadata is stored in Convex. Transcript text is stored in a private R2 bucket. Session cookies are opaque, HttpOnly, SameSite=Lax, and Secure on HTTPS; we store only a SHA-256 hash of the session token.

Who processes data for us

Google authenticates you. Paddle processes payments as the merchant of record. A private transcription service converts media to text. BossyScript checks plans and quotas; the transcription service does not.

Retention

Transcripts are kept for 30 days, then deleted automatically. You can delete a job earlier. Account deletion removes remaining transcripts, revokes sessions, and anonymizes the profile.

We do not write full transcripts, source URLs, filenames, or secrets into logs, error payloads, or public admin views.

Your choices

You can download a JSON export of your profile, job metadata, and saved transcripts from Settings. You can delete the account from the same page. In-app support is available after sign-in.