Legal
Privacy Policy
Last updated 8 August 2026
The short version
Your video, audio, transcripts, projects, exports, and the voices Rescript clones never leave your device. Not to us, not to anyone. There is no upload step, because there is nowhere for it to go — the transcription, editing, voice cloning, and export all run on your own hardware. You can verify this in the source, or by disconnecting from the network after the models have downloaded.
What we do hold is small and specific: your email address if you gave us one, anonymous usage counts from the app, and ordinary website analytics. Everything below explains exactly what those are.
This summary is here to be read. It is not part of the agreement and the full text below governs if the two ever disagree.
01What never reaches us
This is the part that matters most, so it goes first. None of the following is transmitted to us, at any point, for any reason:
- your video and audio files, or any part of them;
- the transcripts generated from them, imported into them, or edited by you;
- filenames, file sizes, or durations;
- speaker names or labels;
- the reference audio Rescript uses to clone a voice, the voice embedding produced from it, or any speech it synthesizes;
- your projects, cut lists, or timeline edits; or
- anything you export.
Cloned voices in particular are created and used entirely in memory on your machine and are cached only for the session. No voice profile is uploaded, stored on a server, or shared. We could not produce your voice on request, because we have never had it.
Projects auto-save locally — in your browser's IndexedDB storage, or on disk in the desktop application. That storage is yours; clearing site data or uninstalling removes it.
02What the website collects
If you give us your email address
The download and web-app buttons on getrescript.com invite you to leave an email address. It is optional and every one of those prompts can be skipped. If you submit it, we store:
- the email address itself, lowercased;
- which prompt it came from (a download button, the footer, or the web app link) and, for a download, which platform you were downloading;
- when you signed up, when you confirmed, and when you unsubscribed if you have.
We send you a confirmation email that doubles as a sign-in link. Following it creates an account record on getrescript.com containing your email address, a display name, and confirmation status.
Signing in creates a session record that includes the IP address and browser user-agent of the device that used the link, alongside the session token and its expiry. This is standard session-security data from the authentication library we use. It applies only to signing in on this website — the editor itself has no accounts and no sessions.
We use your address to send release notes and occasional project updates. We do not sell it, rent it, or share it for anyone else's marketing.
Website analytics
We use Vercel Web Analytics to count page views on this site. It is cookieless and does not build a profile of you across sites. We may also run Google Analytics on the marketing site; where it is enabled it sets its own cookies and is subject to Google's privacy policy. Both are blocked by ordinary content blockers, and blocking them does not affect anything on the site.
Like any web server, our hosting provider processes your IP address and request headers in order to serve you a page, and keeps short-lived operational logs.
03What the app reports
Anonymous usage telemetry
The Rescript editor reports a small number of events so we can tell roughly how many people use it and how far they get. It is not an analytics SDK and it is not an account. Each report contains:
- an install ID — a random UUID the app generates for itself. It is not derived from your machine, your network, or you, and clearing site data or reinstalling produces a new one;
- one of four event names:
app_opened,project_created,transcription_completed,export_completed. Anything else is rejected by the server; - the app version, your operating system family, and whether you are on the desktop app or the web;
- a handful of coarse properties from a fixed vocabulary, such as which transcription model or export format was used. These are limited to short scalar values so that no field is capable of carrying your content.
IP addresses are not recorded. There is no column for one in the telemetry database, deliberately. No filename, duration, or transcript text is ever included.
You can turn this off in the app's Settings, under “Help improve the app”. When it is off, nothing is sent.
Crash reports
When the same setting is enabled, the app also reports crashes and errors to Sentry so we can fix them. Reports contain the error, a stack trace, breadcrumbs of recent activity, and browser or OS version. Before anything is sent, the app scrubs media filenames, user directory names, and blob: and file: URLs out of every text field. Turning the setting off prevents Sentry from initialising at all, so nothing is captured.
App analytics
The web app and desktop shell also report page views to Vercel Web Analytics, routed through an endpoint on this domain so that all three surfaces land in one dashboard. The same cookieless counting applies.
04Requests that go elsewhere
Some things your device fetches come from third parties rather than from us. We never see these requests, but they are not invisible to the providers, who will at minimum observe your IP address:
- Hugging Face — the speech recognition, speaker segmentation, and voice models are downloaded from Hugging Face the first time you use a feature that needs them, then cached locally. After that, no further request is made.
- GitHub— desktop applications download from and check GitHub Releases for updates. This website also asks GitHub for the repository's star count, but does so from our server, so your browser does not contact GitHub for it.
Once the models are cached, the editor works with no network connection at all.
05Who processes data for us
We use the following providers, and no others hold personal data for us:
- Vercel — hosting for this website and its analytics.
- Neon — the PostgreSQL database holding mailing-list entries, account records, and telemetry.
- Resend — sends the confirmation and sign-in emails. It processes your email address to deliver them.
- Sentry — receives crash reports when you have not opted out.
- Google Analytics — website measurement, where enabled.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law. We have never received a government request for user data; if we did, we would have very little to give.
07Why we are allowed to hold it
For people in the UK, EU, and other jurisdictions with equivalent law, our legal bases are:
- Consent — for the mailing list. You gave us the address for that purpose and can withdraw at any time; withdrawal does not affect anything already sent.
- Contract — to operate sign-in and send you the link you asked for.
- Legitimate interests — for anonymous usage counts, crash reports, and website measurement, so we can understand roughly how many people use Rescript and fix what breaks. We have kept this to the minimum that answers those questions, and it is opt-out in the app.
08How long we keep it
- Mailing list — until you unsubscribe or ask for deletion.
- Account and session records — accounts until you ask for deletion; sessions expire on their own and are then removed.
- Telemetry — retained in aggregate to measure usage over time. It contains no identifier we could link back to you.
- Crash reports— kept for Sentry's default retention period and then deleted.
09Your rights
Depending on where you live you may have the right to access, correct, delete, port, restrict, or object to our processing of your personal data, and to withdraw consent. Californian residents additionally have the right to know what is collected and to be free from discrimination for exercising these rights.
Write to hello@getrescript.comand we will act on it. In practice, the entirety of what we are likely to hold about you is an email address and the timestamps around it, so “delete everything you have on me” is a quick request to honour.
To unsubscribe, email us and we will remove you. If you are in the UK or EU and think we have handled your data badly, you may also complain to your local data protection authority.
10Where the data is
Our providers are United States companies and the data described here is stored on infrastructure in the United States. If you are in the UK or EU, submitting your email address involves a transfer there; our providers rely on Standard Contractual Clauses and equivalent safeguards for such transfers.
Your media is not part of this and never crosses any border, because it never leaves your device.
11Limits of age
Rescript is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us an email address, tell us and we will delete it.
12Changes to this policy
If what we collect changes, this page changes with it and the “last updated” date at the top moves. If we ever introduce a feature that needs to send your media or transcripts to a server, it will be opt-in, clearly labelled in the app, and described here before it ships — never switched on by default.
Every revision of this page is in the public Git history of this website, so you can see what changed and when.
13Contact
To reach us, emailhello@getrescript.com
If you would rather check than trust: the code that handles all of the above is public at github.com/wassgha/rescript. See also the Terms of Use and the Acceptable Use Policy.