Privacy Policy

Privacy Policy

We believe in transparency about how we collect, use, and protect your data while you build your work timeline with getScribe.

Effective Date: August 29, 2026privacy@getscribe.ai

Overview

This Privacy Policy describes how Open Protocol Labs, LLC ("we," "us," or "our") collects, uses, and protects your information when you use getScribe ("the Service"), our work-evidence aggregation platform.

getScribe is a timeline-based work-evidence aggregator that helps you automatically capture and organize your work activities across git repositories, file systems, and AI coding tool conversations.

Information We Collect

Account Information

  • Email address (required for account creation and verification)
  • Name (required for account personalization)
  • Avatar image (optional, uploaded by you)
  • Authentication data when you sign in via GitHub, Google, or Sigma Identity

Work Timeline Data

When you use our desktop application, we collect work evidence from your local development environment:

  • Git Activity: Repository paths, branch names, commit hashes, timestamps, and author information
  • File System Activity: File paths, modification timestamps, and change patterns
  • AI Conversation Data: Timestamps, titles, summaries, and full content of conversations with AI coding tools (Claude, Cursor, Copilot, etc.)

Organization and Billing Data

  • Organization membership and role information
  • Team invite tokens and invitation history
  • Stripe Customer ID and subscription status (payment details are processed by Stripe and not stored by us)

Technical Data

  • Device identifiers for multi-device sync functionality
  • Session cookies for authentication (HTTP-only and signed)
  • Temporary cookies for specific workflows (e.g., wallet_unlocked with 5-minute TTL)
  • BAP ID when using Sigma Identity authentication (Bitcoin-based pseudonymous identifier)

How We Use Your Data

  • Service Delivery: Provide timeline visualization, project organization, and team collaboration features
  • Invoicing: Generate invoices with work evidence for freelancers and agencies
  • Account Management: Manage your account, authentication, and subscription
  • Security: Detect and prevent security threats, including scanning for exposed secrets in your code
  • Communication: Send transactional emails via Resend (account verification, invoice delivery, important service updates)
  • Improvement: Analyze product usage to improve our service. Usage analytics are collected through PostHog and, once you sign in, are linked to your account rather than anonymized, including analytics collected before you signed in. See Data Sharing below for what is collected.

Data Sharing

We share your data with the trusted service providers we use to operate and promote our service, including:

  • Stripe: Payment processing for subscriptions
  • Resend: Transactional email delivery
  • Vercel: Web application hosting and infrastructure
  • Turso: Database hosting and management
  • Upstash: Session storage and rate limiting
  • PostHog: Product analytics and error tracking. Our web pages load the PostHog browser SDK, which captures page views and page leaves as you navigate, interactions with page elements such as clicks, unhandled exceptions, campaign parameters and the referrer from the URL you arrived on, and a device identifier that PostHog stores in your browser. These requests go to /ingest on our own domain and we forward them to PostHog, so they are first-party requests rather than requests your browser makes directly to PostHog. When you sign in, we attach your account ID and your name to that PostHog profile, along with your BAP ID and your role when those are available. Sign-in also links analytics collected before sign-in from the same browser to that profile, so analytics collected before and after sign-in is linked to your account and is not anonymous. Our servers also send PostHog events for account signup, device registration, first sync, and subscription trial and conversion, identified by your account ID and carrying details such as device count, event count, organization ID, and plan name. We send PostHog product events from the browser as well, such as waitlist signup. If a PostHog key is not configured for a deployment, the SDK is never initialized and no PostHog analytics is sent.
  • GitHub/Google: When you authenticate via these services, we receive basic profile information as permitted by your OAuth consent
  • Google Preferred Sources: Our public marketing and blog pages load Google's Preferred Sources script (news.google.com) so you can choose getScribe as a preferred source in Google Search. Google receives request data and may collect its own analytics when this script runs. If you move from a public page into the app without a full page reload, the already-loaded script can remain present in that browser tab.

We do not sell your data to third parties or use it for advertising purposes.

Data Storage and Jurisdiction

Your data is stored in the United States through our service providers (Vercel and Turso). Our infrastructure is designed with industry-standard security measures including encryption in transit and at rest.

For desktop application users, your work data is first processed locally on your device before being optionally synced to our cloud infrastructure.

Your Rights

  • Access: Request a copy of your personal data
  • Correction: Update or correct your account information through your profile settings
  • Deletion: Request deletion of your account and associated data
  • Export: Export your timeline data through our platform
  • Withdrawal: Stop using our service at any time

To exercise these rights, please contact us at privacy@getscribe.ai.

Cookies

We set the following cookies to provide our service:

  • Authentication Cookies: HTTP-only, signed cookies to maintain your login session (Better Auth)
  • Workflow Cookies: Temporary cookies for specific user flows (e.g., wallet unlock verification with 5-minute expiry)
  • Analytics Storage: PostHog's browser SDK stores a device identifier in a first-party cookie on our domain and in your browser's local storage, so repeat visits from the same browser are recognized as the same device
  • Attribution Storage: A first-party cookie on our domain that records how you first reached us: the campaign parameters in the URL you arrived on, Google and Facebook ad click IDs, the external site that referred you, and the page you landed on. We write it once on your first visit and never overwrite it, so it always reflects that first visit rather than your most recent one. It lasts one year, and we set it even when analytics is disabled and no PostHog key is configured.

We do not set third-party tracking cookies or advertising cookies. Third-party scripts we embed, such as Google's Preferred Sources script on our public marketing and blog pages, may set cookies that we do not control.

Children's Privacy

Our service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently received personal information from a child under 13, we will delete such information from our records.

Beta Considerations

Important Notice: getScribe is currently in private beta. During this phase:

  • Data may be deleted as part of beta testing and system improvements
  • We will provide advance notice before any destructive changes that could affect your data
  • You can export your data at any time through our platform
  • Features and data structures may change as we iterate on the product

Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will notify you via email and provide notice through our service. Your continued use of the service after such modifications constitutes your acceptance of the updated privacy policy.

Contact Us

If you have questions about this privacy policy or our data practices, please contact us at:

Open Protocol Labs, LLC
Email: privacy@getscribe.ai
Website: getscribe.ai