Scribena

Privacy Policy

1. Scope of this policy

Scribena (“we”) complies with applicable data-protection laws. This policy covers only the account and billing records we actually receive and hold to operate software subscription licences, and for those records we follow a data-minimization principle.

Scribena is software that runs on the user's own device. Files created in the app (recordings, transcripts, summaries, notes) are encrypted on that device and are never transmitted to our servers, so they fall outside this policy; the user is the controller of those files.

2. Information we collect

  • Account: email (required), name (optional), social-login identifier (if you use Google/Kakao)
  • Billing: subscription status, payment/refund receipt metadata, payment-method identifier (card numbers are not stored by us; they are handled by the payment provider)
  • Logs & safety: access logs, IP, admin-access records (fraud prevention and accountability)

3. Purpose of use

Member identification and authentication, subscription/billing and refund management, customer support, fraud prevention and dispute handling, and legal compliance.

4. Retention and deletion

We delete personal data without delay once its purpose is fulfilled (account and session data are deleted immediately on account closure). Where law requires retention, we keep those records stored separately and destroy them when the period ends.

  • Contract / withdrawal-of-subscription records: 5 years
  • Payment and supply-of-goods records: 5 years
  • Consumer complaint / dispute records: 3 years

Retained items: transaction-party identifiers (email, etc.) and payment/contract records. Destruction: electronic files are permanently and irrecoverably deleted.

5. Processors

To operate the service we entrust processing to, and supervise, the following:

  • Supabase Inc. — authentication, database, hosting
  • Vercel Inc. — web hosting
  • PortOne · NHN KCP Corp. — domestic (Korea) payments
  • Paddle.com Market Ltd — international payments (Merchant of Record)

6. International transfers

Some processors are located abroad, so personal data may be transferred and processed outside Korea — Supabase Inc., Vercel Inc. (USA) and Paddle.com Market Ltd (UK). Transferred items: account identifiers (email, etc.) and billing/subscription metadata, transmitted over the network during service use, for the purposes above and until the processing contract ends.

7. Third-party disclosure

We do not provide personal data to third parties without your consent, except where required by law or upon a lawful request by an investigative authority.

8. Your rights

You may at any time request access, correction, deletion, suspension of processing, or withdrawal of consent (account closure), via in-app settings or the contact below; we act without delay. Personal data of children under 14 requires the consent of a legal guardian.

9. Security measures

For the account and billing records we hold: encryption in transit, access controls, and retention of admin-access logs. Separately, the app encrypts the files it creates on the user's own device, and those files never reach our systems.

10. California residents (CCPA/CPRA)

We do not sell or share personal information as defined by the CCPA/CPRA, and have not done so in the preceding 12 months — so no "Do Not Sell or Share" opt-out is needed. California residents may exercise rights to know, delete, correct, and non-discrimination via privacy@scribena.com. The Service is not directed to children under 13, and we do not knowingly collect their personal information.

11. Privacy officer

Name: Heeman Kim · Contact: privacy@scribena.com · Company: Mindlogin

12. Changes

We will announce any changes on this page before they take effect. Effective date: July 12, 2026