PRIVACY POLICY

Collect less.
Explain the rest.

The short version: ordinary transcript use needs no account, name, or payment details. We process the link and options you submit, public YouTube metadata and captions, job records, and limited technical data needed to secure and operate the Service. We do not sell personal information, run behavioral advertising, or use third-party analytics as of this policy’s effective date.

1. Scope

This Privacy Policy explains how the operator of ScriptHaul (“ScriptHaul,” “we,” “us,” or “our”) handles information when you use scripthaul.com, create or revisit a transcript job, download output, or contact us about support, privacy, or rights. For personal information whose purposes and means we determine, the ScriptHaul operator acts as the data controller or business.

This policy does not govern YouTube, Google, Cloudflare, Fly.io, DataImpulse, or another third party when it processes information for its own purposes. Their own policies apply to that processing.

2. Information we process

Request and job information

We process the YouTube URL you submit; your requested file format, transcript view, language, fallback choice, and continuation position; a random request key used to prevent duplicate jobs; and the job address generated for you. Job records can include source and video identifiers, titles, channel information, publication dates, available caption-track details, progress and outcome states, error details, request and completion times, and measured proxy traffic.

Public source and caption data

We obtain public channel, playlist, video, and caption information from Google and YouTube. Successful caption responses are stored as compressed source caption data and converted into the formats you request. Public captions may incidentally contain names, opinions, health information, political or religious discussion, or other material that could be sensitive in context. We do not ask you to add sensitive personal information to the submission form.

Network, device, and security information

Like any web service, Cloudflare receives the request needed to connect you to the site. It may process your IP address, browser or user-agent, request URL and headers, referrer, approximate network location, security signals, and request timing in order to deliver and protect the Service.

Our Worker uses your IP address transiently to create a shortened, keyed HMAC identifier for rate limits, daily quotas, job idempotency, and abuse prevention. That pseudonymous value—not the raw IP address—is stored in our D1 job and quota tables. It is still treated as protected technical data. When Turnstile is required, the Worker also sends your IP address and the single-use challenge token to Cloudflare for verification. Infrastructure and error logs may contain ordinary request metadata.

Messages you send us

If you email us, we process your email address, message, attachments, and any information you choose to provide. A copyright or takedown notice may include your name, address, telephone number, signature, and statements required to evaluate the notice. Ordinary transcript use does not ask for an account, name, contact details, or payment information.

3. Where information comes from

We receive information directly from you and your browser, automatically from network and security systems, and from public Google and YouTube APIs or caption endpoints. We may also receive information from someone who contacts us about a privacy, support, copyright, or legal matter.

4. Why we use information

We use the information described above to:

5. Legal bases where required

Where law requires a legal basis, we process information as necessary to provide the Service you request and perform our agreement with you; for our legitimate interests in operating, securing, limiting abuse of, and improving the reliability of a free service; and to comply with legal obligations or establish, exercise, or defend legal claims. If we introduce optional processing that requires consent, we will request it separately and you may withdraw it as allowed by law.

6. Public cache and unlisted links

Successful public caption data may be cached by video and caption track so another request does not require another upstream fetch. The cache is source-based, not organized by the identity of the person who requested it. There is no public browsable transcript directory.

Job and transcript pages are marked to discourage search indexing and job identifiers are randomly generated, but this is not account-based access control. Anyone who has a job URL may be able to see the submitted source URL, job inventory, progress, outcomes, and transcript links. Cached transcript endpoints can also return available public-caption data for a video identifier. Do not submit or share a job URL if its contents would be sensitive.

7. Cookies and browser storage

The application code does not set its own cookies. Cloudflare may use necessary security technologies when it delivers the site or performs a Turnstile check.

The current browser tab uses sessionStorage to carry the submitted YouTube URL, preferences, random request key, and—briefly after a successful challenge—the single-use Turnstile token between the landing, verification, and job pages. The app rejects pending request state older than 15 minutes when it is revisited and normally removes that state when the flow completes, expires, or reaches a terminal error. Browser session storage also ends when the tab or browser session ends.

Your theme choice and dismissal of the bookmark reminder are stored in localStorage until you clear site data or change the setting. We do not use advertising cookies or cross-site tracking cookies as of the effective date.

8. Service providers and disclosures

We disclose only the information reasonably necessary for the following providers to perform their roles:

We may also disclose information when reasonably necessary to comply with valid legal process; protect a person, the public, rights holders, or the Service; investigate abuse; or complete a merger, financing, reorganization, or transfer of the Service, subject to applicable notice and confidentiality requirements.

9. No sale, targeted advertising, or profiling

We do not sell or rent personal information. As of the effective date, we do not share personal information for cross-context behavioral advertising, use ad-tech or third-party analytics, target ads based on activity across other services, or make decisions with legal or similarly significant effects through automated profiling. Because that activity does not occur, Do Not Track and Global Privacy Control signals do not change the Service’s behavior today. We will honor legally recognized opt-out signals if our practices change in a way that makes them applicable.

10. Retention

Public caption data and related source metadata may be retained indefinitely to make repeat requests faster, unless we remove them or a valid privacy, copyright, or legal request requires action. Completed and failed job records, including their per-video rows, are deleted automatically after about 90 days, so bookmark a job's files rather than the job page itself if you need them long-term. Daily quota counters are deleted after about three days and expired source inventories within about two days of expiring. Records still reasonably needed for cache decisions, abuse controls, reliability, legal compliance, or dispute handling may be kept longer.

Browser request state follows the periods described above. We retain support, privacy, and takedown correspondence for as long as reasonably needed to answer the request, maintain a record of the action taken, comply with law, or resolve a dispute. Infrastructure providers may retain security and technical logs according to our settings and their own policies.

11. Security

We use HTTPS, separate public application code from operational secrets, restrict the relay contract, generate hard-to-guess job identifiers, pseudonymize IP addresses in our application database, and limit the data sent between service components. No internet service or storage system is perfectly secure. A job link should be treated like an unlisted sharing link: anyone who obtains it may be able to use it.

12. International processing

Cloudflare operates a global network, the fetch relay is hosted in the United States, and Google, YouTube, DataImpulse, and other providers may process information in the United States and other countries. Those countries may have privacy laws different from the laws where you live. Transfers are handled as required by applicable law and the relevant provider arrangements.

13. Your choices and privacy rights

You may choose not to submit a link, clear local and session storage through your browser, avoid sharing a job URL, or ask us to delete identifiable job metadata. Deleting job metadata does not necessarily require deletion of source-based public caption data from the shared cache unless a valid privacy, copyright, or other legal basis requires removal.

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability; withdraw consent where processing relies on consent; appeal a refusal; and complain to a privacy regulator. You will not be discriminated against for exercising a privacy right. These rights can be limited by exceptions in applicable law.

To help us locate records without creating an account profile, include the relevant job URL, submitted YouTube URL, or correspondence address. We may ask for information reasonably necessary to verify your identity or authority. Our use of pseudonymous identifiers and minimal direct identifiers may mean we cannot reasonably connect some records to you.

14. Children

The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has provided personal information through the Service, contact us so we can review and delete it where appropriate.

15. Third-party sites

The Service links to YouTube and other third-party sites. We are not responsible for their content or privacy practices. Review the privacy notice of any third-party service you use.

16. Changes to this Policy

We may update this Policy when the Service, providers, law, or our practices change. We will post the revised Policy here with a new effective date and provide a prominent notice for material changes where reasonably practical.

17. Contact us

Send a privacy request or question to support@scripthaul.com with “Privacy request” in the subject line. Copyright and takedown requests should follow the DMCA and takedown process.