Skip to main content

Privacy Policy

What GistCite collects when you use it, what it deliberately never sees, which third parties process your requests, how long data is kept, and how to export or delete it yourself. Matched to what the service actually stores, not boilerplate.

Last updated August 31, 2026

The short version

We keep what the tools need, and nothing to sell

Your email, your history, and cached extractions; no card numbers, no ad trackers, and no data sales. PDF and media files are processed in memory and never stored. Export or delete everything yourself from the Account page.

Manage my data

The full policy

1. What we collect

Account data: your email address and a hashed password (or one-time login codes). API keys are stored only as SHA-256 hashes.

Usage data: the extractions, summaries, and PDF operations you run while signed in (your history), monthly quota counters, and standard technical logs (IP address for rate limiting, timestamps, error diagnostics).

Content data: extracted transcript and document text is stored and cached by content fingerprint so repeat operations are instant. Files processed by the PDF tools are handled in memory and not stored.

2. What we deliberately don't collect

Free browser text-to-speech playback and microphone dictation run in your browser — that playback text and dictated audio do not reach our servers. Neural MP3 export sends the text you submit to the configured speech provider, but we do not store the generated audio.

Payment card details never touch our systems; Stripe handles all payment data.

We don't sell personal data, and we don't use advertising trackers.

3. Why we process it

To provide the service (process your requests, keep your history, enforce quotas), to secure it (rate limiting, abuse prevention), to bill Pro subscriptions, and to fix problems (error logs). That's it.

4. Third parties we rely on

Stripe for subscription billing. Anthropic (Claude) processes the text you summarize or use for AI clip suggestions. OpenAI processes uploaded audio/video transcription and neural MP3 export when those features are configured. Your browser vendor (e.g. Google for Chrome, Apple for Safari) processes dictation audio through its built-in speech service. YouTube, TikTok, or Instagram may be contacted to fetch transcripts or public media you request. Dropbox, when you choose Upload from Dropbox on the Documents or PDF Editor page: the picker runs in Dropbox's own popup, and your browser downloads only the files you pick from a short-lived link; we never receive your Dropbox credentials or file list. Microsoft, when you choose Upload from OneDrive: you sign in to Microsoft in its own popup, and your browser downloads only the files you pick from a short-lived link (for a link the browser cannot read, our server fetches that one file); we never receive your Microsoft password or file list. Google, when you choose Upload from Google Drive: Google asks you to grant access to the files you pick (the drive.file scope, nothing else in your Drive); your browser downloads or exports those files with a token that stays in the browser and is never sent to or stored by us.

Each processes data under its own privacy policy; we send them only what the operation needs.

5. Retention and deletion

Your account, history, and cached extractions are kept while your account is active. You can revoke API keys yourself at any time. Deletion is self-service and immediate: the Account page's Privacy & data section deletes your account and every record tied to it (history, usage, API keys) and cancels any active subscription. You can also email us (section 7); we honor requests within 30 days, except records we must keep for legal or billing reasons.

6. Cookies and local storage

We use browser local storage for your session token and interface preferences (like the collapsed sidebar). No third-party advertising cookies.

7. Your rights and contact

Depending on where you live (e.g. GDPR in the EU, CCPA/CPRA in California), you may have rights to access, correct, export, or delete your personal data, and to complain to a supervisory authority. Export and deletion are self-service on the Account page; for anything else: support@transcriptfetch.ai.

Related pages