Privacy Policy
SCAPTION processes live event audio to provide transcription and translation, relayed through our backend to the third-party processors listed on our subprocessors page. Questions about data handling: [email protected]. Last updated: 29 August 2026. An improved version of this policy will be published soon; substantial changes are announced in advance.
Esta política también está disponible en español.
Who we are
SCAPTION is a trading name of Luis Miguel Burgaz Olmeda (sole trader), NIF 73052907P, registered address Paseo Constitución 8, local izquierda, 50008 Zaragoza, Spain. Data-protection contact: [email protected].
Who is responsible for what
Two different roles, and the distinction decides who you ask about what. For event content — the audio we relay, the captions, an attendee's question — the SCAPTION customer running the event is the controller and SCAPTION is their processor: we process it on their instructions and for no other purpose. For your account, billing, this website and our marketing emails, SCAPTION is the controller. We sign a Data Processing Agreement (GDPR art. 28) with any customer who needs one, on every plan and at no charge — write to [email protected].
Why we may process your data
- Performance of a contract (art. 6.1.b) — running your account, relaying your events, metering usage and billing what you used.
- Legal obligation (art. 6.1.c) — invoices and the accounting records tax law requires us to keep.
- Legitimate interest (art. 6.1.f) — keeping the service secure and available, preventing abuse of a live relay, filtering audience-submitted questions, and the product telemetry and diagnostics described below.
- Consent (art. 6.1.a) — marketing emails and the analytics cookies described below. Both are optional, both are withdrawable, and neither affects the service.
What we store
During a live event, audio and the resulting captions are processed in real time and streamed to the audience output — they are not retained after the session. What we keep for your account is session metadata only: start time, duration, and the languages used, which is what your usage and billing are based on. We do not store your event audio, and we do not keep transcripts by default. Neither do our providers keep it to improve their own products: every request we make to our speech-to-text provider carries an explicit opt-out, so your event audio is not retained by them and is never used to train or improve their models. The one provider retention we cannot switch off is OpenAI's, which holds API requests for 30 days for abuse monitoring and then deletes them; OpenAI does not use API data to train its models.
Everything we do store — your account, session metadata, and the optional AI Summary transcripts described below — rests encrypted in our database hosted in the European Union (Frankfurt, Germany).
AI Summary (optional)
If — and only if — an operator uses the AI Summary feature, that session’s transcript is sent to our backend and stored so you can generate and re-download the summary from your dashboard — and from the room link too, if you choose to share one with the event's organiser. The narrower moderation link gives no access to the transcript. The transcript is processed by OpenAI to produce the summary, is kept for at most 30 days, and is then automatically deleted from our servers along with any generated summaries. The feature is off unless you choose it, and the app tells you before the transcript leaves the machine. If you never use AI Summary, no transcript is ever stored. While stored, the transcript rests in the EU (Frankfurt, Germany); the summary itself is generated by OpenAI under a Data Processing Agreement with OpenAI Ireland Ltd incorporating the EU Standard Contractual Clauses.
If you are in the audience, not the customer
Anyone can follow an event on their own phone by scanning the room's QR code — no app, no account, no sign-in. We do not know who you are and we do not track you: choosing a language registers the language on the event, not you, and no analytics or session-replay script ever loads on that page. If the event has audience questions enabled: giving a name is optional and the name is never stored; every question passes through an automatic content filter (OpenAI moderation) before a moderator sees it; and only if a moderator puts your question on the venue screen is its text kept as part of that event's record, for at most 30 days, after which it is deleted automatically. The same 30-day clock applies to the results of any live poll. Anyone holding the room code can read along — the code is an access convenience, not a confidentiality control.
Product telemetry & diagnostics
We record a small number of facts about how SCAPTION itself is used — an account was refused a live session and which plan limit refused it, a checkout was started, a signup attempt failed and for which reason — plus diagnostic reports when something breaks (what failed, where, how often, on which app version). This is our own server-side measurement: no third-party analytics product is involved, nothing is loaded into your browser or the app for it, and none of it leaves our infrastructure. The legal basis is our legitimate interest (art. 6.1.f) in understanding where our own product fails people and in fixing it.
What these records may contain is fixed in code and enforced automatically: counts, timestamps, an account reference, and short pre-defined values such as a plan name or a failure reason. They can carry no event content of any kind — no audio, no caption, no transcript, no attendee question, no speaker name — and no free-text field exists for one to end up in. Signup failures record only the reason, never the email address or IP that tried. Product telemetry is kept for 12 months and then deleted automatically by a daily job; you may object to it at any time under "Your rights" below.
If you arrive from one of our campaigns and then create an account, we record where the link said you came from — the campaign parameters carried in the link itself, the referring website's domain (never the full address, which can contain a search you typed), and which page you landed on. It is stored once, with the account, and is never updated afterwards. Nothing is stored on your device for this: the information travels in the link you clicked, so if you leave and come back later there is nothing to remember you by, and the signup is simply recorded as direct.
How long we keep things
- Live audio and captions — never stored. They exist only while they are in flight.
- Account and session metadata (who you are, when a session ran, for how long, in which languages) — kept while your account exists, and deleted when you close it or ask us to. You can close it yourself at any time, without contacting us, from Account in your dashboard; doing so deletes every login on the account, its name, any transcript stored by AI Summary and any room code you had reserved, and cancels any subscription. Invoices and accounting records are kept for as long as tax law requires, which we cannot shorten on request — that is the exception the GDPR itself makes to the right to erasure (art. 17.3.b) — and once the account is closed they are no longer linked to any login.
- AI Summary transcripts and the summaries generated from them — at most 30 days, deleted automatically by a daily job.
- Launched audience questions and poll results — at most 30 days, same automatic deletion.
- Questions and votes you prepare in advance for a room — kept with that room, and deleted when the room ends: you release its code, its reservation runs out, or you close the account. This is your own material, written by you or by whoever you gave the moderator link to; nothing an attendee types is ever stored here.
- Product telemetry and diagnostic reports — 12 months, deleted automatically by the same daily job. Counts and short pre-defined values only; never event content.
- Marketing consent records — the date, and the exact wording you were shown. Kept while the consent stands and afterwards as evidence that it was freely given, because the law requires us to be able to prove it.
Where your data goes
Everything we store rests in the European Union (Frankfurt). Some of the processors on our subprocessors page are based outside the EEA — transfers to them are covered by a data processing agreement incorporating the EU Standard Contractual Clauses, or by an adequacy decision. If an operator turns on the optional Zoom captions integration, finished caption lines are additionally sent to Zoom at the customer's own instruction, under the customer's own agreement with Zoom.
Your rights
You may ask us for access to your data, and for its rectification, erasure, restriction or portability; you may object to processing based on legitimate interest; and you may withdraw consent at any time, without that affecting what was lawful before you withdrew it. Two of these you can exercise yourself, immediately, from Account in your dashboard: withdrawing marketing consent, and erasure by closing the account. For anything else, write to [email protected] and we will answer within one month. If you are an event attendee rather than a customer, ask the organiser of that event first — the event content is theirs, and we act on their instructions — but you may write to us and we will route it. You can also lodge a complaint with a supervisory authority: in Spain, the Agencia Española de Protección de Datos.
Analytics & cookies
On our public marketing pages we use Google Analytics and Microsoft Clarity to understand how visitors use the site, gated behind the cookie-consent banner — neither loads until you accept. They never load on a page carrying a credential in the URL or an event's content: not on the live attendee page, the Live Q&A link, the sign-in flow, or your dashboard. See our subprocessors page for what each one does with your data.
Marketing emails (optional)
If you tick the marketing checkbox at signup, we use your email address to send you SCAPTION news and offers. The legal basis is your consent (GDPR art. 6.1.a) — the box is optional, unticked by default, and signup works the same without it. We keep a record of when you consented and the exact text you were shown, as the law requires us to be able to prove it. These emails are sent through MailerLite, which processes your email address solely on our behalf and only for this purpose. Your address is stored in the European Union; our contract is with MailerLite, Inc. (United States) and incorporates the EU Standard Contractual Clauses. MailerLite is listed on our subprocessors page. You can withdraw consent at any time — from Account in your dashboard, from the unsubscribe link in every marketing email, or by writing to [email protected] — and withdrawing never affects your account or service. The dashboard setting is yours personally rather than the account's: if several people share an account, each manages their own. Transactional emails about your account (receipts, trial notices, payment issues) are separate and don’t depend on this consent.
For events with strict confidentiality requirements, simply don’t enable AI Summary — the live captioning path stores no transcript at all.