What information StenoDesk collects, how we use and share it, and the choices you have.
StenoDesk LLC ("StenoDesk," "we," "us," or "our") operates the StenoDesk platform at stenodesk.com and related subdomains (the "Service"). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have.
StenoDesk is a business-management platform for court reporters, scopists, stenographers, and legal-support professionals. By using the Service you agree to this Privacy Policy and our Terms of Service ("Terms").
The Service is for business use by professionals and is not directed to children under 18.
a. Account & profile information. Name, email address, phone number, business name, professional certification/license number (e.g., CSR/CCR/RPR), state, role, avatar, and authentication credentials (managed by our auth provider).
b. Client, contact & case information you enter or upload. Client and law-firm records (names, emails, phone numbers, addresses, EIN/tax IDs), contacts, case captions and numbers, witnesses/deponents, cast-of-characters/appearance details, exhibits, job and scheduling details, notes, rate sheets and other personal information you may upload to the Service.
c. Transcript and case-file content. Documents and recordings you upload to a job, including legal transcripts (ASCII/PDF), notices, exhibits, correspondence, and audio or video recordings of proceedings. These may contain sensitive personal information about third parties. We process this content to provide features you request (e.g., document generation, exhibit indexing, AI-assisted proofing and extraction, and, if you enable it, transcription of a recording so you can search it and line it up with the transcript).
d. Photos you capture with your device camera (optional). Where your device supports it, you may take or upload a photo instead of a file, for example to capture a business card, a receipt, a shipping label, or a case exhibit. We do not record video or audio, capture images in the background or access your camera at any time other than when you are taking a photo. Your browser or device will ask your permission before the camera is used, and you can decline or revoke it at any time in your browser or device settings; declining only disables photo capture, and you can still upload images from your device. Photos you capture are then stored and processed in the same way as any other file you upload, including the AI-assisted extraction described in Section 5.
e. Financial and billing information. Invoices, amounts, payment status, and subscription details. Payment card data is handled by our payment processor (Stripe); we do not store full card numbers.
f. Email and calendar data (only if you connect an account). If you connect a Google (Gmail) or Microsoft (Outlook) mailbox/calendar through our integration provider (Nylas), we access messages and calendar events to provide the email and calendar features inside StenoDesk and to extract job details when you ask us to. This access is optional, requires your explicit OAuth consent, and can be revoked at any time. Nylas processes your connected-account data in accordance with its own privacy policy. See §4 for Google-specific terms.
f-2. Cloud backup connections (only if you connect an account). If you connect a Dropbox or Google Drive account, StenoDesk stores the authorization tokens needed to copy your StenoDesk job files into that account. Backups flow one way, from StenoDesk into a folder in your cloud account; StenoDesk never treats your cloud account as a source and never deletes files from it. For Google Drive we request only the drive.file scope, which limits our access to files and folders StenoDesk itself creates. For Dropbox we use app-folder access, limited to the Apps/StenoDesk folder. We do not read, list, modify, or delete your other cloud files. The tokens are stored server-side and are not readable by the application running in your browser. Connecting is optional, requires your explicit OAuth consent, and can be disconnected at any time in Settings, which revokes our access with the provider and deletes the tokens we held. If your account is deleted, we revoke that access as part of the deletion. Files already copied to your cloud account remain there under your control and your provider's terms.
g. Usage and device information. Product-analytics events (pages/features used), error/diagnostic data, and limited technical information (browser, approximate region). We use privacy-preserving settings: error monitoring with IP storage disabled and analytics without session replay.
h. Support communications. Information you provide when you contact us.
i. Operational usage metering. We record operational usage metrics — for example, the number of AI processing tokens consumed, the volume of storage used, and how often features are invoked — to monitor performance, manage capacity and cost, bill usage-based features (such as per-page proofing overage), and detect abuse. These metrics measure the volume of your activity, not the content of your documents, transcripts, communications, or connected-mailbox data, which we do not read or retain for this metering purpose.
We do not intentionally collect special-category data about you as an account holder; however, case materials you upload may contain sensitive third-party data, which you are responsible for handling lawfully (see §9 and the Terms).
We use information to:
We do not sell your personal information or use it for advertising. We do not use the contents of your connected email, calendar, or uploaded case files to train generalized AI/ML models. For CCPA/CPRA-specific disclosures, see §8.
If you connect a Google account, StenoDesk requests access to Google user data solely to provide user-facing features within StenoDesk: (i) through our integration provider Nylas, Gmail messages and Google Calendar events, to provide the email and calendar features (reading and sending email you initiate, displaying your calendar, and extracting job details you ask us to capture); and (ii) directly, Google Drive access limited to files and folders StenoDesk creates (the drive.file scope), to copy your StenoDesk job files into your own Google Drive when you enable cloud backup. We never request access to the rest of your Drive.
StenoDesk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:
You can disconnect a Google account at any time in Settings, which revokes our access going forward; for Google Drive this also deletes the stored authorization tokens. Revocation can also be managed at myaccount.google.com/permissions. The same principles apply to Microsoft/Outlook data.
Certain features (e.g., proofing of transcripts, extraction of case details from documents or email, glossary generation, and transcription of audio or video recordings you choose to index) send the relevant content to a service provider to process your request and return a result. Our current providers are Anthropic (Claude API) for text processing and AssemblyAI for speech-to-text. We send only the content needed for the task you initiate.
We share information with service providers ("subprocessors") that help us run the Service, under contractual confidentiality and security obligations. We share only what is necessary. The following list of subprocessors is provided as an example of the types of the data shared and such subprocessors may change as the Service evolves.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | Account, client/case, transcript files, app data |
| Cloudflare R2 | Media/file object storage | Uploaded media/files |
| Firebase Hosting (Google) | Static web hosting / CDN | App delivery; technical logs |
| Nylas | Email & calendar integration | Connected mailbox/calendar data |
| Google / Microsoft | Email/calendar providers (your connected accounts) | Email and calendar data of the account you connect |
| Stripe and other payment processors at our discretion | Payment processing / subscription billing | Billing details (card data held by payment processor) |
| Anthropic (Claude) | AI processing of content you submit to AI features | Task-specific content |
| AssemblyAI | Speech-to-text processing of recordings you submit to transcription features | The audio/video you submit for the task and the resulting text, deleted after retrieval (see §5) |
| Resend | Transactional email delivery | Recipient email, message content |
| Sentry | Error/crash monitoring | Diagnostic data (IP storage disabled) |
| PostHog | Product analytics | Usage events (no session replay) |
Destinations you choose. Some features send your data to services you connect and control rather than to our subprocessors. Cloud backup copies your job files into your own Dropbox or Google Drive account, and connected email sends messages through your own mailbox provider. Those providers process that data under your agreement with them, not as our subprocessors, and you can stop the flow at any time by disconnecting the account in Settings.
We may also disclose information (a) to comply with law, legal process, or lawful requests; (b) to protect the rights, safety, and security of users, the public, or StenoDesk; (c) in connection with a merger, acquisition, or asset sale (with notice where required); (d) to subsidiaries and affiliates; and (e) with your consent.
Depending on your location, you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Account holders can edit/delete most data directly in the Service.
For data that an account holder uploaded about you (e.g., you are an attorney or witness in a case file), please contact the account holder (the controller); we will assist them as their processor.
When you upload client, contact, case, transcript, or connected-mailbox data, you are the controller of that data and StenoDesk acts as your processor. You are responsible for having a lawful basis to collect and process it (including any sensitive personal information in transcripts) and for honoring the rights of those individuals. We process such data per your instructions and our Terms of Service.
We use cookies/local storage that are strictly necessary to run the Service (e.g., authentication/session) and limited analytics. For full details on the cookies and similar technologies we use, their categories, and how to manage them, and our Do Not Track disclosure, please see our Cookie Policy.
The Service is not intended for, and we do not knowingly collect personal information from, children under 18. If you are under 18, do not use or provide any information on the Service or through any of its features, or provide any information about yourself to us, including any personal information. If you believe we might have any information from or about a child under 18, please contact us immediately at legal@stenodesk.com.
We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, provide at least 30 days' advance notice (e.g., by email or in-app notification). Continued use after changes take effect constitutes acceptance. If you do not agree to the updated Terms, you may close your account before they take effect.
StenoDesk LLC · Email: legal@stenodesk.com