Legal

Privacy Policy.

What information StenoDesk collects, how we use and share it, and the choices you have.

StenoDesk LLC ("StenoDesk," "we," "us," or "our") operates the StenoDesk platform at stenodesk.com and related subdomains (the "Service"). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have.

StenoDesk is a business-management platform for court reporters, scopists, stenographers, and legal-support professionals. By using the Service you agree to this Privacy Policy and our Terms of Service ("Terms").

1. Who this applies to

The Service is for business use by professionals and is not directed to children under 18.

2. Information we collect

a. Account & profile information. Name, email address, phone number, business name, professional certification/license number (e.g., CSR/CCR/RPR), state, role, avatar, and authentication credentials (managed by our auth provider).

b. Client, contact & case information you enter or upload. Client and law-firm records (names, emails, phone numbers, addresses, EIN/tax IDs), contacts, case captions and numbers, witnesses/deponents, cast-of-characters/appearance details, exhibits, job and scheduling details, notes, rate sheets and other personal information you may upload to the Service.

c. Transcript and case-file content. Documents and recordings you upload to a job, including legal transcripts (ASCII/PDF), notices, exhibits, correspondence, and audio or video recordings of proceedings. These may contain sensitive personal information about third parties. We process this content to provide features you request (e.g., document generation, exhibit indexing, AI-assisted proofing and extraction, and, if you enable it, transcription of a recording so you can search it and line it up with the transcript).

d. Photos you capture with your device camera (optional). Where your device supports it, you may take or upload a photo instead of a file, for example to capture a business card, a receipt, a shipping label, or a case exhibit. We do not record video or audio, capture images in the background or access your camera at any time other than when you are taking a photo. Your browser or device will ask your permission before the camera is used, and you can decline or revoke it at any time in your browser or device settings; declining only disables photo capture, and you can still upload images from your device. Photos you capture are then stored and processed in the same way as any other file you upload, including the AI-assisted extraction described in Section 5.

e. Financial and billing information. Invoices, amounts, payment status, and subscription details. Payment card data is handled by our payment processor (Stripe); we do not store full card numbers.

f. Email and calendar data (only if you connect an account). If you connect a Google (Gmail) or Microsoft (Outlook) mailbox/calendar through our integration provider (Nylas), we access messages and calendar events to provide the email and calendar features inside StenoDesk and to extract job details when you ask us to. This access is optional, requires your explicit OAuth consent, and can be revoked at any time. Nylas processes your connected-account data in accordance with its own privacy policy. See §4 for Google-specific terms.

f-2. Cloud backup connections (only if you connect an account). If you connect a Dropbox or Google Drive account, StenoDesk stores the authorization tokens needed to copy your StenoDesk job files into that account. Backups flow one way, from StenoDesk into a folder in your cloud account; StenoDesk never treats your cloud account as a source and never deletes files from it. For Google Drive we request only the drive.file scope, which limits our access to files and folders StenoDesk itself creates. For Dropbox we use app-folder access, limited to the Apps/StenoDesk folder. We do not read, list, modify, or delete your other cloud files. The tokens are stored server-side and are not readable by the application running in your browser. Connecting is optional, requires your explicit OAuth consent, and can be disconnected at any time in Settings, which revokes our access with the provider and deletes the tokens we held. If your account is deleted, we revoke that access as part of the deletion. Files already copied to your cloud account remain there under your control and your provider's terms.

g. Usage and device information. Product-analytics events (pages/features used), error/diagnostic data, and limited technical information (browser, approximate region). We use privacy-preserving settings: error monitoring with IP storage disabled and analytics without session replay.

h. Support communications. Information you provide when you contact us.

i. Operational usage metering. We record operational usage metrics — for example, the number of AI processing tokens consumed, the volume of storage used, and how often features are invoked — to monitor performance, manage capacity and cost, bill usage-based features (such as per-page proofing overage), and detect abuse. These metrics measure the volume of your activity, not the content of your documents, transcripts, communications, or connected-mailbox data, which we do not read or retain for this metering purpose.

We do not intentionally collect special-category data about you as an account holder; however, case materials you upload may contain sensitive third-party data, which you are responsible for handling lawfully (see §9 and the Terms).

3. How we use information

We use information to:

We do not sell your personal information or use it for advertising. We do not use the contents of your connected email, calendar, or uploaded case files to train generalized AI/ML models. For CCPA/CPRA-specific disclosures, see §8.

4. Google user data — Limited Use disclosure

If you connect a Google account, StenoDesk requests access to Google user data solely to provide user-facing features within StenoDesk: (i) through our integration provider Nylas, Gmail messages and Google Calendar events, to provide the email and calendar features (reading and sending email you initiate, displaying your calendar, and extracting job details you ask us to capture); and (ii) directly, Google Drive access limited to files and folders StenoDesk creates (the drive.file scope), to copy your StenoDesk job files into your own Google Drive when you enable cloud backup. We never request access to the rest of your Drive.

StenoDesk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:

You can disconnect a Google account at any time in Settings, which revokes our access going forward; for Google Drive this also deletes the stored authorization tokens. Revocation can also be managed at myaccount.google.com/permissions. The same principles apply to Microsoft/Outlook data.

5. AI-assisted features

Certain features (e.g., proofing of transcripts, extraction of case details from documents or email, glossary generation, and transcription of audio or video recordings you choose to index) send the relevant content to a service provider to process your request and return a result. Our current providers are Anthropic (Claude API) for text processing and AssemblyAI for speech-to-text. We send only the content needed for the task you initiate.

6. How we share information (subprocessors)

We share information with service providers ("subprocessors") that help us run the Service, under contractual confidentiality and security obligations. We share only what is necessary. The following list of subprocessors is provided as an example of the types of the data shared and such subprocessors may change as the Service evolves.

SubprocessorPurposeData involved
SupabaseDatabase, authentication, file storage, realtimeAccount, client/case, transcript files, app data
Cloudflare R2Media/file object storageUploaded media/files
Firebase Hosting (Google)Static web hosting / CDNApp delivery; technical logs
NylasEmail & calendar integrationConnected mailbox/calendar data
Google / MicrosoftEmail/calendar providers (your connected accounts)Email and calendar data of the account you connect
Stripe and other payment processors at our discretionPayment processing / subscription billingBilling details (card data held by payment processor)
Anthropic (Claude)AI processing of content you submit to AI featuresTask-specific content
AssemblyAISpeech-to-text processing of recordings you submit to transcription featuresThe audio/video you submit for the task and the resulting text, deleted after retrieval (see §5)
ResendTransactional email deliveryRecipient email, message content
SentryError/crash monitoringDiagnostic data (IP storage disabled)
PostHogProduct analyticsUsage events (no session replay)

Destinations you choose. Some features send your data to services you connect and control rather than to our subprocessors. Cloud backup copies your job files into your own Dropbox or Google Drive account, and connected email sends messages through your own mailbox provider. Those providers process that data under your agreement with them, not as our subprocessors, and you can stop the flow at any time by disconnecting the account in Settings.

We may also disclose information (a) to comply with law, legal process, or lawful requests; (b) to protect the rights, safety, and security of users, the public, or StenoDesk; (c) in connection with a merger, acquisition, or asset sale (with notice where required); (d) to subsidiaries and affiliates; and (e) with your consent.

7. Data storage, security & retention

8. Your rights and choices

Depending on your location, you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Account holders can edit/delete most data directly in the Service.

For data that an account holder uploaded about you (e.g., you are an attorney or witness in a case file), please contact the account holder (the controller); we will assist them as their processor.

9. Account holders as controllers; your responsibilities

When you upload client, contact, case, transcript, or connected-mailbox data, you are the controller of that data and StenoDesk acts as your processor. You are responsible for having a lawful basis to collect and process it (including any sensitive personal information in transcripts) and for honoring the rights of those individuals. We process such data per your instructions and our Terms of Service.

10. Cookies and similar technologies

We use cookies/local storage that are strictly necessary to run the Service (e.g., authentication/session) and limited analytics. For full details on the cookies and similar technologies we use, their categories, and how to manage them, and our Do Not Track disclosure, please see our Cookie Policy.

11. Children

The Service is not intended for, and we do not knowingly collect personal information from, children under 18. If you are under 18, do not use or provide any information on the Service or through any of its features, or provide any information about yourself to us, including any personal information. If you believe we might have any information from or about a child under 18, please contact us immediately at legal@stenodesk.com.

12. Changes to this Policy

We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, provide at least 30 days' advance notice (e.g., by email or in-app notification). Continued use after changes take effect constitutes acceptance. If you do not agree to the updated Terms, you may close your account before they take effect.

13. Contact us

StenoDesk LLC · Email: legal@stenodesk.com