Privacy Policy
Last Updated: February 7, 2026
1. Introduction
SketchScript ("we", "our", or "us") is committed to protecting your privacy and handling your data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller: SketchScript, Vienna, Austria
Contact: support@sketchscript.app
2. What Data We Collect
2.1 User-Provided Data
- Meeting Transcripts: Text content you upload to generate sketchnotes
- Account Information: Email address, name (if you create an account)
- Payment Information: Processed by Stripe (we do not store credit card details)
2.2 Automatically Collected Data
- Usage Analytics: Page views, feature usage (via Piwik PRO, EU-hosted)
- Technical Data: IP address, browser type, device information
- Generated Content: Sketchnote images you create using our service
3. How We Use Your Data
We process your data for the following purposes:
- Service Delivery: To generate sketchnotes from your transcripts
- Account Management: To maintain your account and preferences
- Payment Processing: To handle subscriptions and payments
- Service Improvement: To analyze usage patterns and improve features
- Communication: To send service updates and support responses
Legal Basis: We process your data based on:
- Consent: When you agree to upload transcripts for processing
- Contract: To fulfill our service agreement with you
- Legitimate Interest: To improve our service and prevent abuse
4. Data Processors & Third Parties
Your data is processed by the following third-party services:
| Service | Purpose | Location | Data Transferred |
|---|---|---|---|
| Pickaxe | Chatbot platform & conversation processing | United States | Meeting transcripts, generated sketchnotes |
| Anthropic (Claude API) | AI model for content analysis | United States | Meeting transcript excerpts (via Pickaxe) |
| Stripe | Payment processing | United States / EU | Payment information, email |
| Piwik PRO | Privacy-first analytics | European Union | Usage data, IP address (anonymized) |
Cross-Border Data Transfers: When you upload transcripts, your data is transferred to the United States for processing by Pickaxe and Anthropic. These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.
5. Your Responsibility: Confidential Information
IMPORTANT: SketchScript processes user-provided transcripts. We do not create or verify the content of transcripts.
You are solely responsible for:
- Removing confidential, sensitive, or proprietary information before uploading transcripts
- Ensuring you have the right to share and process the transcript content
- Complying with your organization's data handling policies
- Redacting personal data of third parties (names, email addresses, etc.) if required
We are not liable for:
- Disclosure of confidential information you include in uploaded transcripts
- Privacy violations resulting from your failure to redact sensitive data
- Unauthorized use of proprietary information you choose to process
If your meeting contains confidential business information, trade secrets, personal data of others, or sensitive content, you must sanitize the transcript before uploading it to our service.
6. Data Retention
- Transcripts: Retained for 90 days after upload, then automatically deleted
- Generated Sketchnotes: Retained while you have an active account
- Account Data: Retained until you request account deletion
- Payment Records: Retained for 7 years for legal/tax purposes
- Analytics Data: Anonymized and retained for 2 years
You can request earlier deletion of your data at any time (see Section 8).
7. AI Training & Data Usage
Free Tier: Your transcript data may be used by Pickaxe for AI model training and service improvement.
Pro & Team Tiers: Your data is NOT used for AI training. We have agreements with Pickaxe to opt out of training for paid accounts.
Knowledge Bases: Any documents or templates you upload to customize your sketchnote style are stored separately and never used for AI training (all tiers).
8. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to certain types of processing
- Right to Withdraw Consent: Withdraw consent at any time
To exercise your rights: Email support@sketchscript.app with your request. We will respond within 30 days.
Self-Service Data Management:
- Delete your account: Settings → Account → Delete Account
- Download your sketchnotes: Library → Export All
- Delete individual sessions: Library → [Session] → Delete
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Multi-factor authentication, role-based access
- Monitoring: Automated threat detection and security audits
- Vendor Security: Our processors (Pickaxe, Anthropic) maintain SOC 2 Type II compliance
10. Cookies & Tracking
We use cookies for the following purposes:
Essential Cookies (No Consent Required)
- Session Cookie: Maintains your logged-in state
- Preference Cookie: Remembers your settings
Analytics Cookies (Consent Required)
- Piwik PRO Analytics: Tracks page views and feature usage
- Retention: 13 months
- Opt-Out: You can disable analytics in Settings → Privacy
We do NOT use advertising cookies or third-party tracking.
11. Children's Privacy
SketchScript is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us immediately at support@sketchscript.app.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via:
- Email notification (if you have an account)
- Banner notification on the website
- Updated "Last Updated" date at the top of this page
Continued use of SketchScript after changes constitutes acceptance of the updated policy.
13. International Users
EU Users: We are based in Austria and comply with GDPR. Your data is protected under EU law.
Non-EU Users: Your data may be transferred to and processed in the European Union or United States. By using our service, you consent to such transfers.
14. Data Breach Notification
In the event of a data breach that affects your personal data, we will:
- Notify you within 72 hours of becoming aware of the breach
- Report the breach to relevant data protection authorities (if required)
- Provide details of the breach, affected data, and steps we're taking
15. Contact & Complaints
Privacy Questions: support@sketchscript.app
Data Protection Officer: Jim Christian, support@sketchscript.app
Right to Lodge a Complaint: If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority:
- Austria: Österreichische Datenschutzbehörde (www.dsb.gv.at)
- EU/EEA: Find your local authority at EDPB Members
16. Definitions
- Personal Data: Any information relating to an identified or identifiable person
- Processing: Any operation performed on personal data (collection, storage, use, transmission, deletion)
- Data Controller: The entity that determines purposes and means of processing (SketchScript)
- Data Processor: The entity that processes data on behalf of the controller (Pickaxe, Anthropic)
- Consent: Freely given, specific, informed, and unambiguous indication of agreement