---
title: "Privacy Policy for Verbafy"
description: "How Funtitled Labs Pte. Ltd. collects, uses, and discloses personal data for Verbafy, and how to contact the Data Protection Officer."
canonical: "https://verbafy.io/privacy"
last-updated: "2026-09-15"
---

# Privacy Policy

This notice explains how Funtitled Labs Pte. Ltd. (UEN 202641216G) ("we", "us") collects, uses, and discloses personal data for Verbafy at [https://verbafy.io](https://verbafy.io).

The Data Protection Officer is reachable at [privacy@verbafy.io](mailto:privacy@verbafy.io). We do not publish a telephone number or a street address.

Singapore's Personal Data Protection Act 2012 ("PDPA") applies. This notice is the usual way we inform you of purposes before or at the time we collect personal data. The [Terms of Service](/terms) are a separate contract.

## Who this notice covers

It covers people who:

- open the public site
- create a Guest session
- register with Clerk
- buy a paid plan
- call the REST API
- use Remote MCP with an API key
- email us

A Guest or a Registered User. Guests use a seven-day session in the `verbafy_guest_session` cookie. Registered Users sign in with Clerk (email and password, or Google).

Signing in can move Guest Transcripts and Chats onto a Registered User. A free Guest subscription is deleted on claim. A paid registered subscription is kept.

## What we collect

We collect only what we need to run Verbafy:

- **Account and profile.** Email address, authentication data, full name, and nickname. Email is read-only. Name and nickname are stored on the registered account. Translation-language preference is application data.
- **Guest session.** A hashed session token and related session state. We do not ask Guests for an email address to start.
- **Service content.** YouTube URLs, public video metadata, and existing captions when we show a caption preview; Spotify episode links, matching public RSS episode records, and episode audio used for transcription and playback; uploaded audio or video files; transcripts, summaries, speaker labels, translations, chat messages, ratings, and export files.
- **Billing.** Plan, usage, subscription status, and billing email. Stripe processes card details. We do not store full card numbers. The Free Plan is a weekly transcribed-minute allotment. It is not a Paid-plan Trial. Monthly Starter and Pro can include a 3-day Paid-plan Trial with a card on file.
- **API access.** Named API keys for registered users. We store only a hash. The secret is shown once at creation.
- **Security and reliability.** Bot-check telemetry from Cloudflare Turnstile when configured, request metadata, and error reports. Sentry session replay, when enabled, masks text and blocks media. Cloudflare Web Analytics records aggregated site use. We do not use advertising cookies.
- **Support.** The contents of messages you send to `privacy@verbafy.io` or `support@verbafy.io`.

We do not collect NRIC numbers, FIN, or passport numbers for signup or use of the product.

Audio and transcripts can identify speakers who are not the person who submitted the media. If you submit media that contains other people's personal data, you must have a lawful basis to do so. See the [Terms of Service](/terms).

## Purposes

We collect, use, and disclose personal data to:

- create and maintain Guest sessions and Registered User accounts
- fetch public YouTube metadata and existing captions, and matching public Spotify RSS records, when you paste a supported link
- transcribe media, label speakers, summarise, translate, and power chat
- store private media, return short-lived object-scoped playback URLs, and let you export files
- bill plans, enforce minute allotments, run Paid-plan Trials, and handle plan changes
- secure the product, prevent abuse, and diagnose faults
- respond to access, correction, withdrawal, deletion, and support requests
- meet legal duties, including tax and accounting records

We do not send marketing email today. Clerk authentication messages and Stripe receipts are transactional. If we later send marketing, we will ask for consent where the PDPA requires it.

We do not require consent, as a condition of using Verbafy, to collection, use, or disclosure beyond what is reasonable to provide the service.

## Cookies and similar technologies

Singapore's PDPA applies to cookies when they collect personal data. We use:

- the Guest session cookie (`verbafy_guest_session`, HttpOnly), to provide the service you request
- Clerk cookies, to authenticate Registered Users
- Turnstile, to reduce automated abuse when it is configured
- Cloudflare Web Analytics, for aggregated site measurement

These support a service you request, authentication, security, or site operation. We do not use cookies to target advertisements. You can block cookies in your browser. Blocking the Guest session cookie or Clerk cookies will stop those parts of the product from working.

## Processors and overseas transfers

We remain responsible under the PDPA for personal data that vendors process for us. Vendors may process or store data outside Singapore. We take steps so they provide a standard of protection comparable to the PDPA, including contracts where required.

Current processors and typical roles:

| Vendor                  | Role                                                             |
| ----------------------- | ---------------------------------------------------------------- |
| Clerk                   | Registered identity, email, Google sign-in                       |
| Stripe                  | Payments, invoices, Customer Portal                              |
| AssemblyAI              | Speech-to-text from a short-lived signed audio URL               |
| Together AI             | Chat, summaries, embeddings, and speaker naming                  |
| Exa                     | People search used to enrich multi-speaker names                 |
| Cloudflare              | Public site, Turnstile, Web Analytics, and private media storage |
| Sentry                  | Error monitoring and masked session replay                       |
| Google YouTube Data API | Public video metadata and caption preview for YouTube URLs       |

Browsers receive short-lived, object-scoped media URLs only. They never receive storage credentials. Media is not made public in order to send it to AssemblyAI.

We do not sell personal data.

## Retention

We cease to retain personal data, or remove the means of associating it with an individual, when the collection purpose is no longer served and retention is no longer necessary for legal or business purposes.

In practice:

- Guest sessions last seven days unless claimed or replaced
- account, library, and preference data last while the account is open
- private uploads and transcripts are removed when the related item is deleted, subject to backup cycles
- billing and tax records may be kept for the period Singapore law requires
- support email is kept as long as needed to handle the request and related records

Public YouTube or Spotify source metadata used to serve other users is not treated as your private library. Deleting your history does not take a public source off the product for everyone else.

## Access, correction, and withdrawal

You may:

- request access to personal data we hold about you, and information about how it has been used or disclosed in the year before the request
- request correction of an error or omission
- withdraw consent for a purpose, on reasonable notice

Send requests in writing to [privacy@verbafy.io](mailto:privacy@verbafy.io). We will tell you the likely consequences of withdrawal. Withdrawal can mean we can no longer provide the service. We will not prohibit withdrawal.

To close an account and ask us to erase library data, email [privacy@verbafy.io](mailto:privacy@verbafy.io). We may keep billing and tax records as required by law.

Registered Users can also edit name and nickname in Settings, change translation language, revoke API keys, and manage billing through the Stripe Customer Portal.

We aim to respond as soon as reasonably possible. If we cannot respond within 30 days, we will say when we will respond.

## Children

Verbafy is for persons 18 years or older. We do not target children. Do not create an account or a Guest session for a person under 18.

## Protection

We use access controls, hashed Guest tokens, hashed API keys, private media storage, and short-lived signed URLs. Private uploads stay in private storage. This is not local, offline, or end-to-end encrypted transcription. No method of transmission or storage is perfectly secure.

## Data breaches

If a data breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission as required, and we will notify affected individuals when the PDPA requires it.

## Changes

We may update this notice. The `updatedAt` date above is the latest revision. Material new purposes will be notified before we use personal data for those purposes.

## Contact

Data Protection Officer: [privacy@verbafy.io](mailto:privacy@verbafy.io)

Product, billing, and API questions: [support@verbafy.io](mailto:support@verbafy.io)

See also [contact](/contact) and the [Terms of Service](/terms).

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://verbafy.io/#organization",
      "name": "Verbafy",
      "url": "https://verbafy.io",
      "inLanguage": "en",
      "knowsAbout": [
        "YouTube transcription",
        "Spotify episode transcription",
        "Meeting recording transcription",
        "Speaker diarization",
        "Transcript export"
      ],
      "hasOfferCatalog": {
        "@id": "https://verbafy.io/pricing#offers"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "support@verbafy.io",
        "url": "https://verbafy.io/contact"
      }
    },
    {
      "@type": "WebPage",
      "@id": "https://verbafy.io/privacy#page",
      "name": "Privacy Policy",
      "description": "How Funtitled Labs Pte. Ltd. collects, uses, and discloses personal data for Verbafy, and how to contact the Data Protection Officer.",
      "url": "https://verbafy.io/privacy",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://verbafy.io/#website"
      },
      "publisher": {
        "@id": "https://verbafy.io/#organization"
      }
    },
    {
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://verbafy.io"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Privacy Policy",
          "item": "https://verbafy.io/privacy"
        }
      ]
    }
  ]
}
```
