Legal & Compliance
Privacy Policy
[COMPANY_NAME], [LEGAL_ADDRESS], and [CONTACT_EMAIL] represent owner identity and entity placeholders that will be finalized prior to public commercial launch.1. Architectural Boundary and Non-Storage of Media
TranscripNusantara does not download, transcode, stream, host, or store raw YouTube video or audio files.
Our systems process only YouTube URLs, official video metadata, and timestamped text transcript segments. All media playback occurs directly through official third-party channels (such as YouTube's official player or website) and never through our infrastructure.
2. Information We Collect
We collect only data necessary to authenticate users, manage credit balances, retrieve transcripts, and maintain platform security:
- Account & Authentication: Your email address, hashed authentication credentials managed via Supabase Auth (we never store plain-text passwords), internal user ID (UUID), and optional display name.
- Submitted YouTube URLs & Metadata: YouTube video IDs, video titles, channel names, and trusted durations retrieved via official Google APIs.
- Transcripts & Timestamped Segments: Extracted transcript text, millisecond offsets, and search vectors. We distinguish between Global Reusable Transcripts (publicly available, cached globally to prevent redundant external API calls) and User-Scoped Transcripts (retrieved via your authorized Google connection, bound exclusively to your account).
- Google OAuth Connection (Optional): If you connect your Google Account, we store encrypted access and refresh tokens to manage captions via
youtube.force-ssl. Tokens are encrypted at rest and never shared with browser code. - Credit & Accounting Ledger: Wallet balances, purchased packs, reservations, and consumption records calculated as
ceil(duration_seconds / 600). - Planned Payment Data (Via Mayar): When commercial payments are enabled, transaction IDs, invoice status, payment amounts in IDR, and mobile numbers for invoice delivery may be processed. We do not process, receive, or store credit card numbers or bank credentials.
- Operational Logs: Sanitized HTTP logs omitting transcript text, authentication headers, API keys, and OAuth secrets.
3. Purpose of Processing
We process your data to:
- Provide timestamped search, transcripts, and contextual research tools;
- Manage credit balances and calculate usage accurately;
- Prevent scraping, brute-force attacks, and abuse;
- Maintain operational uptime and diagnose system errors;
- Maintain financial record integrity, dispute resolution, and applicable accounting or tax obligations.
4. Third-Party Service Providers
| Provider | Purpose | Data Handled |
|---|---|---|
| Supabase | Authentication & PostgreSQL Database | User credentials, encrypted tokens, database records |
| Google LLC | YouTube Data API & Authorized Captions | Video identifiers, authorized user OAuth tokens |
| Scrapingdog | Public YouTube transcript retrieval | Public video identifier and language code only (no user PII) |
| Mayar | Planned payment processing & invoicing | Invoice mobile number, transaction references, amount (IDR) |
5. Data Retention and Deletion
We retain data according to strict lifecycle rules:
- Google OAuth Disconnect: You can disconnect Google at any time from your Account settings. Disconnecting revokes tokens and immediately deletes all user-scoped captions and credentials.
- Library Item Removal: Removing a video revokes your entitlement. If the transcript was user-scoped to you, it is deleted immediately.
- Account Deletion: You may request account deletion from Account settings. Deletion permanently erases your library entitlements, user-scoped captions, OAuth tokens, and anonymizes your profile.
- Accounting Preservation: In accordance with our append-only accounting ledger architecture and for legitimate accounting integrity, dispute resolution, and potential legal obligations, historical credit ledger transactions and purchase records remain archived in an immutable state (specific statutory retention periods remain subject to final owner and legal counsel determination).
6. Contact & Legal Entity
For privacy inquiries, rights requests, or data deletion assistance:
Entity: [COMPANY_NAME]
Address: [LEGAL_ADDRESS]
Support: [CONTACT_EMAIL] (placeholder: support@transcripnusantara.com)
Privacy Officer: [DPO_EMAIL] (placeholder: privacy@transcripnusantara.com)