Your privacy
Privacy Policy.
Last updated 27 July 2026
The short version
The ScribeLM™ app runs on your computer and your notes stay there. No account, no telemetry, no analytics, in the app or on this website. If you subscribe to Sync, your notes are encrypted on your device before they travel, and we cannot read them. The only things we ever hold about you are what a subscription needs: an email address, a subscription record, and sealed data only you can open.
01Who we are
ScribeLM is made by Arivo Labs Ltd ("we", "us"), a company registered in England and Wales, and we are the data controller for everything this policy covers. You can reach us at hello@scribelm.app.
02The app on your computer
ScribeLM works entirely on your computer. Your notes are ordinary files in folders you choose. The free app has no account, sends us no usage data, no crash reports, and no telemetry of any kind, and it works with the internet switched off. The AI, the search, the voices, and the dictation all run on your device. We cannot see your notes, and nothing you write is used to train any AI.
03Updates and downloads
The app never phones home on its own: it does not check for updates in the background, and installing it triggers no registration. When you choose to download the app from this site, the file comes from our download server, and we keep only anonymous counts: which file, which version, on which day. No address, no identifier, and nothing that says who asked. When you choose to download an AI model or a voice inside the app, your device fetches it from our public repository hosted on Hugging Face, so Hugging Face's servers see the request the way any download host does; we learn nothing about it.
04Your own AI and search keys
If you connect an AI service you already use (such as OpenAI, Anthropic, or Google), the text you are working with is sent directly from your computer to that service, under your own key and their privacy terms. It never passes through us. The same applies if you add a web search key. Both are off until you switch them on, and your keys live in your operating system's secure credential store.
05This website
This site sets no cookies and runs no analytics scripts. With one exception, no page loads anything from anyone else's servers; the exception is the checkout page, which loads Paddle's payment script (see section 06). The site is served by Cloudflare, which processes visitors' network addresses transiently to deliver pages and block attacks, as any host does. When you download the app we count the download itself: which installer, for which system, on which day. Nothing about you is stored with that count.
06When you buy Sync
Checkout runs inside Paddle's payment overlay. To show it, our checkout page loads Paddle's script, and that script may in turn load resources from Paddle's own service providers (its error monitoring and fonts among them) — so on that one page, those providers see your network address, as any page you visit does. None of your notes or account data is involved. Paddle is our merchant of record and an independent controller for the purchase: it collects your name, email, payment details, and billing country, and handles tax and refunds under Paddle's privacy policy. From Paddle we receive your email address, the plan you chose, and the state of the subscription. We never see your card number.
07What a Sync account holds
Everything we hold about a Sync subscriber, and why:
| What | Why | How long |
|---|---|---|
| Email address | To know whose subscription and account it is, and to reach you | While your account exists |
| Password, hashed | To sign you in; we never store the password itself | While your account exists |
| Two-factor secrets and hashed recovery codes | To protect your account | While your account exists |
| Device list (name, last seen) | So you can spot and revoke a lost device | While your account exists |
| Subscription state from Paddle | To know Sync is paid for; we never see card numbers | While your account exists, then tax records as the law requires |
| Sign-in attempt counters, keyed by a one-way hash | To slow down break-in attempts; we never store a readable network address | Cleared automatically shortly after the attempts stop |
| Your encrypted notes | To carry them between your devices; encrypted with your password, unreadable to us | Until you delete them or 90 days after your subscription lapses |
The encrypted notes deserve their own sentence: they are encrypted on your devices with keys derived from a password only you hold, before they reach us. We store sealed data we cannot open. If you forget your password and no signed-in device remains, we cannot recover your notes; a security reset erases our sealed copies and your local notes stay untouched. If you have never subscribed to Sync, we hold nothing about you at all.
08Emails we send
Account confirmation, security alerts, renewal and lapse warnings, and answers when you write to us. No newsletters you did not ask for, and we never share your address for marketing. Receipts come from Paddle.
09Why we may lawfully do this
Under UK and EU data protection law: we process account and subscription data because our contract with you requires it; security logs under our legitimate interest in keeping accounts safe; and tax records because the law demands them. We run no advertising, no profiling, and we never sell data.
10How long we keep things
The table above gives each item's lifetime. Two dates matter most: encrypted data is deleted 90 days after a subscription lapses, with an email warning first, and deleting your account removes your data promptly, with backup copies falling out of rotation within 30 days. Anonymous counts, which identify nobody, are kept as statistics.
11Where your data lives
Sync runs on servers in the European Union, operated for us by Hetzner. This website is delivered from Cloudflare's global network. Paddle and Resend may process data outside the UK and the European Economic Area; where they do, transfers are covered by recognised safeguards such as standard contractual clauses.
12Who works for us
Four companies process data on our behalf or alongside us, and no others:
Cloudflare
Serves this website and the app downloads from its network
Hetzner
Runs our sync servers, in the European Union
Paddle
Merchant of record: takes payment, handles tax, invoices, and refunds
Resend
Delivers our transactional email, such as confirmations and warnings
13Your rights
You can ask us for a copy of what we hold about you, have it corrected, have it deleted, or object to how we handle it, by writing to hello@scribelm.app. Portability is built into the product: your notes are already ordinary files on your own devices. If you are unhappy with our answer, you can complain to the UK Information Commissioner's Office or your local data protection authority.
14Children
The app collects nothing, whoever uses it, and students of any age are welcome to it. A Sync account requires you to be at least 13; we do not knowingly hold account data about anyone younger, and we will delete it if we learn we do.
15Security
Synced notes are end-to-end encrypted with keys only you hold; connections are encrypted in transit; passwords are stored only as hashes; accounts support two-factor sign-in with recovery codes; and you can see and revoke every signed-in device. If a breach ever put your personal data at risk, we would tell you and the regulator as the law requires. The strongest protection remains structural: the content of your notes is something we never possess in readable form.
16Changes and contact
If this policy changes, the date at the top changes with it; material changes will be announced in the app's release notes, and by email if you hold a Sync account, before they take effect. Questions: hello@scribelm.app.