Skip to Content
DocumentationSecurityTrust & Compliance

Privacy & Data Handling

⚡ 4 min read

Transcodes is built with privacy at its core. This page details our data handling practices.


What Data We Collect

Data TypePurposeRetention
Email AddressAccount identificationAccount lifetime
Public KeyAuthentication verificationAccount lifetime
Credential IDPasskey identificationAccount lifetime

Data Minimization: We only collect data essential for authentication. No tracking, no profiling, no data selling.


What We Don’t Collect

  • ❌ Private keys (stored on your device only)
  • ❌ Biometric data (never transmitted)
  • ❌ Passwords (we don’t use them)
  • ❌ Tracking or analytics data

Data Encryption

In Transit

  • TLS 1.3 for all API communications
  • Perfect Forward Secrecy (PFS) enabled
  • HSTS (HTTP Strict Transport Security) enforced

At Rest

  • AES-256 encryption for stored data
  • Encryption keys managed separately from data

On Your Device

  • Private keys stored in browser’s IndexedDB
  • On supported devices, keys protected by Secure Enclave or TPM
  • Biometric data never leaves your device

Your Rights

Under privacy regulations, you have the right to:

  • Access your data
  • Delete your account and all associated data
  • Export your data in a machine-readable format

Data Requests: privacy@transcodes.io

Response Time: Within 30 days


Third-Party Services

We use the following third-party services:

ProviderPurposeLocation
Amazon Web ServicesCloud infrastructureUS, EU
CloudflareCDN, DDoS protectionGlobal

Your Responsibilities

When using Transcodes, you are responsible for:

  1. User Consent: Informing users about authentication data processing
  2. Privacy Policy: Disclosing Transcodes usage in your privacy policy
  3. Security Practices: Following our Implementation Guide
  4. Data Requests: Handling your users’ data rights requests

Contact

For privacy-related inquiries:

Email: privacy@transcodes.io


Last updated on