SoriCue Transcribe
SoriCue Transcribe Privacy Policy
- Version
- 2026-08-26.v1
- Effective
- 2026-08-26
- Updated
- 2026-08-26
This operational draft reflects the current code and processor inventory. It is not legal advice or a warranty of compliance. Final legal review and all missing transfer details must be completed before production publication.
1. Controller
The controller is the Korean sole proprietor 엘레노어마튼, represented by 주민재. Business registration number: 568-39-01427. Address: Room 404, 47 Nambusunhwan-ro 210-gil, Gwanak-gu, Seoul, Republic of Korea. Contact: soricue@gmail.com.
The privacy lead is the representative, 주민재, reachable at the same email address.
2. Data, purposes, legal bases, and retention
- Account: Google or legacy GitHub authentication identifier, account email, Supabase user ID, and authentication session — contract performance, account security, and legitimate security interests — account email and account data until account deletion
- Legal-consent ledger: user ID, consent kind, document version/language/SHA-256 hash, grant/decline/withdrawal or existing-marketing-state preservation event, server time, source, and idempotency request ID — proof of consent, version gating, and rights handling — until account deletion
- Optional marketing email: account email plus consent state — with consent, service updates, new features, discounts/events, and newsletters — until withdrawal or account deletion; refusal does not affect service
- Central authorization and operations metadata: access and legacy licence state plus limited security/error events — service delivery, abuse prevention, and reliability — until account deletion or the minimum period defined for the operation
- Recording usage: Supabase user ID, usage date in Korea time, recording start/completion counts, seconds from recording start to stop, and an idempotency operation ID — service delivery, usage monitoring, customer support, abuse prevention, and operational reliability — until account deletion
- Administrator access: 1/7/30/90-day views combining account name, email, sign-up date, latest sign-in, and the recording usage above — usage monitoring and operational support — available only to administrators whose immutable user ID is listed in SORICUE_ADMIN_USER_IDS, within the source retention period and without a separate copy
- Dictionary: administrator default terms in a separate global snapshot and no more than 200 insertion-ordered personal terms, revision, schema version, and update time per authenticated user — supplying unfamiliar spellings to STT and synchronizing another computer signed into the same account — the personal snapshot remains in Supabase for the account lifetime and only the same account's last validated bundle is cached in device IndexedDB. Individual deletion and device-cache deletion are available. Local export requests the current authenticated account snapshot and falls back only to that account's validated cache, exporting the personal snapshot but never administrator terms or the compiled prompt. Account deletion explicitly removes the personal row and Auth cascade applies again; another user's deletion does not remove the administrator global snapshot. Terms and compiled prompts are not stored in logs, diagnostics, analytics, extension protocols, or schedule payloads
- Product UX path analytics: a pseudonymous user value derived with a dedicated server-only HMAC salt, a random session ID and sequence per journey, screen route, strict-allowlist action ID and outcome, duration capped at 24 hours, online/offline/file mode, mobile/tablet/desktop bucket, and UTC calendar date — aggregate transcription start/completion funnels, transcript use, Google Sheets connection-to-export, next action/drop-off, and median duration for product-flow improvement — retained in Supabase for no more than 90 UTC calendar dates including today, with authenticated daily Cron and request-time expiry pruning, and exposed to administrators only as aggregates. It excludes transcript, hash, prompt, AI response, member/schedule/file name, exact time, email, token, API key, audio, DOM text, and session replay. Ingestion is blocked when account deletion starts and data is purged again after Auth deletion; a calendar-date-only HMAC tombstone blocks residual access tokens and is removed after no more than 31 UTC calendar dates
- Central manual schedule series: authenticated SoriCue user-scoped opaque series ID, title, date, start/end, colour, recurrence rule, online/offline mode, autoRecord, revision, and update time — creating and managing fixed or recurring schedules in daily, weekly, and monthly views without Biz PT or the extension — no more than 100 series or 128 KiB in one RLS-protected Supabase snapshot and no more than 60 occurrences in one UI projection. Exact SoriCue-origin localStorage and, after extension connection, the current user/device extension-private state hold execution/recovery copies; deletion updates the central source and copies, and account deletion removes the source by Auth cascade
- Central Biz PT schedule snapshot: for each authenticated SoriCue user, no more than 500 actual/projected occurrences or 512 KiB plus repeat configuration for no more than 32 weeks or 16 KiB — restoring Biz PT schedules, edits, and the member-admin deep link on another computer signed into the same account — stores occurrence key/revision; current and original title, which may be a member or student name; source ID, logical identity, optional 1–20-digit numeric member ID (`member.uid`), week/template identity and projection flag; current/original start/end, timezone, online/offline mode, enabled, offsets, explicit times and hidden state; base settings and title/time/mode/enabled/offset/hidden override flags. Repeat data contains enabled, template week, imported weeks and update time. The account-owned Supabase snapshot remains until you overwrite/clear it or delete the account, is removed by Auth cascade, and is subject to backup cycling. It excludes the Biz PT password, cookie/session, original HTML, phone number, and email; description and location; SoriCue device ID/binding, alarms, runs/status/failures and actual-run times; audio, transcript, prompt, AI response, provider key and local MP3 path
- Extension-local scheduled state: SoriCue user/device binding; up to 100 manual series with title/date/start/end/colour/recurrence/online-offline mode/autoRecord/revision; materialized manual or Biz PT occurrence key/title/date/start/end/enabled/revision/device binding and optional 1–20-digit numeric Biz PT `member.uid`; and operation ID/status/redacted failure/planned and actual times/transcript, MP3, and prompt-stage outcomes — scheduled execution, failure display, and preserving the member-admin deep link after same-account restoration on another computer — the current device builds its execution cache from the central manual and Biz PT account sources, and the execution snapshot is limited to 500 occurrences regenerated over a 31-day-past/90-day-future window. The ordinary content-free run ledger is limited to 100 entries/30 days, and a separate terminal-tombstone ledger that blocks replay of an irreversible terminal for the exact same occurrence revision is also limited to 100 entries/30 days in this browser extension. Neither ledger contains the Biz PT password, cookie/session, original HTML, phone number, email, audio, transcript, prompt, AI response, schedule title, or local file path; neither is sent to the central Biz PT source or a separate execution database, and device disconnect, account switch/deletion, or extension removal purges both
- Biz PT import receipt: receipt/device identifiers, week range, snapshot revision, imported/removed/preserved-preference counts, unchanged flag, and capture/create/expiry timestamps — import-result confirmation — no more than 16 content-free receipts for 24 hours in this browser extension. They contain no schedule title, description, attendee/participant data, transcript, prompt, AI response, provider key, or local path and are not sent to another app runtime, account, session, or database
- Biz PT import recovery status: current device/week, reading/completed/login_required/failed state, redacted failure code, and update/expiry timestamps — restoring login-required and failed screens after refresh — only one content-free status, with reading retained for no more than 10 minutes and terminal states for no more than 24 hours. It contains no schedule row/title, participant data, transcript, prompt, AI response, provider key, local path, raw error, Biz PT cookie, or source session
- Biz PT schedule-reduction confirmation marker: SoriCue user/device, week, snapshot revision, SHA-256 of the normalized candidate, and expiry time — requiring confirmation before removing a cancelled/deleted actual occurrence or user-edited projection after a single potentially incomplete read — one content-free marker for no more than two minutes in this browser extension. Deletion occurs only after a second fresh read returns the same candidate; the marker contains no title, schedule row, raw lesson time, transcript, prompt, AI response, provider key, local path, Biz PT cookie, or source session
- Default content-free operational diagnostics: authenticated SoriCue user ID; UUID event ID; system-event occurredAt and server receivedAt; allowlisted eventName/result/failureCode; SHA-256 session/tab/operation/trace values; incident UUID; required allowlisted source, moduleId and codePathId; actionId; from/to state and web/extension-parity stateAction/stateReason; expected next event and deadline; producer plus separately named ingest release ID/git commit; extension version; bounded duration, attempt, queue depth, HTTP status and terminal reason/actor; and, only for errors, bounded class/digest/message SHA-256 and project frames. Schedule localStorage is capped at 400 rows/14 days. Web IndexedDB has a delivery outbox capped at 256 rows/14 days and a separate local journal capped at 20,000 rows and 6 MiB/14 days. Each extension account-hash partition has a delivery queue capped at 800 rows and 512 KiB/30 days and a separate local journal capped at 20,000 rows and 6 MiB/30 days, with at most 4 KiB per event and eight recent partitions. Every TTL, row cap, and byte cap is absolute, including for pending, terminal, and critical rows, so no absolute no-loss guarantee is made under capacity, expiry, or quota pressure. An event is journaled locally before asynchronous delivery. A durable web ACK deletes the web delivery row and sets the matching web-journal row's `replicaState` to `acknowledged` until its 14-day TTL or an earlier user/site-data purge. A durable extension ACK deletes only the extension delivery row and retains the raw content-free journal event unchanged, with no acknowledged field, until its 30-day TTL or an earlier user/extension purge. A random per-tab nonce stays only in sessionStorage; events receive only its SHA-256 tabHash, it survives same-tab reload, and it rotates or is deleted on account change, logout, device-data purge, or account purge/deletion. A well-formed stale/invalid build proof downgrades only that event to unknown-producer and never trusts claimed release/commit; malformed, extra, or event-map-mismatched proof input is 400. Keepalive fetch dynamically keeps the final serialized body including proofs at or below 56 KiB, with 20–50 events in every non-final chunk and only a smaller final remainder; sendBeacon is not used. The same-origin API matches expected subject to the authenticated session, accepts no more than 8 KiB per event and 50 events per batch, and retains RLS-protected Supabase Postgres events/incidents for 30 days by default. Central Supabase remains the unchanged asynchronous replica, and no Supabase Storage object log is used. Chat, prompt, AI response, transcript, summary, audio, name, email, schedule title, memo, input/keystrokes/clipboard, screen/DOM/session replay, URL query, body/raw header/error, cookie/JWT/Authorization/session/password/key, raw nonce, local path, IP and location are rejected
- Operational-diagnostic Postgres storage boundary: a strict wire event is stored only in individually constrained typed columns, never as an arbitrary event payload or broad JSON object. Only the at-most-eight project-frame array uses exact-schema, enum-validated JSON; incidents use typed evidence UUID arrays, missing-event enums, and last-normal-state columns. A new event and its scope-generation advance commit together through the service-only typed persist RPC, and an idempotent duplicate does not advance generation. The service role has no direct event INSERT or UPDATE privilege; the atomic reconcile RPC is the only incident write/resolution path and direct incident writes are denied
- Operational-diagnostic incident reconciliation generation state: Supabase user ID, an opaque 64-hex correlation-scope hash, two monotonic counters, and database-managed updated/expiry times only — retained without diagnostic payload for no more than 30 days after the last state activity and deleted sooner by the auth.users cascade. The target generation is reserved before fresh typed context is read; lifecycle reconciliation also reserves an opaque lineage-guard generation, and the atomic reconcile RPC requires target-plus-lineage dual-generation CAS before an incident may be written or resolved. A stale writer cannot reopen a resolved incident. A separate permanent payload-free singleton round-robin scheduler retains only a last-user pointer and update time; account deletion sets a matching pointer to null
- Operational-diagnostic deadline claim/evaluation metadata: only a UUID claim token, database claim and lease-expiry times, claimed generation, evaluation time, and completed/context_overflow result are kept inside a retained event row, excluded from client input, the authenticated user's diagnostic response, and the private operator export. The service-only claim RPC uses the database clock, FOR UPDATE SKIP LOCKED, and the singleton cursor for user/scope fairness and reserves generation before fresh context is read. Null, expired, superseded, or token/generation-mismatched claims fail closed and cannot write an incident; lease expiry permits crash recovery. More than 1,000 fresh typed context rows is durably marked context_overflow without truncation, incident creation, or resolution. The metadata expires with its source event within 30 days and is deleted sooner by account cascade
- User-unlinked Next.js service errors: when instrumentation onRequestError or the proxy request-error boundary may not have a trustworthy authenticated subject, a separate RLS-protected Postgres table retains only UUID v1–v8, occurred/received time, next_server, release/commit, allowlisted route group and HTTP method, one of two exact code paths, an allowlisted error class, an optional SHA-256 error digest, a SHA-256 message fingerprint, and up to eight enum-allowlisted project frames for no more than 30 days. It rejects user ID, payload, URL/query, body/header, cookie/token/session, IP/location, content, local path, raw error, and source map. onRequestError awaits durable persist-RPC acknowledgement or an actual 1.8-second abort/rejection; the proxy schedules the same bounded fail-open sink with waitUntil and immediately rethrows the original error. The row remains outside per-user account/portability export but is included in the approved Mac's `events/YYYY/MM/DD/service-errors.ndjson` and daily report. Account deletion cannot select it; bounded expiry cleanup removes the database row
- Personal-account Full Diagnostic: default-off and available only while the server feature flag and exact Auth-UUID allowlist both permit the account and you enable Shadow Mode in that browser. A separate IndexedDB retains incidents and original provider results for no more than seven days; anomalous audio is a separate default-off choice for no more than 24 hours, 20 clips, and 50 MiB. Its server path receives only a strict content-free stage/aggregate/hash/safe-error subset. Audio bytes, original provider results, prompts, and API keys remain local-only and are not mixed into default operational Postgres or the Mac archive. Diagnostic failure or capacity loss never blocks transcription
- Operator Mac diagnostic archive: a dedicated server-only bearer retrieves content-free events/incidents and strict user-unlinked service errors from the no-store private operator cursor export and stores `events/.../events.ndjson`, `events/.../service-errors.ndjson`, incident JSON, and daily reports under `~/Library/Application Support/SoriCue/Diagnostics` on an approved Mac with 0700/0600 permissions for 365 days by default. Installation passes the token through controlled stdin to interactive `/usr/bin/security -i`, verifies Keychain readback, and never puts it in argv, a URL, source, log, or plist; every managed symlink chain fails closed. Rights deletion of an exported copy is not automatic. The operator obtains the exact lowercase 64-hex userHash from the server-side rights/export workflow and runs delete-user with that value, never an email, name, or Supabase user UUID. It removes only matching event/incident/pending rows, rebuilds affected reports, and preserves other users, global service errors, and legacy records
- Local-device data: transcripts, settings, the same account's last validated dictionary bundle, unified ChatGPT/Gemini/Claude external-summary v5 consent, user/device/day scheduled-capture v1 consent, a Google-permission-ID-specific Sheets file/tab mapping, user-scoped schedule execution caches and a content-free Biz PT cloud-sync marker, the extension-local execution snapshot, bounded runs/attempts, and your STT API keys — requested schedule automation, transcription, preferences, and export — until the applicable consent withdrawal, TTL, active binding, or your deletion. Google access tokens remain only in page memory; there is no server backup except for the central dictionary, manual-schedule, and Biz PT schedule sources
- Optional MP3: audio inside the recording interval and a filename based on the safely sanitized schedule title — written only when enabled to the local folder you select — until you delete it from the file system; no SoriCue server upload
- Audio, prompts, and transcript payload: performing the selected STT/AI request — contract performance and your instruction — SoriCue uses request memory only and does not retain them; the selected provider's retention applies
3. Local storage, cookies, and tracking
Supabase authentication session cookies use SameSite=Lax and Secure in production. They are not HttpOnly because the browser authentication runtime needs to read them. Pre-OAuth consent intent and account-deletion reauthentication proofs use separate signed, short-lived HttpOnly, Secure, SameSite cookies.
The browser may use localStorage, IndexedDB, or extension storage for transcripts, settings, API keys, schedule execution snapshots, daily scheduled-capture consent, and account-specific Google Sheets file/tab mappings. A Google Sheets access token is never written to localStorage or IndexedDB and remains only in current-page memory. Manual schedule series and device-free Biz PT schedules/edit settings are stored in user-scoped Supabase snapshots; SoriCue-origin localStorage and, after extension connection, the current user/device extension-private state receive execution/recovery copies. Editable local values and user metadata are not trusted as the legal-consent ledger or for server authorization.
SoriCue-origin localStorage may hold no more than 400 content-free schedule diagnostics per user. Web IndexedDB has a delivery outbox capped at 256 rows/14 days and a separate local journal capped at 20,000 rows and 6 MiB/14 days. Each extension-private account-hash partition has a delivery queue capped at 800 rows and 512 KiB/30 days and a separate local journal capped at 20,000 rows and 6 MiB/30 days, with at most eight recent partitions. All expiries and row/byte caps apply absolutely to pending, terminal, and critical rows. A web server ACK deletes the web delivery row and sets the matching web-journal row's `replicaState` to `acknowledged` until its 14-day TTL. An extension server ACK deletes only the extension delivery row and retains the raw content-free journal event unchanged, with no acknowledged field, until its 30-day TTL. Expired rows are removed on the next SoriCue access or queue maintenance, and clearing site data or an applicable user/extension purge removes them sooner. This design does not promise absolute no-loss. Logout, account switch, device-data deletion, and account deletion remove the target user's diagnostic rows and leave a global purge generation, UUID, and timestamp containing no user or event information so tabs opened before deletion cannot recreate them. This content-free marker may remain until replaced by the next purge or cleared with site data; a target-user purge does not delete another user's diagnostic rows.
Creating a manual schedule, enabling autoRecord, importing Biz PT, or connecting a SoriCue device is not recording consent. Wall-clock start/stop becomes active only after you review the scheduled-capture disclosure and affirmatively run `Prepare today's automatic recordings`, bound to your user, device, and date. Prepared microphone/system-audio tracks may remain active for that day and stay visibly indicated by the browser and app. Outside an occurrence gate, audio is not stored, transcribed, written to MP3, or externally transferred, and video frames are never consumed or stored.
Unified ChatGPT/Gemini/Claude external-summary v5 consent lasts until withdrawal, logout, account switch, device-data deletion, or account deletion, and material notice changes require renewed consent. It separately covers paste and automatic submission versus the two-tab parallel double prompt, and you can disable it independently of scheduled recording.
We do not currently operate advertising cookies, behavioural advertising, or third-party analytics cookies. We will update this policy and obtain any required consent before introducing them.
4. Processors, third-party services, and international transfers
- Supabase: SoriCue Auth, central authorization, legal-consent ledger, licence state, a per-user manual-schedule source of no more than 100 series or 128 KiB, no more than 500 Biz PT occurrences or 512 KiB plus repeat configuration for no more than 32 weeks or 16 KiB, minimum recording-usage aggregation, content-free operational diagnostic events/incidents, and pseudonymous Product UX path events. Account email/user ID/session, consent events, authorization/licence state, manual schedule fields, Biz PT current/original title (which may be a member or student name), source ID/logical identity, optional 1–20-digit numeric `member.uid`, current/original times, mode/enabled/offset/hidden/base/override/repeat-week settings, and daily start/completion counts and recording seconds may be processed. Diagnostics retain user ID plus strictly allowlisted lifecycle/state/hash/code-path/release/error fingerprints for 30 days by default. Product UX events retain only a dedicated server-HMAC pseudonym, random journey session/sequence, allowlisted route/action/outcome, bounded duration/mode/viewport, and UTC calendar date for no more than 90 calendar dates including today. Both table families force RLS, revoke direct anon/authenticated privileges, and are accessed only by authenticated same-origin Route Handlers' service-role admin clients. The `member.uid` preserves the member-admin deep link after same-account restoration on another computer. The Biz PT schedule source does not transfer the Biz PT password, cookie/session, original HTML, phone number, or email; description/location, device binding/alarms/runs/status/failures/actual-run times, audio, transcripts, prompts, AI responses, provider keys, and local MP3 paths are also excluded. Diagnostics and Product UX analytics also exclude transcript/audio/prompt/AI response, schedule title, exact personal time, and secrets. Retention follows the periods above, account lifetime, and applicable backup cycling. Supabase processing location and region: ap-southeast-2 (Oceania, Sydney, Australia)
- Supabase dictionary: the administrator global snapshot is separated from each user's snapshot of no more than 200 personal terms; revision, schema version, and update time support account synchronization. RLS is forced, direct anon/authenticated DML is revoked, and only the authenticated same-origin server boundary uses the service role. A personal snapshot remains for the account lifetime and is deleted by the account-deletion privacy plane and Auth cascade, while the administrator global snapshot remains. Supabase backup cycling applies.
- Supabase's service-only incident reconciliation state retains only the user ID, an opaque 64-hex correlation-scope hash, two monotonic counters, and database-managed updated/expiry times for no more than 30 days after the last state activity. It contains no diagnostic payload and is deleted sooner by auth.users cascade. The target generation is reserved before fresh context; lifecycle reconciliation also reserves an opaque lineage-guard generation, and only the atomic reconcile RPC may write or resolve incidents after target-plus-lineage CAS. Direct incident writes are denied and stale writers cannot reopen resolved incidents. A separate payload-free singleton scheduler stores only a round-robin last-user pointer and update time; account deletion sets a matching pointer to null.
- Service-only deadline metadata on an operational event retains only a UUID claim token, database claim/lease times, claimed generation, evaluation time, and completed/context_overflow enum, with no product payload or arbitrary JSON. It is excluded from client input, authenticated-user responses, and operator export. The service-only claim RPC uses the database clock, FOR UPDATE SKIP LOCKED, and singleton cursor fairness and reserves generation before fresh context. Null, expired, superseded, or mismatched claims fail closed and cannot write incidents; lease expiry provides crash recovery. More than 1,000 fresh typed context rows is durably marked context_overflow without truncation, incident creation, or resolution. The metadata follows the source event's 30-day expiry and account-deletion cascade.
- A separate user-unlinked Next.js service-error table in Supabase processes only the bounded service-error fields above for no more than 30 days and forces RLS. The service role has direct table select only; writes use the dedicated atomic persist RPC and deletion uses the bounded cleanup RPC. The RPC deduplicates only when UTC minute, release, route, method, code path, error class, optional digest, and message fingerprint all match; separate one-minute global, release/route, and fingerprint buckets retain accepted and saturating dropped counts only. It stores no user ID or user payload and remains outside per-user account/portability export and account-deletion selection, but the private operator export includes it in the approved Mac archive. Database rows are removed by expiry cleanup; Mac copies follow configured local-retention and rights-request deletion.
- Google OAuth: account authentication. Google identifier and email may be processed through Google's global infrastructure and the configured Supabase project under Google's policy.
- Google Sheets API: only after you separately approve drive.file access and click export, the current filter's record ID, member, activity type, full title, timestamps, status, mode, transcript, and summary go directly from your browser to your Google Drive/Sheets. They do not pass through the SoriCue server, and the access token stays only in page memory. Disconnecting or deleting SoriCue device data does not delete your spreadsheet; you must delete it separately in Google Drive.
- GitHub OAuth: for a legacy GitHub-account sign-in, the GitHub identifier and email may be processed through GitHub's global infrastructure and the configured Supabase project under GitHub's policy.
- Groq/OpenAI API: when you choose a provider and start transcription, an audio window, model/language/prompt, and your API key go directly from your browser to that provider without passing through the SoriCue server. Groq states that retained customer data may be processed in U.S. GCP buckets; OpenAI processing locations and policies depend on the API account and endpoint you use.
- The dictionary prompt is a `Preferred spellings:` hint compiled with administrator terms first and personal terms in insertion order within the 224-token OpenAI Whisper multilingual-tokenizer budget. It is frozen when the operation starts and included only for models that support it; a request is retried once without the prompt only when an HTTP 400/422 response identifies the prompt as the cause. SoriCue cannot recall or delete a prompt or copy already transferred to a provider.
- ChatGPT/Gemini/Claude web handoff: after a manual action or unified three-provider v5 automatic-submit consent, a transcript and summary instruction are delivered to the selected account. With separate double-prompt consent, two new conversations receive the transcript with a different prompt and submit in parallel. Provider policy applies to both submitted transcript/prompt copies and generated answers.
- SoriCue Chrome capture extension and operational diagnostic runtime: the minimum schedule read directly from the Biz PT page, SoriCue-origin manual series and their materialized occurrences, manual capture, PTT, external-summary handoff, and explicitly prepared scheduled recording handle audio chunks, target-tab details, schedule snapshots, bounded runs/attempts, content-free import receipts, and the reduction-confirmation marker in browser components. A Biz PT occurrence may contain an optional 1–20-digit numeric `member.uid` to preserve the member-admin deep link after same-account restoration on another computer, but the extension-local schedule copy does not contain the Biz PT password, cookie/session, original HTML, phone number, or email. Device-free Biz PT occurrences/repeat settings needed for another-computer restore are sent through the authenticated SoriCue API to the Supabase account source described above, while device binding, alarms, execution state, runs and import receipt/recovery/reduction-confirmation state remain in the browser and are not sent to a separate schedule-execution database. Content-free diagnostics apply absolute caps of 400 browser-localStorage entries/14 days; a 256-row/14-day web delivery outbox plus a separate 20,000-row/6-MiB/14-day local journal; and, per extension account-hash partition, an 800-row/512-KiB/30-day delivery queue plus a separate 20,000-row/6-MiB/30-day local journal. Events are journaled locally first and central Supabase remains the unchanged asynchronous replica. A web ACK deletes the web delivery row and sets the matching web-journal row's `replicaState` to `acknowledged` until its 14-day TTL or an earlier purge. An extension ACK deletes only the extension delivery row and retains the raw content-free journal event unchanged, with no acknowledged field, until its 30-day TTL or an earlier purge; absolute no-loss is not promised. After expected-subject/authenticated-user matching and strict-schema validation, the same-origin API stores events/incidents in Supabase Postgres for 30 days by default; no Storage object log is written. Diagnostics, receipts, and markers allow only bounded identifiers, revision, state/counts, operational timestamps, or SHA-256—not transcript, audio, prompt, AI response, member/student identity, schedule title, exact personal lesson time, raw error, local path, provider key, or authentication cookie. Local provider results and separately opted-in audio in the personal allowlisted Full Diagnostic stay separate from this default path and are never sent to the server/Postgres.
- Lemon Squeezy: only for legacy licensed users, licence, instance, and transaction metadata may be processed for validation and deactivation. Provider statutory payment and tax retention applies.
- Automated marketing delivery and an email delivery vendor are out of scope and are not currently connected.
5. Deletion
Device-data deletion removes the current account's last validated dictionary cache while retaining its central personal snapshot. The account-deletion privacy job explicitly deletes that central personal snapshot and the Auth foreign-key cascade applies again; the administrator global snapshot and another account's cache remain outside the target.
Disarming releases capture tracks, that day's alarms, and unsubmitted prompt stages. Disconnecting the SoriCue device removes the binding's extension-local schedule snapshot, alarms, ordinary run ledger, terminal-tombstone ledger, and Biz PT reduction-confirmation marker. Logout/account switch/device purge removes the current device's manual and Biz PT schedule caches, content-free cloud-sync and reduction-confirmation markers, both execution ledgers, prepared state, schedule payload, and consent while retaining the central manual and Biz PT Supabase sources for that account; uninstalling the extension causes Chrome to remove its local extension state.
After Supabase Postgres durably accepts a diagnostic event, the web path removes the corresponding IndexedDB delivery row, sets the matching web local-journal row's `replicaState` to `acknowledged`, and retains it until its 14-day absolute TTL or an earlier purge. The extension path removes only the corresponding delivery row and retains the raw content-free journal event unchanged, with no acknowledged field, until its 30-day absolute TTL or an earlier purge. Logout, account switch, device-data deletion, and account deletion remove the target user's browser/extension delivery and journal rows plus the matching per-tab nonce and use the global content-free purge marker to block recreation by tabs opened before deletion, while preserving other users' rows. The account-deletion privacy job explicitly deletes central operational diagnostic events and incidents before Auth deletion, the auth.users foreign-key cascade applies again, and a matching singleton scheduler user pointer becomes null.
Completed account deletion removes the account's browser-local schedule cache and other schedule-automation local state from the current browser, central operational diagnostic events/incidents, pseudonymous Product UX events, the central manual and Biz PT schedule sources, authorization/consent/usage, and the Supabase Auth user and email. Product UX ingestion is blocked when deletion begins and purged again after Auth deletion. Diagnostics and both central schedule sources are covered by Auth foreign-key cascades, while device binding, alarms and scheduled runs are not stored in a separate schedule-execution database. An idempotent job tracks each plane and never reports a partial failure as complete. Final erasure of Supabase backup copies follows the project's cycling policy. An approved Mac archive copy is not deleted automatically. The operator must obtain the exact lowercase 64-hex userHash from the server-side rights/export workflow and run delete-user with only that value, never an email, name, or Supabase user UUID. The command removes matching event/incident/pending rows and rebuilds affected reports while preserving other users, user-unlinked service errors, and legacy records. Operator-console copies require separate rights-request and retention action.
User-unlinked Next.js service-error rows have no account identifier and therefore cannot be selected by account deletion, and they remain outside per-user account/portability export. Their database rows are removed by the 30-day maximum expiry and bounded cleanup, while `service-errors.ndjson` and daily-report copies made by the private operator export on an approved Mac follow configured local-retention and rights-request deletion.
A content-free deletion tombstone may remain for 30 days after the user identifier is detached. A separate Product UX HMAC tombstone contains only calendar dates to block residual-access-token reinsertion and remains for no more than 31 UTC calendar dates. Database and host backups rotate under operator policy and may not support immediate record-level erasure.
You must separately ask the relevant provider to delete data already sent there, provider usage records, statutory payment records, or provider backups.
6. Security measures
- Server verification of authentication and required document versions, with RLS and service-only RPC boundaries
- Append-only consent events in normal operation, without duplicating account email
- Purpose-bound, expiring signed cookies for OAuth consent intent and reauthentication proof
- Local API-key storage or encryption on central legacy paths, data minimisation, same-origin checks, rate limits, and security headers
- Exact binding of scheduled occurrence/revision/operation/device and external-AI provider/tab/document/conversation/stage/turn, with fail-closed handling of stale, ambiguous, or worker-restart states
7. Your rights and request process
Settings shows document versions and marketing status and lets you immediately withdraw marketing consent or request account deletion. For access, correction, deletion, restriction, objection, consent withdrawal, portability, or appeal, email soricue@gmail.com.
Include your account email, the right requested, and scope. We may request further authentication to protect the account, and an agent must show authority. We will respond within the applicable legal period or explain an extension, refusal, and appeal route.
Users in Korea may exercise rights under applicable Korean privacy law. EU/EEA and UK residents may, where applicable, request access, correction, erasure, restriction, portability, objection, and complain to a supervisory authority. California residents may, where applicable, request knowledge/access, deletion, correction, non-discrimination, and opt out of sale or sharing. We do not currently sell personal information or share it for cross-context behavioural advertising.
8. Children
The service is not available to anyone under 14. If local law sets a higher minimum age, that higher age applies. If we learn that an account is below the applicable age, we will restrict it and initiate deletion.
9. Technical data flow and changes
The /privacy technical data-flow page describes active processors, local storage, and exact transfer paths. If it conflicts with this legal policy, we will promptly inspect the code and correct the inaccurate description.
We will announce the effective date and material changes in the service. If a material purpose or legal basis changes and consent is required, we will request acceptance of the new version.