ScriptLoop (“we”, “us”, “our”) provides a web tool that turns your written scripts into looping audio so you can memorize them. This Privacy Policy explains what we collect, why, and what choices you have.
Information we collect
- Account information. When you sign up we collect your email address and a hashed password through our authentication provider, Neon Auth (powered by Better Auth). We never see or store your password in plaintext.
- Script content. The text you paste, the title you give it, your chosen voice, and your loop-gap setting are stored in our PostgreSQL database (Neon) so you can come back to them later.
- Generated audio. When you generate audio, we send your script text to a text-to-speech provider — by default Kokoro, run on Replicate, with ElevenLabs as the alternative — and store the resulting audio file in Cloudflare R2 object storage. The audio file itself is hosted at a public, hard-to-guess URL (a long random-looking path under our R2 bucket). The URL is not listed anywhere public, but anyone who obtains it — via browser history, copy/paste, a shared link, or a leaked log — can play the audio without signing in. Treat the audio URL like a secret. The script text and the link between you and the audio are kept private behind your account. Regenerating audio produces a new URL and best-effort deletes the previous R2 object at the origin. Browser and CDN caches that already hold the audio may keep serving it for a while, so rotation is not instantaneous.
- Generated songs. If you use the song-generation feature, we send your script text to an AI music provider — by default MiniMax, accessed through fal.ai, with Google’s Lyria and ElevenLabs Music as alternatives — which returns lyrics and an audio track. Those are stored the same way as spoken audio, under the same public-by-design URL posture described above. As part of an automated quality check, we also send the generated audio to fal.ai’s Whisper model to transcribe it back to text, so it can be compared against the lyrics we asked for; the transcript is used only for that check and is not stored separately from the ordinary song record.
- Household profiles. The adult account holder can create profiles for other household members (for example, children) to share the account. A profile stores a first name, an optional avatar color, and an optional PIN (stored as a salted hash, never in plaintext) — no email or password, and no separate login. Profile PINs are a speed bump against a household member wandering into another profile’s scripts, not a security boundary; anyone with access to the account holder’s signed-in device can already reach every profile. Scripts and audio created under a profile are stored as account data, separated from other profiles only by which profile created them.
- Payment information. Subscriptions bought on the web are processed by Stripe, and in-app purchases on iOS and Android by RevenueCat together with the Apple App Store or Google Play. We receive a subscription status, tier, and provider reference for your account. We never receive or store your card number — card details are entered directly with the payment processor.
- Operational logs. Server-side errors and 5xx responses are sent to Sentry for debugging. These reports may include your user id and the route that errored, but not your script content or password.
- Analytics. We use Plausible Analytics, a privacy-friendly, cookie-less analytics tool. Plausible records aggregate pageviews and basic referrer / device information. It does not use cookies, does not collect personal data, and is GDPR-compliant by design.
How we use information
- To let you sign in and access your scripts.
- To generate and play back audio of your scripts.
- To monitor and debug the service (Sentry).
- To understand aggregate usage patterns so we can improve the product (Plausible).
Sharing
We do not sell your data. We share information only with the sub-processors strictly required to operate the service:
- Neon (database hosting and authentication)
- Replicate (Kokoro text-to-speech generation — the default voice provider)
- ElevenLabs (text-to-speech and music generation)
- fal.ai and MiniMax (AI song generation — the default music provider)
- Google (Lyria and Gemini, AI song generation)
- Cloudflare R2 (audio file storage)
- Netlify (web hosting and serverless functions)
- Stripe (payment processing for web subscriptions)
- RevenueCat (in-app purchase processing on iOS and Android)
- Sentry (error tracking)
- Plausible Analytics (anonymous pageview analytics)
- Encharge (marketing email delivery — only for addresses submitted to a subscribe form, never account data)
Marketing emails
If you enter your email address into a subscribe form on our site, we store that address to send you occasional emails about ScriptLoop. This is separate from your account: you can be on the mailing list without having an account, and having an account does not put you on the mailing list. We record the page the form was submitted from so we know which content people found useful.
We do not sell or rent this list. Every marketing email includes an unsubscribe link, and you can ask us to remove your address at any time by emailing [email protected].
Retention
Your scripts and generated audio are kept for as long as your account exists. Deleting a script removes its database row and the associated audio reference; deleting your account removes all of your scripts. Audio objects in R2 may persist briefly after the referencing script is deleted (orphan cleanup is best-effort), but they are no longer linked to your account.
Audio URL privacy posture
We deliberately chose “public-by-design behind an unguessable URL” over signed, expiring URLs. The trade-off:
- Pro: Audio playback is fast, cacheable, and works in any <audio> element without re-fetching tokens.
- Con: If the URL leaks, the audio is exposed until you regenerate (which rotates the URL).
Before generating audio for the first time on a device, the app asks you to acknowledge this trade-off. If you ever suspect a URL has leaked, regenerate the audio from the script’s detail page — we issue a delete against the old R2 object at the origin as part of the regenerate flow. Deletion is best-effort; if it fails, the old URL may remain accessible. And because audio is served with long public caching, browsers and CDNs that already cached the file may keep serving it for some time after the origin object is gone.
Your rights
You can delete any of your scripts at any time from your dashboard. To delete your account or request a copy of your data, email us. If you are in the EU/UK you have the right to access, correct, port, and erase your personal data, and to lodge a complaint with your local data-protection authority.
Cookies
ScriptLoop uses a single first-party session cookie set by the authentication provider so you stay signed in. We do not set advertising cookies. Plausible Analytics is cookie-less.
Children
ScriptLoop is not directed at children under 13 and we do not knowingly collect data from them.
Changes
We may update this policy. The “last updated” date at the top will reflect any changes.
Contact
Questions or requests? Reach out via the support email listed on our deployment.