ScriptHaul API
Log inGet API key

Legal

ScriptHaul API Privacy Policy

Effective September 4, 2026 · Last updated September 5, 2026

This policy covers the account-based API product at api.scripthaul.com. The anonymous free site has a separate privacy policy.

1. Data we hold

Account data includes your email, normalized email, accepted terms version, verification time, hashed one-time codes, hashed dashboard sessions, API key hashes and display prefixes, key names and caps, and account status. We never store the complete API key after it is shown.

Billing data includes Stripe customer, session, payment, refund, and dispute identifiers; purchased blocks; invoices and tax records; and the append-only credit ledger. Stripe receives payment details; ScriptHaul does not receive full card numbers.

Service data includes per-key usage rollups, request events, request addresses or protected address-derived identifiers used for abuse control, video and channel identifiers, job inputs and rows, selected formats and languages, webhook URLs, delivery attempts and response status, and support messages. Webhook bodies are not logged.

2. Why we use it

We use this data to verify accounts, authenticate keys, maintain balances, deliver and resume work, enforce capacity and abuse limits, send transactional messages, process purchases and refunds, secure the service, diagnose failures, answer support, meet accounting and legal duties, and publish aggregate service health. Depending on location, the legal bases are contract, legitimate interests in operating and protecting the service, consent where requested, and legal obligations.

We do not train models on customer traffic and do not sell usage data.

3. Transcript cache and YouTube data

The shared transcript cache may be retained indefinitely and is keyed by video and language, not by customer. A cache object can serve later users without another upstream fetch. Transcript bodies come from public caption tracks, not the YouTube Data API. Data API fields exposed to API customers—such as titles and dates in job rows, manifests, and usage records—are refreshed or purged after 30 days.

ScriptHaul uses YouTube API Services. By using the API you also agree to the YouTube Terms of Service; read the Google Privacy Policy for how Google handles data. ScriptHaul does not download video or audio.

4. Retention

5. Processors and recipients

Cloudflare provides the Worker, D1 database, R2 storage, rate limiting, security, and edge delivery. Fly.io runs the transcript relay. Residential network providers carry bounded upstream requests. Stripe processes checkout, tax, invoices, refunds, and disputes. Cloudflare Email Sending or Resend sends verification and service emails. Uptime probes monitor public health. Google Analytics may run on indexable marketing pages only, not authenticated API responses or the dashboard. A managed transcript fallback vendor is used only when armed and needed.

We share data when necessary with these processors, to comply with law, protect rights and service security, complete a business transfer, or at your direction. We do not provide public transcript browsing or a customer-traffic data feed.

6. Security

Keys, sessions, and codes are stored as hashes made with a secret pepper outside the database. Keys are accepted only in the Authorization Bearer header. Dashboard cookies are HttpOnly, Secure, SameSite=Strict, and confined to dashboard-safe routes. No system is perfectly secure; rotate a key promptly if it may have leaked.

7. Controller and international processing

The controller for this data is the operator of ScriptHaul, reachable at support@scripthaul.com. Processors may handle data in countries other than yours. Where required, we rely on the processor’s transfer mechanism and contractual safeguards.

8. Your choices and rights

You can name, cap, rotate, and revoke keys; export usage; request account closure; and ask for access, correction, deletion, restriction, objection, or portability where applicable. Financial and fraud records may remain when law or a dispute requires them. You may complain to your local data-protection authority.

9. Contact

Send privacy requests to support@scripthaul.com. We may verify the request through the account email before acting.