Last updated: August 9, 2026
Privacy Policy
What This Policy Covers
This Privacy Policy explains how Nonymize collects, uses, stores, shares, and deletes information when you use our website and transcript anonymization service.
Nonymize is built for professionals who need to anonymize sensitive text before using it in downstream tools. It is not intended for HIPAA-regulated use, and we do not sign Business Associate Agreements for V1.
Information We Collect
- Account information, including your email address, encrypted password, email confirmation status, account settings, and authentication/session data.
- If you connect Google Drive or Microsoft OneDrive, the connected account identifier and label, tenant identifier where applicable, granted permission scopes, encrypted OAuth access and refresh tokens, selected drive and folder identifiers and displayed destination name or path, connection status, and—when you request an export—records such as timestamps, status, and the identifier and link for a file Nonymize creates.
- Transcript content you paste or upload, plus optional labels, selected anonymization mode, selected detection categories, and replacement rules.
- Anonymized transcripts, replacement keys, replacement counts, processing status, timestamps, and privacy-safe provider attempt metrics.
- Billing and subscription records handled through Stripe, including customer, subscription, charge, and payment metadata returned to our app.
- Support messages you send through the contact form, along with your plan tier, last anonymization status, and user agent.
- Technical and security information such as IP address, browser/user agent, request metadata, rate-limit signals, logs, and error diagnostics.
- Privacy-safe product analytics handled through PostHog. We do not use marketing pixels.
How Transcript Processing Works
When you submit a transcript, we temporarily store the original transcript so the service can process it and let you review the result. We send transcript content to the configured managed extraction backend, currently Novita/DeepSeek by default, Cerebras when enabled, or Fireworks as a fallback provider, solely to provide the anonymization service.
We do not use customer transcripts to train, fine-tune, evaluate, or improve models. We do not send raw transcripts to downstream general-purpose AI analysis tools such as Claude, ChatGPT, or OpenAI for user analysis.
Google Drive Connection And Exports
If you explicitly connect Google Drive, Nonymize requests the limited drive.file permission. This lets Nonymize create files and work with only the files and folders you select with Google Picker or share with Nonymize. It does not provide general access to all content in your Google Drive.
Nonymize stores the OAuth access and refresh tokens for this connection using application-level encryption so it can complete exports you request, including when the export runs in the background. We use the connection, selected-folder information, and Google file metadata only to select your destination, save the file, show its status and link, prevent duplicate uploads, troubleshoot failures, and protect the service. We do not use this Google Drive data for advertising or model training.
When you choose to save to Google Drive, Nonymize sends the exact finalized anonymized output—not the original transcript or replacement key—to the folder you selected. Revoking Nonymize's access through your Google Account prevents future Drive exports, but it does not delete copies already saved in Drive; those remain under your control in Google Drive.
Microsoft OneDrive Connection And Exports
If you explicitly connect Microsoft OneDrive, Nonymize requests the delegated Files.ReadWrite permission. Microsoft defines this permission as allowing an app to read, create, update, and delete the signed-in user's files. Nonymize limits its use of that permission to listing folder metadata in your own OneDrive, validating and remembering a folder you explicitly choose, and saving exact finalized anonymized output to that folder when you request an export. Nonymize does not read the contents of your existing OneDrive files and does not request Files.ReadWrite.All or any Microsoft Graph application permission.
Nonymize requests openid, profile, and email to identify the Microsoft account you connect, and offline_access so Microsoft can issue a refresh token for future exports you request. We store the connected account and tenant identifiers, account label, granted scopes, selected drive and folder identifiers and path, and OAuth access and refresh tokens. The tokens are protected using application-level encryption.
When you choose to save to OneDrive, Nonymize sends the exact finalized anonymized output—not the original transcript or replacement key—to the folder you selected. Revoking Nonymize's access through your Microsoft account or organization prevents future OneDrive access, but it does not delete copies already saved there; those remain under your control in OneDrive.
How We Use Information
- Provide, secure, maintain, and improve the Nonymize service.
- Authenticate accounts and manage sessions.
- Process transcripts, generate replacements, display review diffs, and export anonymized output.
- Enforce free-tier limits, manage subscriptions, and process billing.
- Provide support and respond to user requests.
- Monitor reliability, diagnose errors, prevent abuse, and protect the service.
- Comply with legal, tax, accounting, and security obligations.
Retention And Deletion
- Original transcript text is deleted when you finalize an anonymization.
- Replacement key CSVs are retained for 7 days after finalization so you can see what changed, then permanently purged.
- Abandoned pending, processing, or review records older than 7 days have original transcript text and replacement keys purged.
- Anonymized transcripts, labels, statuses, timestamps, and privacy-safe metrics remain in your account until you delete the anonymization or your account.
- Account deletion deletes your account data, transcripts, replacement rules, settings, and contact messages, except billing, tax, security, or legal records we must retain.
- Stripe may retain billing and tax records according to its own legal obligations and policies.
How We Share Information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We share information only with service providers needed to operate Nonymize, including Google when you choose Google authentication or direct Nonymize to export anonymized output to Google Drive, Microsoft when you connect OneDrive or direct Nonymize to export anonymized output there, hosting and infrastructure providers, email delivery providers, Stripe for payments, Honeybadger for error monitoring, PostHog for product analytics, and managed AI inference providers such as Novita, Cerebras, and Fireworks.
We may also disclose information if required by law, to protect rights and safety, to investigate abuse, or as part of a business transaction such as a merger, financing, or acquisition.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including HTTPS, secure authentication, parameter filtering for sensitive transcript fields, and error-report scrubbing. No internet service can guarantee absolute security.
Your Choices And Rights
You can update your email, password, default settings, and subscription from your account settings. You can delete individual transcripts from your dashboard. You may contact us to request access, correction, export, deletion, or other privacy rights available under applicable law.
California residents may have rights to know, access, correct, delete, and limit certain uses of personal information, and the right not to be discriminated against for exercising privacy rights.
Children
Nonymize is for users who are at least 18 years old. We do not knowingly collect personal information from children.
Changes
We may update this Privacy Policy from time to time. When we do, we will update the date above. If changes are material, we will provide additional notice where required by law.
Contact
Questions or privacy requests can be sent to support@nonymize.com.