Security and Data Handling

Company / Security

Last reviewed: 2026-09-07. These practices apply to the Speech is Cheap transcription service. Read them alongside our Privacy Policy and Terms of Service.

Retention and Deletion

Original Media

For jobs submitted by URL, we stream media to an ephemeral processing server and delete the working copy when the job finishes. We do not retain media working copies or media backups afterward.

Files sent to the Upload API become eligible for deletion after one hour. Cleanup runs every 15 minutes, so uploaded files are normally deleted within 75 minutes. This is the normal cleanup schedule, not a guarantee that filesystem or service failures can never delay deletion.

Transcripts and Job Records

By default, transcripts and job records remain available indefinitely. Non-private transcript recovery backups are retained for 30 days.

Set is_private when creating a job to redact its input URL and delete transcript segments after 12 hours. Private transcript content is excluded from recovery backups. After content deletion, operational metadata remains, including the job ID, duration, request flags, and status. Private mode does not delete every record of the job and limits what we can investigate during troubleshooting.

Failed and canceled job records are retained indefinitely. The job cancellation endpoint cancels pending work; it is not a completed-transcript deletion endpoint.

For deletion requests beyond private mode, email privacy@speechischeap.com. We confirm completion of the request. We do not publish a fixed completion deadline. Non-private recovery backups follow their 30-day retention cycle.

See the job creation documentation for the private-job option and the cancellation documentation for pending jobs.

Training and Access

We never use customer data to train our own models or allow our providers to use it for model training.

Personnel do not access private-job content. Access to non-private customer data is limited to support, debugging, and abuse investigations. The founder controls that access, and access is logged.

Encryption, Providers, and Regions

Customer data is encrypted in transit. Transcript outputs are not encrypted at rest. Other customer data is encrypted at rest. Stripe handles payment information.

Cloudflare provides the global edge and API infrastructure. Transcript storage uses AWS S3 in the US East, Northern Virginia region, us-east-1. Processing infrastructure operates globally. We do not currently offer customer-selectable data residency; contact sales@speechischeap.com to discuss a required arrangement before using the service.

These are disclosed infrastructure facts, not a claim that this page is a complete contractual subprocessor register. Send vendor or security questionnaires to security@speechischeap.com.

Compliance and Contracting

Speech is Cheap does not currently hold compliance certifications, including SOC 2 certification or attestation. We do not claim HIPAA compliance. Do not assume that a Business Associate Agreement, or BAA, covers use of this service.

Speech is Cheap does not currently offer a Data Processing Agreement, or DPA. This page does not establish GDPR compliance or suitability for regulated data. If your organization requires a DPA, BAA, residency commitment, or other contractual protection, contact legal@speechischeap.com before sending that data. Do not proceed on the assumption that the required protection is in place.

Report a Security Issue

Send vulnerability reports and security questions to security@speechischeap.com. Include the affected service, reproduction steps, and the likely impact. Do not include API keys or unrelated customer content in the report.

Our machine-readable reporting contact is at security.txt. For service availability, use the public status page and our service commitments. Privacy and deletion requests belong at privacy@speechischeap.com.