Effective date: 21 September 2026
This policy explains how Skrivla handles personal data when you use the Android app and keyboard.
Who is responsible for your data?
Skrivla is provided by:
OPIM AB, Postia 1145, 214 13 Malmö, Sweden.
Swedish organisation number: 559573-8799
For privacy questions, support, or requests concerning your personal data, email olivier.payen@gmail.com.
The short version
- When you dictate, your phone sends the audio directly to ElevenLabs, which converts it into text and returns the text directly to your phone. The audio and transcript do not pass through Skrivla's server or database.
- Skrivla does not write microphone audio to disk. It can keep a small amount in memory for up to five minutes to recover an interrupted dictation.
- Skrivla keeps up to 20 recent transcripts in private storage on your phone so you can recover, preview, insert, copy, or delete them. Android backup and device transfer are disabled for this storage.
- Google and Firebase handle sign-in, app-integrity checks, and crash reporting. RevenueCat and Google Play handle subscription information. Skrivla's database stores account, access, quota, and entitlement records, but not audio or transcript text.
- Skrivla uses limited, pseudonymous PostHog product analytics in internal testing and Production builds to measure setup and reliability. New events are not linked to your account and do not include dictated text, audio, selected languages, account identity, or location.
- Skrivla does not sell personal data and does not use it for advertising.
Dictation and ElevenLabs
Skrivla records microphone audio only after you start a dictation. The app sends 16 kHz mono audio directly from your phone to the ElevenLabs realtime speech-to-text service. ElevenLabs produces transcript text and returns it directly to the app. Skrivla's Cloudflare service and Neon database never receive the audio or transcript.
Skrivla does not store audio itself. During an interrupted dictation, the app may retain up to 10 MB of audio in memory for recovery. This audio is never written to disk and is cleared when recovery finishes, is discarded, expires, the service is destroyed, or the process ends. The recovery offer lasts no longer than five minutes.
ElevenLabs processes the audio, generated transcript, and ordinary technical request data in the United States under its standard service settings. Zero Retention Mode is not enabled, so ElevenLabs may retain input and output under its own retention rules. ElevenLabs does not publish a fixed ordinary retention period for this processing. Skrivla has disabled the use of new workspace data for ElevenLabs model training, but this does not delete earlier data or prevent standard service retention. Skrivla does not send your Firebase account ID or email address to ElevenLabs. As a result, Skrivla cannot search for individual provider-held dictations by your Skrivla account. For more information, see the ElevenLabs privacy policy: https://elevenlabs.io/privacy-policy
We process dictation data because it is necessary to provide the transcription service you request.
Transcript history on your phone
Skrivla stores up to 20 recent non-empty transcripts in credential-protected, app-private storage on your phone. Each entry contains the transcript, its date and time, and a random local identifier. It does not contain audio, the identity of the app or field where you dictated, surrounding text, your account ID, or the detected language.
Skrivla may also keep one recent transcript recovery file after an unexpected process stop. Its recovery offer expires after five minutes; valid text may then be moved to the 20-entry history before the recovery file is deleted.
You can preview, insert, copy, delete individual entries, or clear all history from the keyboard. Copy places the text on the Android clipboard, where other software may be able to read it. Skrivla does not automatically clear the clipboard. History is cleared when the keyboard observes that you signed out or changed accounts. An offline installation cannot receive a remote deletion instruction, so you should also clear the history, clear the app's data, or uninstall Skrivla on devices you no longer use.
We process this local history because it is necessary to provide the recovery and history features of the service. It stays on your device until you delete it, clear the app's data, uninstall Skrivla, or the app clears it after observing a sign-out or account change.
Account and sign-in
Google sign-in is handled through Android Credential Manager and Firebase Authentication. Firebase may receive your Google account identifier, name or display name, email address, authentication data, IP address, and technical security information. The app displays your email in the account screen, but Skrivla does not copy your name or email into its own database, telemetry, or crash reports. Skrivla's service uses your Firebase user ID and a coarse account type to authenticate requests and manage access.
Firebase says authentication IP logs are kept for a few weeks. Other Firebase Authentication information is retained until OPIM AB deletes the account, after which removal from Firebase live and backup systems can take up to 180 days. Firebase Authentication processing occurs in the United States. See Firebase privacy and security: https://firebase.google.com/support/privacy
We process account data because it is necessary to provide and secure your account and the service.
Access, quotas, and security
Skrivla uses a Cloudflare Worker to authenticate requests, enforce trial and paid-access limits, and issue short-lived transcription credentials. Cloudflare necessarily processes ordinary network and security information such as IP addresses and request metadata. Skrivla's application logs exclude request bodies, account IDs, dictated content, credentials, headers, and raw provider responses.
The Skrivla database is hosted by Neon in an EU region. It stores your Firebase user ID, account and access state, quota periods and usage grants, subscription entitlement state, and minimal webhook or event identifiers needed to process updates safely. It does not store your email, audio, transcript, clipboard, surrounding text, or the app in which you dictate.
Firebase App Check with Google Play Integrity processes attestation material and short-lived tokens to verify that requests come from the genuine app. Firebase says App Check does not retain attestation material. Tokens can remain valid for up to seven days, and tokens used for replay protection can be stored for up to 30 days.
We process this technical data because it is necessary to provide the service and for our legitimate interests in preventing abuse, enforcing access limits, and protecting Skrivla and its users.
Purchases and subscriptions
Google Play processes your payment and subscription. OPIM AB does not receive your card or bank details. The app sends your Firebase user ID to RevenueCat as the subscription customer identifier. Google Play and RevenueCat process purchase tokens, product and transaction information, subscription status, renewal, cancellation, expiry, and entitlement information. RevenueCat sends entitlement updates to Skrivla, and Skrivla's database is authoritative for paid access.
We process this information because it is necessary to provide purchased access and manage the subscription. OPIM AB also uses RevenueCat's subscription reports to understand purchase and subscription performance, based on its legitimate interests in operating and improving Skrivla's paid service. Google and RevenueCat retain transaction information according to their own legal and service requirements. See Google's privacy policy (https://policies.google.com/privacy) and RevenueCat's privacy policy (https://www.revenuecat.com/privacy-policy/).
Crash reporting and application sessions
Production releases use Firebase Crashlytics to receive fatal JVM crash reports and supported Android not-responding reports. Skrivla also records two types of non-fatal technical failures: when the transcription provider rejects a realtime request or returns a malformed response. Reports can contain a crash or failure stack trace, a fixed technical error code, timestamps, app version, operating-system and device details, hardware state, and service-generated installation and session identifiers. Skrivla does not add your account ID, custom logs, custom keys, dictated text, audio, selected languages, clipboard data, surrounding text, target-app identity, or the provider's response.
Crashlytics includes Firebase Sessions. It automatically collects the package name, operating-system and SDK versions, network connection type, device manufacturer and model, and a foreground-time signal used to start a session. OPIM AB uses this only to calculate crash-free users and sessions and to monitor the stability of releases. Skrivla does not link it to your signed-in account or user content.
Firebase says Crashlytics crash traces and associated identifiers are retained for 90 days before deletion begins. Firebase does not publish a separate retention period or a developer-accessible deletion control for the automatic Sessions measurements. OPIM AB has accepted this limited uncertainty because the fields are fixed technical metadata and are not linked by Skrivla to your account or content. See Firebase's Android data disclosure: https://firebase.google.com/docs/android/play-data-disclosure#firebase-sessions
We process this data for our legitimate interests in finding crashes and provider compatibility problems, measuring reliability, and safely releasing fixes.
Analytics
PostHog receives a closed list of coarse events from internal testing and Production builds to measure setup, dictation reliability, broad performance ranges, and the purchase funnel. The events include the app version and environment so testing and Production can be separated. They use a random installation identifier that is not linked to your Firebase account. They never contain audio, transcript or typed text, selected languages, clipboard or surrounding text, the app or field in which you dictate, exact purchase information, your name or email, or location. PostHog profiles, autocapture, session replay, surveys, exception capture, client-IP storage, and GeoIP enrichment are disabled. PostHog necessarily receives the connection IP while accepting an event, but Skrivla does not store it or use it to derive location for new events.
We process these limited events for our legitimate interests in finding reliability problems, improving setup and dictation, and operating the purchase funnel. Before 21 September 2026, PostHog added country and other GeoIP-derived location fields to internal-testing events from the connection IP. That enrichment is now disabled. Historical events may retain those fields for the remainder of the one-year retention period.
How long we keep data
- Local transcript history stays on your device as described above. Recovery audio remains only in memory and the recovery offer lasts no more than five minutes.
- Firebase Authentication keeps logged IP addresses for a few weeks. Other account data remains until account deletion; Firebase says removal from its live and backup systems may then take up to 180 days.
- Skrivla keeps account, quota, entitlement, and purchase-event records in Neon while your account exists. Dictation-grant records older than seven days are deleted when that account next requests a grant. If the account does not return, those records remain until account deletion. All records linked to your account are removed from the active database during account deletion after the credential-expiry delay described below. As of the effective date, deleted rows can remain recoverable in Neon's Production restore history for up to six hours; no separate snapshots are configured.
- Cloudflare Workers logs are kept only for Cloudflare's short plan-defined dashboard period, currently no more than seven days. Skrivla does not export them to a longer-term log archive.
- Crashlytics records follow Firebase's 90-day schedule. Firebase has not published a separate retention period for Firebase Sessions measurements.
- PostHog events are retained for one year.
- ElevenLabs and the payment providers keep the information they process according to their own retention rules and legal obligations.
- Support correspondence is kept only as long as needed to answer and document the request. Deletion-form responses and the related confirmation thread are deleted 30 days after the request is completed.
Support and deletion requests
If you contact support, OPIM AB processes the email address, message, and other information you choose to provide so that we can answer you. Do not send dictation content unless it is necessary for your request. Ordinary support is processed because it is necessary to perform the Skrivla contract or take steps you request before entering into it. Privacy and deletion requests are processed to comply with OPIM AB's legal obligations. OPIM AB relies on its legitimate interests in keeping a limited record that a request was handled, so that it can demonstrate compliance and resolve disputes.
To delete your Skrivla account without reinstalling the app, use the Skrivla account-deletion form while signed in to the same Google account you use for Skrivla: https://docs.google.com/forms/d/e/1FAIpQLSd0rgLxXkq9IXeijENVCtjl2U9vwCo24yqruK9bPkmqMQgTPA/viewform
Google Forms receives the verified email address, acknowledgements, and deletion timing you submit. OPIM AB verifies the request by email before acting.
Deleting your Skrivla account does not cancel a Google Play subscription or automatically issue a refund. Cancel the subscription in Google Play first. You can ask deletion to start immediately after verification or at the end of your current paid period.
At the chosen start time, OPIM AB deletes your Firebase Authentication account. A previously issued Skrivla installation credential may remain valid for up to 14 days. After 15 complete days, OPIM AB deletes all Neon records associated with your Firebase user ID, including subscription-event records, from the active database and deletes the RevenueCat customer. Deleted Neon rows can remain recoverable for the six-hour restore-history period described above. The Google Form response and confirmation email thread are deleted 30 days after the request is completed.
Account-specific deletion cannot remove data that Skrivla deliberately does not link to your account. This includes local data on an offline phone, Crashlytics and Firebase Sessions records that Skrivla does not link to your account, and any dictation content retained by ElevenLabs without your Skrivla account identifier. Crashlytics crash records follow Firebase's 90-day schedule; Firebase does not publish a separate Sessions schedule. Other information may be retained where required by law, to resolve disputes, or to establish or defend legal claims.
Service providers and international transfers
OPIM AB uses the following processors and platforms:
- ElevenLabs for realtime speech-to-text processing;
- Google and Firebase for sign-in, app-integrity checks, and crash/session reporting;
- Google Play for distribution, purchases, and subscriptions;
- RevenueCat for purchase validation and subscription entitlements;
- Cloudflare for the authentication and access-control service and network protection;
- Neon for the account, quota, and entitlement database;
- PostHog for limited analytics in internal testing and Production builds; and
- Google Forms and Gmail for verified support and deletion requests.
Some providers process data outside the EU/EEA, including in the United States. OPIM AB uses the following safeguards where a transfer is not covered by an adequacy decision:
- For Firebase Authentication, App Check, Crashlytics and Sessions, Google Play, Google Forms, and Gmail, transfers to Google LLC in the United States rely on Google's EU-US Data Privacy Framework certification. Google's European data-transfer framework also provides Standard Contractual Clauses as a fallback if that framework does not apply: https://policies.google.com/privacy/frameworks
- ElevenLabs processes standard service data in the United States. Its DPA incorporates the European Commission's Standard Contractual Clauses for this transfer: https://elevenlabs.io/dpa
- RevenueCat's DPA (https://www.revenuecat.com/dpa), Cloudflare's DPA (https://www.cloudflare.com/cloudflare-customer-dpa/), and Neon's DPA (https://neon.com/pdf/DPA.pdf) incorporate the European Commission's Standard Contractual Clauses for their restricted transfers.
- Analytics data is hosted in PostHog's EU region. For access from the United States, OPIM AB relies on PostHog's EU-US Data Privacy Framework certification, as described at https://posthog.com/dpa
Neon database data is stored in the selected EU region, but providers and their subprocessors may still perform support, security, or other processing elsewhere under these safeguards.
You can contact OPIM AB if you would like more information about the safeguards used for an international transfer.
How we protect data
Skrivla uses encrypted HTTPS or secure WebSocket connections when data leaves the phone. Local transcripts are kept in credential-protected, app-private storage with Android backup and device transfer disabled. Provider and database access is restricted, long-lived service credentials are not included in the app, and Skrivla minimizes the data included in operational logs and crash reports. No security measure can guarantee absolute protection.
Your rights
Subject to applicable law, you may ask OPIM AB to:
- provide access to your personal data;
- correct inaccurate data;
- delete data;
- restrict or object to processing; or
- provide portable data where applicable.
You may also object specifically to processing based on legitimate interests. OPIM AB normally responds within one month. Contact olivier.payen@gmail.com to exercise these rights. You can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), using its GDPR complaint service: https://www.imy.se/en/individuals/forms-and-e-services/file-a-gdpr-complaint/
Skrivla does not make automated decisions that have legal or similarly significant effects. Automated account, entitlement, quota, and security checks can allow or refuse a dictation request. Contact support if you believe one of these checks is wrong.
Children and teenagers
Skrivla is not intended for children under 13 and they must not use it. Users aged 13 to 17 may use Skrivla only with permission from a parent or legal guardian. This reflects the current ElevenLabs rules for customer applications that use its transcription service. See the ElevenLabs Prohibited Use Policy: https://elevenlabs.io/use-policy
If you believe a child under 13 has used Skrivla, contact OPIM AB so that the account and associated data can be investigated and deleted where possible.
Legal obligations and changes
OPIM AB may process or retain information when necessary to comply with law, respond to lawful requests, or establish, exercise, or defend legal claims.
We may update this policy when Skrivla or its providers change. The effective date at the top will be updated, and material changes will be communicated in the app or through another appropriate channel.