Privacy Policy
Last updated: July 2, 2026 · Effective date: July 2, 2026
1. About this Policy
This Privacy Policy explains how StenoScore (“StenoScore”, “we”, “us”) collects, uses, shares, and protects personal information when you use the StenoScore website, applications, and related services (the “Service”), and the rights you have over that information.
This Policy applies to court reporters, attorneys, and other professional users of the Service. The Service is not intended for, and we do not knowingly collect personal information from, anyone under 18.
By using the Service you agree to the practices described here. This Policy is part of, and is incorporated into, our Terms of Service.
“Your California Privacy Rights” — see Sections 7, 8, and 9 below for the disclosures California residents have a right to receive under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”) and the California Shine the Light Law (Cal. Civ. Code § 1798.83).
2. Information we collect
2.1 Information you give us
- Account profile. Name, email address, professional role (court reporter or attorney), certification information (for example, CSR number, bar number), reporting method, phone number, mailing address, and any optional profile information you choose to provide.
- Authentication data.We use passwordless (“magic-link”) authentication and Google OAuth. We do not store passwords.
- User Content. Reviews, ratings, written narratives, profile responses, and other content you submit through the Service. Reviews are submitted anonymously with respect to other users of the Service: attorneys can see aggregated ratings and category-level trends but cannot identify the individual reviewer (see Section 3.3).
- Support and feedback. Information you provide when you contact support, submit a takedown dispute, or use the in-product feedback widget.
2.2 Information we collect automatically
- Device and connection data. IP address, user-agent string, device type, operating system, browser, language, and approximate location derived from IP.
- Usage data. Pages visited, features used, links clicked, search queries within the Service, timestamps, referring URLs, and session duration.
- Cookies and similar technologies. See Section 6.
- Error and performance data. Logs, stack traces, and performance metrics captured by our error-monitoring and analytics tools (see Section 5).
2.3 Information from third parties
- Google OAuth. If you sign in with Google, Google shares your name, email address, and profile picture with us. We do not receive your Google password.
- Public legal directories.We may incorporate publicly available information about attorneys — for example, name, bar number, status, firm affiliation, and practice areas — from the State Bar of California (CalBar) and equivalent state bar directories to populate attorney profiles and pre-fill review forms. Importation of public-directory information is governed by the source's terms.
- Email delivery vendors. We receive delivery, bounce, and engagement signals from our transactional-email provider.
2.4 Information we do not collect
- We do not knowingly collect Social Security numbers, government identifiers, financial-account numbers, biometric data, precise GPS location, or any “sensitive personal information” beyond what you choose to include in a review or profile.
- We use Stripefor any payment processing. Card numbers and bank-account numbers are sent directly to Stripe and are not stored on StenoScore's servers.
3. How we use information
We use personal information to:
- Provide the Service. Create and manage your account, authenticate you, display attorney profiles and aggregate ratings, deliver reviews to authorized viewers, and operate the takedown process.
- Communicate with you. Send transactional email (account, takedown, security), digest email if you opt in, respond to your inquiries, and notify you about changes to the Service or these policies.
- Improve the Service. Analyze how the Service is used; debug; develop new features.
- Protect the Service. Detect and prevent abuse, fraud, spam, defamatory content, scraping, and security incidents; enforce our Terms; comply with legal obligations and respond to lawful requests.
- Aggregate analytics. Produce de-identified statistics about industry trends and platform usage. Aggregated data is not personal information and is not subject to the deletion rights described in Section 8.
We do not“sell” or “share” personal information as California law defines those terms (see Section 7.2).
3.1 Legal bases (for users in jurisdictions where this matters)
Where applicable law (such as the EU/UK GDPR) requires us to identify a legal basis for processing, we rely on:
- Contract. Where processing is necessary to provide the Service you have requested.
- Legitimate interests. To secure the Service, prevent abuse, and analyze usage in privacy-respecting ways.
- Consent. Where we explicitly ask for it (for example, optional digest email).
- Legal obligation. Where we are required to retain or disclose information by law.
3.2 No automated decision-making with legal effects
We do not currently make automated decisions about you that produce legal or similarly significant effects without human involvement. Aggregate ratings displayed on profiles are arithmetic averages — they do not score, rank, or recommend individual professionals to other users in any way that is determinative.
3.3 Reviewer anonymity
Reviews are displayed to attorneys and to other authorized viewers without the reviewer's name, profile photo, or any other identifier. We do, however, retain the reviewer's identity in our internal records so that we can:
- enforce these Terms, including the prohibition on duplicate, paid, or coordinated reviews;
- respond to lawful requests (see Section 9);
- defend against legal claims; and
- contact the reviewer if a review is disputed.
Reviewer anonymity on the Service is not the same as anonymity to courts and regulators. A subpoena, court order, or valid legal process may compel us to identify a reviewer (see Section 9.3). Where we are permitted by law, we will give the reviewer notice and a reasonable opportunity to object before disclosing.
4. How we share information
We share personal information only as described below.
4.1 With other users of the Service
- Profile information you choose to make public is visible to other authenticated users.
- Reviews are visible (de-identified) on the profile of the attorney being reviewed.
- Aggregated ratings and statistics are visible to the relevant attorney and, where you choose, to the public.
4.2 With our service providers (“subprocessors”)
We use the following subprocessors to operate the Service. Each is contractually required to use personal information only on our instructions and to maintain appropriate safeguards.
| Subprocessor | Function | Location of processing |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Vercel | Application hosting, edge delivery | United States (with global edge) |
| Resend | Transactional email delivery | United States |
| Stripe | Payment processing (when paid features are offered) | United States |
| PostHog | Product analytics, feature-usage telemetry | United States |
| Sentry | Error monitoring, performance traces | United States |
| Google (OAuth) | Sign-in via Google account | United States |
A current list of subprocessors is maintained at stenoscore.com/subprocessors and updated when we add or change a vendor. We will give existing users reasonable advance notice of material changes.
4.3 With professional advisors
We may share information with our lawyers, auditors, accountants, insurers, and similar professional advisors where they are bound by duties of confidentiality.
4.4 In connection with a corporate transaction
If StenoScore is acquired, merged, financed, restructured, or sells substantially all of its assets, personal information may be transferred to the relevant counterparty as part of that transaction. We will notify users of any change in ownership through the Service and continue to honor commitments made in this Policy.
4.5 For legal and safety reasons
See Section 9.
4.6 With your consent
In any case not covered above, we will ask for your consent before sharing personal information about you.
5. Analytics, error monitoring, and tracking
We use the following tools to operate and improve the Service. Each has a privacy policy you can review.
- PostHog for product analytics — page views, feature usage, conversion funnels. We do not send reviews, takedown content, raw email addresses, Stripe customer IDs, or other sensitive identifiers to PostHog.
- Sentryfor error and performance monitoring. We do not send passwords, session cookies, payment details, or raw review content to Sentry. Where stack traces include user identifiers we send only the StenoScore user ID, not the user's email.
- Vercel Web Analytics (privacy-respecting, cookie-less) for aggregate traffic metrics.
We do not use advertising-network trackers and do not allow third parties to use the Service for advertising re-targeting.
6. Cookies and similar technologies
We use a small number of cookies and local-storage entries to operate the Service:
- Strictly necessary — authentication session cookies, CSRF protection. These cannot be turned off.
- Functional — remember your interface preferences.
- Analytics — PostHog analytics cookie, where enabled. You can opt out of analytics at any time by emailing privacy@stenoscore.com.
We do not use cookies for advertising. We respond to Do Not Track (DNT) browser signals by disabling in-browser analytics capture; error monitoring and strictly necessary services are unaffected.
7. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the rights described below under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
7.1 Categories of personal information
In the past twelve months we have collected the following categories of personal information about California residents:
| Category (Cal. Civ. Code § 1798.140) | Examples for StenoScore | Sources | Purposes | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email, account ID, IP address | You; Google OAuth | Provide the Service; communicate | Subprocessors (§ 4.2); other users where you choose |
| Customer records (§ 1798.80(e)) | Phone, address, certification info | You | Provide the Service | Subprocessors |
| Internet / network activity | Pages visited, clicks, device | Automatic | Analytics, security | PostHog, Vercel, Sentry |
| Geolocation (approximate) | IP-derived city | Automatic | Security, analytics | Subprocessors |
| Professional / employment | Role, firm, bar number | You; public bar directory | Profile, verification | Other users; subprocessors |
| Inferences | None of a profiling nature | n/a | n/a | n/a |
| Sensitive personal information | None collected | n/a | n/a | n/a |
7.2 “Sale” and “Sharing” of personal information
We do not“sell” personal information for monetary consideration, and we do not “share” personal information for cross-context behavioral advertising. The subprocessors listed in Section 4.2 — including PostHog (analytics), Sentry (error monitoring), and Vercel (hosting and cookie-less aggregate analytics) — process personal information as our service providersunder written contracts that restrict their use of it to our instructions, so those disclosures are not “sales” or “sharing” under the CCPA/CPRA (Cal. Civ. Code § 1798.140). Analytics events are keyed to your StenoScore account identifier, not your email address (see Section 5).
7.3 Retention
We retain personal information only as long as needed for the purposes described in this Policy or as required by law. Specifically:
- Account data — retained for the life of your account and for 90 days after account closure for fraud-prevention and dispute purposes.
- Reviews and User Content — soft-deleted on request (hidden from the Service immediately). We target permanent deletion of soft-deleted content within 90 days, and you can request immediate permanent deletion by emailing privacy@stenoscore.com. We may retain content longer where required to comply with a legal hold, ongoing dispute, or law-enforcement request.
- Aggregate / de-identified data — retained indefinitely.
- Logs and backups — retained for up to 12 months.
7.4 Your CCPA/CPRA rights
You have the right to:
- Know — request what personal information we have collected about you and how we have used and disclosed it.
- Delete — request that we delete personal information we have collected from you, subject to legal exceptions (for example, we may retain a review where a takedown is pending).
- Correct — request that we correct inaccurate personal information.
- Opt out of “sale” or “sharing” — we do not sell or share personal information as the CCPA/CPRA defines those terms (see Section 7.2). If that ever changes, we will provide an opt-out mechanism and advance notice.
- Limit the use of sensitive personal information — we do not collect sensitive personal information beyond what you choose to include in your User Content, so this right has limited practical effect on the Service.
- Non-discrimination — we will not deny service, charge different prices, or provide a different level of service to you because you exercised any of these rights.
To submit a request: email privacy@stenoscore.comfrom the email address associated with your StenoScore account, or use the “Delete my account” control in account settings. We will verify your identity before acting and will respond within the timelines required by law (currently 45 days, extendable once by 45 days).
7.5 Authorized agents
You may use an authorized agent to submit a request on your behalf. We will ask for written permission and verification of your identity. Agents must comply with Cal. Code Regs. tit. 11, § 7063.
7.6 Shine the Light (Cal. Civ. Code § 1798.83)
StenoScore does not share personal information with third parties for those third parties' own direct-marketing purposes. To make a Shine the Light request, email privacy@stenoscore.comwith “California Shine the Light Request” in the subject line.
8. Other state privacy laws
If you are a resident of a U.S. state with a comprehensive privacy law (currently including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, and others as they take effect), you have rights similar to the CCPA/CPRA rights described in Section 7. The exact rights depend on your state of residence. To exercise them, contact privacy@stenoscore.com.
9. Other disclosures, legal process, and international users
9.1 Government and legal requests
We may disclose personal information when we believe in good faith that disclosure is necessary to:
- comply with a subpoena, court order, or other valid legal process;
- comply with a law or regulation;
- protect the rights, property, or safety of StenoScore, our users, or the public;
- investigate or prevent fraud, abuse, or security incidents; or
- defend StenoScore in a legal proceeding.
9.2 Transparency
We will, where we are not prohibited by law and where it would not undermine an investigation, give a user reasonable advance notice of a government or third-party request for their personal information and an opportunity to object.
9.3 Reviewer-identity subpoenas
If we receive a subpoena or other legal process seeking to identify a reviewer (sometimes called “unmasking”), we will, to the extent permitted by law, notify the reviewer in advance, decline to produce identity beyond what is required by the legal process, and assert applicable First-Amendment and anti-SLAPP defenses. We may charge the requesting party for reasonable costs of compliance.
9.4 International users
The Service is operated from the United States. If you access the Service from outside the United States, you understand that your personal information will be processed in the United States. We do not currently target the Service at users in the European Economic Area, the United Kingdom, or Switzerland; if we did, we would identify the legal basis for processing and the cross-border transfer mechanism we rely on in this Policy.
10. Children
The Service is not intended for individuals under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have inadvertently collected personal information from a person under 18, we will delete it promptly. Parents or guardians who believe a person under 18 has provided us with personal information can contact privacy@stenoscore.com.
11. Security
We take reasonable administrative, technical, and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- TLS encryption in transit and at-rest encryption for data we host;
- Postgres row-level security policies that restrict data access by user identity and role;
- separation of administrative and end-user roles;
- secret-handling practices that keep tokens out of logs and analytics;
- audit logging of administrative actions;
- vendor due diligence on our subprocessors.
No method of transmission or storage is perfectly secure. If we become aware of an unauthorized acquisition of personal information that triggers a notification obligation under applicable law, we will notify affected users and regulators within the required time frame.
To report a vulnerability, email security@stenoscore.com.
12. Changes to this Policy
We may update this Policy from time to time. When we make a material change, we will:
- update the “Last updated” date at the top of this Policy;
- post a prominent notice on the Service for a reasonable period; and
- where practical, send an email to the address on your account.
Material changes will not take effect retroactively. We will continue to handle previously collected information in accordance with the Policy that was in effect when it was collected, except as required by law.
13. Contact us
| Purpose | |
|---|---|
| Privacy questions, CCPA/CPRA requests, Shine the Light | privacy@stenoscore.com |
| Security disclosures | security@stenoscore.com |
| Legal notices | legal@stenoscore.com |
| General support | support@stenoscore.com |
For postal mail: StenoScore — Attn: Privacy. Our mailing address will be published here once our registered-agent setup is complete; in the meantime, contact privacy@stenoscore.com to request it.