Earzbook
OpenClawHow it worksFeaturesPrivacy
Login

Privacy Policy

Last updated: 26 July 2026

This Privacy Policy governs your use of the Earzbook products operated by Earzbook.com (“Earzbook”, “we”, “us”, or “our”) and explains how we handle your information. Please also review our Terms of Service. By creating an account or using the Service, you agree to both.

Earzbook is a speech-capture, transcription, and knowledge-insight product. This Privacy Policy applies to the web app (a viewer, account, and billing dashboard at earzbook.com), the Chrome browser extension (which captures and transcribes the audio of a browser tab you choose), the Android app (which provides these same features on your phone), and an optional integration with OpenClaw, an AI agent that you install and run on your own computer. Together these let you transcribe audio, browse and search your transcripts, chat with your own AI agent about them, and derive interest and knowledge insights. The Android app offers the same features and follows the same data practices described in this Privacy Policy, so this policy applies to it as well; the main difference is that, where the extension captures the audio of a browser tab you choose, the Android app captures the audio you choose to record on your device.

Earzbook sells recording time as prepaid credits, so the Service does process payments (see “Paid Credits & Payment Data”); new accounts also receive a one-time free grant of recording time. Our server infrastructure runs on Google Cloud Platform in the Asia–Southeast (Singapore) region.

Contact: contact@earzbook.com. Governing law: India.

Overview & Scope

This Privacy Policy describes what information the Earzbook web app, Chrome extension, Android app, and backend services collect, how we use and share it, how we protect it, how long we keep it, and the choices you have. It applies to the features that are live and reachable in the current products; where a capability is not enabled, we do not collect data for it.

Some information is collected automatically as part of providing core functionality (for example, transcribing the audio you choose to capture), and some is provided by you (for example, your email address or profile details). We explain each category below.

The web app, Chrome extension, and Android app contain no advertising, analytics, crash-reporting, fingerprinting, or behavioral-tracking software of any kind. None of them access your device location (GPS), your contacts, or your camera, and they use no biometric identifiers or advertising identifiers. The web app and Chrome extension do not use your microphone at all — the Chrome extension transcribes only the audio of a browser tab you choose to record — and the Android app records audio only when you start a recording, solely to transcribe the audio you choose to capture (see “Device, App & Extension Permissions”). Your IP address is used transiently — to route traffic, enforce rate limits, and auto-detect your display currency — as described under “Information We Collect” and “Paid Credits & Payment Data.” The one exception is OpenClaw device pairing: when you pair an agent we store certain IP details as part of pairing and audit metadata, as described under “Information We Collect” and “The OpenClaw AI Agent & Relay.”

Limited Use of Data

The Earzbook web app and Chrome extension’s use of the information they receive complies with the Chrome Web Store Limited Use requirements, and the Android app follows the same principles. In particular:

  • We use the data we collect only to provide and improve the features described in this policy — capturing and transcribing the tab audio you choose, storing and searching your transcripts, generating your knowledge insights, running the OpenClaw integration you set up, and handling your account, credits, and support.
  • We do not transfer your data to third parties except to the subprocessors listed below that are needed to provide these features, to comply with applicable law or a lawful request, or to detect, prevent, or address security, fraud, or abuse.
  • We do not use or transfer your data for advertising, and we do not use it to determine creditworthiness or for any lending purpose. We do not sell your personal information.
  • Earzbook personnel do not read your transcripts, insights, or AI-chat content. The only exceptions are your explicit consent or a binding legal obligation we cannot lawfully refuse. As explained under “Security & Encryption,” your content is decrypted server-side so the Service can display it to you and generate your insights, and transcript text is sent to our AI processor (Anthropic) during knowledge processing, as described below.

Information We Collect

We collect the following categories of information from live features:

  • Account and identity information. To sign in you use one of our two supported methods in both the web app and the extension: Google sign-in (OAuth 2.0 with PKCE) or an email one-time code (OTP). From a Google sign-in we receive, from your Google ID token, your email address, name, given and family name, locale, profile-picture URL, your Google account ID, and whether your email is verified; a unique username is automatically derived from your email on first sign-in. With email OTP we receive your email address and the code you enter. In the web app’s Settings you may optionally set a username, a display name, and a profile photo. We do not collect your age or gender. If your account was created without an email address, the web app lets you add and verify one.
  • Authentication and session data. An application access token (a long-lived JWT) issued after sign-in; a per-installation device identifier (a random value generated on install — not a hardware or browser fingerprint); and your app/extension version. Email one-time codes are stored only as a bcrypt hash, never in plaintext, and expire after 10 minutes.
  • Audio you choose to capture. In the Chrome extension, when you start a recording we capture the audio of the specific browser tab you are recording — not your microphone, your screen, or your system/desktop audio. Capture only begins on a fresh user action (a toolbar click, pressing play, or the keyboard shortcut). In the Android app, capture likewise begins only when you start a recording, using the device audio-recording permission, and covers the audio you choose to record on your device. In every case, raw audio is processed transiently for transcription and is never stored by us (see “How Audio, Transcripts & AI Chat Are Processed”).
  • Transcripts. The text produced from your audio, with timestamps and session-end markers, organized by your device’s local calendar day, plus your chosen transcription language (about 99 languages, or auto-detect). Only transcript text is saved — there is no audio field and no upload path.
  • Derived AI insights. From your transcripts we derive interest labels, theme classifications, context summaries, and numerical embedding vectors used for search and insights, together with the verbatim transcript passages surfaced in the Insight and Theme views.
  • OpenClaw pairing and chat data. When you pair a self-hosted OpenClaw agent, we store pairing metadata (the machine identity your agent reports — hostname, platform, architecture, OS release, and CLI version, all self-reported and unverified — the request IP address and IP network, user agent, and approver IP), and one-way SHA-256 hashes of the device and MCP tokens (the plaintext tokens are shown once and never stored). Chat message content is not stored on our backend; chat titles are synced encrypted; session metadata (an opaque session key, a pin, and timestamps) is stored in plaintext.
  • Billing and credits data. Your credit balance and an append-only credit ledger (stored as recording seconds, never as a money value) and, for each purchase, transaction metadata (order id, payment-provider order and payment ids, amount in minor units, currency, status, pack id, credits/seconds granted, a frozen catalog snapshot that serves as your receipt, and timestamps). We do not receive or store any card, UPI, or bank details.
  • Recording and session metadata. Session start/end timestamps, a per-account recording-lock record (device identifier and whether the source is the app or the extension), a metering ledger tied to the recording lifecycle, and your device time zone/UTC offset (so “today” resolves to your local day).
  • Technical data. Standard information involved in any internet request, including your IP address, which our servers generally process transiently to route traffic, enforce rate limits, and auto-detect your display currency (via an offline database — your IP is not sent to a third party for this). The exception is OpenClaw device pairing described above: the request IP address, IP network, and approver IP are stored as part of pairing and audit metadata, and are retained (soft-revoked, not deleted) when you unpair a device. Profile photos you upload are hosted through our image provider.

How Audio, Transcripts & AI Chat Are Processed (and by Whom)

Audio. When you record with the extension, the tab audio is downsampled to 16 kHz mono PCM16 and streamed over a secure WebSocket to Earzbook’s own self-hosted speech-to-text service (a faster-whisper model that we operate on Google Cloud Run). It is transcribed in real time, and only the resulting text is returned to your device and our backend. On the server the audio exists only in an in-memory rolling buffer that is trimmed as words are committed and is never written to disk. We do not upload or store raw audio files, and audio is not sent to any third-party transcription vendor. A local passthrough routes audio back to your speakers so you continue to hear it at full quality.

Transcripts. Finalized transcript lines are saved locally on your device (including a durable retry queue and a per-tab snapshot) and synchronized to our backend, where they are stored encrypted at rest under a key unique to you (see “Security & Encryption”). Transcript text is also processed by our knowledge service to generate the insights and search index that power the Insight and Theme features.

AI knowledge processing. While you record, the extension triggers knowledge processing when recording starts, every five minutes during recording, and when it stops. During this processing, transcript paragraph and sentence text is sent to Anthropic’s Claude API to produce interest labels, context summaries, validation, and discourse segmentation, and is then returned. Embeddings are computed in-house on our own self-hosted models, so no third-party embedding vendor sees your text. Our vector database (Pinecone) receives only the numerical embedding vectors plus non-text metadata; the verbatim and derived text is stripped before it reaches Pinecone and kept only in encrypted, per-user form in our primary database.

Insight and Theme views. The web app’s Insight tab shows a Knowledge Radar and a progress Timeline derived from the labels above. Opening a specific Theme shows the interests and the actual verbatim transcript passages classified under that theme, which are decrypted server-side at the time you read them.

The OpenClaw AI Agent & Relay (Runs Locally on Your Computer)

OpenClaw is an AI agent that you install and run on your own computer; it is not hosted by us. Chatting with it is an AI-agent conversation, not a person-to-person feature — you are talking to your own agent, not to other Earzbook users.

Codeless pairing. Pairing is authorized through a consent screen in the web app; there are no user-visible pairing codes. We store the pairing metadata described under “Information We Collect” and keep only one-way SHA-256 hashes of the device and MCP tokens. An authorization request expires after 10 minutes, and when you unpair a device its record is soft-revoked (kept as an audit record) rather than deleted.

Account-scoped read access. Your own agent can read your own recordings and insights through a set of read-only tools scoped to your account. This returns verbatim transcript text and insights to your agent; what your agent then does with that information is under your control, on your machine.

Where chat lives. OpenClaw chat message content is not persisted on Earzbook’s backend — it lives on your own machine and is cached in your browser’s local storage. Only chat titles sync to our backend, encrypted at rest; session metadata (an opaque session key, a pin, and timestamps) is stored in plaintext, and message previews never sync.

The relay. While your OpenClaw machine is online, messages between the web app and your agent pass through our relay in memory and are not stored. The client blocks you from sending when your agent is offline (it does not buffer on your device). However, the relay maintains a bounded server-side buffer of up to 50 app-to-agent messages: if your agent is briefly offline, those pending messages may be held in plaintext in our database until your agent reconnects and receives them, after which they are cleared. These buffered messages are not end-to-end encrypted and are not encrypted at rest during that short window; agent replies produced while your app is not connected are dropped rather than stored.

How We Use Your Information

We use the information we collect to:

  • provide the core Service — capture and transcribe the audio you choose, and store, browse, and search your transcripts;
  • authenticate you, keep your account secure, and enforce a single active recording per account across your devices;
  • generate your interest and knowledge insights (Knowledge Radar, themes, and progress timeline) and the semantic search that powers them;
  • enable the OpenClaw AI agent integration you set up, including account-scoped read access for your own agent and the message relay;
  • process credit purchases, grant recording time, maintain a metering ledger of recording time tied to your credit balance (and, where enabled, debit usage against that balance), and handle refunds;
  • operate, secure, and troubleshoot our infrastructure, prevent abuse, and enforce rate limits;
  • communicate with you about your account — for example, sign-in codes, and account-deletion or restoration notices; and
  • comply with applicable law.

We do not use your information for advertising, and we do not sell your personal information.

Paid Credits & Payment Data

Earzbook sells recording time as prepaid credits, so the Service is not free-only and we do process payments. Credits are stored as recording seconds, never as a money value (one credit equals 3,600 seconds, or one hour). New accounts receive a one-time 30-minute (1,800-second) free grant, which is not recurring.

Payment gateway. Razorpay is our sole active payment processor, and all supported currencies (INR, USD, EUR, GBP, AUD, CAD, SGD, and AED) are processed through it. Checkout is web-only: the extension’s “Buy” option opens a focused web checkout window — your access token is never placed in the URL — which starts Razorpay’s hosted checkout.

What Razorpay handles versus what we store. Your card, UPI, or bank credentials are entered on Razorpay’s own hosted checkout surface and are never received or stored by Earzbook. Earzbook prefills only your name (your email prefix) and email address into the Razorpay modal, and stores only the transaction metadata described under “Information We Collect” (order and payment identifiers, amount, currency, status, pack, credits granted, a receipt snapshot, and timestamps) plus an append-only credit ledger. Credits are granted only by a payment webhook whose signature we verify (HMAC); browser “success” callbacks are not trusted. Refunds are processed by webhook and reverse credits proportionally.

Currency detection. Your display currency is auto-detected (from your explicit choice, then your last paid currency, then IP-to-country mapping via an offline database, your device time zone, and locale, defaulting to USD) and can be overridden. Non-INR prices use live exchange rates fetched server-to-server from an external rates service; no user or financial data is sent to that service, and your IP address is not sent externally for currency detection.

Third-Party Subprocessors

We use a limited set of service providers to operate the Service. Each receives only the data needed for its function. We do not use advertising networks, analytics vendors, or data brokers. The providers below are the ones actually used by the web app, extension, and Android app today.

ProviderPurposeWhat it receives
Google Cloud Platform (Cloud Run, Cloud KMS & Artifact Registry)Hosts all backend services and our first-party self-hosted transcription service (Singapore); Cloud KMS wraps and unwraps each user’s data-encryption key; Artifact Registry stores build images onlyAll backend HTTP/WSS traffic transits Cloud Run (transcripts, profile data, the audio stream, and payment metadata). Cloud KMS receives only wrapped key material — never your plaintext content.
Self-hosted Whisper transcription (first-party, on Google Cloud)Real-time speech-to-text; company-operated, not a third-party ASR vendorTransient 16 kHz PCM16 audio frames, your access token, session id, and selected language. Audio is processed in memory and never persisted.
MongoDB AtlasPrimary datastore for user data (transcripts, profiles, key material, OTP hashes, orders and credit ledger, analytics)All persisted user data; sensitive fields are per-user AES-256-GCM encrypted. The cluster region is configured by us; contact us if you need it confirmed.
Google OAuth“Sign in with Google” (PKCE; the code-to-token exchange runs server-side)The OAuth authorization code / ID token exchange. We receive your email, name, given and family name, locale, profile-picture URL, Google account id, and email-verified flag.
Anthropic (Claude API)Knowledge-processing AI — interest labeling, theme classification, summarization, and discourse segmentation, run whenever you record via the extensionVerbatim transcript paragraph and sentence text plus derived labels, sent transiently at ingest time.
PineconeVector database powering the Insight and Theme semantic searchNumerical embedding vectors and non-text metadata only. Verbatim and derived text is stripped before upsert and stored encrypted elsewhere.
CloudinaryHosting and serving profile photos (web only)The profile image you upload, its filename, and MIME type; returns a URL stored on your record.
Email delivery provider (SMTP)Sending email one-time codes, email-link verification, and account deletion/restore noticesYour recipient email address and the 6-digit code or notice content. The exact vendor is set by configuration.
RazorpaySole active payment gateway for credit purchases (all supported currencies), via web-only hosted checkoutOrder amount, currency, our order id, the pack and user id in notes, and your name (email prefix) and email prefilled into the modal. Card/UPI/bank credentials are entered on Razorpay’s surface and are never sent to or stored by Earzbook.

Two additional services receive no personal data: our exchange-rate source (an outbound request for rate data only) and our IP-to-country lookup (a bundled offline database queried in-process, so your IP never leaves our servers). OpenClaw runs on your own computer and is configured by you; it is not a subprocessor we operate. We may update this list as our providers change and will reflect changes in this policy.

Cookies, Analytics & Tracking

The Earzbook web app, Chrome extension, and Android app contain no analytics, advertising, crash-reporting, fingerprinting, or behavioral-tracking software. We do not use tracking cookies (the web app does not use document.cookie), and we do not track you across other apps or websites. The extension enforces a strict content-security policy that only allows scripts from itself.

The extension and web app store data locally in your browser (extension storage, localStorage, and sessionStorage), and the Android app stores your transcripts and session data locally on your device — such as your session token, preferences, recording state, a durable transcript retry queue, and a credits cache — strictly to make the products work and to provide the Service offline and in real time. This local storage is not used for tracking and is cleared on sign-out.

Security & Encryption

We use technical and organizational measures designed to protect your information, including:

  • Encryption in transit. Connections between our clients and our production services — including the audio stream to our transcription service and the OpenClaw relay — use TLS and secure WebSockets (HTTPS/WSS). Our backend runs behind Google Cloud Run’s TLS termination with HTTP security headers, a cross-origin allowlist, and input sanitization against NoSQL injection.
  • Per-user encryption at rest. Your transcripts and live-entry payloads, AI chat history and summaries, OpenClaw chat titles, and free-text notes are encrypted at rest using AES-256-GCM under a 32-byte data-encryption key unique to you. That per-user key is itself stored only in a form wrapped by Google Cloud KMS, and plaintext keys are held only briefly in a bounded in-memory cache — never written to disk. A database copy alone cannot read this content.
  • This is encryption at rest, not end-to-end. By design, our servers decrypt this content in memory to serve it to you and to call the AI knowledge service. Transcripts and AI content are therefore readable by Earzbook’s servers and are not end-to-end encrypted. We also do not offer end-to-end encrypted user-to-user messaging in the web app or extension.
  • Migration in progress. We are migrating existing data to the per-user scheme above. Some older, not-yet-migrated data remains encrypted under an earlier scheme that used a single shared key rather than a per-user key, so we cannot represent that all data at rest is currently protected by the stronger per-user encryption.
  • Sign-in code handling. Email one-time codes are stored only as a bcrypt hash, expire in 10 minutes, have a 60-second resend cooldown, and allow at most five attempts.
  • Pairing-secret handling. OpenClaw pairing, device, and MCP secrets are stored only as one-way SHA-256 hashes; plaintext tokens are shown once and never persisted; authorization requests expire in 10 minutes. Google sign-in uses PKCE, with the client secret kept server-side.
  • Abuse prevention. Per-user-keyed rate limiting and a single-active-recording lock per account.

No method of transmission or storage is completely secure. Certain data required for AI and knowledge features is, by design, stored in a form our servers can process; and, as noted above, messages queued for a temporarily offline OpenClaw agent may be held briefly in plaintext to enable delivery, then cleared. We cannot guarantee absolute security, and you use the Service at your own risk.

Data Retention

We keep information for as long as needed to provide the Service and for the periods below:

  • Transcripts and derived insights are kept until you trash and delete them or delete your account.
  • Trashed transcripts are soft-deleted and then automatically and permanently purged 30 days after being trashed by a daily job. Choosing “delete permanently” removes the transcript immediately and also removes its embedding vectors from our vector database along with the related analytics and paragraph-index entries.
  • OpenClaw chat message content is not retained on our backend (it lives on your machine and in your browser storage); chat titles are retained encrypted, and session metadata is retained. The relay’s offline buffer holds at most 50 undelivered messages briefly and clears them on delivery.
  • Sign-in codes and OpenClaw authorization codes expire within about 10 minutes or on use.
  • Credit ledger and order records are append-only and retained indefinitely for financial and audit purposes.
  • Account data is retained until you delete your account, subject to the deletion process below.

Data Deletion & Cryptographic Erasure

You have several ways to remove data, and it is important to understand exactly what each one does:

  • Deleting a recording. Moving a recording to Trash soft-deletes it; permanently deleting it removes the transcript immediately and removes its searchable embedding vectors, daily analytics, and paragraph-index entries.
  • Account deletion. You can request account deletion in the web app’s Settings (confirmed by an emailed code). Deletion has a 14-day grace period: signing in again within that window automatically restores your account. After the grace period, a daily job permanently and cascadingly purges your transcriptions, live-entry tail, knowledge cache, processing state, progress analytics, AI summaries, shared-content preferences, and your user record, and destroys (crypto-shreds) the per-user encryption key and device keys held for your account. Destroying those keys is a cryptographic erasure that renders content encrypted under them permanently unreadable, even where a stored record is not physically removed.

Please note precisely what is not removed by account deletion. For deliberate reasons, some records are intentionally retained: your knowledge embedding vectors in our vector database are not deleted; certain derived analytics ledgers may persist; and your order, credit-ledger, and credit-balance records are retained for financial and audit purposes. In addition, a record of your email address is retained indefinitely after deletion to prevent re-registration with the same address. If the retention or erasure of a specific item matters to you, contact us at contact@earzbook.com and we will address it.

Device, App & Extension Permissions

The Chrome extension requests only the permissions it needs to capture and transcribe tab audio and to keep that process running. Each is justified below.

PermissionWhy we request it
tabCaptureCapture the current tab’s audio (via a user-gesture stream id) for transcription
offscreenHost the audio graph and transcription WebSocket so recording survives service-worker eviction
scriptingInject the transcript sidebar and recording UI (there are no declarative content scripts)
identityGoogle sign-in via the browser’s web-auth flow (PKCE)
storagePersist the session token, preferences, recording state, the durable transcript retry queue, and the credits cache
activeTabGesture-scoped access to the active tab to acquire the audio stream and inject UI
alarmsTrigger periodic knowledge processing every five minutes while recording
commandsThe keyboard shortcut to start and stop recording
action (toolbar)Start/stop control and the credits badge (badge only; no notifications permission)
externally_connectable (earzbook.com)Hand off your access token to the web app for checkout over an origin-gated channel (never via the URL)
host_permissionsBroad host access to all sites (*://*/*) so the extension can inject the transcript sidebar and capture tab audio on whatever page you choose to record, and reach our first-party backend and transcription endpoints. The extension only activates on a page when you start a recording.
OAuth scopes: openid, email, profileGoogle sign-in identity

The extension does not request content scripts, notifications, geolocation, webRequest, cookies, history, bookmarks, downloads, or clipboard access. The web app uses only ordinary browser storage and the same Google OAuth scopes, with no special browser permissions.

Android app. The Android app requests only the device permissions needed to provide these same features on a phone — in particular, permission to record audio so it can capture and transcribe the audio you choose, the ability to keep a recording running in the background with a persistent notification while it is active, and network access. It does not access your location, contacts, or camera, and it contains no advertising, analytics, or tracking software. Recording happens only when you start it, and you can stop it at any time.

International Data Transfers

Earzbook operates from India and hosts its core infrastructure on Google Cloud in the Asia–Southeast (Singapore) region. Some of our subprocessors — for example Anthropic, Google, Cloudinary, Pinecone, and Razorpay — may store or process data in other countries, including India, the United States, and the European Union. By using the Service, you understand that your information may be transferred to, stored in, and processed in countries other than your own, which may have different data-protection rules. We take steps designed to ensure your information receives an appropriate level of protection wherever it is processed.

Children's Privacy

The Service is not directed to children, and we do not knowingly collect personal information from children below the age at which consent is required under applicable law. The live product does not collect age or gender. If you believe a child has provided us personal information without appropriate consent, please contact us at contact@earzbook.com and we will take reasonable steps to delete it.

Your Rights & Choices

Subject to applicable law, you may:

  • Access and update your profile information (username, display name, and profile photo) in the web app’s Settings;
  • Delete individual recordings, and delete your account entirely (see “Data Deletion & Cryptographic Erasure”);
  • Control recording — capture only occurs when you start it, only for the tab you choose, and you can stop it at any time;
  • Manage OpenClaw — pair and unpair (revoke) devices at any time; your agent runs on your own machine under your control;
  • Manage your credits and receipts — view your purchase history and order status in the web app; and
  • Request a copy of your personal information, or ask questions about our processing, by contacting us.

To exercise any right not available directly in the product, email contact@earzbook.com. We may need to verify your identity before acting on a request.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. When we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice within the Service. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.

Privacy Contact

If you have questions, concerns, or requests regarding this Privacy Policy or your information, contact us at contact@earzbook.com.

Earzbook

Live transcription of everything you hear — handed to an AI agent you own.

Powered byOpenClawOpenClaw

Product

  • Get the Android app
  • Add to Chrome
  • How it works
  • Features

Company

  • Privacy Policy
  • Terms of Service
  • Contact

© 2026 Earzbook. All rights reserved.

Hear beyond words · contact@earzbook.com