Draft — not yet in force
Privacy Policy
This is a draft written alongside the product rather than after an audit of it. The commitments described below are the ones this codebase is built to keep; the retention windows are the part most likely to need adjusting once the service has been running for long enough to have real numbers.
What we collect
We collect what the service needs to work, and as little else as we can get away with.
- Your email address, and a display name if you give one.
- A hashed copy of any password you set. We cannot read it.
- Which podcasts and episodes you search for, and the filters you use.
- Which alerts you set up and when they fired.
- Errors and performance measurements, which are used to fix things.
What we do not collect
We do not sell anything, and we do not build advertising profiles. There is no third-party advertising or tracking script on this site.
We do not ask for a company name, a role or a billing address unless a feature needs one.
Podcast content is not ours
The transcripts and episodes we index belong to the people who publish them. Having them in our index is not a claim on them, and our terms of service do not let you take them away as a dataset.
If you are a publisher and want something removed, ask and we will do it.
Cookies
Two cookies, both strictly necessary, and neither readable by JavaScript.
- A session cookie, so you stay signed in.
- A refresh cookie, so signing in every hour is not required.
- A cross-site request forgery token, held in memory to prove a write came from this site.
Where your data goes
Your account data goes to the database and object storage that run this service. Error reports may go to a third-party monitoring service, which processes them on our instructions.
We do not send your data to advertising networks, and we do not use it to train models.
How long we keep it
Searches and alerts are kept while your account exists, because they are your workspace. Sign-in tokens expire on their own and are deleted shortly afterwards. Error logs are kept for a limited period and then discarded.
The exact windows are not settled yet and will change as this document becomes real.
Your rights
You can see and change what we hold about you, export it, and ask us to delete it. Closing your account starts that process.
Where you are in a region that gives you more rights — the UK and EU in particular — we will honour those too, and you do not have to ask twice.
Security
Passwords are hashed and the sign-in tokens are held server-side so that a compromise of this site cannot replay them. Access to accounts requires the httpOnly cookie, which is why script running on the page cannot steal it.
No system is perfect. If you think yours has been broken, tell us.
Contact
Ask us anything about this, or about anything we hold on you, using the address on the sign-in page.