Privacy Policy

This policy explains what personal data Podzone collects, why, who we share it with, how long we keep it and what rights you have over it. It applies to visitors to this website, to customers of the service, and to people who contact us.

1. Podcast content is not covered by this policy

Podzone indexes podcasts that their publishers have already made public. Those episodes, their transcripts, and any names or organisations spoken about in them are third-party published content. They are not personal data that we collect about you, and this policy does not treat them as such.

Everything below is about the data we hold on customers and visitors: your account, the alert rules you configure and how you use the service. Section 8 deals separately with people who appear in podcast content.

2. Who we are

Podzone is the controller of the personal data described in this policy. Contact: [email protected].

3. What we collect

Account data, provided by you when you register:

  • your email address and, optionally, your name;
  • your organisation's name and the plan it is on;
  • your credentials. Podzone has no passwords. You sign in with a single-use link sent to your email address, and we store only a one-way hash of that link's token, never the token itself.

Product data, created as you use the service:

  • the alert rules you configure — the keywords and questions you monitor for;
  • the matches those rules produce, including a short excerpt of the transcript around each mention, and which matches you have read;
  • API keys you create, and counts of API requests made with them per time window, which is how quotas and rate limits are enforced. We do not log the individual requests themselves — no URLs, query strings, IP addresses or user agents;
  • sign-in records: a hashed session token and when it was last used.

We do not record your searches. Searches are answered and not stored: there is no search history, and we cannot tell you or anyone else what you have searched for.

Correspondence: messages you send us, and anything in them.

Technical data: our infrastructure provider processes network-level data such as IP addresses and request headers to route traffic and block abuse.

We do not collect:

  • payment card details. There is no billing system yet; when one is added, this policy will be updated to say who processes payments and what they receive;
  • special categories of personal data — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, sex life or sexual orientation;
  • data from children (see section 12).

4. Why we use it, and our lawful basis

  • To provide the service — running your alert rules, delivering matches, answering your searches and serving the API. Basis: performance of a contract.
  • To authenticate you and secure your account — issuing and checking credentials. Basis: performance of a contract, and our legitimate interest in keeping the service secure.
  • To enforce quotas and prevent abuse — counting API requests, investigating suspected misuse. Basis: legitimate interest.
  • To support you — replying to your messages. Basis: performance of a contract, and legitimate interest.
  • To operate and improve the service — diagnosing faults and understanding aggregate usage. Basis: legitimate interest.
  • To meet legal obligations — tax, accounting and lawful requests. Basis: legal obligation.

We do not sell personal data, share it with advertisers or data brokers, or use it for advertising. We do not use your alert rules or account data to train machine learning models.

Where the service uses a language model — to judge whether a keyword match is genuinely about what you are monitoring — that model runs on our own infrastructure. Your alert rules and the transcript text they are evaluated against are not sent to any third-party AI provider.

5. Who we share it with

We share personal data only with the service providers that operate Podzone, each processing it on our instructions and for no other purpose:

  • DigitalOcean — application hosting and the managed database holding account and product data. United States.
  • Cloudflare — DNS, TLS termination and edge protection for our websites, and the object storage (R2) holding transcripts and, transiently, audio being processed. Network metadata; global edge.
  • Resend — delivery of the emails we send you: alert notifications and login links. Receives your email address and the message. United States.
  • Paddle — payment processing. Receives your payment information and email address. US / UK.
  • Plausible Analytics — website analytics. Receives anonymized usage data. US / EU.

Transcription runs on our own hardware, using models we host ourselves. Podcast audio is not sent to a third-party transcription service, and no third-party AI provider receives transcripts, your alert rules or your data.

We may also disclose personal data where the law requires it, to establish or defend legal claims, or in connection with a merger, acquisition or sale of assets — in which case we will tell you before your data becomes subject to a different policy.

6. Where your data is stored

Podzone runs in the United States which is where our primary infrastructure and data storage are located.

If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to and processed in the United States.

7. How long we keep it

We keep personal data for as long as we need it to provide the service, and then only as long as the law requires.

  • Account data — for the life of your account.
  • Alert rules and matches — for the life of your account, or until you delete them.
  • Credentials — login links expire shortly after they are issued and are deleted once used or once expired; session tokens expire and are deleted when you sign out; API keys last until you revoke them.
  • API usage counts — per-minute counts for 2 days, per-day counts for around 13 months.
  • Transcripts — retained indefinitely. Transcripts are the service's corpus rather than customer data, and are not deleted when an account closes. See section 8.
  • Podcast audio — deleted as soon as an episode has been transcribed. We do not keep a copy of the audio.

8. People mentioned in podcasts

Podzone transcribes podcasts that are already public, and those transcripts inevitably contain the names of hosts, guests and people discussed on air. We process that content to make it searchable, on the basis of our legitimate interest in providing a search and monitoring service over published material, and we do not use it to build profiles of individuals.

If you appear in podcast content indexed by Podzone and want to raise a concern about it, contact [email protected]. Note that we do not control the original recording: removing a transcript from our index does not remove the episode, which remains published by whoever made it.

9. Security

We protect personal data with measures appropriate to the risk, including encryption in transit, restricted administrative access, and network-level protection against abuse. Because there are no passwords, there is no password database to steal. Sign-in tokens and API keys are stored only as one-way hashes and compared in constant time, so a copy of our database does not yield a working credential.

If you believe your account has been compromised, contact [email protected] immediately. We will notify affected users and the relevant authorities of a breach within 72 hours where required by GDPR Article 33.

10. Cookies and tracking

Plausible Analytics is used for website analytics. It receives anonymized usage data and does not track you across sites.

Our network provider, Cloudflare, may set a cookie of its own to distinguish automated traffic from real visitors. That is a security measure, not analytics, and it does not track you across sites.

The Podzone application, once you sign in, stores a sign-in token in your browser so that you stay signed in. That is functional and necessary to the service; it is not a tracking cookie and is not used for advertising.

11. Children

Podzone is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we rely on it. Where the GDPR or UK GDPR applies you also have the right to complain to your data protection supervisory authority.

If you are a California resident, you have the right to know what personal information we collect and how we use it, to have it deleted or corrected, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law.

To exercise any of these rights, email [email protected]. We will verify your identity before acting and respond within the period the law allows. (30 days under the GDPR, 45 under the CCPA.)

13. Changes to this policy

We may update this policy as the service changes. When we make a material change we will, if you are a customer, notify you by email.

14. Contact

Questions about this policy or about your personal data: [email protected].