Privacy Policy

Last updated: March 14, 2026

Podtyper (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, the legal basis for that use, and the rights you have regarding your data when you use Podtyper at podtyper.com.

This policy applies to all users, including those in the European Economic Area (EEA), United Kingdom, and other jurisdictions with data protection laws.

1. Information We Collect

We collect the following categories of information:

  • Account information: When you sign up, we collect your email address and a hashed password (or, if you use Google OAuth, your name and Google profile ID).
  • Transcription data: The podcast URLs you submit, the resulting transcript text, speaker labels, AI-generated insights, and episode metadata (title, duration, platform type).
  • Usage metrics: How many minutes of audio you have transcribed, your subscription tier, and when you created each transcription.
  • Payment information: Billing is handled entirely by Stripe. We store only a Stripe customer ID — we never see or store your full card number.
  • Analytics data: If you consent, we collect aggregated usage statistics via Google Analytics (pages visited, session duration, general location by country). See Section 5 for details.
  • Technical data: Standard server logs (IP address, browser type, pages visited) for security and debugging purposes.

2. Legal Basis for Processing (GDPR Art. 6)

We only process your personal data when we have a valid legal basis to do so:

  • Contract performance (Art. 6(1)(b)): Account registration, delivering transcription results, enforcing usage quotas, and managing your subscription. This processing is necessary to provide the service you signed up for.
  • Legal obligation (Art. 6(1)(c)): Retaining payment and invoice records for tax and accounting compliance (typically 7 years under applicable financial regulations).
  • Legitimate interests (Art. 6(1)(f)): Security logging, fraud prevention, and sending transactional service emails (e.g., subscription confirmations, payment failures). Our legitimate interest in running a secure, reliable service outweighs any minimal privacy impact of these activities.
  • Consent (Art. 6(1)(a)): Google Analytics cookies for measuring aggregate site traffic. You may withdraw this consent at any time via the cookie consent banner or by clearing your browser cookies.

3. How We Use Your Data

  • To provide the transcription service and display your results.
  • To track your usage quota and enforce plan limits.
  • To process payments and manage your subscription via Stripe.
  • To send transactional emails (e.g., subscription confirmations). We do not send marketing emails unless you explicitly opt in.
  • To improve the accuracy and performance of the service.
  • We do not sell your data to third parties. We do not use your transcript content to train AI models.

4. Data Retention

We retain your personal data only as long as necessary for the purposes described in this policy:

  • Account data: Retained until you delete your account. Upon deletion, all account data is permanently removed within 30 days.
  • Transcriptions and history: Retained until you manually delete them or delete your account. Audio files are deleted immediately after processing is complete — they are never stored long-term.
  • Payment and billing records: Retained for 7 years from the date of the transaction to comply with tax and accounting legal obligations, even after account deletion.
  • Server logs: Retained for up to 90 days for security and debugging purposes, then automatically purged.
  • Analytics data: Google Analytics retains data for 26 months by default. This applies only if you have consented to analytics cookies.

5. Cookies and Analytics

We use two categories of cookies:

  • Necessary cookies (always active): Authentication session cookies set by Supabase Auth to keep you logged in. These are strictly necessary for the service to function and do not require consent.
  • Analytics cookies (consent required): Google Analytics 4 sets cookies to measure aggregate site traffic. We only load Google Analytics after you accept analytics cookies via our consent banner. You can withdraw consent at any time by clicking “Reject optional” in the banner (which reappears if you clear your browser storage).

Analytics cookies set by Google Analytics:

CookiePurposeDuration
_gaDistinguishes unique users for aggregate traffic analysis2 years
_ga_*Persists session state for Google Analytics 42 years
_gidDistinguishes users within a 24-hour session window24 hours

6. Data Storage and Security

  • Transcripts and account data are stored in encrypted PostgreSQL databases hosted by Supabase, with row-level security enforced.
  • Audio files are not stored permanently. They are downloaded to a temporary processing environment (Fly.io worker), transcribed, and deleted immediately after the job completes.
  • All data is transmitted over HTTPS (TLS 1.2+).
  • Access to production data is limited to authorized personnel only.

7. Third-Party Services and International Transfers

Podtyper uses the following third-party services to operate. Some of these services are based outside the EEA. Where personal data is transferred internationally, we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms as required by GDPR Chapter V.

  • Supabase — database and authentication hosting (US/EU). Supabase is GDPR-compliant and provides a Data Processing Agreement (DPA). supabase.com/privacy
  • Deepgram — AI speech-to-text transcription (US). Your audio and transcript data is sent to Deepgram's API for processing. Deepgram is SOC 2 Type II certified and provides SCCs for EU data transfers. deepgram.com/privacy
  • OpenRouter / Meta Llama — AI language model for generating insights (US). Transcript text is sent to this API. OpenRouter processes data under its privacy policy and applicable data processing terms. openrouter.ai/privacy
  • Stripe — payment processing (US/global). Stripe is PCI DSS Level 1 certified, SOC 2 compliant, and provides SCCs for EU data transfers under their DPA. stripe.com/privacy
  • Vercel — hosting and CDN for the web application (US/global). Vercel provides a DPA covering GDPR-compliant international data transfers. vercel.com/legal/privacy-policy
  • Google Analytics — website analytics (US), only loaded with your consent. Google LLC participates in the EU-US Data Privacy Framework and processes data under Google's DPA with SCCs. policies.google.com/privacy

8. Your Rights

If you are located in the EEA or UK, you have the following rights under GDPR. We will respond to all valid requests within 30 days.

  • Right to access (Art. 15): You can view all your transcriptions and history in your account at any time. To request a full copy of your personal data, contact support@podtyper.com.
  • Right to rectification (Art. 16): To correct inaccurate personal data (e.g., your email address), contact us at support@podtyper.com.
  • Right to erasure (Art. 17): You can delete individual transcriptions from your history at any time. To delete your entire account and all associated data, use the Delete Account option in your account menu. Account deletion is permanent and removes all data except payment records retained for legal compliance.
  • Right to data portability (Art. 20): You can export any transcript in TXT, SRT, or VTT format from your history at any time.
  • Right to object (Art. 21): You can object to processing based on legitimate interests by contacting us. For analytics cookies specifically, you can withdraw consent at any time using the cookie consent banner.
  • Right to restrict processing (Art. 18): In certain circumstances, you can request that we restrict processing of your data. Contact us to exercise this right.
  • Right to withdraw consent (Art. 7(3)): Where processing is based on consent (analytics cookies), you may withdraw your consent at any time by clicking “Reject optional” in the cookie banner. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right to lodge a complaint: You have the right to lodge a complaint with your national data protection supervisory authority. For EU residents, you can find your local authority at edpb.europa.eu.

9. Children's Privacy

Podtyper is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email. Continued use of Podtyper after changes constitutes acceptance of the updated policy.

11. Contact and Data Controller

Podtyper is the data controller for personal data collected through this service.

If you have questions about this Privacy Policy, wish to exercise your rights, or have a data protection concern, please contact us at: support@podtyper.com