Draft — not legal advice
This document is an unreviewed draft written alongside the product. It has not been checked by a lawyer and PodDrop is not yet charging money. Do not rely on it as a binding agreement.
Last updated 4 September 2026
Privacy Policy
PodDrop holds the documents you upload, the scripts generated from them, and the audio we publish to your private feed. This explains what we keep, who else sees it, and how to make it all go away.
1. What we collect
- Account data — your email address, and a session cookie so you stay signed in.
- Content you provide — uploaded files, URLs you ask us to fetch, extracted text, generated and edited scripts, and the audio produced from them.
- Usage data — job history, episode counts and credits consumed, so we can bill correctly and show you your usage.
- Operational logs — request and error logs containing IP address and user agent, kept for a short window for debugging and abuse prevention.
- Billing data — handled by Stripe. We store a customer id and subscription state; we never see your card number.
Your feed is served from a URL containing a random token. We log feed requests in aggregate to keep the service running; we do not build a listening profile from them, and we do not know which app on which device fetched an episode beyond what an ordinary web server sees.
2. Why we hold it
To run the service you asked for: to convert your documents, to keep your feed serving the episodes it has already published, to bill you for metered work, and to fix the service when it breaks. We do not sell personal data, we do not run advertising, and we do not use your content to train models.
3. Who processes your content
Content leaves our systems only to reach the providers that do the generation, hosting and payment work:
- Google (Gemini) — script generation and default text-to-speech. Receives extracted source text and approved scripts.
- OpenAI — fallback script generation and text-to-speech. Same content, only when the default path fails or you choose it.
- ElevenLabs — premium and cloned voices. Receives approved scripts, and voice samples you record if you use voice cloning.
- Object storage and CDN provider — stores uploads, transcripts and MP3 files and serves audio to podcast apps.
- Application hosting and managed database — runs the app and stores account, job and episode rows.
- Stripe — subscriptions, payments and tax. Receives billing identity, not your documents.
- Transactional email provider — sign-in links, failure notices, billing receipts. Receives your email address.
These providers may process data outside your country. Each is used under its own data-processing terms; the current list lives on this page and material changes are announced before they take effect.
4. How long we keep it
- Uploads and extracted text — kept while the episode exists, so you can re-run or re-review a job.
- Scripts and edit history — kept with the episode. Edit history exists so the audio can be traced to the text you approved.
- Audio — kept while the episode is published to your feed.
- Logs — 30 days.
- Encrypted backups — 30 days, then overwritten.
- Invoices and payment records — as long as tax law requires.
5. Deletion, export and your rights
Deleting an episode purges its audio and transcript from object storage and removes its rows from the database. Deleting your account does the same for everything you have ever uploaded, revokes your feed tokens so the feed URL stops resolving, and removes your account row. Both are self-serve, and both are real deletions rather than a hidden flag — the deletion path is covered by tests before the service starts charging money.
You can export your account data from the app. Wherever you live, you can ask us for a copy of what we hold, ask for corrections, or ask for erasure; if you are in the EU/UK or California you have those rights by statute and we apply them to everyone.
6. Security
Traffic is encrypted in transit. Feed tokens are stored hashed, are at least 128 bits of entropy, and can be rotated at any time from the app, which invalidates the previous URL immediately. Treat your feed URL like a password: anyone holding it can listen to your episodes.
No system is perfect. If we discover a breach affecting your data we will tell you and the relevant authority within the timeframes the law sets.
8. Children
PodDrop is not intended for anyone under 16, and we do not knowingly collect their data.
9. Contact
For any privacy request, write to the support address on your receipt. The terms of service explain the rest of the arrangement.
Questions about this document? Start with the FAQ, then write to the support address on your receipt.