Privacy Policy

Last updated: September 15, 2026

This Privacy Policy describes how the operator of PodGuard collects, uses, discloses, retains, and protects personal information when you use the PodGuard application, podguard.app, and the related account, subscription, episode-processing, and support services. It also explains the choices and legal rights that may be available to you.

1. Scope and summary

PodGuard does not sell or rent personal information, display third-party advertising, or track you across unaffiliated applications and websites. The application does not request access to your microphone, camera, photos, contacts, or precise location.

We process the information reasonably necessary to provide and secure the Services: account and subscription records, a protected identifier for each installation, episode-processing and credit records, limited product analytics, and information you deliberately submit in a report or support request.

In this Policy, "PodGuard," "we," "us," and "our" refer to the operator of PodGuard, and "you" refers to the individual using the Services. This Policy applies to the PodGuard application, website, processing systems, account and subscription features, and support. It does not govern third parties acting under their own privacy policies.

2. Your account, and what it holds

During onboarding, we ask for your first name and an optional last name. We save the names you provide with your account for personal greetings and customer support. They may appear with your account in our private PostHog support information. We do not use them for advertising or sell them. You can change your name on the account name page; deleting your account removes the names from our account records.

PodGuard requires an account. You create one when you first open the app, or here on the website, and either one works in both places. An account is what a subscription is attached to, what carries your plan across devices, and what survives a new phone, so it is what we ask for before the app will prepare anything. It is also the reason we hold an email address for you at all.

An account made with an email address and a password means we store:

If you use Sign in with Apple, we store the identifier Apple gives us and the email address Apple provides, which may be a private relay address. PodGuard does not retain the name Apple may provide, and we never receive your Apple ID password.

3. Your installation of the app

Your account is not the only thing we can tell apart. Each installation of the app also registers itself with our server, the first time it needs something from us, and it does that on its own rather than as part of signing in. That registration uses Apple App Attest, which lets Apple vouch that the request came from a genuine, unmodified copy of PodGuard on real Apple hardware.

What we keep from it is a key identifier, the public key Apple attested, a hash of the access token issued to that installation, and the date. We link registered installations to your account to share credit balances and processing limits across the website and your linked iPhone installations. We keep installation identifiers to authenticate app requests and preserve independently supplied Apple entitlements. It exists because the alternative is a single shared key that anyone could pull out of the app and use to spend our processing budget.

App Attest does not tell us who you are. It does not give us your Apple ID, your name, your phone number, your device's serial number, or an identifier that any other app or website can recognize.

4. Preparing episodes, and the records it leaves

When you prepare an episode, the app or website sends our server the episode's public audio address, its identifier from the feed, the show and episode titles, and the requested filtering settings. The server records which account or installation requested the work, its status, the processing time, and the credit reserved, spent, or refunded. Linked installations and the website use the same account allowance.

We keep those records for three plain reasons, and no others:

Shared processing results and their cut lists are stored against the episode rather than against you. An authorized listener may reuse a compatible existing result. Browser listening also creates a private prepared-audio file and an account-specific access record. Your browser Library and access records identify which prepared episodes your account can play; shared processing results themselves are not labeled with your account identity.

The iPhone app keeps your playback position on your device unless you explicitly enable listening sync in a version that supports it. Depending on the app version, it sends our server an episode-level playback signal or a session identifier and cumulative listening duration. These support prepared-audio retention and usage measurement. Seeking does not count as listening time. Older app versions send only a best-effort retention signal, limited to once every six hours for the same episode in the running app.

For browser listening, we store your account's playback speed, volume, and per-episode playback position on our server so the browser can restore them after a refresh or another sign-in. We also record listening-session timing and credited listening duration to apply the five-minute credit threshold for an already-prepared episode and prevent duplicate charges. The filtering settings requested for an episode are kept with its preparation record. Optional listening sync can connect supported devices to shared positions, a queue, playback speed, and filter defaults. Each device must be explicitly connected before it reads or uploads that shared state.

5. Episode audio, and who processes it

Our server obtains a requested episode from its publisher's public feed. Cloudflare Workers AI performs whole-episode speech-to-text and may perform a configured initial pass. AssemblyAI performs a latency-sensitive pass over the beginning of the episode and may review bounded audio windows when the ordinary transcript is uncertain. Transcript excerpts may be sent either through OpenRouter to a selected language-model provider or directly to OpenAI to identify ad reads, identify mature-topic passages under the selected settings, and resolve bounded filtering uncertainty. These providers receive the podcast audio or transcript content and technical request information needed for processing, not your email address, password, account credentials, or payment information.

The processed audio is the publisher's podcast, not a recording of you. PodGuard does not activate or request your microphone. Results may be stored by episode so another authorized listener requesting the same public episode can use the existing result instead of causing duplicate processing. Shared results are not labeled with your account identity. We may change providers as the Services develop and will update this Policy when a change materially affects these disclosures.

6. What stays on your device

The following iPhone app data stays on your phone unless you choose a supported sharing feature. A shared account allowance alone does not enable listening sync:

If you connect Spotify to import the shows you follow, the connection is optional, the access and refresh tokens are held in your device's Keychain and never sent to us, the imported list of shows stays on the device unless you separately connect supported follow syncing, and you can disconnect at any time.

The app can send you a notification when an episode is ready, but only if you allow notifications. Those are scheduled locally on the device. PodGuard has no push service and no device push token.

When you connect listening sync, your account stores episode feed addresses, episode identifiers and titles, show titles, the recording identity and saved position, completion state, your queue, playback speed, and supported filter defaults. A supported iPhone version can upload previously local listening history after your explicit confirmation. Audio files, downloads, recent searches, and local listening statistics are not uploaded by sync. Followed shows use a separate account record. Merely connecting devices never prepares or purchases an episode.

You can disconnect a device, or delete shared positions, the queue, and preferences from sync settings, which also disconnects every device. Local audio and followed shows remain. Connection-choice versions and dates are retained with your account so we can honor and document your choices. Deleting your account removes these sync records. Supported devices preserve offline changes and ask you to resolve conflicts instead of silently overwriting newer state. Read the listening sync notice before connecting.

7. Subscriptions and payments

We never see your card details. Neither shop hands them over, and we have no field to put them in.

We keep these records to honor subscriptions, resolve billing and support issues, and measure confirmed purchases, renewals, cancellations, refunds, and failed payments.

8. Reports and diagnostics you send us

PodGuard processes limited automatic analytics and two categories of information that are sent only when you deliberately submit a report.

Report an issue, in the player, tells us about a cut that went wrong. It sends the episode identifier and titles, where in the episode you were, what was cut nearby, your filter level, the app version, whatever note you typed, and a reply address if you chose to give one. It is otherwise anonymous. Reports go to our review process; they do not automatically change anything for other listeners.

Send a report, in Settings, sends timestamps, subsystem categories, coarse crash metadata, a reference code, and application, iOS, and device versions. The "Include episode IDs and log text" control is on by default and may add episode identifiers and the log's own messages, which can name shows and feed addresses. You may turn that control off before sending. Diagnostic reports never contain audio, transcripts, cut content, your name, email address, Apple Account, precise location, contacts, or photos.

Automatic product and error analytics go to PostHog. PodGuard measures account creation, checkout and confirmed billing outcomes, preparation timing and failures, playback sessions, listening duration, return use, use of the homepage podcast search, visits from specifically labeled PodGuard campaign links, and anonymous qualified website sessions. A qualified website session is counted once per browser tab only after a page has remained visible for at least eight seconds and the visitor scrolls, clicks, taps, or types. It includes a coarse page category, the kind of interaction, and a random identifier limited to that tab session. Homepage search analytics include the exact search text and the same tab-limited identifier. Campaign measurement includes the campaign label and whether an attributed visit reached account creation and confirmed email verification. The campaign completion count is sent as a separate anonymous event and is not added to the account's email or PostHog profile. Other analytics may include your account identifier and email address, podcast show title, platform and app version, durations, counts, and sanitized failure categories. Email helps us locate the correct account during support; show titles help diagnose preparation and playback problems. Server reporting also includes processing counts, pseudonymous prepared-episode identifiers, and provider usage and cost evidence. We do not send Discover searches, transcripts, custom filter words, feedback text, feed URLs, precise location, full website addresses, referrers, or raw server responses to product analytics. Session replay, screen recordings, general automatic pageview or click capture, and tracking across other apps or websites remain disabled. Our browser event collection respects Do Not Track and Global Privacy Control signals.

9. Using this website

This site runs no advertising-network analytics, cross-site tracking scripts, or tracking cookies.

If you sign in here, your browser stores one item in local storage holding your session token and a cached copy of your email address and plan, so the page can label itself without asking the server every time. Signing out removes it.

Search on this site calls Apple's public podcast search directly from your browser, and podcast artwork is loaded straight from Apple's image servers. That is how those APIs are meant to be used, and it means Apple receives your IP address and your search text for those requests, exactly as it would if you searched in Apple Podcasts. When your browser cannot make that call, the search falls back through our own server instead, which caches the results of a search term for fifteen minutes without attaching it to anyone. On the homepage only, pausing after typing at least two characters or pressing Search also sends the trimmed search text to PostHog. A random identifier stored only for the current browser tab session lets us count searchers without creating a person profile. The event does not include the page URL or your PodGuard account.

When a PodGuard QR code or campaign link includes a short campaign label, the homepage sends one campaign-visit event for that browser tab and temporarily remembers the label in that tab. If you create an account in the same tab, the label is kept only until email verification so PodGuard can count a confirmed conversion. The completion event is anonymous and separate from your account analytics. This is not general pageview tracking.

This site also sends one anonymous qualified-session event after the page has remained visible for at least eight seconds and you interact with it. Ordinary page loads, the specific element you use, form values, full website addresses, and referrers are not included. This measurement is intended to separate meaningful visits from automated requests without creating a person profile.

This site loads its typeface from Google Fonts, which means Google receives your IP address when a page loads. Sign in with Apple loads a script from Apple. Checkout loads Stripe, and choosing a homepage video loads YouTube. Homepage search, labeled campaign, and qualified anonymous session measurements go directly to PostHog. Other authenticated browser product events go to PodGuard's server, which forwards approved fields to PostHog.

Cloudflare serves and secures this website and processes ordinary request information, including IP addresses and browser headers, under its own operational logging practices. PodGuard does not maintain a separate raw first-party log of ordinary website requests; the limited qualified-session measurement is described above.

Your saved website filter preferences and whether you have finished setup are stored by Cloudflare under an account identifier. They expire after 180 days without use. Saving these website preferences does not turn on listening sync with the iPhone app.

Before the browser sends newly added account email and show-title analytics, it asks you to review the updated policy. The updated iPhone app separately offers a choice to share listening and support details, which you can change in Settings under Legal. Older app versions continue to use their existing limited measurement. Basic account, payment, service, and error records remain separate from optional detailed app analytics.

10. What PodGuard does not do

11. Other companies involved

We disclose information to service providers only as reasonably necessary to operate, secure, and support the Services:

We require service providers to process information for the contracted service and to protect it consistently with applicable law and their agreements with us. We may also disclose information when reasonably necessary to comply with law or legal process, protect rights or safety, investigate fraud or security incidents, enforce our Terms, or complete a financing, merger, acquisition, reorganization, or transfer of the Services. We will not use a corporate transaction to avoid the commitments in this Policy.

12. Emails we send

Our email is sent through Resend. There are only a few kinds:

We do not send marketing email beyond that single launch announcement, and there is no newsletter to be signed up for by accident.

13. The launch list

If you leave your email address on the launch list at podguard.app, we store that address and the plan you tapped, and we use it to send you one message when PodGuard opens, and for nothing else. We do not sell or share it. You can ask us to remove it at any time by writing to support@podguard.app, and it will be gone.

The form is rate limited so it cannot be flooded. That check uses a salted, truncated hash of the requesting IP address rather than the address itself, the hash expires after an hour, and the raw IP address is never written down.

14. Where information is kept, and for how long

Accounts, subscriptions, credits, and processing records are stored in a database hosted on Railway in the United States. Private browser audio is stored on our server. Prepared audio and shared episode results may also be stored in private Cloudflare object storage. The launch list is held separately by Cloudflare. If you use PodGuard from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live.

We retain each category only for as long as reasonably necessary for the purpose described, to protect the Services, or to satisfy applicable legal obligations. Current operational periods include:

Backups, provider records, security records, and information that must be retained by law may persist for a limited additional period. When retention is no longer justified, we delete, de-identify, or allow the information to expire.

15. Deleting your account

You can delete your PodGuard account yourself, in two places:

Deleting removes your account record, email address, password hash, sessions, pending verification, reset, and email sign-in credentials, account-to-install links, browser Library access, browser preferences and playback progress, and the PodGuard record linking the account to Stripe. Financial records needed to preserve credits, prevent duplicate charges, and support independent Apple entitlements can remain separately; deleting an account does not create another trial. Devices signed in to the account are signed out and retain only an entitlement independently supplied by Apple.

Two caveats we would rather say out loud than let you discover:

Episodes already downloaded to your devices remain there. Non-account-linked shared results for public episodes may remain in the processing cache. If you would rather we assist with deletion, write to support@podguard.app.

16. Children

PodGuard is often used by parents so that a household can listen to a show together, but the app itself is meant for adults and is not directed at children under 13. We do not knowingly collect information from a child under 13. If you believe a child has given us information, write to support@podguard.app and we will delete it.

17. Your choices and requests

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a portable copy of personal information; to withdraw consent where processing depends on consent; to restrict or object to certain processing; or to appeal a denied request. We will honor rights required by applicable law and will not discriminate against you for exercising them.

Send requests to support@podguard.app. We may verify that you control the relevant account or email address before responding. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and verification of the account holder.

18. Data security

We use administrative and technical safeguards designed to protect information, including Argon2 password hashing, one-way token digests, short-lived single-use verification, reset, and email sign-in credentials, Apple App Attest, signed subscription events, authenticated episode grants, access controls, and private object storage. Payment-card details are handled by Apple or Stripe rather than stored by PodGuard.

No method of transmission, storage, or authentication is completely secure, and we cannot guarantee absolute security. Use a unique password, protect your devices and email account, sign out of shared browsers, and notify support@podguard.app if you suspect unauthorized access.

19. Changes to this policy

We may update this Policy to reflect changes in the Services, providers, law, or data practices. The effective date appears at the top. If a change materially affects how we use information already collected, we will provide notice and obtain consent when required by applicable law. We will not rely solely on silently changing this page when the law requires more.

20. Governing law

This policy is governed by the laws of the State of New Jersey, without regard to its conflict of laws rules, and sits alongside our terms and conditions. Nothing here takes away rights you have under the consumer or privacy law where you live.

21. Contact us

Questions, privacy requests, account-deletion concerns, and complaints may be sent to support@podguard.app. Please do not send passwords, reset links, complete payment-card numbers, or other credentials by email.