Privacy Policy
Last updated: 17 August 2026
podstow converts text into podcast episodes for your personal listening. You can submit web articles, or text directly (including from an AI assistant via our MCP integration). This policy explains what data we collect, why, and what happens to it. We've kept it short and in plain English.
What we collect
- Account information — your email address and how you signed in (email/password, Google, or Apple).
- Content you submit — the URLs and text you send us (and the article text we extract from any URLs), so we can convert it to audio.
- Audio files — the podcast episodes we generate from your articles, stored in your personal feed.
- Usage data — how many articles you've converted in the current billing period, so we can apply plan limits.
- Feed access data — when your podcast feed or audio files are fetched, we record the requesting IP address, user-agent, and time. We use this to detect misuse (such as feed sharing) and enforce our personal-use policy.
- Operational logs — standard request logs for our other websites, APIs, and extensions (IP address, user-agent, request path, time, response status), kept for security, abuse prevention, and debugging.
- Payment information — if you subscribe on the web, our payment processor (Stripe) handles your card details. We store your Stripe customer ID but never see or store your card number. If you subscribe inside one of our apps, Apple handles the payment and we never see your card details; we store the identifiers Apple gives us for the subscription — its transaction ID and the app account token that links it to your podstow account.
Why we collect it
We use your data to:
- Provide the service — convert your articles and text to audio, generate your podcast feed, manage your account, and process payments.
- Detect and prevent misuse — such as feed sharing in violation of our personal-use policy, and general security and abuse prevention across the service.
- Fix problems — diagnose errors and improve the service.
- Comply with the law — respond to legal requests where required.
We don't sell your data, we don't serve ads, and we don't share your data with advertisers. We may look at how you use podstow to send you the occasional in-product nudge.
Apps, extensions, and integrations
Our browser extensions (Chrome, Firefox, Safari), our mobile and desktop apps (including the share menu), and MCP integration only send podstow the URL or text you submit, along with your account credentials. The browser extensions and apps don't read the web page or track your browsing.
Third-party services
We use the following categories of third-party service to run podstow. Each handles data only as needed to provide their part of the service:
- Cloud infrastructure (AWS) — hosting, storage, compute, and authentication.
- OAuth providers — handle sign-in when you choose to use a third-party account.
- Email delivery — sends transactional emails (account verification, billing notices, support replies).
- Content extraction — fetches the article text from URLs you submit.
- Text-to-speech — converts text into audio.
- AI / language models — process submitted text for things like summarisation, categorisation, and translation.
- Payment processing (Stripe) — handles subscriptions and billing for subscriptions bought on the web.
- Payment processing (Apple) — handles subscriptions bought inside our iPhone, iPad and Mac apps, and tells us when one starts, renews, lapses or is refunded.
Cookies and tracking
podstow does not use third-party trackers, advertising scripts, or analytics scripts, and does not set tracking or analytics cookies.
We do keep our own first-party logs of a small set of product events on our servers so we can understand how podstow is used and measure the visit → sign-up → first-article → first-listen funnel. The events we record are:
- Server-side events — when you sign up, submit an article, or complete a checkout, we record the event type, the time, your signed-in user ID, and a small set of event-specific properties (such as your subscription tier or the amount of a completed checkout).
- Page-view events — when you visit a page on
podstow.com or podstow.app, your browser sends us the path you
visited (e.g.
/,/settings), the time, and an anonymous session identifier (see below). If you're signed in, your user ID is included as well. - Campaign labels — when you reach podstow
from a link we tagged for a particular promotion (a newsletter, a
podcast directory listing, an advert), that link carries standard
campaign parameters in its web address —
utm_source,utm_medium,utm_campaign,utm_termandutm_content. We record those five labels with your page-view and also save them in your browser's local storage, so that if you go on to create an account we can record once that the account came from that promotion. We stop attributing an account to them after 30 days; the saved labels themselves stay in your browser until an account is created or you clear your site data. This is how we tell whether a promotion brought anyone, rather than just clicks. These labels describe the link, not you: they are words we chose when we made the link (newsletter, august-launch), they are the same for everyone who follows it, and they do not identify you. We record only those five parameters — any other information in the web address is discarded before anything is sent or stored — and you can remove the stored labels at any time by clearing your browser's site data. - Demo interaction events — when you try the audio demo on the podstow.com home page, your browser sends us the interaction (adding a sample article to the queue, pressing play, the queue advancing on its own, or clicking the sign-up button below the demo), which sample article was involved, the time, and the same anonymous session identifier. The demo plays audio files served from our own site; trying it involves no third party and no account.
- Engagement events — on the podstow.com home page, your browser sends us a small set of reading signals: which sections of the page you scrolled into view (for example, reaching the pricing section), clicks on the buttons and links we mark as calls to action — sign-in and sign-up, the app-store badges, and links like “see how it works” and “connect your assistant” (which one was clicked, not where you went afterwards) — and a one-time signal that the page stayed visible for at least ten seconds. Each carries the page path, the time, and the same anonymous session identifier — no scroll positions, mouse movements, or keystrokes are recorded.
- Subscribe page events — when you scan a podstow subscribe QR code, the page it opens records the visit and which of its two options you chose — listening in podstow, or subscribing in your own podcast app — along with the time and the same anonymous session identifier. The identifier of the feed the QR code points at is not recorded with either event — the page reports itself simply as the subscribe page — and the page itself asks you for nothing: you're signed out until you choose to sign in.
- Listening milestones — the first time you start playing an episode, and the first time one plays through to the end, your browser sends us a single marker for each along with the identifier of the episode involved, the time, your user ID, and the same anonymous session identifier. These are recorded once, not on every play: we use them to see how many people who sign up go on to actually listen. These two markers are all we add to the event log for listening — they don't tell us what else you play, how far through an episode you are, or when you pause or skip. (Your place in an episode is saved to your account separately, so playback resumes where you left off; that is part of your account data, not this event log.)
- Upgrade events — when you're signed in and we show you the paid plan options — in the app's Subscription settings, or on our billing page — we record that the plan options were shown, which of those two places showed them, and the plan you're currently on. If you then press a plan's button to start a checkout, we record which plan you chose. Both carry the time, your user ID, and the same anonymous session identifier. We use these only to see how many people who look at the plans go on to subscribe; no payment details reach these records — the checkout itself is handled by Stripe (see above).
- Playback diagnostics — if audio playback hits a problem (for example, the next episode fails to start while your screen is locked), your browser sends us a short technical record of what the player was doing around that moment: timings, buffer positions, and the internal episode identifiers involved. It carries no article text, titles, or URLs — only numbers and identifiers — and is tagged with the same anonymous session identifier (and your user ID if you're signed in). We use it only to diagnose and fix playback faults, and these records are kept for 30 days.
Alongside each event we record the country your request came from (derived from your IP address at our CDN edge, then the raw IP is discarded before the event is stored), and a coarse browser-family token derived from your User-Agent header (e.g. Chrome, Firefox, Safari — not the full User-Agent string).
The anonymous session identifier is a random UUID generated by your browser on your first visit and stored in your browser's local storage (not a cookie). It has no expiry and is not tied to your identity in any way; clearing your browser's site data removes it. We use it only to count distinct visitors in the funnel ratios and to link a sign-up back to the visit it originated from.
We don't record the contents of form fields, your raw IP address, or any third-party identifiers, we don't share this data with anyone outside podstow, and no third-party scripts run on any podstow page.
Data retention
We keep your data for as long as you have an account. Your articles and audio files remain in your feed until you delete your account. Operational logs are retained for 90 days.
Deleting your data
You can delete your account yourself: in the app, open Settings → Account → Delete account; on the web, sign in to your account settings and choose Delete account. Deletion takes effect immediately, cancels any active subscription, and removes your sign-in details, feed, and episodes from our active systems. If you can't sign in, email support@podstow.com and we'll delete it for you; we may ask you to verify your identity first. Generated audio and transcripts are stored deduplicated across accounts and are not linked to you; any such content that no remaining account references is removed shortly after deletion. Copies in automated backups may persist for a short time before being purged. Payment records held by Stripe or by Apple are subject to their own retention policies; the subscription identifiers we store are removed with your account. See Delete your account for the full picture.
Children
podstow is not intended for children under 13 (or under 16 in the EEA and UK). We don't knowingly collect data from anyone in this age group. If you believe a child has given us data, contact us at support@podstow.com and we'll delete it.
Legal basis for processing (GDPR)
If you're in the European Economic Area or the UK, here's the legal basis we rely on for each type of processing:
- Contract — processing your articles and other submitted content, generating your feed, managing your account, and processing payments are necessary to provide the service you signed up for.
- Legitimate interest — detecting misuse, fixing bugs, keeping the service secure, and sending you the occasional in-product nudge.
- Consent — where you've explicitly opted in (for example, to an optional feature).
- Legal obligation — where we need to comply with applicable law.
Your rights (EEA, UK, and California)
Depending on where you live, you may have additional rights regarding your data:
- Access and portability — you can ask us for a copy of the data we hold about you.
- Correction — you can ask us to fix inaccurate data.
- Deletion — you can ask us to delete your account and data (see "Deleting your data" above).
- Restriction and objection — you can ask us to limit or stop certain processing in some circumstances.
- Withdraw consent — where we rely on consent, you can withdraw it at any time.
We do not sell or share your personal information as defined by the California Consumer Privacy Act (CCPA). To exercise any of these rights, email support@podstow.com. If you're in the EEA or UK, you can also lodge a complaint with your local data protection authority.
Changes to this policy
If we make material changes, we'll update the date at the top of this page and notify you (for example, by email or an in-app message) before they take effect. Continued use of podstow after a change means you accept the updated policy.
Contact
podstow is operated by podstow Ltd, a company registered in England and Wales (company number 17278697). podstow Ltd is the data controller for the personal data described in this policy.
Questions about this policy? Email support@podstow.com, or write to us at:
podstow Ltd66 Paul Street
London EC2A 4NA
United Kingdom