Skip to main content
PodAction
HomePricing
Sign in

Privacy Notice

Effective 6 August 2026. This document is written and kept current by the team that operates PodAction and has not been reviewed by outside lawyers. When it changes materially, this date changes with it.

This notice explains what PodAction does with your data. It is written and kept current by the team that operates PodAction, and it has not been reviewed by outside lawyers — we tell you that plainly rather than pretend otherwise. Where we are not certain of something, we say so rather than promise it.

PodAction is a private workspace. We only process content you add after signing in — a transcript you paste, an episode link you give us, or an audio or video file you upload. We do not crawl or collect anything on our own.

You sign in with a one-time link sent to your email. There is no password. A session cookie keeps you signed in on that browser.

Your episodes, your profile and your sprints are stored against your account only. Other customers cannot see them, and our own access is limited to what is needed to run and support the service.

How long we keep things: transcripts and episode links stay stored until you delete them or close your account; your briefs, sprints and check-ins stay stored until you delete them or close your account. You can delete any episode and everything built from it at any time in History.

Audio and video you upload, stated exactly: uploading files is switched off today, so there is nothing of yours in our file storage. The retention rule is built and scheduled: after we verify an uploaded file, we keep it for about 24 hours and then delete the stored file itself. A cleanup job runs every 15 minutes to enforce that clock, which is why we say about 24 hours rather than promising an exact minute; and if our storage provider keeps refusing a deletion we stop retrying after a fixed number of attempts and raise it internally rather than tell you the file is gone. An upload you start and never finish expires when its short upload window closes. Every file you have uploaded is deleted when your account is deleted, and there too we delete the stored file itself rather than only our record of it: we will not report a deletion as finished while a file is still there. Deleting a single episode clears what we derived from it and does not immediately remove the original uploaded file — that file leaves on the 24-hour clock, or with your account, whichever comes first. When uploads are switched on for customers, this is the rule your files will be under from the first upload.

Where your data lives: our database and application run on infrastructure in the United States (our database provider's us-west-2 region, measured on 6 August 2026). An earlier version of this notice said we intended to run in São Paulo, Brazil; that is not where the service runs today, and we will update this notice if the region changes. If you are in the EU, the UK or Brazil, this means your data is transferred internationally to the United States. Those transfers rest on the contractual safeguards each of our providers publishes for its own service; we have not had those safeguards independently reviewed, and we say that rather than claim a certification we have not checked.

AI processing: to build a sprint we send your content to OpenAI — the transcript we fetched, the transcript you pasted, or the transcription of a file you uploaded. Under the OpenAI account settings we currently use, the inputs and outputs of those requests are shared with OpenAI and may be used by OpenAI to evaluate and improve its models. That applies to everything we send, not only publicly available captions, so do not submit content you are not willing to have processed this way. We do not claim zero retention by third-party AI providers, and what OpenAI does with shared data is governed by its own documentation.

Companies that help us run PodAction, and what each one does: Supabase (database, sign-in and storage), OpenAI (AI processing, and transcription of uploads when uploads are on), Stripe (payments and subscriptions — your card details go to Stripe, never to us), Cloudflare R2 (storage for uploaded media), Cloudflare Turnstile (abuse protection when you submit a source), Brevo (outbound email such as check-in reminders), Sentry (error reporting — an error report can carry fragments of the request that failed), and Vercel (hosting and request logs). We will keep this list current as providers change.

Deleting an episode removes your access to it and clears the content we derived from it, wherever the connected systems allow. Deleting your whole account is built into Settings; where that control is not yet switched on, email us from your sign-in address and we run the same deletion for you. After a deletion finishes we keep a small deletion record — which account asked, what scope was deleted, and when each step completed — so we can prove the deletion happened; that record never contains the deleted content itself. We will not claim we erased something from a backup or a third party when we cannot confirm it.

We measure how the product is used — for example which input type you chose, or whether a step succeeded. We never put transcript text or episode content into those measurements.

Questions about your data: email us from the address you use to sign in. A dedicated privacy contact will be published before launch.

Return home · Sign in

PodActionFrom episode to execution
PrivacyTermsRefundsAcceptable use