Legal
Privacy Policy
This policy explains what personal data Repodcast collects, why we collect it, how long we keep it, and the choices you and your clients have.
Last updated July 2, 2026
1. Who we are
Repodcast is a business-to-business platform built for podcast agencies. Our customer (“you”) is the agency operating a Repodcast workspace. The agency’s own clients (the podcasters and brands they serve) and the audiences those podcasts reach may also appear in the data we handle — this policy covers all three.
If you have privacy questions, reach us at privacy@repodcastapp.com.
2. Data we collect
2.1 Account and workspace data
When you sign up we collect the name, email address, profile image, and authentication identifiers your identity provider gives us (see Section 8 — authentication runs through Clerk). We also record the workspace, role, and permissions you hold inside Repodcast.
2.2 Billing data
Paid plans are handled by Stripe. Repodcast does not store card numbers or bank details — we only retain the customer ID, subscription state, plan, and invoice history Stripe returns to us.
2.3 Content you upload or generate
- Audio files, RSS URLs, and YouTube links you submit for transcription and generation.
- Transcripts produced by our transcription provider.
- Voice-style profiles derived from your client’s prior writing and approved episodes.
- Generated outputs (X threads, LinkedIn posts, show notes, etc.) and any edits or approvals you make on them.
This content may include personal information about your clients, guests, or third parties mentioned in an episode. You are responsible for having a lawful basis to submit it — see Section 6.
2.4 Product and diagnostic data
We log pages viewed, features used, buttons clicked, request timings, and error stack traces so we can improve reliability and troubleshoot issues. Product analytics runs through PostHog with IP anonymisation enabled. We do not sell this data.
2.5 Support communications
Emails you send to hello@repodcastapp.com, support@repodcastapp.com, privacy@repodcastapp.com, or legal@repodcastapp.com are retained for as long as needed to resolve the matter and demonstrate that we did.
3. How we use data
- To operate the service— authenticate you, run the workspace you belong to, transcribe audio, generate content in your client’s voice, deliver approved content to platforms you connect.
- To bill you — meter usage against your plan and process payments through Stripe.
- To keep the service safe and reliable — detect abuse, prevent fraud, triage security incidents, respond to abuse reports.
- To improve the product — measure feature adoption, diagnose failures, evaluate model quality. Where we use content to evaluate voice-fidelity, we do so under strict internal access controls; we do not train third-party foundation models on your content (see Section 5).
- To communicate with you — service notices, security alerts, and product-relevant updates. Marketing emails, when we send them, always include a one-click unsubscribe.
4. Lawful basis (EEA/UK)
Where GDPR applies we rely on one of the following: performance of the contract with your agency, our legitimate interest in operating and securing the service, your consent (for optional cookies and marketing email), or compliance with a legal obligation.
5. AI, model training, and voice profiles
Repodcast uses third-party AI providers to transcribe audio (Deepgram) and generate content (Anthropic). Those providers process your content only to return the requested output — under our commercial agreements, your content is not used to train their public foundation models.
Voice-style profiles are derived from content the agency has uploaded or approved for a specific client and are scoped to that client’s workspace. They are not shared across agencies or clients.
6. Your responsibilities as the agency
- Have a lawful basis to upload each episode, transcript, or voice sample — including consent from your client and, where relevant, from guests.
- Do not upload content you do not have the right to process (see our Terms).
- Honour data-subject requests you receive from your clients or their audiences promptly; contact us if you need our help to fulfil one.
7. Who we share data with
We share personal data only with the subprocessors listed in Section 8, and only as required to run the service. We may also disclose data to comply with a valid legal request or to protect the rights and safety of Repodcast, our customers, or the public. We do not sell personal data.
8. Subprocessors
The current list of subprocessors we rely on:
- Clerk — user authentication and session management.
- Stripe — subscription billing and invoicing.
- Amazon Web Services (S3) — object storage for audio, transcripts, and generated content.
- Vercel — application hosting and edge delivery.
- Inngest — background job orchestration.
- Deepgram — audio transcription.
- Anthropic — large-language-model generation.
- PostHog — product analytics (IP anonymised).
- Resend — transactional email delivery.
See our Security page for how we vet and monitor these providers. We notify workspace admins by email before adding a new subprocessor that materially changes the data-handling picture.
9. How long we keep data
- Account and workspace data — for as long as the workspace is active, then 90 days after cancellation to allow reactivation.
- Uploaded audio and transcripts — until you delete the episode, then purged from primary storage within 30 days and from backups within a further 60 days.
- Generated outputs — retained with the episode; same 30-/90-day purge window on deletion.
- Billing records — retained for the period required by tax and accounting law (typically 7 years).
- Diagnostic logs — 30 days by default; security-relevant logs up to 365 days.
10. Your rights
Depending on where you live you have rights to access, correct, export, or delete personal data we hold about you, to object to certain uses, and to withdraw consent. To exercise a right, email privacy@repodcastapp.com from the address on file and we will respond within 30 days. If you believe we have not resolved a concern adequately you may complain to your local data-protection authority.
11. International transfers
Repodcast is operated from Canada. Some of our subprocessors are based in the United States or the European Union. Where personal data crosses borders we rely on the Standard Contractual Clauses or an adequate transfer mechanism recognised by the exporting jurisdiction.
12. Children
Repodcast is a business tool not directed at children under 16 and we do not knowingly collect data from them. If you believe a child has provided us data, email privacy@repodcastapp.com and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we do we’ll update the “Last updated” date at the top and, if the changes are material, notify workspace admins by email at least 14 days before they take effect.
14. Contact
Repodcast — privacy@repodcastapp.com. For abuse or content complaints use the report form instead.