
Privacy Policy
Last updated July 2026
This document describes how PodMind actually handles data, but it is not legal advice. Have it reviewed by a qualified lawyer in your jurisdiction, and replace every highlighted placeholder, before you rely on it.
Who we are
PodMind AI (“PodMind”, “we”) is operated by [legal entity name], [registered address]. For any privacy question, contact [privacy@yourdomain.com].
What we collect
- Account details — your email address, and any name, company, role, country or timezone you choose to add in Settings.
- Content you create — projects, research, outlines, scripts, guest briefings, chat messages and any documents you upload to the Knowledge Hub.
- Usage records — which AI features you used, when, how many tokens were consumed and whether the request succeeded. We keep these to meter credits and to diagnose failures.
- Audit events — a record of significant changes to your data, so you and we can see what happened to an account.
We do not collect payment card details. When paid plans are enabled, our payment provider handles the card and we never see it.
How your content reaches AI models
This is the part most worth understanding. When you run research, generate a script, check facts or chat, the relevant content — your prompt, your project context and, where applicable, passages retrieved from your Knowledge Hub — is sent to a third-party AI provider so it can produce the answer. Without this the product cannot function.
Which provider receives it depends on the task and on availability. Today those providers are OpenAI, Anthropic and Google. You can pin a specific provider for most features, and Settings lets you set a preferred one.
We send only what a request needs. We do not send your content to AI providers for any purpose other than producing your requested output, and we do not use your content to train our own models.
Sub-processors
These are the third parties that process data on our behalf:
- Supabase — database, authentication and file storage.
- Vercel — hosting for the web application.
- Railway — hosting for the API.
- OpenAI, Anthropic, Google — AI model providers, as described above.
- [payment provider] — payments and invoicing, once paid plans are enabled.
Each of these operates under its own privacy terms and may process data outside your country.
Why we are allowed to process it
- To provide the service — performing the contract you enter into when you create an account.
- To keep it working and secure — our legitimate interest in diagnosing failures, preventing abuse and metering usage.
- With your consent — for optional product emails, which you can turn off in Settings at any time.
How long we keep it
Your content stays until you delete it or close your account. Deleting a project, document or conversation removes it from the application immediately; residual copies may persist in encrypted backups for up to [30] days before being overwritten. Usage and audit records are retained for [12] months so we can answer billing questions and investigate incidents.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to certain processing, or to complain to a data protection authority. You can edit or delete most data directly in the application; for anything else, contact us at [privacy@yourdomain.com] and we will respond within [30] days.
Security
Access to your data is scoped to your organization at the database level, so one account cannot read another's content. Passwords are handled by our authentication provider and never stored by us. API keys you create are stored only as a hash — we cannot recover one, which is why the key is shown to you exactly once.
No system is perfectly secure. If a breach affects your personal data we will notify you and any required regulator without undue delay.
Children
PodMind is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes
If we change this policy in a way that materially affects you, we will tell you before it takes effect — by email or in the application — rather than quietly updating the date at the top.
