Privacy Policy
Last updated: June 25, 2025
What we collect
When you create an account, we collect:
- Email address — used for authentication and account communications
- Profile information — display name you optionally provide
- Usage data — podcasts you save, transcriptions you request, and chat interactions
We do not collect or process data from users who have not registered an account.
Cookies
We only use strictly necessary cookies for authentication. These are session cookies that keep you signed in and cannot be disabled without breaking core functionality.
- Auth session cookie — HttpOnly, Secure, SameSite=Lax. Contains your encrypted session token.
We do not use any analytics cookies, tracking cookies, advertising cookies, or third-party cookies.
Third-party services
We use the following services to operate Findcast:
- Supabase — database and authentication (data stored in EU region)
- Cloudflare — hosting, content delivery, and AI vector search
- Polar — subscription billing (you are redirected to their domain for payment)
- Groq — AI processing for transcription and chat (no personally identifiable information is sent)
We do not sell, share, or provide your personal data to any other third party.
Data retention
Your account data is retained for as long as your account is active. If you request account deletion, we will remove all personal data within 30 days. Aggregated, anonymized data may be retained for service improvement.
Your rights
Under the GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a machine-readable format
- Restriction — limit how we process your data
- Objection — object to processing based on legitimate interests
To exercise any of these rights, please contact us. We will respond within 30 days.
Security
We implement industry-standard security measures including encrypted connections (TLS), secure cookie handling, and access controls. Authentication is handled through a proven third-party service (Supabase Auth) with support for secure password hashing and session management.
Changes to this policy
We may update this policy from time to time. Significant changes will be communicated via email to registered users. The "last updated" date at the top reflects the most recent revision.
Contact
For privacy-related inquiries, please reach out via our contact page.