Privacy Policy
Effective September 10, 2026
Pod Your Way turns articles you choose — sent by email, saved with our browser extension, or shared from our iOS app — into audio episodes on your personal podcast feed. This policy explains what we collect, why, and what we do (and don't do) with it.
What we collect
- Invite requests. If you request an invite, we store your email address, request date, and review status to manage early access.
- Account information. Your email address, a hashed password, timezone, and plan tier.
- Emails you send to your save address. When you (or a
newsletter you subscribed with your save address) email
yourslug@podyourway.com, we receive and store the sender, subject, and message body so we can turn it into an episode, show it on your account pages, or forward verification emails back to you. - Articles you save with the browser extension. The extension sends us the readable text of a page only when you click its button, along with the page URL and title. It never reads pages you don't explicitly save, and it stores your API token only in your own browser.
- Articles you save with the iOS app. The app sends us what you explicitly share: a link (which our server then fetches), a page's readable text when you share from Safari, or a PDF you import (we extract and keep its text, not the file). The app stores its sign-in token only on your device.
- Feed access records. When a podcast app polls your feed or downloads an episode, we log the request's IP address and app identifier (user agent) to show you listening stats and to detect abuse of feed URLs. These raw logs are deleted after 180 days; only aggregate counts (e.g. download totals) are kept longer.
- Service records. Article processing status, episode metadata, monthly usage counts, and error logs needed to run the service.
How we use it
For exactly one purpose: producing your podcast. Article text is converted to speech, merged into an episode, and published to your private show. We also use your email address to send you service messages — for example, forwarding a subscription-confirmation email that arrived at your save address, or resetting your password. If you request an invite, we use your email address to follow up about early access.
Service providers
Producing your episodes involves a small set of processors, each receiving only what it needs:
- Text-to-speech providers (OpenAI and Google Cloud Text-to-Speech) receive article text to generate audio.
- Cloudflare routes email addressed to podyourway.com, proxies traffic to our servers, and stores your episode audio (R2). Your podcast feed is served by us directly; its URL is unlisted, and anyone you share it with can access your episodes.
- Resend delivers the emails we send you (verification links, password resets, forwarded verification emails).
- Render hosts our application and database.
- Sentry receives error reports (configured to exclude personal information).
What we don't do
- We do not sell your data or share it with anyone for advertising.
- We do not track your browsing. The extension and app act only on your explicit save; the website uses only essential cookies (login session and CSRF protection) — no analytics or advertising trackers.
- We do not use your content to train models or for any purpose other than producing your episodes.
Retention & deletion
Article text and episode records are kept while your account is active so your feed keeps working. Held emails appear on your inbox page, where you can delete them yourself at any time. Feed access logs are deleted automatically after 180 days. To delete specific content, remove it from your articles list. To delete your entire account and all of its data, use Account → Delete account on the website or in the iOS app; deletion is immediate and cannot be undone.
Payments
Paid plans are billed through RevenueCat, which processes App Store purchases in the iOS app and card payments (via Stripe) on the website. We send RevenueCat an opaque account identifier and, for web checkout, your email address for receipts; we never see or store card numbers. RevenueCat's processing is described in its privacy policy. The iOS app includes RevenueCat's SDK for purchases only; it does not track you across apps or websites.
Security
Traffic is encrypted in transit (HTTPS). Extension and app tokens are stored only as cryptographic hashes and can be revoked at any time. Passwords are hashed with Django's standard password hasher. Security researchers can reach us via security.txt.
Contact & changes
Questions or requests: privacy@podyourway.com. If this policy changes materially, we'll note the new effective date here.