Privacy policy
Last updated: September 27, 2026
This policy describes how webpod.ai ("we," "us," or "our") accesses, uses, stores, shares, protects, retains, and deletes data collected through our website, application, and browser extension (the "Service"), including data we receive from your Google Account when you sign in with Google.
Google user data we access
When you sign in with Google, we request only the openid,
email, and profile scopes. Through them we
access:
- your email address;
- your name; and
- your Google account identifier.
We do not request access to your Gmail, Google Drive, Calendar, Contacts, or any other Google service. Google also issues sign-in tokens so you stay signed in; the long-lived refresh token is stored only in your browser's local extension storage on your device, is never stored on our servers, and is revoked with Google when you sign out.
How we use Google user data
We use Google user data only to provide and improve the Service:
- to sign you in and authenticate your requests to our servers;
- to create and identify your account, and to link it to your podcast feed, subscription, and credits;
- to set up your private podcast feed, which is delivered to your email address;
- to send you service emails, such as feed confirmations and narration updates; and
- to understand how the Service is used so we can fix problems and improve its features (see "Usage data" below).
Limited Use disclosure
webpod.ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide or improve user-facing features of the Service, and we do not:
- use or transfer it for serving ads, including personalized, retargeted, or interest-based advertising;
- sell it, or transfer it to data brokers or information resellers;
- use it to determine creditworthiness or for lending purposes; or
- use it to develop, improve, or train generalized AI or machine learning models.
Other data we collect
- Content you choose to narrate. When you ask the Service to narrate a page, the extension sends that page's address, title, and content to our servers. If you email us a link, we receive the email's sender, recipient, subject, and the link, and we fetch the linked page. We store the page content, its cleaned-up text, and the resulting audio so we can publish it to your feed.
- Billing information. Payments are handled by Stripe. We store your Stripe customer identifier, subscription status, and credit balance. Your card details are entered directly with Stripe and never reach our servers.
- Usage data. We collect basic information about how the Service is used, such as feature usage, response times, errors, and browser or application version.
How we share data
We do not sell your data. We share data only with the service providers that operate the Service on our behalf, only to the extent each one needs to perform its function, and under terms that require them to protect it:
- Google Cloud (application hosting and file storage) and Supabase (database): all account data and narration content we store.
- Transistor.fm (podcast hosting): your email address and name, to create your private feed, plus your narration audio.
- Stripe (payments): your email address and name, and your billing details.
- Resend (email delivery): your email address and the content of service emails.
- PostHog (product analytics): usage data, linked to your email address, name, and account identifiers, used to diagnose problems and improve the Service.
- Inngest (background job processing): account and narration identifiers needed to run narration jobs.
- OpenRouter and the AI model providers it routes to (text cleanup) and ElevenLabs (voice synthesis): the text of pages you choose to narrate. We do not send your Google user data to these AI providers.
We may also disclose data if required by law, to protect the rights or safety of our users or others, or as part of a merger or acquisition, in which case this policy will continue to apply to your data.
How we protect data
- All data sent between the extension, our website, our servers, and our service providers is encrypted in transit using HTTPS/TLS.
- Data stored in our database and cloud storage is encrypted at rest by our hosting providers (Google Cloud and Supabase).
- Every request made on your behalf must carry a Google-issued sign-in token, which our servers verify (signature, issuer, audience, and expiry) before returning or changing any of your data.
- Google refresh tokens are kept only on your device, not on our servers, so a breach of our systems would not expose them.
- Access to production systems and data is limited to authorized personnel who need it to operate the Service. Credentials and API keys are held in a dedicated secrets manager and are never stored in source code.
No method of storage or transmission is completely secure, but we work to protect your data and will notify affected users of a breach as required by law.
Retention and deletion
We keep your account data, including the Google user data described above, and your narrations for as long as your account is active, so your feed keeps working. Usage data is kept only as long as needed to diagnose problems and improve the Service.
You can sign out at any time, which revokes the Service's Google access and removes your sign-in tokens from your device. You can also remove the Service's access from your Google Account permissions page.
To delete your account and data, email support@webpod.ai from the address associated with your account. Within 30 days we will delete your account data, including your Google user data, your stored narrations and audio, and your podcast feed, and we will ask our service providers to delete the copies they hold. We may keep limited billing records where the law requires it.
Changes to this policy
We may update this policy as the Service evolves. We will post the updated policy on this page and revise the date above. If we change how we use Google user data, we will notify you before the change takes effect and, where required, ask for your consent.
Contact
Questions about this policy or your data can be sent to support@webpod.ai.