Privacy Policy
Last Updated: June 2025
PodCrisp ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website located at podcrisp.com (the "Service"), operated by Haimo ("Company").
1. Information We Collect
1.1 Information You Provide to Us
- Account Information: Email address, password (stored as PBKDF2-SHA256 with 100,000 iterations hash), and subscription tier
- Podcast URLs: Links to podcasts you submit for summarization
- Payment Information: Handled entirely by our payment processor Dodo Payments. We do not store credit card details
- Communications: Any correspondence you send us via email
1.2 Information Collected Automatically
- Usage Data: Number of summaries generated, timestamps, and feature usage patterns
- Device Information: IP address, browser type, operating system, and device identifiers
- Cookies: Essential session cookies for authentication and security
1.3 AI Processing Data
When you submit a podcast URL for summarization:
- The podcast audio may be transcribed using our AI providers (DeepSeek or Groq)
- Transcription text is processed to generate structured summaries
- Summary outputs are cached for performance using SHA-256 hashed keys
- Podcast metadata (title, episode name, artwork URL) may be retrieved from podcast feeds
2. AI Data Processing
Important: We use third-party AI providers to process podcast content. These providers act as data processors under this Privacy Policy.
| Provider | Purpose | Data Location | Data Use for Training |
|---|---|---|---|
| DeepSeek | Primary AI summarization | China (CN) | No |
| Groq | Backup AI processing | United States (US) | No |
AI-generated summaries are not used to train or improve AI models. Input data is processed only for the requested summarization and discarded after caching (if applicable).
3. How We Use Your Information
- Provide, maintain, and improve our Service
- Generate podcast summaries as requested
- Manage your account and process subscriptions
- Enforce our Terms of Service and prevent abuse
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
4.1 Service Providers
- Cloudflare Workers: Our infrastructure provider (data centers in the United States)
- Dodo Payments: Payment processing for subscriptions
- DeepSeek / Groq: AI processing for summarization
4.2 Legal Requirements
We may disclose your information when required by law, court order, or government request, or when we believe disclosure is necessary to protect our rights, prevent fraud, or ensure safety.
5. Data Retention
- Account Data: Retained until account deletion; deleted within 30 days of request
- Summary Cache: Stored with SHA-256 hashed keys; retained for performance caching
- Usage Logs: Aggregated and anonymized after 90 days
- AI Provider Logs: Governed by respective provider policies (DeepSeek, Groq)
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- PBKDF2-SHA256 (100,000 iterations) for password storage
- SHA-256 hashing for cache keys
- Access controls and authentication for internal systems
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure.
7. Usage Limits by Plan
Monthly summary quotas reset on the 1st of each calendar month (UTC) — not on a rolling 30-day window. Unused quota from a previous month does not roll over.
| Plan | Monthly Summaries | Features |
|---|---|---|
| Free | 3 per month | Basic summaries, public pages |
| Starter | 20 per month | Email digest, knowledge base |
| Pro | Unlimited | All features, priority processing |
| Creator | Unlimited | Show notes, social posts, brand pages |
8. GDPR Compliance (EU/EEA Users)
If you are located in the European Economic Area (EEA), this section applies to you.
8.1 Data Controller
Haimo is the data controller for processing your personal data under GDPR Article 4(7).
8.2 Legal Basis for Processing
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Provide summarization service | Contract performance (Art. 6(1)(b)) |
| Account management | Contract performance (Art. 6(1)(b)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
8.3 International Data Transfers
⚠️ Critical Disclosure: Our primary AI provider, DeepSeek, processes data in China. Transfers from the EEA to China require appropriate safeguards under GDPR Chapter V. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for such transfers. For backup processing, Groq (US) participates in the EU-US Data Privacy Framework.
8.4 Your GDPR Rights
You have the following rights under GDPR:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Request correction of inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Request limitation of processing
- Right to Portability (Art. 20): Receive your data in a structured format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Right to Withdraw Consent: Where consent is our legal basis
To exercise any of these rights, contact us at privacy@podcrisp.com.
Self-service: Sign in to your dashboard at podcrisp.com/app and use the “Delete my data” button — this is the fastest path and authenticates the request against your account so only the email owner can initiate erasure. You may also submit a deletion request by emailing support@podcrisp.com (or privacy@podcrisp.com) from the address on file. Developers integrating PodCrisp may call the authenticated REST endpoint POST /api/dsr/delete with a valid session bearer token in Authorization: Bearer <token> and JSON body {"email":"<your account email>"} — the request body email must match the authenticated session email, and the endpoint is rate-limited to 5 requests per hour per IP and per email. All requests are processed within 30 days per GDPR Art.17 / PDPA / CCPA §1798.105.
8.5 Data Protection Officer (DPO)
For GDPR matters, contact our privacy team: privacy@podcrisp.com
8.6 Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority. For EU member states, contact your national supervisory authority. For the UK, contact the Information Commissioner's Office (ICO).
9. CCPA Compliance (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights:
9.1 Your CCPA Rights
- Right to Know: Request disclosure of personal information collected, used, disclosed, or sold
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of personal information
- Right to Limit Use: Limit use of sensitive personal information
- Non-Discrimination: We will not discriminate against you for exercising your rights
9.2 Categories of Personal Information Collected
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Email, IP address | Account, authentication |
| Commercial Information | Subscription tier, usage | Service delivery |
| Technical Data | Browser, OS, device | Security, analytics |
9.3 We Do Not Sell Your Data
We do not sell your personal information for monetary consideration. We do not "share" information for cross-context behavioral advertising.
10. EU AI Act Compliance
As an AI-powered service, we comply with transparency requirements under the EU AI Act (Regulation (EU) 2024/1689):
- Article 50 (Transparency): Users are informed that AI is used to generate podcast summaries
- Article 53 (GPAI Providers): We provide documentation on the AI systems used
- Technical Documentation: Summary outputs are clearly identified as AI-generated
- No High-Risk AI Systems: PodCrisp does not deploy AI systems classified as "high-risk" under the AI Act
11. Geographic Restrictions
Notice: PodCrisp is not intended for users located in mainland China, Hong Kong, Macau, or Taiwan. We do not offer services to users in these regions. If you access the Service from these locations, you do so at your own initiative and are responsible for compliance with applicable local laws.
12. Cookies and Tracking
We use essential cookies for:
- Authentication and session management
- Security and fraud prevention
- Core service functionality
We do not use advertising cookies or tracking pixels. We do not participate in cross-site tracking.
13. Children's Privacy
Our Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware of collection from a minor, we will take steps to delete such information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. We encourage you to review this policy periodically.
For GDPR compliance, significant changes may require additional notification to affected users.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights:
- Email: privacy@podcrisp.com
- Company: Haimo
- Service: PodCrisp (podcrisp.com)