Privacy Policy
Last Updated: June 27, 2026
1. Introduction
Welcome to PodCurator ("we," "our," or "us"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy explains our practices regarding data collection and use when you use our podcast discovery and curation service.
By using PodCurator, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our service.
2. Information We Collect
2.1 Information You Provide
We collect the following information when you create an account or use our service:
- Account Information: Email address, name, and password (hashed and securely stored)
- Profile Information: Profile picture/avatar if you sign in with Google
- Search Queries: Your podcast search requests and preferences
- Payment Information: Processed securely through our payment provider (Polar.sh). We do not store complete credit card numbers
2.2 Information from Spotify and YouTube
PodCurator integrates with Spotify and YouTube to provide podcast and video discovery services. When we search these platforms' catalogs on your behalf, we access and store the following content data:
- Podcast episode and video titles, descriptions, and metadata
- Episode/video duration, release dates, and language information
- Podcast show names, YouTube channel names, and identifiers
- Cover art, thumbnails, and images
- Platform-specific URIs and IDs (Spotify URIs, YouTube video IDs)
- Content flags (explicit content markers, playability status)
Important: We do not access your personal Spotify or YouTube account data, listening/watch history, playlists, or require you to connect your accounts. We only search these platforms' public catalogs using their Web APIs to find content matching your queries.
2.3 Automatically Collected Information
- Usage Data: Search queries, search timestamps, episodes viewed, and interaction patterns
- Device Information: Browser type, device type, and operating system (via user agent)
- Performance Metrics: Search response times and API usage statistics
- Session Information: Authentication tokens and session data (stored securely with JWT)
2.4 AI Processing Data
We use artificial intelligence (xAI's Grok models, accessed via OpenRouter) to analyze and curate podcast recommendations. The following data is sent to our AI service provider:
- Your search queries (text only)
- Episode metadata (titles, descriptions, podcast names) for curation analysis
- Language and content preferences extracted from your search
Important clarifications:
- We do not send personally identifiable information (name, email, or account details) to AI service providers
- We do not use your data to train, fine-tune, or improve any machine learning or AI models
- Your data is processed in real time to generate recommendations; provider-side retention is limited to that processing and governed by our AI provider's data policies (OpenRouter and xAI)
- We do not contribute your data to any third-party AI training datasets
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Service Delivery
- Provide personalized podcast episode recommendations
- Execute search queries and curate results using AI
- Maintain your account and authenticate your access
- Process credit purchases and manage your subscription
3.2 Service Improvement
- Analyze search patterns to improve recommendation algorithms
- Optimize search performance and response times
- Identify trending topics and popular search queries
- Debug technical issues and improve user experience
3.3 Communication
- Send transactional emails (account creation, password resets, purchase confirmations)
- Notify you about service updates or changes to our policies
- Respond to your inquiries and support requests
3.4 Legal Compliance
- Comply with legal obligations and respond to lawful requests
- Protect against fraud, abuse, and security threats
- Enforce our Terms of Service and other policies
4. Data Sharing and Third Parties
4.1 Third-Party Service Providers
We share data with the following third-party services to operate our platform:
- Spotify: We access Spotify's Web API to search their podcast catalog. Data exchanged is limited to search queries and public episode metadata. We comply with Spotify's Developer Terms.
- YouTube: We access YouTube's Data API to search their video catalog. Data exchanged is limited to search queries and public video metadata. We comply with YouTube's API Services Terms.
- OpenRouter (xAI / Grok): Search queries and episode/video metadata are sent to xAI's Grok models, accessed via OpenRouter, to generate AI-powered curation. No personally identifiable information is shared. Provider-side processing is subject to OpenRouter's and xAI's privacy policies.
- Polar.sh: Payment processing for credit purchases. Polar handles payment information securely; we only receive confirmation of successful transactions.
- Google OAuth: If you sign in with Google, we receive basic profile information (name, email, profile picture) as authorized by you.
- Database Hosting (Neon/PostgreSQL): Your data is stored in encrypted databases hosted by our infrastructure provider.
- Trigger.dev: Background job processing for asynchronous search tasks.
4.2 Data Not Sold
We do not sell, rent, or trade your personal information to third parties for marketing purposes.Any data sharing described above is solely for the purpose of providing and improving our service.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental request, or to protect our rights, property, or safety, or that of our users or the public.
5. Data Security
We implement industry-standard security measures to protect your data:
- Passwords are hashed using bcrypt before storage
- All data transmission is encrypted using HTTPS/TLS
- Database access is restricted and uses encrypted connections
- Authentication tokens are securely generated and stored
- Regular security audits and updates to our infrastructure
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Account Data: Retained until you delete your account
- Search History: Retained for service improvement and analytics; you can request deletion
- Transaction Records: Retained for 7 years for tax and accounting purposes
- Platform Content Data (Spotify & YouTube): Stored to operate the discovery service and periodically refreshed from the source platform. YouTube-sourced metadata is refreshed or deleted within 30 days, consistent with YouTube's API Services Terms; Spotify-sourced metadata is refreshed from Spotify and shown subject to a freshness window
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law.
7. Your Rights (GDPR & Data Protection)
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Request restriction of processing in certain circumstances
- Portability: Request a copy of your data in a machine-readable format
- Objection: Object to our processing of your data for certain purposes
- Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, please contact us at [email protected]. We will respond within 30 days.
8. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States and European Union, where data protection laws may differ.
For transfers from the EEA/UK, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Compliance with GDPR requirements for third-country transfers
9. Children's Privacy
PodCurator is not intended for use by children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete it.
10. Cookies and Tracking
We use the following types of cookies and similar technologies:
- Essential Cookies: Required for authentication and core functionality (e.g., session tokens)
- Analytics: Track usage patterns to improve our service (anonymized where possible)
You can control cookies through your browser settings. Note that disabling essential cookies may affect your ability to use certain features of our service.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification for material changes (if you have an account)
Your continued use of PodCurator after changes become effective constitutes acceptance of the updated policy.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Know what personal information we collect, use, disclose, and sell
- Request deletion of your personal information
- Opt-out of the sale of personal information (Note: We do not sell personal information)
- Non-discrimination for exercising your privacy rights
To exercise these rights, contact us at [email protected].
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
14. Platform-Specific Disclosures
As required by Spotify's Developer Terms and YouTube's API Services Terms, we provide the following additional disclosures:
Spotify Integration
- Spotify Data Usage: We access Spotify's Web API solely to search for and display podcast episode information. We store and periodically refresh episode metadata from Spotify to power search and improve performance, and apply a freshness window to the results we display.
- No Account Linking: PodCurator does not require or support linking your Spotify account. We do not access your personal Spotify data, playlists, or listening history.
- Spotify Content Rights: All podcast content, metadata, and images sourced from Spotify remain the property of Spotify and the respective content creators. We display this content in accordance with Spotify's Developer Terms.
- Spotify Trademark: "Spotify" is a trademark of Spotify AB. PodCurator is not affiliated with, endorsed by, or sponsored by Spotify.
YouTube Integration
- YouTube Data Usage: We access YouTube's Data API solely to search for and display video and channel information. We store video metadata to power search, and refresh or delete it within 30 days in line with YouTube's API Services Terms.
- No Account Linking: PodCurator does not require or support linking your YouTube or Google account. We do not access your personal YouTube data, playlists, or watch history.
- YouTube Content Rights: All video content, metadata, and thumbnails sourced from YouTube remain the property of Google LLC/YouTube and the respective content creators. We display this content in accordance with YouTube's API Services Terms.
- YouTube Trademark: "YouTube" is a trademark of Google LLC. PodCurator is not affiliated with, endorsed by, or sponsored by YouTube or Google.