Privacy Policy
Last updated: April 1, 2026
1. Data Controller
The data controller for personal data processed through PodDigest (podsumujpodcast.pl) is:
DMC Filip Olender
ul. Lamparcia 10A, Lochowo, Poland
NIP (Tax ID): 5542813570 · REGON: 526888290
Email: kontakt@podsumujpodcast.pl
2. Data We Collect and Why
2.1 Account Data (Google Sign-In)
When you register or sign in via Google OAuth, we collect your email address and name from your Google account. This data is necessary to provide the service (GDPR Art. 6(1)(b)). It is retained for the lifetime of your account and permanently deleted within 30 days after account deletion.
2.2 Generated Summaries
We process the podcast or video URL you submit and generate an AI summary stored with the selected template, language, and creation date. Legal basis: performance of a contract (GDPR Art. 6(1)(b)). Retention: 90 days from generation.
2.3 Email Subscriptions (Automatic Digests)
If you subscribe to a podcast channel, we collect your email address, channel URL, chosen template, and language. Legal basis: consent (GDPR Art. 6(1)(a)). Data is retained until you unsubscribe. You can unsubscribe at any time via the link in every digest email.
2.4 Payment Data
Payments are processed by Stripe, Inc. We do not store your credit card details. We retain your Stripe customer ID and subscription status to manage your plan. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
2.5 Technical and Analytics Data
- IP address— collected for rate limiting and aggregate analytics. Retained up to 12 months.
- Geolocation (country, city)— derived from Vercel request headers, used for aggregate statistics only.
- User agent / device type— aggregate statistics only.
- Anonymous usage events(e.g., number of summaries generated, template types) — non-personally-identifiable.
- Feedback (ratings, comments)— provided voluntarily. Retained up to 12 months.
Legal basis for analytics: legitimate interest (GDPR Art. 6(1)(f)) — improving service quality.
3. Third-Party Data Processors
We do not sell or share your data with third parties for marketing purposes. We use the following sub-processors:
- Supabase Inc. (USA, EU region) — database, user authentication.
- Vercel Inc. (USA) — application hosting, CDN, anonymous traffic analytics.
- Resend — transactional email delivery (summaries, digests).
- Stripe, Inc. (USA) — payment processing.
- OpenRouter Inc. (USA) — AI model request routing.
- Anthropic PBC (USA) — Claude language model for generating summaries. Your data is not used to train models.
- Perplexity AI Inc. (USA) — fact-checking (Fact Check template).
US-based processors handle data under Standard Contractual Clauses (SCCs) approved by the European Commission or the EU-US Data Privacy Framework, ensuring an adequate level of protection under GDPR.
4. Cookies and Tracking
PodDigest uses the following cookies:
- lang — stores your selected language. Strictly necessary.
- consent — stores your cookie consent decision. Strictly necessary.
- theme — stores your dark/light mode preference. Strictly necessary.
We use Vercel Analytics for anonymous traffic statistics (no individual user identification) and our own analytics table in Supabase for aggregate usage statistics.
Your local summary history is stored in your browser's localStorage and can be cleared in your browser settings at any time.
We do not use cookies for marketing or cross-site tracking.
5. Your Rights Under GDPR (EU/EEA Residents)
If you are located in the EU or EEA, you have the right to:
- access your personal data (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure — "right to be forgotten" (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing (Art. 21),
- withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3)).
To exercise these rights, contact us at: kontakt@podsumujpodcast.pl. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (UODO): uodo.gov.pl
6. Your Rights Under CCPA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:
- Right to Know — request disclosure of the categories and specific pieces of personal information we have collected.
- Right to Delete — request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out — we do not sell your personal information. If this changes, we will provide an opt-out mechanism.
- Right to Non-Discrimination — we will not discriminate against you for exercising your CCPA rights.
To submit a CCPA request, email: kontakt@podsumujpodcast.pl. We will verify your identity and respond within 45 days.
7. Data Retention
- Account data — retained while your account is active; deleted within 30 days of account closure.
- Summaries — 90 days from generation.
- Subscription data — until unsubscription.
- Technical logs (IP, user agent) — up to 12 months.
- Feedback — up to 12 months.
- Payment records — as required by applicable tax law (typically 5 years).
8. International Data Transfers
Your data may be processed outside the EU/EEA by our sub-processors listed in Section 3. All transfers are protected by Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework, ensuring compliance with GDPR requirements.
9. Children's Privacy
PodDigest is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.
10. Changes to This Policy
Any changes will be published on this page with an updated date. For material changes, we will notify account holders by email.
11. Contact
For any privacy-related questions or requests, contact us at: kontakt@podsumujpodcast.pl