Privacy Policy
How Podhoc handles your data and protects your privacy.
Data Controller
This website and the Podhoc service are operated by Nexo Apex SL (“Podhoc”, “we”, “our”, or “us”), acting as data controller for the personal data described in this policy.
Company details
- Company: Nexo Apex SL
- Address: Edificio Cami Reial c/ Cami Reial, 13-17, 3a planta, 43700 El Vendrell, Tarragona, Spain
- Email: hi@podhoc.com
- Website: nexoapex.com
Scope
This Privacy Policy explains how we process personal data when you:
- visit the Podhoc website,
- create and use a Podhoc account,
- submit sources and generate podcasts,
- contact support or communicate with us.
By registering, creating an account, or signing up in Podhoc, you acknowledge and consent to the processing described in this Privacy Policy, together with the applicable Terms and policies.
Data We Process
We apply data minimization and process only what is necessary to operate, secure, and improve Podhoc.
1) Data you provide
- Account data: email address, authentication details, and profile preferences.
- Generation input data: URLs, text, and uploaded files (for example PDF, DOCX, TXT) used to create podcasts.
- Support data: information included in support requests and communications.
- Billing and subscription data: plan, credits, invoices, and payment status (full card data is processed by Stripe, not stored by Podhoc).
2) Data generated during service use
- Service metadata: timestamps, status events, language, generation settings, and technical processing events.
- Security and operational logs: anonymized or pseudonymized logs used for reliability, abuse prevention, and troubleshooting.
3) Cookie and analytics data
- Essential cookies: required for basic functionality and security.
- Analytics cookies: third-party analytics (Google Analytics) and the
_podhoc_uidlinker described below are enabled only if you explicitly allow them through the cookie banner/preferences. One narrowly-scoped first-party cookie,podhoc_afs, is an exception: it serves only aggregate audience measurement of our own site, is never shared with anyone, and is set without prior consent under the audience-measurement exemption to the prior-consent rule (ePrivacy Art. 5(3) / LSSICE Art. 22.2, as interpreted in the Spanish AEPD’s cookie guidance). It is described in full below, and it is suppressed entirely if you refuse analytics or if your browser sends a Do Not Track signal. _podhoc_uid(cross-subdomain analytics linker): a first-party cookie set on.podhoc.comonce you sign in onapp.podhoc.com,login.podhoc.com, oradmin.podhoc.com, and readable across all*.podhoc.comsubdomains (including the marketing site and our browser extensions). It carries a stable pseudonymous identifier (the Cognito subject for your account — never your email, name, or other personal field) so that Google Analytics can attribute the full conversion funnel across our subdomains. The cookie has a lifetime of 30 days (matching the Cognito refresh-token window so stale sessions on shared devices age out within a month), is refreshed on each sign-in, is cleared on logout, and is never used for authentication or authorization (the authentication boundary is the Cognito JWT validated by our API). The cookie is set withSecureandSameSite=Laxflags.podhoc_afs(first-session activation measurement): a first-party cookie set on.podhoc.comwhen you open our sign-in or app pages (login.podhoc.com,app.podhoc.com). Its only purpose is aggregate audience measurement of the first-session activation funnel — telling us at which step of a first session (for example: page opened, sign-up submitted, first source added, first podcast generated, first playback) people stop, so we can fix the step that loses them. It is not used for advertising, personalisation, profiling, automated decision-making, or cross-site tracking, and it is never shared with third parties or sent to any other website — the resulting records are stored only in our own database and are read only in aggregate. The cookie value is a randomly generated identifier and nothing else: it holds no email address, no name, no URL, no hostname, no filename, and no text you typed. Its lifetime is 2 hours from the moment it is created — a hard cap that continued browsing does not extend — and it is additionally deleted when you log out. It is set withSameSite=Laxand, over HTTPS,Secure. It is not set at all if you have refused analytics through the cookie banner, or if your browser sends a Do Not Track signal. Our mobile apps measure the same funnel using an equivalent random identifier held in local app storage under the same 2-hour limit, rather than a cookie. The activation records derived from it are kept for a maximum of 90 days from the moment we receive them and are then deleted.
4) Advertising data (Android app only)
Our Android mobile app shows banner advertising to accounts on the Free tier. The ads are served by Google AdMob. For ad serving, Google acts as an independent data controller and not as our processor — see Data Sharing below.
- Advertising identifier. Google’s Mobile Ads SDK reads your device’s advertising ID: a resettable identifier assigned by Google Play, and not your name, email address, or Podhoc account ID.
- Other data the ad request carries. Like any internet request, an ad request carries your device’s IP address, from which Google can infer an approximate — typically city-level — location, together with general device and app information such as device model, operating-system version, screen size, and language.
- What we never send. We never combine the advertising identifier with your account data, and we never send your Podhoc account data — your email address, your account ID, your uploaded sources, your scripts, or your podcasts — to the ad network.
- The ads are personalised. If you consent, Google may combine the advertising identifier with data it holds from other apps and sites to select ads it considers relevant to you, and to limit how often the same ad repeats. If you decline, no ad is requested at all and no banner appears; declining does not restrict any Podhoc feature.
- Consent. Where EEA, UK or Swiss rules require consent, no ad is requested until you have answered the consent form presented by Google’s consent management tool, which the app shows before the first ad loads.
- Withdrawing consent. Wherever we asked for your consent, the Profile tab of our Android app offers an Ad privacy options control that reopens Google’s consent form so you can change your answer at any time. Resetting or deleting the advertising ID in your Android system settings is a separate and additional step: it gives you a new identifier, but it does not withdraw your consent.
- Retention. Podhoc does not receive, store, or retain the advertising identifier or any data returned by the ad network. The identifier is read on your device by Google’s SDK and sent directly to Google, and Google’s own retention periods govern it from that point.
- Where no advertising happens. No advertising identifier is read on iOS, in the Android Automotive (in-car) build, or for Creator and Pro subscribers, who see no advertising at all.
Google’s handling of this data is described in Google’s Privacy Policy and in how Google uses information from sites or apps that use its services.
User Responsibility for Submitted Content
You are solely responsible for any information or materials you submit to Podhoc for AI generation, including URLs, text, documents, and files.
By using Podhoc, you confirm that:
- you have the legal right to submit and process that content,
- your submissions comply with applicable law,
- you will not submit unlawful, sensitive, or third-party data without a valid legal basis.
Nexo Apex SL does not pre-validate all dynamic user-submitted content and is not responsible for illegal, sensitive, infringing, or unauthorized data provided by users.
This includes, without limitation, copyright-protected material uploaded or processed without required permissions.
Podhoc reserves the right to suspend or restrict accounts if anomalies are detected in usage behavior or in the nature of submitted content, including signals of abuse, illegal activity, or policy non-compliance.
How We Use Data
We process data to:
- provide account access and authentication,
- run podcast generation workflows and deliver outputs,
- manage subscriptions, credits, and transactions,
- maintain security, prevent abuse, and monitor reliability,
- provide support and respond to legal requests,
- improve product quality using anonymized/aggregated metrics.
Legal Bases (GDPR)
Where GDPR applies, our legal bases are:
- Contract performance: to provide Podhoc features you request.
- Legitimate interest: service security, fraud prevention, quality, and reliability.
- Consent: third-party analytics cookies (including Google Analytics and the
_podhoc_uidlinker) and similar optional tracking. - Legitimate interest — first-party audience measurement: the
podhoc_afscookie and the aggregate first-session activation statistics derived from it. The storage of the cookie itself relies on the audience-measurement exemption to the prior-consent rule rather than on your consent. You can object at any time by refusing analytics in the cookie banner or by enabling Do Not Track in your browser, and we will then stop setting it. - Consent — advertising: reading your device’s advertising identifier and requesting personalised banner ads in our Android app, wherever consent is required (today, the EEA, the UK and Switzerland). You can withdraw this consent at any time from Ad privacy options on the app’s Profile tab; withdrawal does not affect the lawfulness of processing carried out before it, and it does not restrict any Podhoc feature.
- Legal obligation: accounting, compliance, and lawful disclosure obligations.
Data Sharing
We do not sell personal data for money.
One qualification: under some US state privacy laws — including the California CPRA — disclosing an advertising identifier to an ad network for personalised advertising is itself defined as a “sale” or a “share”, even when no money changes hands. That disclosure happens only in our Android app, only for Free-tier accounts, and only where consent allows. To stop it you can withdraw consent from Ad privacy options on the app’s Profile tab, opt out of ads personalisation or delete the advertising ID in your Android system settings, upgrade to a paid tier (which shows no advertising at all), or write to us at hi@podhoc.com.
We share data with the third parties below. Apart from advertising — explained in its own entry — they act as our processors, providing services strictly on our instructions:
- Infrastructure and hosting: AWS
- Authentication providers: Google and Apple (when you choose SSO)
- Payments: Stripe
- AI processing providers: providers used to generate scripts/audio
- Operational communications: email/support tooling
- Analytics tooling: only when analytics consent is enabled
- Advertising — an independent controller, not our processor: Google AdMob, for banner ads in the Android app only, shown to Free-tier accounts, and only where consent allows. For ad serving Google determines its own purposes for the data it receives, and we cannot confine that use to purposes we specify. Its handling is governed by Google’s Privacy Policy, not by our instructions
Apart from advertising, these providers act as our processors: they handle data on our documented instructions, under contractual obligations and applicable data protection laws.
Public Discover Publication
Podhoc operates a public Discover surface where generated podcasts can be discovered, streamed, and shared by other users and search engines. Publication to Discover is a separate processing activity from generating the podcast for your private use and is governed by the rules below.
What is published. When a podcast is published to Discover, the audio, the title, the cover image, the script summary, and non-sensitive generation metadata (style, language, duration) are made publicly accessible. The source materials you upload (PDFs, DOCX, TXT, notes) are never published. Source files remain private to your account and are processed only to generate the podcast.
Default behaviour by tier.
- Free tier: generated podcasts are published to Discover by default and cannot be made private. To keep a podcast private, upgrade to a paid tier before generation, or delete the podcast / account to withdraw the listing.
- Creator and Pro (paid tiers): generated podcasts are published by default, but you can disable publication per-podcast or globally via the “Auto-publish to Discover” toggle in advanced settings. You may also retract a previously published podcast at any time.
- API integrators: the
auto_publishparameter defaults totrue. Production tokens on paid tiers may setauto_publish: false.
Legal basis (GDPR). Publication to Discover relies on:
- Contract performance for users on the Free tier — publication is part of the Free service, disclosed before account creation and at the point of generation.
- Consent for users on paid tiers, given each time you generate a podcast with auto-publish enabled; consent is withdrawable per-podcast (toggle off, retract, or delete).
Withdrawal of consent and right to be forgotten. You can withdraw consent at any time on paid tiers by toggling auto-publish off, retracting individual podcasts, or downgrading your account. Free-tier users can withdraw consent by deleting individual podcasts or their account. We will remove the public listing within a reasonable propagation window (CDN/cache typically clears within 24 hours). Retracted podcasts remain in your private library unless you also delete them.
Discoverability. Published podcasts can be indexed by search engines, embedded by third parties, and referenced from RSS feeds. We cannot guarantee that third-party caches, archives, or downloaded copies are removed after retraction.
Personal data warning. Do not generate (and therefore do not publish) podcasts from material that contains personal data of others, confidential information, copyrighted text without permission, or anything you would not want listed publicly. Free-tier users in particular should treat every generated podcast as a public statement.
Public Discover Visibility, Comments, and Embeds
This section complements the previous one and explains the privacy implications of the public-facing surfaces of Discover — search-engine discoverability, the comments system, anonymous browsing, and the embed widget.
Search-engine indexing and third-party referencing. Published podcasts are intended to be discovered. Their listing pages, audio URLs, covers, AI-generated summaries, and the public username of the creator are crawlable by search engines, ingestible by RSS readers, and addressable by third-party indexes. Once a podcast is published, you should expect copies of its metadata to appear in third-party caches that we do not control.
What public Discover data contains. Each public listing includes the podcast title, the AI-generated summary, the generated audio file, the cover image, and the public username of the creator. The username is the public-by-design identifier and is the only personal field we expose on Discover. Email addresses, account IDs, billing data, source files (PDF, DOCX, TXT, notes), and any other private account data are never published.
Comments and feedback. Logged-in users can post comments and feedback on public podcasts. When a comment is stored, we record the internal commenter_user_id for audit, moderation, and abuse-handling — but the display surface only shows users.username. We never display email addresses, account IDs, or any other identifier next to a comment. Comment text is public on submission and is included in third-party crawls of the listing page. By submitting a comment, you accept that it is public, attributable to your public username, and subject to the moderation rules in the Terms of Use.
Anonymous browsing and comment viewing. Visitors who are not signed in can browse Discover listings and read comments without an account. For abuse-protection purposes we log anonymous request metadata (IP address, user-agent, route) at the edge for a short retention window, but these logs are not linked to any user account and are not used for profiling or advertising. Edge logs are aggregated and rotated according to our standard retention schedule.
Embed widget telemetry. Podhoc offers an embed widget so third-party sites can play published podcasts inline. Plays from the embed widget are counted at the (embed_id, slug, day) level only — we record no IP address, no user-agent string, no referrer, and no visitor identifier in the embed-play counters. This counter exists solely to throttle abuse and to surface aggregated play counts to creators.
Right of erasure (per-podcast and global).
- Paid-tier users (Creator, Pro) can opt out of Discover publication per-podcast or globally from their account preferences. Opting out retracts the public listing and removes the slug, audio URL, cover, and summary from Discover within a reasonable CDN propagation window. The same retraction also removes any comments attached to that listing.
- Free-tier users cannot opt out of publication while remaining on the Free tier — to remove a listing they must upgrade to a paid tier (which exposes the per-podcast retract control) or delete the individual podcast / their account. Deleting the account removes all Discover presence including comments authored by that account.
- Erasure of a specific comment (e.g. a comment posted by another user that mentions you) can be requested via legal@podhoc.com; we will review and act on legitimate erasure requests per the rights section below.
Caveats on erasure. As noted above, search-engine caches, third-party archives, downloaded audio files, and other re-publications are outside our control. We will retract from podhoc.com but cannot guarantee removal from external indexes.
International Transfers
Some providers may process data outside your country. When required, we use appropriate safeguards (for example, contractual safeguards and equivalent protections under applicable law).
Providers that process data in the United States include Google LLC — for Google Analytics and, in our Android app, Google AdMob — alongside our payment and AI processing providers. Transfers to them rely on an adequacy decision where the provider is certified under the EU–US Data Privacy Framework, and on standard contractual clauses otherwise.
Retention
We keep data only for as long as needed for the purposes above, including legal and security obligations. Retention periods vary by data type (account, billing, logs, generated assets, support records). When data is no longer required, it is deleted or irreversibly anonymized.
Security
We implement technical and organizational safeguards including encrypted transport, controlled access, log sanitization, and monitoring. No system is absolutely risk-free, but we continuously improve our protections.
Your Rights
Depending on applicable law, you may have the right to:
- access your personal data,
- correct inaccurate data,
- request deletion,
- object to or restrict certain processing,
- request portability,
- withdraw any consent you have given, at any time — including consent for analytics cookies, and consent for advertising in our Android app, which you can reopen and change from Ad privacy options on the app’s Profile tab,
- object to first-party audience measurement (
podhoc_afs) by refusing analytics in the cookie banner or by enabling Do Not Track.
To exercise your rights, contact us at hi@podhoc.com with subject “Podhoc Privacy Request”.
Children
Podhoc is not intended for children under the minimum age required by applicable law. If you believe a minor has provided data unlawfully, contact us and we will review and act promptly.
Because Podhoc is not directed to children, advertising in our Android app is requested with a general-audience content rating, and we do not knowingly show advertising to a child.
Policy Updates
We may update this Privacy Policy to reflect legal, technical, or operational changes. The latest version is always published on this page with the updated date.
Legal Questions
If you have legal questions about this policy or your obligations when submitting content, contact legal@podhoc.com.
Last Updated: September 9, 2026