privacy policy

Privacy

Effective 2026-09-07. The short version still holds: Podmenti keeps an email address and a key so you can log in, a ledger so credits add up, and nothing about you beyond what the service needs. No tracking cookies, no analytics, no advertising, no selling or sharing of addresses. The long version is below, because you are entitled to it.

1. Who is responsible

The data controller is Eggvelop ApS, CVR 44287463, Denmark. Questions, requests and complaints go to contact@podmenti.com. We answer within a few days and always within a month.

2. What we store, and why

datawhy
Email addressLogin links, the email that tells you a transcript you asked for is ready, receipts from Stripe, and notices about these terms or the service. Never newsletters or marketing.
API keyThe key is your account. It identifies you on the site and the API.
Plan, credit balance and ledgerEvery credit added or spent, with a reason and a time, so your balance is explainable and disputes can be settled.
UnlocksWhich episodes your account has unlocked, so you are never charged twice.
Transcription jobsThe episodes you requested (title, audio URL, show), the lane, the estimate and promise, and a webhook URL if you gave one, so we can deliver, notify you and refund a missed promise.
Request countsHow many API requests your key made each day, for the plan's daily allowance. A number per day, not a log of what was called.
AI Search topicsThe topic you asked for is sent to the model together with the transcript to produce the answer. We do not keep a history of your topics.
Stripe customer idLinks your account to your subscription so the plan follows payments. Card details never reach us; Stripe holds them.
Verification tokensThe one-time token in a login link, valid for 30 minutes, and how many links an address asked for in the last hour, to stop abuse.
Technical logsCloudflare, which serves the site, records request metadata (IP address, URL, time, user agent) for security and error diagnosis. We look at these only to fix problems and stop abuse.

Transcripts themselves are not personal data about you: they are renderings of public podcast episodes and are the same for every user. Which episodes you unlocked is personal data, listed above.

3. Legal basis

  • Performing the contract (GDPR article 6(1)(b)): the email, key, ledger, unlocks, jobs, request counts and Stripe id are all needed to provide the service you signed up for.
  • Legitimate interest (article 6(1)(f)): rate limiting, security logs and abuse prevention, so the service stays up for everyone. We judged this interest against your privacy; the data involved is minimal and short-lived.
  • Legal obligation (article 6(1)(c)): payment records are kept for the period the Danish Bookkeeping Act requires.

4. How long we keep it

  • Account data (email, key, plan, ledger, unlocks, jobs) for as long as the account exists. Ask, and we delete the account; see section 8.
  • Verification tokens expire after 30 minutes and are pruned afterwards.
  • Daily request counts are kept for 90 days.
  • Test webhook inboxes and what was delivered to them are deleted after 24 hours.
  • Cloudflare's technical logs are held by Cloudflare for a short, rolling period, currently up to seven days.
  • Payment records at Stripe and in our bookkeeping for five years after the end of the financial year, as Danish law requires, even if the account is deleted.

5. Who processes it for us

These companies handle data on our behalf, under data processing agreements, and only to provide their part of the service:

processorwhat forwhere
Cloudflare, Inc.Hosts the site and the API, stores accounts and transcripts, and sends our emails (login links, transcript-ready notices).Global network; EU data centres serve EU visitors. US company.
Stripe Payments Europe, Ltd.Subscriptions, card payments, invoices and the billing portal. Stripe is an independent controller for the payment itself.Ireland, with processing in the US.
Hetzner Online GmbHThe server that runs our standard transcription queue. It holds the episodes you requested (title and audio URL) and your email while the job is delivered.Germany.
Replicate, Inc.The rented GPU behind the fast lane. It receives the public audio file of the episode, nothing about you.United States.
Google LLC (Gemini API)AI Search: the transcript text and your topic are sent to the model to produce the answer, under Google's Gemini API terms. The transcript is public content and the topic is a short phrase; nothing that identifies you is sent.United States.

Show and episode listings come from public directories (Podcast Index and Apple Podcasts charts). Requests to them carry no information about you. We do not sell, rent or share personal data with anyone else, and we do not use advertising or analytics services.

6. Transfers outside the EU

Cloudflare, Stripe, Replicate and Google are US companies or process data in the US. Those transfers rely on the EU-US Data Privacy Framework where the company is certified, and otherwise on the European Commission's standard contractual clauses. What crosses the border is small: your email and account records at Cloudflare and Stripe, and public episode audio or transcript text at Replicate and Google.

7. Cookies and your browser

Podmenti sets no cookies of its own and uses no tracking or analytics scripts. Your browser keeps one thing in local storage: your own API key, so you stay logged in on that device. Log out, or clear site data, and it is gone. Cloudflare may set a strictly necessary cookie for its bot protection during unusual traffic; it is not used to track you. Stripe's checkout and billing pages set their own cookies under Stripe's policy.

8. Your rights

Under the GDPR you can, at any time and free of charge:

  • See what we hold. Most of it is already on your account page and behind GET /api/v1/usage. Ask and we send a complete export.
  • Correct it. Write to us to change the email on an account.
  • Delete it. Write to us and the account, its ledger, unlocks and jobs are deleted within 30 days. Payment records stay for the statutory period, and transcripts stay in the library since they are not about you.
  • Take it with you. The export is JSON and includes your ledger and unlock list.
  • Object or restrict. To processing based on legitimate interest, such as the technical logs.
  • Complain. To the Danish Data Protection Agency, Datatilsynet, at datatilsynet.dk, or to the supervisory authority where you live. We would rather hear from you first.

Requests come from the email on the account, or with the account's key, so that we know it is you.

9. Security

Everything travels over https. Keys are random and never emailed after creation; login is by one-time link. Account data lives in Cloudflare's managed database with access limited to the service itself. Card details never touch our systems. If a breach ever affected your data we would tell you, and the authority, as the law requires.

10. Children

Podmenti is not directed at children and accounts require the holder to be at least 18. If you believe a child has created an account, write to us and we will delete it.

11. Changes

The date at the top is the effective date of the current version. For changes that affect what we collect or why, we email every account before they apply.

See also the terms of service. Contact: contact@podmenti.com.