Skip to content

Template — have this reviewed by counsel before launch.

Privacy Policy

Last updated October 6, 2026

This policy explains what Afterair collects when you use it, why, who we share it with, and the choices you have. The short version: we use your podcast audio and text only to produce your outputs, we don't sell your data, and we don't use your content to train AI models.

What we collect

  • Account details: your name, email address and a password (stored as a hash by our authentication provider, never in plain text).
  • Show details: show titles, RSS feed URLs, past show notes or episode descriptions you provide for your voice profile, your show dictionary and speaker names.
  • Episode content: audio files you upload or that we fetch from your feed or a link you give us, the transcripts we make from them, and the outputs we generate, including every version you keep.
  • Integration credentials: if you connect a podcast host such as Buzzsprout or Transistor, the API token and podcast ID you give us.
  • Billing records: your plan, credit balance and payment history. Card details go directly to Stripe; we never see or store full card numbers.
  • Usage and diagnostics: pages visited, features used, device and browser information, and error reports, so we can fix problems and improve the product.

How we use it

  • To transcribe your episodes and generate the outputs you ask for, in your show's voice.
  • To publish outputs to your podcast host when you choose to.
  • To run your account, process payments, grant and refund credits, and send service emails (for example, “Your show notes are ready”).
  • To keep the service secure, prevent abuse and diagnose errors.

We don't sell your personal data and we don't use your audio, transcripts or outputs to train AI models.

Service providers we share data with

We use a small number of processors, each only for the purpose listed:

  • AI processing by Anthropic and OpenAI, through Vercel AI Gateway. Transcripts, your voice profile and related text are sent through Vercel's AI Gateway to Anthropic's Claude models to generate outputs, and to OpenAI's models when Claude is unavailable. Under their API terms, inputs and outputs are not used to train their models.
  • Transcription by a speech-to-text provider (such as Deepgram or AssemblyAI). Your audio and your show dictionary terms are sent to the provider to produce a transcript with speaker labels and timestamps.
  • Payments by Stripe. Stripe processes payments and stores payment methods under its own privacy policy.
  • Hosting and storage (Supabase and Vercel) for the database, file storage and the web application.
  • Background jobs (Inngest), which run transcription and writing steps and briefly hold the text passed between them.
  • Email (Resend) for account and notification emails.
  • Product analytics and error monitoring (PostHog and Sentry).
  • Your podcast host (for example Buzzsprout or Transistor), only when you connect it and choose to publish.

We may also disclose information if the law requires it, or to protect the rights and safety of our users or the service.

How long we keep it

  • Audio: deleted at most 30 days after processing by default, and sooner where your workspace settings say so. You can change this retention period in your workspace settings.
  • Transcripts and outputs: kept until you delete the episode or your account, so you can edit and regenerate later.
  • Billing records: kept as long as tax and accounting law requires.
  • Account data: deleted when you delete your account, apart from records we must keep by law.

Security

Data is encrypted in transit (TLS). Integration tokens, such as your Buzzsprout or Transistor API key, are encrypted at rest with AES-256-GCM before they're stored, and are never shown back to you or sent to the browser. Audio files are stored in a private bucket that only your workspace can access. Database access is restricted per account with row-level security. See our security page for more.

Your choices and rights

  • Delete any episode, its audio, transcript and outputs from the app at any time.
  • Disconnect an integration at any time; we delete the stored token.
  • Ask us for a copy of your data, to correct it, or to delete your account by emailing us.
  • Depending on where you live (for example under the GDPR or CCPA), you may have further rights, including objecting to processing or complaining to a data protection authority.

Cookies

We only use essential cookies, to keep you signed in. Product analytics runs without cookies or local storage, and we don't use advertising cookies.

Children

Afterair isn't intended for anyone under 16, and we don't knowingly collect their data.

Changes

If we make material changes to this policy, we'll update the date above and tell you by email or in the app.

Contact

Questions or requests: support@afterair.app.