Skip to content

Security

Last updated October 6, 2026

Your unreleased episodes and your podcast host credentials deserve care. Here's how Afterair handles them.

Your audio

  • Uploaded audio goes to a private storage bucket. Each workspace can only read and write its own folder.
  • Audio is deleted at most 30 days after processing by default, and you can change that in settings.
  • Uploads are resumable, so a dropped connection doesn't mean starting over.

Your account data

  • All traffic is encrypted with TLS, and HTTPS is enforced with HSTS.
  • Every table is protected by row-level security, so a signed-in user can only reach their own workspace's rows.
  • Privileged operations (charging and refunding credits, publishing) run only on our servers after an ownership check.
  • Passwords are handled by our authentication provider and stored only as salted hashes.

Integration tokens

  • Podcast host tokens, such as your Buzzsprout or Transistor API key, are encrypted at rest with AES-256-GCM.
  • They are decrypted only on the server at the moment we publish, and are never sent back to your browser.
  • Disconnecting an integration deletes the stored token.

AI and transcription

  • Transcription runs through a speech-to-text provider; generation runs through Vercel AI Gateway on Anthropic's Claude models, with OpenAI models as a fallback.
  • Audio is sent to the transcription provider only to produce your transcript. Under Anthropic's and OpenAI's API terms, inputs and outputs aren't used to train their models.
  • Pull quotes are checked word for word against your transcript, so we never put invented words in someone's mouth.

Web application

  • A strict Content Security Policy, frame blocking and other security headers on every page.
  • Sign-out and other state-changing actions require a POST request; redirects after sign-in only go to our own pages.

Reporting a vulnerability

If you find a security issue, email support@afterair.app with the details. Please give us a reasonable chance to fix it before disclosing it publicly. We'll reply within a few working days.