Legal
Privacy Policy
Last updated July 10, 2026
This policy explains what we collect, how we use it, who processes it for us, and the choices you have. We collect what the product needs, analytics only run with your consent, and we don’t train AI on your content.
Overview
PodCut is operated by Eastbase Studio, which is the data controller for the personal data described here. This policy explains what we collect, why, who processes it for us, and the choices you have. It covers our website and the PodCut application.
The short version: we collect what we need to run the product and bill you, we rely on a set of named, reputable processors, analytics only run if you accept them, and we don’t use your content to train PodCut’s AI models. Questions or requests? Email support@eastbase.studio.
Personal data in your episodes
Podcast episodes you upload or import can contain personal data — for example voices, names, opinions, personal stories, client information, guest information, and sensitive topics. When you process an episode through PodCut, that personal data is processed too (transcribed, clipped, captioned, summarised, and so on).
You should not upload content you are not authorised to process or repurpose. You are responsible for the permissions and consents covered in our Terms of Service.
What we collect
We collect:
- Account data — your name, email, and authentication details (or your Google profile basics if you sign in with Google).
- Workspace and content data — episodes you upload or import, transcripts, clips, graphics, generated copy, brand kits, and team membership.
- Billing data — your plan and subscription status. Card details are handled by Lemon Squeezy; we never see or store your full card number.
- Usage and diagnostic data — error reports and, only with your consent, product analytics events that help us improve the service.
How we use it
We use your data to:
- Run the product — transcribe, select clips, render media, and generate copy.
- Manage your account, workspace, seats, and access.
- Process subscriptions and send service email (verification, invites, notifications).
- Keep the service secure and debug problems.
- With your consent, understand which features are used so we can improve them.
We do not sell your data.
Legal bases for processing
Where data-protection law (such as the GDPR/UK GDPR) applies, we rely on:
- Contract — to provide the service you sign up for, including processing your episodes and managing your account.
- Legitimate interests — to keep the service secure, prevent abuse, and run basic error monitoring.
- Consent — for optional product analytics and any non-essential cookies. You can withdraw consent at any time.
- Legal obligation — to keep billing, tax, and accounting records.
AI processing
We do not use your audio, video, transcripts, clips, or generated outputs to train PodCut’s own AI models.
To produce your outputs, relevant content is sent to AI providers and processed under their API terms: OpenAIfor transcription, clip selection, transcript embeddings (search), and written outputs. We use paid API configurations chosen so that your content is not used to train those providers’ models.
Processors and third parties
PodCut runs on a set of third-party services that process data on our behalf. The current list:
| Service | What it does |
|---|---|
| Vercel | Web application hosting and edge delivery. |
| Neon | Postgres database — your account, workspace, and transcript data. |
| Cloudflare R2 | Object storage for uploaded audio/video and rendered media. |
| Better Auth + Google | Authentication; Google is used for optional sign-in. If the Better Auth hosted dashboard is enabled, Better Auth also processes auth, session, IP, and approximate location activity. |
| Lemon Squeezy | Merchant of Record — checkout, subscriptions, tax, and the billing portal. |
| OpenAI | Speaker-labeled transcription, clip selection and written outputs, and transcript embeddings for search (via the OpenAI API). |
| Trigger.dev | Runs background jobs (transcription, rendering, scheduled sweeps). |
| Resend | Transactional email — verification, invites, and notifications. |
| Upstash | Redis for rate limiting and session storage. |
| PostHog | Product analytics — only after you accept analytics (proxied through our own domain). |
| Sentry | Error monitoring and diagnostics. |
| Vercel Web Analytics | Privacy-friendly, cookieless traffic measurement. |
International processing.These providers — including our database (Neon) and object storage (Cloudflare R2) — may process and store data in the United States and other countries. Where data is transferred internationally, we and our providers rely on appropriate safeguards such as standard contractual clauses and the providers’ own data-processing terms.
Data retention
We keep your content for as long as your workspace is active so the product can use it. After that:
- When you delete content or your account, we remove it from active systems within about 30 days.
- Residual copies may remain in encrypted backups, which are rotated and purged within about 90 days. Operational and security logs are kept for a short period (typically up to 30 days).
- Temporary rendered files are cleaned up automatically on a daily schedule.
- We keep limited billing records for as long as required by tax and accounting law, even after an account is closed.
Your rights and choices
You can access, export, correct, or delete your content from within the product, and you can delete your account. Depending on where you live, you may also have rights to object to or restrict certain processing, to data portability, or to lodge a complaint with a data-protection authority.
To make a request, email support@eastbase.studio. We’ll respond within the timeframe required by applicable law.
Security
Customer-facing access is scoped to your workspace. A tightly allowlisted operator admin console is the controlled cross-workspace exception for support and account operations. Public share, review, and guest links are unlisted, excluded from search engines by default, and revocable at any time. Sensitive actions are recorded in your workspace activity log. You can read more in the landing FAQ.
No system is perfectly secure, but we use reputable infrastructure and follow sensible practices to protect your data.
Children’s privacy
PodCutis not intended for anyone under 18, and we don’t knowingly collect data from children. If you believe a child has provided us data, contact us and we’ll delete it.
Changes to this policy
We’ll update this policy as the product and our obligations change, revising the date at the top and giving notice for material changes. Continuing to use PodCut after an update means you accept the revised policy.