Privacy Policy
Last updated: August 2026
This Privacy Policy explains how PodHerd ("Service", "we", "us", or "our") collects, uses, stores, and protects your personal data. We are committed to protecting your privacy and complying with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
PodHerd is the data controller responsible for your personal data. If you have questions about this policy or your data, contact us at:
Email: gdpr@podherd.com
2. Information We Collect
Information you provide
- Account information: Name, email address, password, and billing details when you register or subscribe
- Payment information: Processed securely through our payment provider; we do not store full card details
- Content you upload: Podcast episodes, audio files, video files, and any metadata you provide
- Communications: Messages you send us via email or support channels
Information generated through your use
- Transcripts and clips: Text and video content generated from your uploaded media
- Usage data: Features used, clips created, searches performed, and time spent on the platform
- Technical data: IP address, browser type, device information, and operating system
Information from third parties
- RSS feed data: Podcast metadata, episode information, and media URLs from feeds you connect
- Authentication providers: If you sign in via a third-party service, we receive basic profile information as permitted by that service
- Google Search Console: If you choose to connect your Google account, we receive search performance data for the property you select. See section 4 for full details.
3. How We Use Your Information
We process your personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Service | Performance of contract |
| Processing payments and managing subscriptions | Performance of contract |
| Transcribing audio and generating clips | Performance of contract |
| Showing Google Search Console insights for a property you connect | Performance of contract |
| Sending service-related communications | Performance of contract |
| Responding to support requests | Performance of contract |
| Improving and developing the Service | Legitimate interests |
| Analysing usage patterns and performance | Legitimate interests |
| Preventing fraud and ensuring security | Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Marketing communications (with consent) | Consent |
4. Google Account Data (Google Search Console)
PodHerd offers an optional integration with Google Search Console so you can see how your podcast pages perform in Google Search from within your PodHerd dashboard. This section explains exactly what we access, why, and how to revoke it.
PodHerd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
Connecting is entirely optional and initiated by you. Nothing is accessed unless you complete the Google consent screen.
We request a single, read-only scope:
| Scope | What it permits |
|---|---|
https://www.googleapis.com/auth/webmasters.readonly |
Reading search performance and index-coverage data for Search Console properties you own |
This scope cannot modify, publish, or delete anything in your Google account or in Search Console. We do not request access to Gmail, Drive, Contacts, Calendar, or any other Google service.
During the connection flow we also receive your Google account email address, solely so we can show you which account is connected.
What we store
- Your chosen property: The Search Console property URI you select, and its type
- An access credential: A refresh token, encrypted at rest with AES-256-GCM. This is never displayed, exported, or shared, and is used only to request the data described below
- Your Google account email: Shown back to you so you can confirm which account is connected
- Search performance data: For the property you select — dates, page URLs, search queries, countries, device types, clicks, impressions, click-through rate, and average position
- Index coverage data: For a sample of your pages — coverage state, indexing state, and last crawl date
We retain up to 16 months of search performance history, mirroring the window Google itself makes available.
How we use it
Google user data is used for one purpose: to display search performance insights to you, the owner of the connected property, inside your PodHerd dashboard.
We do not:
- Sell Google user data, or share it with data brokers
- Use it for advertising, ad targeting, or personalisation
- Use it to train, develop, or improve generalised artificial intelligence or machine learning models
- Transfer it to third parties, except as strictly necessary to provide the feature (for example, the cloud infrastructure that stores it), to comply with applicable law, or as part of a merger or acquisition where it remains subject to this policy
- Make it visible to other PodHerd customers
Search performance data is stored against your channel and shown only to users you have granted access to that channel.
Human access
No PodHerd staff read your Google user data, except in these limited cases:
- You have given us explicit permission, for example when you ask us to investigate a support issue
- It is necessary for security purposes, such as investigating abuse or a suspected breach
- We are required to do so to comply with applicable law
- The data is aggregated and anonymised, and used for internal operations such as capacity planning
Revoking access
You can revoke our access at any time, and you do not need our cooperation to do so:
- In PodHerd: Use the Disconnect button on your channel's SEO page. We ask Google to revoke the credential, delete our stored copy of it, and delete the search performance data collected through the integration
- In your Google account: Visit myaccount.google.com/permissions and remove PodHerd's access. This invalidates the credential immediately, and we can no longer request any data
When you delete your PodHerd account, we ask Google to revoke the refresh token outright, so the grant does not survive on your Google account, and we delete the search performance data we hold for you.
If you revoke access from your Google account rather than from within PodHerd, the search performance data we already collected remains stored until you disconnect in PodHerd or ask us to remove it. See section 8 for your erasure rights.
5. Data Sharing
We do not sell your personal data. We may share your information with:
- Service providers: Third parties who help us operate the Service, including cloud hosting, payment processing, and analytics providers. These providers are contractually bound to protect your data.
- Legal requirements: When required by law, court order, or governmental authority, or to protect our rights, safety, or property.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity.
We do not share your uploaded content or generated transcripts with third parties except as necessary to provide the Service to you.
6. Data Storage and Security
Your data is stored on secure servers provided by reputable cloud infrastructure providers. We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and regular security assessments.
While we take reasonable precautions, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.
7. Data Retention
We retain your personal data for as long as necessary to provide the Service and fulfil the purposes described in this policy:
- Account data: Retained while your account is active and for a reasonable period afterward for legal and business purposes
- Uploaded content and transcripts: Retained while your subscription is active; deleted within 30 days of account termination unless you request earlier deletion
- Usage and technical data: Retained in anonymised or aggregated form for analytics purposes
- Payment records: Retained as required by tax and accounting regulations
- Google Search Console data: Up to 16 months of search performance history while the integration is connected; the stored credential and this data are deleted when you disconnect or delete your account
8. Your Rights
Under UK data protection law, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data in certain circumstances
- Restriction: Request that we limit processing of your data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or for direct marketing
- Withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise these rights, contact us using the details above. We will respond within one month, or inform you if we need additional time.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies and Tracking
We use cookies and similar technologies to operate the Service, remember your preferences, and analyse usage. Essential cookies are required for the Service to function. Analytics cookies help us understand how you use PodHerd.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect Service functionality.
10. International Transfers
Your data may be processed by service providers located outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the relevant authorities, to protect your data in accordance with UK data protection law.
11. Children's Privacy
PodHerd is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top indicates when the policy was last revised.
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
For questions, concerns, or to exercise your data rights, please contact us at:
Email: info@podherd.com
