Privacy policy
Last updated 28 August 2026
Podmaniac ("we") is a podcast hosting service at podmaniac.com, operated from New Zealand. This policy explains what we collect, why, and what we never do with it. The short version: we store what is needed to host your podcast and count your downloads, we sell nothing to anyone, and your content stays yours.
What we collect from podcasters
- Account details: your email address, name and a securely hashed password (we never store the password itself). Sign in uses an encrypted session cookie.
- Your content: the audio, artwork, show notes, transcripts and settings you upload or create. It is stored so we can host and deliver your podcast; it remains yours.
- Billing details (when paid plans launch) are handled by our payment provider; we never see or store card numbers.
- Support email you send us, so we can answer it.
What we collect about listeners
When someone downloads or streams an episode we log the request: IP address, user agent (which app was used), country and the episode requested. We use this solely to produce download statistics for the show's owner, following the IAB Podcast Measurement Technical Guidelines v2.3. IP addresses are used to count unique listeners in anonymised, hashed form and are not shown to show owners or anyone else. We do not build listener profiles, we do not track listeners across podcasts or websites, and public show pages carry no advertising trackers.
Google and YouTube data
If a show owner connects a YouTube channel, we use Google sign in to obtain permission to upload videos to that channel. We store the channel's name, thumbnail and an access token; we use them only to upload the episode videos the owner asked for and to show upload status. We do not read any other YouTube data, and we never post anything the owner did not initiate. Podmaniac's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. A connection can be removed at any time in Show settings or at myaccount.google.com/permissions, which deletes our stored token.
AI features
Transcription runs on infrastructure we operate. For AI show notes, the episode transcript is sent to our AI provider (Anthropic) to generate the notes; it is not used to train their models. AI features only run when a show owner switches them on or clicks the button.
We send account email only: invitations, email verification, password resets and service notices, via our email provider (Resend). No marketing lists, no newsletters you did not ask for.
Cookies
The dashboard uses one cookie: the session that keeps you signed in. Public show pages and the player set no cookies and use no third party analytics.
Where data lives
Content and data are stored and served on Cloudflare's global network, with primary storage in their infrastructure. Backups exist for reliability.
Retention and deletion
Your content stays as long as your account does. Delete an episode and its files are removed from storage; delete a show or account (or ask us to) and its content, members and tokens go with it. Raw listener request logs are kept for up to 90 days for counting, after which only aggregated statistics remain.
Sharing
We share data only with the processors that make the service work: Cloudflare (hosting and delivery), Resend (email), Anthropic (AI show notes) and, when billing launches, our payment provider. We do not sell or rent any data, full stop. We would disclose data if the law genuinely required it, and would tell the affected user unless legally barred.
Your rights
Email us to access, correct, export or delete your data. New Zealand's Privacy Act 2020 applies; EU and UK users have their GDPR rights, which we honour.
Changes
If this policy changes materially we will note it here and email account holders.