Privacy Policy
Last updated: 5 August 2026
⚠️ Have a lawyer review this before you submit it to Google or Paddle. The facts about what the system does are accurate; the legal wording is not legal advice. Fill in everything marked [TO FILL IN].
Who we are
Podcast Resolve (https://podcastresolve.com) is operated by RAW Future s.r.o., company number [TO FILL IN], registered office [TO FILL IN], Czech Republic.
For your account data we are the controller. For the content you put into the service (topics, transcripts, notes) we are a processor — that content is yours.
Data protection contact: [TO FILL IN email].
What we process
Account data
| Data | Why |
|---|---|
| sign-in, password reset, service notices | |
| Name (optional) | how we address you in the interface |
| Password | we store only a hash (scrypt); we never see the password |
| Interface language | showing the product in your language |
| Last sign-in time | account security |
Operational data
- Sessions — a
pr_sessioncookie in your browser; we store only its hash. Valid 30 days. - Audit log — who changed a topic, configuration or access, and when. It is evidence of changes, so it is never edited or deleted.
- Usage records — how many tokens and searches the agent consumed. Used for billing and quotas.
- IP address — held briefly in memory to rate-limit sign-in attempts. Never written to the database.
Content you create
Show names, hosts, episodes, topics, texts, fact-checks, source links and configuration. This content is yours; we process it to provide the service.
What we do not do
- We do not sell or share your data with third parties for their own purposes.
- We run no advertising and no third-party tracking scripts.
- We do not read your content for anything other than running the service and fixing faults.
- We do not train any models on your content.
- Our error reporting receives only the error type and a request ID — never the request body, headers or cookies.
- Secrets (passwords, keys, tokens) are masked as they are written to logs.
Who else sees the data
| Processor | What reaches them | Where |
|---|---|---|
| Hetzner Online GmbH | all service data (server and database) | Helsinki, Finland — EU |
| Google (Gemini API) | the research brief and the text of fetched pages | per Google's terms |
| Let's Encrypt | the domain name only (certificate issuance) | — |
| Paddle _(once paid plans launch)_ | billing details, not content | — |
About Google specifically: the daily research sends your show's brief to the Gemini API (name, hosts, categories, tone, titles already in the episode) and, when processing a URL you paste, the text of that page. We do not send your email or credentials. Google's handling is governed by its paid API terms.
The list of processors may change; we will announce material changes in advance.
How long we keep data
| What | How long |
|---|---|
| Account and content | for the life of the account |
| Sessions | 30 days, then removed automatically |
| Password reset link | 1 hour |
| Database backups | 14 days, encrypted |
| Audit log | for the life of the account |
When you close your account we delete everything — data, stored files and content — within 30 days. Backups age out within a further 14 days, because backups are rotated rather than edited.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection. Write to [TO FILL IN email]; we answer within 30 days. You may also complain to the Czech Data Protection Authority (uoou.gov.cz) or to your local supervisory authority.
Security
Each customer's rows are isolated in the database, and the application connects with an account that cannot bypass that isolation. Passwords and tokens are stored as hashes. Traffic is encrypted (HTTPS, HSTS). Only the operator has server access.
No measure is absolute. If a breach occurred that put you at risk, we would tell you without undue delay.
Cookies
We use one cookie: pr_session, which keeps you signed in. It is strictly necessary, so it needs no consent. We use no analytics or advertising cookies.
Changes
If we change this policy materially, we will tell you by email or in the app at least 30 days beforehand.