Privacy Policy
PodcastDraft is a podcast-planning app published under the Vardnir name ("we", "us", "our"). This policy explains what personal data we collect, why we collect it, how we handle it, and the rights you have — wherever in the world you use the app.
1. Who we are (data controller)
PodcastDraft is made and published under the Vardnir name by Tor-Erik Humlen, an independent developer in Norway, who is the data controller for the personal data described in this policy. If you have questions about this policy or your data, email hello@vardnir.com.
2. Using PodcastDraft without an account
You can use the app without signing in. In that case your episode plans are stored only on your own device — they never leave it, and we have no copy of them. Deleting the app deletes them. If you later sign in, your local episode plans are merged into your account so they can sync across devices.
3. What data we collect
- Account data: your email address when you sign up. Sign-in is passwordless (email links or Sign in with Apple), so we never store a password. If you use Sign in with Apple you can hide your real email address; we then only see Apple's relay address.
- Episode data: the content you create and save while signed in (episode names, blocks, notes, durations).
- Purchase data: if you buy Pro, payment is processed by the app store (Apple or Google). We never see or store your card details. RevenueCat, our purchase-management provider, processes an anonymous app user ID and the purchase status so the unlock can follow you across devices.
- Usage data: none from the app. The PodcastDraft app contains no analytics at all — it sends us nothing about how you use it. This website uses Plausible Analytics: aggregated and anonymous, with no cookies, no personal identifiers and no cross-site tracking.
- Support data: if you email us, we keep the correspondence so we can help you.
PodcastDraft never records anything. The app asks for no microphone or camera permission and has no access to either. The “On air” screen is a clock that keeps pace against your plan while your own equipment captures the take; no audio, video or transcript ever reaches us. Photos and guest cover art you add stay on your device.
We do not collect sensitive categories of data, we do not build advertising profiles, and we do not use your content to train AI models.
4. Why we collect it, and our legal bases
Under the GDPR (and UK GDPR), we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — providing the service: your account, saving and syncing episode plans, honouring your Pro purchase, and sending transactional emails such as sign-in links.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse, and understanding overall use of this website through anonymous, aggregated analytics.
- Legal obligation (Art. 6(1)(c)) — keeping accounting and tax records where required by law.
- Consent (Art. 6(1)(a)) — anything optional, such as marketing emails. We do not send marketing emails without your consent, and you can withdraw consent at any time.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
5. Where data is stored and international transfers
Your account and episode data is stored with Supabase on servers in Frankfurt, Germany (EU). Some of our sub-processors are based in the United States. Where personal data is transferred outside the EU/EEA or the UK, we rely on the EU–US Data Privacy Framework (and its UK extension) and/or the European Commission's Standard Contractual Clauses as the transfer mechanism.
6. Data sharing and sub-processors
We do not sell your personal data, and we do not "sell" or "share" personal information as those terms are defined in the California Consumer Privacy Act (CCPA/CPRA). We share data only with the sub-processors needed to run the service, each bound by a data processing agreement:
- Supabase — database and authentication (EU region: Frankfurt)
- Vercel — website and API hosting (US)
- Apple — payment processing for in-app purchases (Apple is the merchant of record and never shares your card details with us)
- Google — payment processing on Google Play, when PodcastDraft is available there
- RevenueCat — in-app purchase management (US; processes an app user ID and purchase status, not payment details)
- Plausible Analytics — cookieless, privacy-friendly analytics for this website only, not the app (EU)
We may also disclose data if required to do so by law, or to protect our rights, users, or the public, and only to the extent legally required.
7. Data retention
- Account and episode data is kept for as long as your account is active. If you delete your account, all your cloud data is deleted within 30 days.
- Purchase and invoicing records are kept longer where accounting and tax law requires it (up to five years under Norwegian bookkeeping rules).
- Support emails are kept as long as needed to handle your request and for a reasonable period afterwards.
8. Your rights
If you are in the EU/EEA, UK, or Switzerland
You have the right to access, correct, delete, and export (data portability) your personal data, to restrict or object to processing, and to withdraw consent at any time where processing is based on consent. To exercise these rights, email hello@vardnir.com — we respond within one month. You can also delete your account and all associated cloud data yourself at any time, directly in the app.
You also have the right to lodge a complaint with a supervisory authority — in Norway, that is Datatilsynet (datatilsynet.no); elsewhere, your local data protection authority.
If you are in California or another US state with a privacy law
Depending on your state (including under the CCPA/CPRA in California and similar laws in states such as Virginia, Colorado, Connecticut, and Texas), you have the right to know what personal information we collect, to access, correct, and delete it, and to opt out of its sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We will never discriminate against you for exercising your rights. To exercise them, email hello@vardnir.com; you may use an authorised agent where your state's law allows it.
Everyone else
We extend the same core rights — access, correction, deletion, and export — to all users worldwide, regardless of where you live. Email hello@vardnir.com and we will help.
9. On-device storage
PodcastDraft does not use tracking or advertising identifiers. On your device the app stores:
- Your episode plans and preferences — strictly necessary, kept locally so the app works offline.
- Your session token, if you sign in — so you stay signed in.
The app itself carries no analytics and no trackers of any kind. Analytics on this website (Plausible) is cookieless and anonymous. Because we use no non-essential trackers, no consent banner is required.
10. Security
All data is encrypted in transit (TLS) and at rest. Access to production data is restricted and sign-in is passwordless, which removes password-theft risk. In the unlikely event of a data breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay if the breach is likely to put your rights at risk.
11. Children
PodcastDraft is not directed at children. You must be at least 13 years old to use the service (16 in the EU/EEA where local law sets that age for consenting to data processing). We do not knowingly collect personal data from children below these ages; if you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
If we make material changes, we will notify you by email (if you have an account) before they take effect. The "last updated" date at the top always reflects the latest version.
Questions? hello@vardnir.com · Terms of Service · PodcastDraft