At PodBrain, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile application, and browser extension (collectively, the "Service").
1. Information We Collect
1.1 Information You Provide
We collect information that you voluntarily provide when you:
- Create an account (email address, name, password)
- Subscribe to our premium service (payment information processed by our payment provider)
- Save transcripts, highlights, or notes
- Contact our support team
- Participate in surveys or promotions
1.2 Automatically Collected Information
When you use our Service, we automatically collect:
- Usage Data: Pages visited, features used, time spent, transcripts viewed
- Device Information: Browser type, operating system, device type, IP address
- Cookies and Similar Technologies: Session cookies, authentication tokens, preference cookies
- Analytics Data: Aggregate usage statistics and performance metrics
1.3 Chrome Extension Data
Our Chrome extension collects:
- YouTube video URLs and metadata (title, channel, thumbnail)
- Transcript text from YouTube videos (only when you explicitly request it)
- Your authentication token (stored locally)
Important: The extension only processes data when you actively use it. We do not track your general browsing activity.
2. How We Use Your Information
We use the collected information to:
- Provide the Service: Process transcripts, generate AI summaries, sync your data across devices
- Improve the Service: Analyze usage patterns, fix bugs, develop new features
- Personalize Your Experience: Remember your preferences, show relevant content
- Communicate: Send service updates, respond to support requests, deliver newsletters (if opted in)
- Security: Detect fraud, prevent abuse, enforce our Terms of Service
- Legal Compliance: Comply with applicable laws and regulations
3. How We Share Your Information
We do not sell your personal information. We may share your information with:
3.1 Service Providers
- Supabase: Database and authentication services
- Fly.io: Hosting infrastructure
- AI Providers: OpenAI, Anthropic, Google, DeepSeek (for generating summaries - only transcript text is sent)
- Payment Processors: Stripe or similar payment services (for premium subscriptions)
3.2 Legal Obligations
We may disclose your information if required by law, court order, or government request, or to protect our rights and safety.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new owner.
4. Data Storage and Security
We implement industry-standard security measures to protect your information:
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest
- Access Controls: Strict access controls and authentication requirements
- Regular Security Audits: Periodic security assessments and updates
- Data Centers: Your data is stored in secure facilities operated by Supabase (AWS)
However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
5. Your Privacy Rights
5.1 Access and Correction
You can access and update your account information through your profile settings.
5.2 Data Portability
You can export your transcripts, highlights, and notes at any time.
5.3 Deletion
You can delete your account and all associated data through account settings or by contacting support.
5.4 Cookie Preferences
You can control cookies through your browser settings. Note that disabling cookies may limit Service functionality.
5.5 Marketing Communications
You can unsubscribe from marketing emails using the link in any email or through account settings.
5.6 Regional Rights
Depending on your location, you may have additional rights under GDPR, CCPA, or other privacy laws, including:
- Right to know what personal data we collect and how it's used
- Right to request deletion of your personal data
- Right to opt-out of data sales (note: we do not sell personal data)
- Right to non-discrimination for exercising your privacy rights
6. PodBrain Chrome Extension Specifics
6.1 Data Boundaries and Scope
The PodBrain Chrome extension is designed with strict privacy protections:
- Limited Scope: The extension only activates on YouTube video pages and does not access or collect information from other tabs, websites, or your general browsing history
- No Background Monitoring: We do not monitor your general user activity, keystrokes, or webpage content outside of YouTube
- Explicit User Action Required: The extension collects YouTube video metadata and transcript text only when you explicitly click the extension icon or button to request a transcript
- No Browsing History: We do not access, collect, or store your Chrome browsing history
6.2 No Sale or Sharing of Data
We do not sell or share any user data collected via the Chrome extension with third parties for advertising, analytics, or any purpose unrelated to providing the transcript summarization service.
6.3 Chrome Permissions Justification
The extension requires the following Chrome permissions, each with a specific purpose:
- storage: To save your authentication token and transcript summaries locally in your browser for quick access
- tabs: To identify the active YouTube video tab and extract the video URL when you request a transcript
- scripting: To extract video metadata (title, channel, thumbnail) from the YouTube page when you request a transcript
- notifications: To alert you when a transcript summary has completed processing or if an error occurs - not used for marketing or unrelated purposes
- Host permission (youtube.com): Required to access YouTube video pages for transcript extraction functionality
6.4 No Remote Code Execution
The PodBrain Chrome extension does not load, fetch, or execute any remote code or scripts from external sources. All code is bundled with the extension package submitted to the Chrome Web Store.
6.5 AI Provider Data Sharing
When you request a transcript summary:
- Only the transcript text (the words spoken in the video) is sent to our AI service providers (OpenAI, Anthropic, Google, or DeepSeek)
- No personally identifiable information (PII) is included in requests to AI providers
- No browsing history, cookies, or unrelated data is shared with AI providers
- This data sharing occurs only at your explicit request when you click to generate a summary
6.6 Notification Usage
Chrome notifications are used exclusively to inform you about:
- Successful completion of transcript summary generation
- Error messages if transcript processing fails
- Service status updates related to your active requests
Notifications are never used for marketing, promotions, or purposes unrelated to the core transcript functionality.
6.7 Authentication and Credentials
The PodBrain Chrome extension handles authentication securely:
- Sign-in State Detection Only: The extension only detects whether you are signed in by checking for an authentication token stored locally in your browser or validating your session with podbrain.app
- No Password Processing: The extension never processes, stores, transmits, or has access to your password or other sensitive login credentials
- Token-Based Authentication: After you log in through the PodBrain website, an authentication token is stored locally in your browser's storage. The extension reads only this token to authenticate API requests
- Local Storage Only: Your authentication token remains in your browser's local storage and is never transmitted to third parties (except to podbrain.app API for verification)
6.8 Data Flow Disclosure
Here's exactly how data flows when you use the Chrome extension:
- You click the extension icon on a YouTube video page
- Extension extracts: Video URL, title, channel name, and thumbnail URL from the YouTube page
- Extension checks: Your local authentication token to verify you're signed in
- Extension sends to podbrain.app: Video metadata + transcript text + authentication token
- Our server processes: The transcript and sends only the transcript text to AI providers (OpenAI, Anthropic, Google, or DeepSeek) for summary generation
- Our server stores: Video metadata, transcript text, and generated summary in our database (Supabase)
- Extension receives: The generated summary and displays it to you
- Extension stores locally: The summary in your browser's local storage for offline access
At no point does the extension access, process, or transmit your password, payment information, or any data unrelated to YouTube transcripts.
6.9 Children and Chrome Extension
The PodBrain Chrome extension is not intended for, and should not be used by, children under 13 years of age.
7. Children's Privacy
Our Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to such transfers.
9. Third-Party Links
Our Service may contain links to third-party websites (e.g., YouTube, podcast platforms). We are not responsible for the privacy practices of these third parties. Please review their privacy policies.
10. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. When you delete your account, we will delete or anonymize your personal information within 30 days, except where we're legally required to retain it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification (for significant changes)
- Displaying a prominent notice in the Service
Your continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:
13. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising CCPA rights
To exercise these rights, contact us at privacy@podbrain.app.
14. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
To exercise these rights, contact us at privacy@podbrain.app.