Legal
Privacy Policy
Effective April 21, 2026 · Last updated April 21, 2026
Draft: review with counsel before launch.
This is a good-faith starter policy describing what the product actually does today. Substitute your legal entity name and jurisdiction-specific language (GDPR data-controller info, CCPA notices, etc.) before going live.
Who this applies to
There are two kinds of people whose data I handle: Podcasters who create accounts, and Listenerswho leave voice messages at a podcaster’s Call.Show URL. This policy covers both.
What I collect: Podcasters
- Email address (used for login via magic link and billing).
- The show details you provide: title, slug, tagline, about text, cover art, links to your podcast and socials.
- Billing information is handled by Stripe; I store only your Stripe customer and subscription IDs, not your card number.
- Basic technical logs: IP address, user agent, timestamps of actions you take in the app, for security and debugging.
What I collect: Listeners
- The voice message you record.
- Your name and email if you choose to enter them (both optional).
- Whether you ticked the “can be played on the show” consent box (required to submit).
- A one-way hash of your IP address and your user-agent string, for abuse prevention. I do not store your raw IP with the message.
I do not track listeners across the web. I do not set advertising cookies. I do not sell any of this data.
How I use the data
- To deliver the service: host your show page, store the audio, transcribe it, generate titles and summaries, email notifications.
- To bill you via Stripe and keep your subscription in sync.
- To send operational email about your account (magic-link login, receipts, service announcements). I don’t send marketing email.
- To investigate abuse, debug errors, and improve reliability.
Third parties I share with
I share only the minimum necessary with service providers who help me deliver the product:
- Supabase: hosts my database, authentication, and audio storage.
- Cloudflare: hosts the web application and delivers transactional email.
- Google (Gemini API): receives the voice message audio to produce a transcript, title, and summary. Google states that inputs to the paid API are not used to train their models; free- tier usage may be. See Google’s AI API terms.
- Stripe: processes payments.
I do not sell personal data. I do not share data with advertisers.
Data retention
While a Podcaster’s subscription is active, their messages and related data are retained indefinitely. After cancellation, I keep data for 30 days (the “grace window”), then permanently delete audio, transcripts, and AI-generated fields. Account records and billing history are kept longer where required by law.
Listeners: if you want a message you left removed before the Podcaster’s retention window ends, contact me and I’ll delete it within 7 days.
Your rights
You can request a copy of the personal data I hold about you, ask me to correct it, or ask me to delete it. Reach out via the contact form on my site and I’ll respond within 30 days. Residents of regions with specific privacy laws (GDPR, CCPA, etc.) have additional rights under those laws, which I honor.
Security
Connections are encrypted in transit (HTTPS). Audio is stored in a private cloud bucket. Access is gated by row-level security tied to your account. I follow reasonable industry practices; no system is perfect, and if I discover a breach affecting your data I will notify you promptly.
Children
Call.Show is not designed for users under 13, and I don’t knowingly collect data from them.
Changes to this policy
I may update this policy. Material changes will be announced by email and the “Last updated” date above will change.
Contact
Privacy questions or requests can be sent via the contact form on my site.