Privacy Policy
Last updated: September 17, 2026
PodPilot360 (“PodPilot360”, “we”, “us”) turns a podcast audio file into a longform video and short clips and publishes them on your behalf to connected platforms. This policy explains what we collect, how we use it, and the choices you have.
Information we collect
- Account information: your name, email, and password (stored hashed) via our authentication system.
- Content you upload: podcast audio you submit, and the transcripts, clips, videos, and metadata we generate from it.
- Brand knowledge and instructions: if you give us notes, FAQs, product details, guidelines, or text documents about a brand, name its website, or write instructions and words to avoid, we store that text so the copy we write can follow it. A website is read by our servers only when you add it or ask for it to be read again, and we keep the text of that page and up to four linked pages on the same site. Brand knowledge never holds content read from YouTube.
- Platform connections: when you connect YouTube, we store the OAuth tokens needed to publish on your behalf, encrypted at rest. We do not receive your Google or YouTube password.
- Billing information: subscription status and customer identifiers from our payment processor (Stripe). We never see or store your full card number.
- Usage data: episode counts, scheduling activity, and operational logs used to run and improve the service.
- Information stored on your device: cookies and browser local storage that we place on, access on, and read back from the device or browser you use to reach PodPilot360. See Cookies and similar technologies below.
How we use your information
- To run the pipeline: transcribe your audio, select and render clips, and schedule and publish posts.
- To publish to platforms you have connected, at the times you configure.
- To write in each brand’s voice: a brand’s instructions, and the few passages of its knowledge most relevant to a piece of copy, are sent with the request that writes it. If you ask PodPilot360 to learn from a brand’s approved projects, the copy we generated for up to twelve of them is sent to suggest preferences you can edit or remove. If you ask for topic ideas for a brand, its instructions, the few passages of its knowledge most relevant to what it covers, and the titles and summaries of up to twelve of its recent approved projects are sent to suggest them; the ideas are not stored.
- To manage your account, subscription, and support requests.
- To maintain security and prevent abuse.
Cookies and similar technologies
PodPilot360 stores, accesses, and recognizes information directly on the device and browser you use to reach the service. We do this with first-party cookies and with your browser’s local storage. Specifically:
- Session cookie: set when you sign in, so the dashboard knows who you are and keeps you signed in between visits.
- Workspace and brand cookies: remember which workspace and which brand you were last working in, so the dashboard opens where you left off.
- Local storage: remembers interface preferences, such as whether you have finished or dismissed the guided tour.
All of these are strictly necessary for the dashboard to function and are set by PodPilot360 itself. We do not use advertising cookies, we do not use analytics or cross-site tracking technology, and we do not allow third parties to place advertising or tracking technology on your device through PodPilot360. If you continue to our payment processor to start or manage a subscription, that provider sets its own cookies on its own pages under its own privacy policy.
We do not store YouTube API Data in cookies or in your browser’s local storage, and we do not use any device storage to collect information about your activity on other sites. You can clear or block cookies and local storage in your browser settings. Blocking the cookies described above will sign you out and stop the dashboard from working.
YouTube API Services
PodPilot360 uses YouTube API Services. By connecting your YouTube channel you agree to the YouTube Terms of Service, and your use of Google data is governed by the Google Privacy Policy.
We access your YouTube account only to do the things you ask us to do in the dashboard:
- Upload and schedule videos: publishing the longform videos and clips you approve, at the times you configure.
- Manage what we publish: setting metadata, thumbnails, captions, and playlist or podcast placement for those videos.
- Read recent comments on your own published videos: so we can display them to you in the dashboard.
- Post comment replies you approve: a reply is posted only when you explicitly approve and send it; we never post comments automatically.
These features require the permissions Google’s consent screen shows when you connect: managing your YouTube videos; viewing your YouTube account; managing your YouTube account; and seeing, editing, and permanently deleting your YouTube videos, ratings, comments, and captions. We use that access only for the actions listed above. We store the resulting authorization tokens encrypted and use them solely to act on your behalf. We do not sell this data, use it for advertising, or share it with third parties except the processors listed below.
The YouTube data we keep is a short list of identifiers: your channel, the videos and playlists PodPilot360 creates on your behalf, and the comments you have replied to through PodPilot360 along with the replies we posted. We keep them so we can link what we published back to the episode it came from, recognize your own channel’s replies on a thread, and avoid replying to the same comment twice. API data is refreshed at least once every 24 hours. API data the YouTube API no longer returns is deleted in that same pass. API data that cannot be refreshed is deleted within 30 days. We do not store YouTube content: comment text, viewer names, view counts and channel statistics are fetched when you view them in the dashboard and then discarded. A response may be held briefly in server memory so that reloading a page does not repeat the same API call, and it is never written to durable storage.
You can revoke PodPilot360’s access to your YouTube account at any time from your Google security settings, or by choosing Disconnect in Settings → Connections. Revoking access deletes the stored tokens.
Service providers we share data with
We use these processors strictly to deliver the service:
- AssemblyAI: speech-to-text transcription of your audio.
- Anthropic: clip selection, copy generation and topic suggestions from your transcript and your brand instructions, knowledge and approved projects.
- Cloudflare R2: storage of your audio and rendered media.
- Stripe: subscription billing.
- Google / YouTube: publishing to your connected channel.
Data retention and deletion
We keep your content and account data while your account is active. You can delete your account from Settings → Profile, which removes your account data and connected-platform tokens. You may also request deletion by contacting us.
Brand knowledge and instructions are kept until you remove them. Removing a knowledge source, an instruction, or a preference PodPilot360 learned deletes it, and it is no longer used; one you switch off is kept but not used. When you delete a learned preference we keep only a one-way fingerprint of it, never its words, so it is not suggested again, until you clear that brand’s memory entirely.
Security
Connections to the service use TLS. Platform OAuth tokens are encrypted at rest, and access to production systems is restricted. No method of transmission or storage is completely secure, but we work to protect your data.
Your rights
You can access, correct, export, or delete your personal data. Contact us to exercise these rights. Depending on your location, additional rights may apply under laws such as the GDPR or CCPA.
Children
PodPilot360 is not directed to children under 16 and we do not knowingly collect their data.
Changes
We may update this policy and will revise the date above when we do.
Contact
Questions about privacy: support@podpilot360.com.
PodPilot360Home