Privacy Policy

Last updated: 14 Jun 2026

PodLog Pro turns podcast listening into continuing professional development records. This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.

What we collect

  • Account information. Your email address, first and last name, profession, and CPD/CME/CLE registration number. Provided by you at sign up.
  • Authentication tokens. Magic-link tokens issued for sign in. We do not collect or store passwords.
  • Listening data from connected services. If you connect Spotify, we read your followed shows, saved episodes, playback positions, and the episode you are currently playing while the PodLog dashboard is open. We do not access your search history, recommendations, friends, payments, or playlists, and we do not modify any Spotify data.
  • Listening records. Episode metadata (title, show, duration, artwork URL), the duration you listened, the date, and any notes or attestations you add. We do not store audio.
  • Billing information. If you subscribe, our payment processor (Stripe) collects your payment details. We store only the subscription status, billing email, and last four digits of your card.

How we use it

  • To detect podcast episodes you have listened to and generate CPD records.
  • To produce certificates and reports you can submit to your accreditation body.
  • To authenticate you, process payment, and send service emails.
  • To improve PodLog Pro and prevent abuse.

Who processes it

  • Spotify: listening data, accessed only with your consent through Spotify's official Web API.
  • Supabase: encrypted database hosting in Sydney, Australia.
  • Vercel: application hosting.
  • Resend: transactional email delivery.
  • Stripe: payment processing and subscription billing.
  • PostHog: product analytics, configured to exclude personal data from event payloads where possible.
  • OpenAI: episode summaries generated from publicly available transcripts or show notes (your account identifiers are not sent).

We do not sell your personal information. We do not share it with third parties for their own marketing.

Your Spotify data

Spotify access is opt in. You can disconnect Spotify at any time from the Integrations page in your dashboard. Disconnecting revokes our refresh token with Spotify and deletes the stored credentials. Existing PodLog records remain in your account until you delete them or close your account.

Retention

We keep your account data for as long as your account exists. You can request deletion at any time from your account settings or by emailing the address below. Backup copies are purged within 30 days.

Your rights

We comply with the Australian Privacy Principles and, where applicable, the EU General Data Protection Regulation. You may request access to, correction of, or deletion of your personal information, export your data, or withdraw any consent you have given. Every marketing email includes an unsubscribe link.

Contact

For any privacy question or request, email hello@podlog.pro.