Privacy & cookies
Last updated: 1 September 2026
Feedcaster turns the sources you choose into a short audio briefing. This page explains what we collect, the cookies we use, and your choices, and it covers both our iOS app and our website — where a practice applies to only one of them, we say so. We keep data to the minimum we need to run the service.
Feedcaster is provided by its operator, an individual sole trader based in Sweden, who is the data controller. For the controller's registered name and postal address, or any data-protection request, contact hello@feedcaster.fm.
What we collect about you
- Account — your email address, and (if you use Sign in with Apple) the identifier and relay email Apple returns. Purpose: create and secure your account. Legal basis: contract (Art. 6(1)(b)).
- Your setup & briefings — the interests, topics, sources, length and schedule you pick, and the pod-briefs and episodes we generate for you (including the generated audio). Purpose: provide the service. Legal basis: contract.
- Listening history & progress — which episodes you play (both the briefings we generate and original source episodes you play in the app), when you played them, and your last playback position, so we can show your History and resume where you left off. Purpose: provide the service. Legal basis: contract.
- Spotify import (optional) — if you connect Spotify, we read the shows you follow (read-only) to build your library. We don't post or change anything on Spotify. To keep the connection working we store the Spotify refresh token and your Spotify display name against your account; both are removed when you disconnect or delete your account. Purpose: build your library from shows you already follow. Legal basis: consent (you choose to connect).
- Push notifications (app, optional) — if you allow notifications, we store the device push token Apple issues so we can tell you when a brief is ready. The alert we send includes a short (1–2 sentence) preview of the brief itself, so you can see what it's about from the notification. Because iOS notifications are delivered through Apple's Push Notification service, that preview text passes through Apple as the delivery network on its way to your device. Purpose: deliver "your brief is ready" alerts with a useful preview. Legal basis: consent (the iOS permission prompt).
- Subscription & billing (app) — if you buy a Premium or Max subscription, Apple processes the payment and we never receive your card or payment details. To unlock and maintain your paid tier we store, against your account, the subscription record Apple confirms to us: the original transaction identifier, the product you bought, your tier and status (active, in grace, expired, cancelled), the renewal/expiry date, whether auto-renew is on, and whether it was a sandbox or production purchase. We verify this state directly with Apple and receive App Store Server Notifications for renewals, cancellations, refunds and expiry. Purpose: provide the paid service and grant the correct entitlement. Legal basis: contract (Art. 6(1)(b)); for keeping the underlying billing records we also rely on legal obligation (Art. 6(1)(c), accounting/bookkeeping).
- Product / usage analytics — how you move through onboarding and use the product (e.g. steps completed, screens viewed, brief created, episode played, and paywall/ subscribe events — which plan you viewed or selected, whether a free trial was offered, and whether a purchase started or succeeded, but never any payment or card data), recorded in PostHog (EU-hosted).
- In the app: events are sent to our own backend, which forwards them to PostHog server-side (the app never contacts PostHog directly). Before you sign in we use a random anonymous id stored on your device; when you sign in we key your analytics to your account so your app and web activity resolve to one profile. Legal basis: legitimate interest (understanding and improving the product) — you can object at any time (see Your choices).
- On the website: before you make a cookie choice this runs anonymously with no cookies or device storage and with your IP discarded; if you accept Analytics we link your session to your account and remember you across visits. Legal basis for the identified, cookie-based version: consent.
- Device performance & crash diagnostics (app) — via Apple's MetricKit, the app sends us stability and performance data so we can find and fix crashes and slowdowns. This includes anonymized crash, hang, disk-write and CPU-exception diagnostics (with anonymized call stacks) and aggregate performance metrics (launch time, memory, disk I/O, CPU/GPU energy, app-exit reasons), together with your device model, OS version, app version, and an anonymous per-vendor device identifier (Apple's
identifierForVendor, which resets when you reinstall). When you're signed in, your email is attached so we can correlate a crash with the affected account. This is first-party (app → our backend → our database) and also appears to us in Apple's Xcode Organizer; there is no third-party analytics SDK. Legal basis: legitimate interest (app stability and security). - Content reports (optional) — if you use the "Report" action (in the app or on the website) to flag a briefing, pod or source as objectionable or an intellectual-property/copyright concern, we store what you reported, the reason you chose, any note you write, and your email so we can review it and follow up. Purpose: moderate content, handle IP/takedown complaints, and keep the service safe. Legal basis: legitimate interest (content moderation and platform safety) and, for copyright/takedown handling, legal obligation. The reports you file are removed if you delete your account.
- Ad measurement with Meta (app, optional — off by default) — the app includes Meta's (Facebook) measurement SDK, but it is completely dormant unless you turn it on. If you enable "Share ad measurement with Meta" in your Profile, the app sends Meta a small number of aggregated app events — that the app was opened, that you started onboarding, that you created an account, and that you started a subscription — so we can measure how well our Meta ad campaigns work. It does not use Apple's advertising identifier (IDFA), does not track you across other companies' apps or websites, and therefore shows no App Tracking Transparency (ATT) prompt. Until you opt in, nothing is sent to Meta at all. Purpose: measure the effectiveness of our advertising. Legal basis: consent (Art. 6(1)(a) GDPR, and the prior-consent rule of the ePrivacy Directive / Swedish LEK) — you can withdraw at any time with the same toggle. Recipient / sub-processor: Meta.
- Install attribution via Apple SKAdNetwork (app) — when you install the app after seeing one of our ads, Apple's SKAdNetwork sends the ad network (e.g. Meta) a privacy-preserving, aggregated install/conversion signal so we can tell which campaigns work without identifying you. This is operated by Apple, carries no identifier that can be tied to you, needs no ATT prompt, and runs whether or not the Meta toggle above is on. Legal basis: legitimate interest (aggregate campaign measurement with no personal data).
How we measure website traffic without identifying you
The following applies to our website only. Two cookieless measurement streams run for every visitor — consented or not — so we can tell which marketing campaigns bring people who actually use the product. Neither captures personal data or links to your account.
- Server-side aggregate counts — we log which pages get visited and from which marketing campaign in our own database. No cookies, no device storage, no account link. The only identifier is a hash of your IP + browser combined with a salt that rotates each day, so the value can't be threaded across days and can't be reversed to identify you. Lawful basis: legitimate interest (audience measurement, per CNIL guidance and GDPR Recital 49).
- Anonymous session recordings — visual playback of clicks, scrolls and navigation between pages, so we can see where visitors hesitate or drop off. Recordings are captured with every visible text node and every form input masked by default, so the playback shows the shape of your journey but never the words on the page, the text you typed, or anything that could identify you. The recording session lives in browser memory only; it isn't persisted with a cookie and isn't linked to your account. Lawful basis: legitimate interest (audience measurement); same scope as above.
Cookies & tracking (website)
Cookies are used on our website. The iOS app uses no cookies and no cross-app or IDFA-based tracking. The only advertising-related data flow in the app is the optional, off-by-default Meta ad-measurement described above, which shares only aggregated events and still sets no cookies.
- Essential — always on. Sign-in/session and security; the service can't work without them.
- Analytics — optional. Product analytics (PostHog) and, if enabled, Google Analytics 4 (via Google Consent Mode, denied by default). Before consent this runs anonymously with no cookies or storage; accepting lets us store a cookie to recognise you across visits and link events to your account.
- Marketing — optional. Ads measurement (Google, Meta) so we can see which campaigns bring people who love the product. With your consent, our server-side measurement to Meta (Conversions API) includes a hashed (irreversibly encoded) email, plus your IP address and browser user-agent, so Meta can match conversions back to your account there. We never share your email in plain text. Marketing tags don't fire at all until you accept.
Your choices
In the app: product analytics run on a legitimate-interest basis, and you can object at any time with the "Share usage analytics" toggle in your Profile. Turning it off stops the app sending further analytics and deletes the analytics profile already tied to your account (GDPR Art. 21). Separately, "Share ad measurement with Meta" is a distinct control that is off by default: the Meta SDK stays dormant and shares nothing until you explicitly switch it on, and you can withdraw that consent at any time with the same toggle. The app uses no cookies and no cross-app/IDFA tracking, so there is no cookie banner in the app.
On the website: you can change your cookie choice any time via Cookie settings in the footer. We honour your browser's Global Privacy Control (GPC) signal as a Marketing opt-out.
- If you tap Reject, we don't store anything on your device and we don't run advertising tags. The two cookieless streams in the section above keep running because they don't identify you; everything else stops.
- If you accepted Analytics and later revoke, we erase the analytics data linked to you — including pre-signup events from sessions we connected to your account — and stop capturing.
- Deleting your account erases your account data and the analytics data linked to you. Anonymous data that was never linked to you may remain in aggregate, as it can't be traced back to you.
Who processes your data (sub-processors)
We use the following providers to run Feedcaster. Each acts as our processor under a data-processing agreement. Region is where the service processes data for us.
- Supabase — database & file storage for your account, library and generated audio. Region: EU. Always used.
- Fly.io — application hosting and on-demand worker compute. Region: EU — Stockholm (
arn). Always used. - PostHog — product/usage analytics (and, on the website only, masked session recordings). Region: EU (eu.i.posthog.com). App analytics run on a legitimate-interest basis (opt-out below); website analytics run on consent. We also use PostHog for staged feature rollouts — for example, showing the subscription paywall to a small test group before a wider launch. When such a rollout is active, your account email is sent to PostHog's EU endpoint so PostHog can tell us which rollout group you fall into; the decision comes back to our backend and is never stored on your device. Legal basis: legitimate interest (controlled, staged rollout of features). This stays within the EU.
- Resend — transactional email (login codes, welcome email). Your email address is sent to Resend to deliver these. Region: United States. Always used for email delivery.
- Google (Gemini) — AI summarization: the article text and podcast transcripts of your chosen sources are sent to Gemini to produce your briefing. We do not send your identity. Region: global (may include the United States). Always used to generate briefings.
- Microsoft (edge-tts) — text-to-speech: the generated briefing script is sent to Microsoft's read-aloud endpoint to produce the audio. Region: global (may include the United States). Always used to generate audio.
- Apple — Sign in with Apple (if you use it), StoreKit subscriptions and App Store Server Notifications (if you subscribe), Apple Push Notification service (if you enable notifications), and MetricKit device/crash diagnostics. Region: global (Apple Inc.). Used depending on the features you use.
- Spotify — only if you connect it, to read the shows you follow (app and website). Region: global.
- Google (Google Analytics 4) — website only, for traffic analytics, and only after you grant Analytics cookie consent. Not used in the iOS app. Region: United States.
- Meta — ads measurement. On the website: the Meta Pixel + Conversions API, only after you grant Marketing cookie consent. In the iOS app: Meta's measurement SDK, only if you turn on "Share ad measurement with Meta" (off by default), sending aggregated app events with no IDFA and no cross-app tracking. Region: United States.
Podcast discovery (matching a show to its feed) also queries Apple's iTunes Search API and, if configured, the Podcast Index API. These lookups send only the podcast title being searched — never your identity or personal data — so they aren't processors of your personal data. We do not use Sentry, Stripe, OpenAI or Anthropic. The only advertising-related SDK in the app is Meta's measurement SDK, and it stays dormant unless you opt in (see "Ad measurement with Meta" above). Podcast audio is transcribed on our own servers (no third-party transcription service).
Where your data is stored & international transfers
Your account data, library, briefings and device-diagnostics are stored in the EU (Supabase database, hosting in Sweden) and usage analytics on PostHog's EU infrastructure. Some providers are based in, or may process data in, the United States or other countries — including Resend (email), Apple (sign-in, subscriptions, push, MetricKit), the AI providers that generate your briefing (Google Gemini, Microsoft edge-tts), Google (on the website with your Analytics consent), and Meta (on the website with your Marketing consent, and in the app if you opt in to "Share ad measurement with Meta"). Where data is transferred outside the EU/EEA we rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
How long we keep it
We keep your account data and library for as long as your account is active. If you ask us to delete your account we remove your personal data within a reasonable period, except where we must keep limited records to meet legal obligations. Email verification codes are short-lived. Website session-recording playbacks are retained per our analytics provider's defaults and never beyond what we need for audience-measurement purposes.
Some data is kept only for a set period and then deleted automatically: your listening history for up to 12 months, device performance & crash diagnosticsfor up to 90 days, and internal back-office activity logs for up to 180 days. Push tokens are removed when you turn off notifications or delete your account. Residual copies in encrypted backups are purged on our backup-rotation cycle.
Subscription & billing records (the Apple transaction identifier, product, tier/status and renewal dates tied to your account) are kept for the life of your subscription and may be retained after you delete your account where we must keep them to meet legal obligations — in particular Swedish bookkeeping/accounting law. We never hold your card or payment details; those stay with Apple.
Your rights (EU/EEA)
Under the GDPR you can access, correct, export, or delete your data, object to or restrict processing, and withdraw consent at any time (without affecting prior processing). You can:
- Access & portability — export your data as JSON, in the app under Profile → "Export my data" or on the website in Settings.
- Erasure — delete your account (and the data linked to it, including your analytics profile) in the app under Profile → "Delete account" or on the website in Settings.
- Objection — turn off "Share usage analytics" in the app, or reject Analytics/Marketing cookies on the website.
You can also lodge a complaint with your supervisory authority — in Sweden, the IMY (Integritetsskyddsmyndigheten). For anything else, email hello@feedcaster.fm.
Your rights (US / California)
If you're a California resident, you have rights to know, delete, and correct your personal information, and to opt out of its "sale" or "sharing." We do not sell your personal information. On the website only, we share data with advertising partners (Google, Meta) for measurement if you grant Marketing consent, and we honor Global Privacy Control (GPC) browser signals as an opt-out. Use Cookie settings in the footer to change your choice. In the iOS app, we share data with an advertising partner (Meta) for ad measurement only if you opt in to "Share ad measurement with Meta" (off by default); this uses no advertising identifier and no cross-app tracking. You can turn it back off at any time in your Profile.
Contact
Questions? hello@feedcaster.fm.