Legal
Privacy Policy
This Policy explains how PodInk collects, uses, discloses, and retains personal information when you use the Service.
- Last updated
- Effective
The short version
This summary makes the policy easier to scan. The full text below provides more detail.
- Ye Haotian operates PodInk and is responsible for its personal-data practices.
- PodInk uses account, episode, transcript, reaction, and draft data to provide the service.
- The Chrome extension works only on supported YouTube pages and PodInk pages.
- Some data may be sent to services that provide sign-in, storage, transcription, or AI features.
- Email privacy support for access, a complete export, correction, or deletion; a person will verify the request.
This Privacy Policy explains how Ye Haotian, an individual operating from Hong Kong SAR, China under the PodInk product name (“PodInk,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you use the PodInk website, browser extension, workspace, and related services (together, the “Service”).Ye Haotianis the data user responsible for the Service under Hong Kong's Personal Data (Privacy) Ordinance.
1. Scope
This Policy applies to information processed through the Service and when you contact us about it. It does not govern the independent practices of YouTube, Google, X, LinkedIn, or other third-party services you choose to use. Their privacy policies apply to their own processing.
2. Information we collect
The information we collect depends on how you use the Service.
Account and profile information
- a guest or account identifier;
- Google account information made available during sign-in, such as email address, display name, and profile identifier;
- locale, time zone, plan code, and account status; and
- authentication and session information needed to keep you signed in on the website and browser extension.
We do not receive your Google password.
Podcast and source information
When you activate the extension on a supported YouTube page or add an episode, we may process:
- the video or episode ID, canonical URL, title, channel name and ID, thumbnail, channel avatar, displayed subscriber information, and duration;
- your playback position and timestamps;
- captions or transcript segments available from the page, a configured transcript provider, or a subtitle file you submit; and
- speaker labels, identities you confirm, and source relationships created through the Service.
The extension is designed to operate on supported YouTube pages and the Service’s own web origin. Its permissions are not intended for general browsing-history collection.
User Content and generated content
We process content you submit or create, including:
- text and short voice reactions;
- voice transcripts, capture messages, and assistant replies;
- context candidates, questions and answers, selections, suppressions, and confirmations;
- themes, viewpoint decisions, Mother Drafts, versions, and edits;
- X and LinkedIn outputs, review decisions, and confirmed versions;
- privacy-request correspondence and any export file prepared after identity verification; and
- feedback or support messages you send us.
Voice recordings may contain voice or other personal information about you or another speaker. Do not submit recordings or other personal information unless you have the right and lawful basis to do so.
Connected-platform and publishing information
If you connect LinkedIn, we process the LinkedIn member identifier, approved scopes, token expiry, connection status, and an encrypted access token. The current integration requests openid, profile, and w_member_social to identify the connection and create a member post when you explicitly request publishing.
If a post is published or manually marked complete, we may store the platform, method, status, provider post identifier, post URL, publication time, attempt state, and error or status codes.
The current X flow does not receive an X access token and does not publish through the X API. It helps you copy content or open the X composer for manual publishing.
Usage, analytics, and diagnostic information
We collect first-party product events and operational metrics needed to operate and improve the Service, such as:
- sign-in, extension installation, episode, reaction, confirmation, publish, quota, export, and deletion events;
- anonymous event identifiers and timestamps;
- fixed public-page, call-to-action, guided-tool, sign-up-start, and acquisition-channel labels, with unknown campaign values reduced to an
othercategory; - usage quantities such as episodes, transcript or voice minutes, feature operations, and AI input or output token counts;
- provider, model, processing duration, cost, success or failure state, and error codes; and
- unresolved publish status, deletion progress, and service-health information.
The current analytics validation is designed to reject transcript text, drafts, outputs, audio, URLs, and access or refresh tokens from analytics payloads.
Our infrastructure and service providers may also receive technical request information such as IP address, browser or device type, timestamps, request identifiers, and security logs when you communicate with the Service.
Payment information
The Service does not currently have connected billing and does not currently collect payment-card information. We will update this Policy and identify the payment processor before enabling paid checkout.
3. How we collect information
We collect information:
- directly from you when you type, speak, upload, edit, confirm, publish, download the Settings JSON snapshot, submit a deletion or privacy request, or contact us;
- from your browser or extension when you activate a supported workflow;
- from Google when you sign in;
- from YouTube or another transcript source when you request episode processing;
- from LinkedIn when you connect an account or publish; and
- automatically from operation of the Service, including usage, security, and diagnostic events.
4. Why we use information
We use information to:
- create and secure guest or signed-in sessions;
- recognize supported episodes and preserve playback context;
- transcribe voice, analyze source context, and generate the content you request;
- maintain your workspace, decisions, versions, the client-side JSON snapshot, and available data controls;
- connect LinkedIn and carry out a publish action you explicitly start;
- enforce usage limits and prevent duplicate, fraudulent, abusive, or unauthorized activity;
- diagnose failures, measure reliability and cost, support users, and improve the Service;
- fulfill deletion, access, and export requests; and
- comply with law, enforce our Terms, and protect users, third parties, and the Service.
Where applicable law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where requested, and compliance with legal obligations.
5. AI and transcription processing
The Service sends the minimum content reasonably needed for a requested feature to configured AI or transcription providers. Depending on production configuration, this may include reaction text or audio, transcript excerpts, source context, instructions, and draft fields.
The current application supports:
- Alibaba Cloud/DashScope Qwen as the default configured provider for text generation and speech transcription;
- OpenAI as an optional fallback provider; and
- Supadata as an optional generated-transcript provider, disabled by default in the current configuration.
Provider availability may change. We will update this Policy when a material change affects how your information is processed.
We do not train a general-purpose AI model owned by us on your User Content. Third-party providers process submitted content under their own service terms, privacy commitments, and our configuration or agreements with them.
AI processing is used to assist with content and source analysis. We do not use it to make legal or similarly significant decisions about you.
6. When we disclose information
We do not sell personal information or use it for cross-context behavioral advertising in the current Service.
Service providers
We use providers that process information on our behalf or help deliver a requested feature. Current provider categories include:
- Supabase for authentication, database, and private file storage;
- configured AI and speech providers, currently Qwen/DashScope with optional OpenAI fallback;
- Trigger.dev or a configured equivalent for background job processing;
- Google for sign-in and YouTube-related source access;
- Supadata only if optional generated-transcript fallback is enabled; and
- infrastructure, security, and support providers used in the production deployment.
Platforms you connect or direct us to use
We disclose confirmed post text and necessary authorization information to LinkedIn only when you connect LinkedIn and start a publish action. When you open X or copy text, your interaction with X occurs under X’s own terms and privacy policy.
Legal, safety, and business events
We may disclose information if reasonably necessary to comply with law or legal process; enforce our Terms; investigate fraud, abuse, or security incidents; protect rights and safety; or complete a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate safeguards.
At your direction
We may disclose information when you ask us to, such as when you publish, export, share, or connect another service.
7. Cookies and local storage
The current website uses essential cookies for secure authentication and PKCE sign-in flows. Web refresh-session cookies may remain for up to 30 days unless they are replaced, expired, or removed earlier. Disabling essential cookies may prevent sign-in.
The website may use browser local storage for local preview workspace data and session storage for interface preferences. The extension uses Chrome local or session storage for session state, active-episode state, workspace handoffs, and a limited native-transcript cache.
The current build does not include advertising cookies or third-party marketing analytics. We will update this Policy and, where required, request consent before adding non-essential tracking technologies.
8. Retention
We retain information only for the period needed for the purposes described above, subject to the following current product rules:
| Information | Current retention rule |
|---|---|
| Extension-native transcript cache | Up to 7 days on the device, limited to the 8 most recent cached entries. |
| Live-capture voice audio | Access expires approximately 2 hours after upload in the current capture flow; deletion processing may follow asynchronously. |
| Other raw reaction audio | Scheduled for deletion no later than 7 days after capture; the derived transcript and confirmed reaction may remain. |
| Episode transcripts, reactions, context, drafts, outputs, and app-side publish records | Retained until you delete the episode or account, unless an earlier product rule applies. |
| LinkedIn connection credentials | Retained until they expire, a verified connection-removal request is completed, or the account is deleted, subject to security and legal requirements. |
| Settings JSON snapshot | Generated in your browser from the data currently shown in the workspace. The downloaded copy remains on your device and is not a complete account export. |
| Account deletion | Sign-in and publishing access are blocked when the request is accepted; application-owned account content is scheduled for permanent deletion within 30 days. |
| Pseudonymous deletion and security records | May be retained as needed to verify deletion, prevent abuse, resolve disputes, or comply with law, without retaining the deleted content itself. |
| Server logs and first-party analytics | Retained only as long as reasonably needed for security, service reliability, legal compliance, and product analysis, then deleted or de-identified. |
Deleting an episode or account does not delete a post already published to X or LinkedIn, and it does not delete files you previously downloaded. You must manage those copies through your device or the external platform.
9. Security
We use technical and organizational safeguards appropriate to the nature of the information, including encrypted transport, private storage access controls, owner-scoped database policies, short-lived signed file access, and encryption of stored LinkedIn access tokens.
No method of transmission or storage is completely secure. You are responsible for protecting your Google account, browser profile, devices, and any downloaded exports.
10. International data transfers
We and our service providers may process information in countries or regions other than where you live. Those locations may have different data-protection laws. Where required, we will use an approved transfer mechanism or other safeguards.
11. Your rights and choices
Depending on where you live, you may have rights to:
- access or obtain a copy of personal information;
- correct inaccurate information;
- delete information;
- receive portable information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- complain to a data-protection authority.
The current Service provides these controls:
- download a client-generated JSON snapshot of data currently shown in Settings;
- request account deletion;
- revoke Google or LinkedIn access through the platform’s own settings; and
- remove local preview data or extension data from your browser.
The Settings download is not a complete account export. To request access, a complete account copy, correction, episode deletion, or another privacy action, contact podink1@outlook.com. A person will review the request, and we may need to verify your identity. We may retain or deny deletion of limited information where permitted or required by law. We will not discriminate against you for exercising a privacy right. Data access and correction requests are handled by Ye Haotian at podink1@outlook.com.
12. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided information, contact podink1@outlook.com so we can investigate and delete it as appropriate.
13. Changes to this Policy
We may update this Policy when the Service, providers, law, or our practices change. We will update the “Last updated” date and provide additional notice when required by law or when a change materially affects your privacy choices.
