Privacy Policy
Effective 21 August 2026 · Version 2026-08-21
monpod is a personal daily audio briefing. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It is written to be read, not to be survived.
monpod is currently in private beta, run by an individual rather than a company. The data controller is Chris, contactable at c.formula1@gmail.com. If that changes, this page will say so.
What we collect
Your account. Your email address and a password, which is hashed by our authentication provider and is never visible to us. Our authentication provider also records IP addresses and timestamps for sign-in attempts, which we hold as part of your account record.
What you tell us to make your briefing. The name you would like the host to greet you by, your time zone, and the way you configure your brief: how long it should be, which voice, what time it should arrive, which topics you enable, and any free-text notes you add to a topic or to the brief as a whole.
What we generate for you. For each episode we store the research document assembled for it, the script written from that research, the audio file, a log of the generation steps, and the API cost of producing it.
Calendars you connect, which we read but do not keep. If you attach a calendar — from Google, from Outlook, or by pasting a subscription link — we read that day’s entries each time a brief is made, use them to write that episode, and then discard them. We do not store your schedule. What we do keep is the permission to ask again: an encrypted access token, or in the case of a subscription link the encrypted link itself, together with the name you gave the calendar.
Two things about this deserve saying plainly rather than being left in the small print. The access covers full event detail — titles, locations and the names of other people on an invitation, not just the times; there is no narrower permission that still lets a brief tell you what a meeting actually is. And those other people are not our users and have not agreed to anything, so their names are used only to describe your day to you, and never stored, analysed or shared.
Technical data. Our hosting provider records request logs, including IP addresses. We also keep a record of how you use the app — when you sign in and how, and which pages you open and for how long — and that record is tied to your account. See Cookies and analytics below for exactly what it contains.
The free-text fields are yours to write whatever you like in, and we do not inspect them. Please keep in mind that whatever you put there is sent to the AI providers listed below in order to build your brief. We would ask you not to put anything sensitive in them — information about your health, your political or religious beliefs, or anything similar — because we have not built this service to handle data of that kind.
Why we process it, and our legal basis
- To provide the service — creating your account, generating your briefs and letting you play them back. Our legal basis is performance of a contract with you. Without this data there is no briefing to make.
- To keep the service secure and working — logs, error diagnosis, and preventing abuse. Our legal basis is our legitimate interests in running a service that is not broken or being attacked.
- To understand how the service is used — which pages get opened, for how long, and how often people come back. Some of this is tied to your account rather than being anonymous, because a product this small learns more from “the same handful of people keep doing this” than from a total. Our legal basis is our legitimate interests in knowing which parts of the product get used. You can object to it at any time by emailing us, and we will stop recording yours.
- To send you occasional product update emails — only if you asked us to. Our legal basis is your consent, which you gave at signup and can withdraw at any time by emailing us.
Who we share it with
We do not sell your data, and we do not share it for advertising. We do rely on a small number of service providers, each of which processes data only on our instructions and under their own data protection terms:
- Supabase — the database, sign-in system and file storage that hold your account, your settings and your episode audio.
- Vercel — hosting for the website and the code that generates your briefs, plus the cookieless analytics described below.
- Anthropic — researches your topics and writes your script.
- Google — an alternative research provider we sometimes use instead of Anthropic; when it is in use, search queries derived from your topics reach Google Search.
- ElevenLabs — turns your script into the voice you hear.
This list will grow or change as the product does. When it does, we will update this page. We may also disclose data if we are legally required to.
How your content is processed by AI providers
This is worth stating plainly rather than leaving you to infer it. To build your brief, the topics you enable, the notes you write and the name you asked to be greeted by are sent to the AI providers listed above — to research the topics, to write the script, and to narrate it aloud. The audio file we produce is a synthetic voice reading content personalised to you.
We use these providers under their business terms, which do not permit them to use your content to train their models. They may retain inputs for a short period for abuse monitoring, in line with their own published policies.
Your brief is assembled automatically, but nothing here makes an automated decision that produces a legal effect for you or similarly significantly affects you.
International transfers
Some of the providers above are based outside the United Kingdom, or process data on infrastructure outside it. Where personal data is transferred outside the UK, that transfer is covered by the data protection terms in the relevant provider agreement, which incorporate the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
How long we keep it
We keep your account and everything associated with it for as long as your account exists. We do not currently apply automatic time limits to stored episodes, scripts or audio — if you have been using the service for a year, a year of briefs is still there.
You can delete everything at any time. Deleting your account from the Settings page immediately and permanently removes your profile, your settings, your topics, every episode and script, and every audio file. There is no grace period and no recovery.
Calendar entries are never kept at all. They are read when a brief is being made, used to write that episode, and gone by the time it finishes. Removing a calendar, or withdrawing our access from your Google or Microsoft account, stops all future use of it immediately. Deleting your account also revokes that access rather than merely forgetting it.
One consequence of that is worth understanding, because it is not obvious. An episode we have already made describes your day in words — in its script and spoken in its audio. Removing a calendar afterwards does not, and cannot, rewrite episodes that already exist. If you want that content gone, delete the episodes, or delete your account, which removes every episode and every audio file with it.
Two further honest caveats. Our providers keep their own operational logs and backups for a period set by them, so some records may persist briefly after deletion before ageing out. And the AI providers listed above may hold their short-term abuse-monitoring copies for their own stated retention window.
Your rights
Under UK and EU data protection law, you have the right to:
- Ask what personal data we hold about you, and get a copy of it
- Have inaccurate data corrected
- Have your data erased
- Ask us to restrict how we use it, or object to us using it
- Receive your data in a portable, machine-readable format
- Withdraw consent for the product update emails, without affecting anything else
The fastest route to erasure is the delete button on your Settings page. For anything else, email c.formula1@gmail.com and we will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can put it right, but that is your right and not conditional on asking us.
Cookies and analytics
We set only the cookies needed to keep you signed in. We do not use advertising or tracking cookies, we do not share any of this with an advertising network, and nothing here follows you to other websites — which is why you are not being asked to dismiss a consent banner.
Two things are measured. Our hosting provider counts page views without cookies and without identifying anyone. Separately, and in our own database, we record each time you sign in (when, and whether by password, Google or an email link) and each page you open in the app (which page, when, and how many seconds it was actually in front of you — the clock stops when the tab is in the background). Each of those records is linked to your account.
What we deliberately do not keep alongside it: your IP address, and the full details of your browser. We store only a rough device type — phone, tablet or computer — and the country your request arrived from. We do not record what you type, what you search for within the app, or anything on the page itself. Deleting your account deletes this record along with everything else, immediately.
Children
monpod is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
Changes to this policy
When we change this policy we will update the version and date at the top of this page. If a change materially affects how we handle your data, we will email you about it rather than rely on you noticing.
Contact
Chris — c.formula1@gmail.com