Privacy
The short version: podnod works without an account, keeps your listening on your device by default, and never sells anything about you.
Without an account
Your subscriptions, queue, play positions, history, downloads and settings live in a database on your own device. Nothing about what you listen to leaves it. The requests podnod makes are for catalogue pages, artwork and transcripts, and those answers are the same for everybody. Searching is the one exception, and it has its own section below.
With an account
Signing in adds one thing: a copy of that same state on the server, so your other devices can see it. That means an email address, a password hash, the mark you picked for yourself, the shows you follow, your position in episodes, your queue, your saved episodes and any notes on them, your playlists, your settings, and a row per device — its name, platform, app version and when it last synced — so you can revoke one without signing out everywhere.
Signing in for the first time merges what you already had; it never replaces it.
Accounts are made in one place, on the web, and the apps open that page rather than carrying a form of their own. If you turn on the second step, its secret and your recovery codes are stored encrypted. If you ask a browser to be trusted for thirty days, podnod stores only a hash of a random token — the cookie on your machine is the one copy — and changing your password, turning the second step off, taking new recovery codes or signing out everywhere revokes all of them. A passkey leaves nothing here but a public key.
Signing out clears the device
Signing out wipes the local copy: subscriptions, queue, positions, history, saved episodes, playlists, settings, the cached catalogue and the downloaded audio. Nothing is deleted on the server — that device simply stops holding a copy, so whoever sits down next does not get your library. Signing back in re-downloads it.
Closing the app, quitting it or letting a session lapse does not wipe anything; signing out is the action that means you are done on this machine.
Listening history
Separate from where you are up to in an episode, podnod keeps a history: one row per stretch of listening, recording the episode, which of your devices played it, when it started and stopped, how long you actually listened, the speed and whether you finished. It is what lets the apps say an episode was played on your phone rather than merely that it was played.
It is the most revealing thing stored here, so it is the one part of your account that expires: rows are deleted outright after 400 days. You can switch it off in Settings, which stops new rows being written — it does not remove the ones already there, and deleting your account is what does. No operator screen reads this.
Playing on your other devices
Signed in on more than one device, each one that is playing reports what it is playing, how far in and how fast, so the others can offer to pick it up. Those reports expire on their own and are never held in a shared cache. Turning off pick-up across devices in Settings stops them at the server as well as on the device, so an installation you have left running elsewhere cannot keep reporting.
Searching
A search has to reach the server, because that is where the catalogue is. What is kept afterwards is a count and not a record: one row per search term per day, with how many times it was asked and how often it found nothing. There is no account, device, session or IP address on that row, and the finest time it holds is the date, so it cannot be reassembled into anyone’s session. Anything shaped like an email address is discarded rather than counted, and rows are deleted after 90 days.
Audio, video and artwork
Episode audio and video stream directly from the publisher, so pressing play — or downloading an episode for later — makes a request to their server, with whatever that server records. podnod cannot see inside that request and does not proxy it.
Everything else comes from podnod rather than from them. Artwork is cached and resized on podnod’s servers so the publisher’s host is not hit once per listener, and transcripts and chapters are fetched once by podnod’s servers and served from there — so reading along with an episode does not tell its publisher that you did.
Notifications
Notifications are optional, and one switch turns them off. It is the first row of Settings → Notifications, it applies to every device you are signed in on, and off means off: nothing is raised on any screen, nothing is sent to you, and podnod stops asking your operating system for permission it would have no use for. Turning it back on restores the choices you had made underneath it rather than asking you to set them up again.
While they are on, each notification is decided on the device itself — from your settings, the permission you gave the operating system, whether podnod is on screen, and your quiet hours. Nothing about that decision is reported anywhere.
Reaching a device that is closed needs one thing podnod cannot decide locally: a push token, issued by Apple, Google or your browser, which podnod’s servers store against that device and use to wake it. A device only has one if you allowed notifications on it. Turning the switch off deletes it, and so does turning notifications off in your operating system, signing out, or revoking the device — after which nothing is sent to it, because a device with no token is not in the list the server sends to. The desktop apps never obtain one at all.
What a push carries is deliberately close to nothing. A new-episode push is silent and names only the show, so the device can look up the rest itself; a browser push carries no content whatsoever, for the same reason. Only a letter from podnod carries words, and they are podnod’s own. None of them carries anything about what you listen to, and no push token appears in your data export, in any log, or anywhere in the sync between your devices.
Your notification inbox inside podnod is not governed by that switch, and this is worth being plain about: turning notifications off stops the interruptions, not the record. What you would have been told still arrives in the inbox for you to read whenever you go looking, and it never leaves your account.
Crash reports
podnod can tell podnod when it breaks, and it is off until you switch it on in Settings → Diagnostics. Off is not a switch on a thing that is running: with it off there is no reporter in the app at all, nothing is watching for errors, and there is no part of podnod that could send one by accident.
Switched on, a crash sends the error, the file and line it happened in, and a few lines of what podnod itself was doing beforehand — a sync that failed, a download that stalled. It carries no account, no email address, no device identifier and nothing about what you listen to; there is no field on it for any of those. The one identifier is a random number made fresh each time the app opens and never written down, which groups the six crashes of one bad afternoon together and cannot connect them to a different afternoon.
On iPhone and iPad the same switch also lets podnod hear when your phone's own system shut it down — for using too much memory, or too much of the processor while playing in your pocket. That one is not a crash podnod can see happening: the app is simply stopped, so the phone tells it afterwards, the next time you open it. What it carries is the same as above and no more — which parts of podnod were running at the moment it was stopped, your iOS version and which build of podnod it was. Never for a shutdown that happened before you turned the switch on, and never on Android, which has nothing of the kind to report.
Anything that looks like an address, a token, a web address with a query on it, or a folder with your name in it is struck out of the message before it leaves the device. Your app does not talk to the crash tracker directly either — the report goes to podnod, which passes it on — so the tracker never sees your IP address. Turning the switch back off destroys the reporter there and then, and unsubscribes from the phone's own reports in the same breath.
Reporting a problem
Separately, Settings → Diagnostics has a form for telling us something is wrong. It needs no account, and every part of it is optional — including all of it. Whatever you attach, you see first: a screenshot is taken by your own operating system's picker, so you choose what is in it, and it is shown back to you at full size before anything is sent. The log is podnod's own record of what it was doing and holds no titles, no searches and nothing you typed. Each part can be removed on its own, and nothing is gathered until you press send.
A report is read by a podnod operator, who is told when one arrives. Opening it is written to the audit log, and opening its screenshot is written separately — looking at a picture of your screen is a bigger thing than reading a sentence, and the record says which happened. Reports and their screenshots are deleted automatically after 90 days, sooner if the bug is understood before then, and deleting your account takes yours with it.
An email address is the only optional field that does anything beyond the report itself: it is never verified, it is used once if somebody writes back, and leaving it out is a complete report.
What there is not
- No advertising, and no advertising identifiers.
- No third-party analytics, no tag managers, no social pixels. Nothing on any page is fetched from another company’s servers, and nothing on any page is sent to one — the crash reporting above is podnod’s own, on podnod’s own servers, and it is off unless you switch it on.
- No crash reporting by default, and none at all without an account. It is the one setting that decides whether anything leaves your device, so it is off, and the server checks your answer again every time rather than trusting the app to remember it.
- No sale or sharing of personal data. There is no arrangement under which that could happen.
- No tracking cookies. There are three cookies: the session cookie that keeps you signed in, the CSRF token that travels with it, and — only if you ask for it — the one that lets a browser skip the second step for thirty days.
- No profiling. Nothing you listen to feeds the charts as anything other than an anonymous count, and no shelf is assembled from your history.
IP addresses
Your address is used to apply rate limits — how many searches a minute, how many new shows one address may add to the catalogue in an hour — and those counters expire by themselves. Nothing stores an address beside what you listened to.
Who can look
A podnod operator can open an account to answer a support request or a legal one. Every time that happens it is written to an audit log with who did it and when, including the times they only looked — opening somebody’s subscriptions is a disclosure whether or not anything was changed.
An operator can also switch crash reporting on or off for an account, which is there so somebody chasing a bug you keep hitting can ask you to turn it on and then turn it off again afterwards. It is worth being plain that this can be done without asking you: what stops it being a quiet tap is that it writes your own setting, so it shows in your Settings as the state you are now in and you can switch it straight back, and that both directions are written to the audit log.
Getting a copy
Account → Settings has two exports. One is a single JSON file holding your account and settings, your devices, the shows you follow, your positions, queue, saved episodes and playlists, deleted rows included; the other is your subscriptions as OPML, which any other podcast app will read. Neither needs to be asked for — they are yours, so you take them yourself. For anything not in them — your listening history, and any problem reports you have sent — write to the address below and it will be sent to you.
Deleting it
Delete your account from Settings in any of the apps. It asks for your password, because nothing can undo it. Removing the account takes every row belonging to it — subscriptions, play states, queue, saved episodes, playlists, settings, devices, listening history, what your devices last reported playing, and any problem reports you sent while signed in, screenshots included — along with every access token, every session and any outstanding password-reset link. The local copy on each device is yours to clear from that device, and signing out clears it.
Contact
Questions about any of this, or a request to see or delete what is stored: support@podnod.eu.
This page was last changed on 10 August 2026. If it changes in a way that matters, the change will be announced in the app before it takes effect rather than quietly swapped in here.