Privacy policy

Curiosity without the creepiness.

The complete, plain-language account of what Resonate handles, why it is needed, and how you can remove it.

Last updated August 6, 2026

Full data-controller contact details are listed under Business information.

Who we are

Resonate is a podcast app and website operated by Gustav Buchholtz, an individual based in Sweden. Gustav Buchholtz is the developer and data controller. In this policy, “Resonate” means the service operated by Gustav Buchholtz. Resonate is intended for people aged 16 and older.

You can contact us about privacy or support at support@resonate-podcasts.com.

Data we handle

Account and contact data: your email address, authentication provider, internal account identifier, optional display name, podcast storefront, and messages you choose to send to support. Our authentication provider handles sign-in credentials; Resonate does not store plaintext passwords.

Library and listening data: podcast subscriptions, notification choices, per-show settings, queue, playback position, completion and listening history, and timestamped bookmarks with any notes you add. If you add a private podcast, its feed URL may contain access credentials and is treated as private account data.

Purchase and Premium data: a subscription-management identifier, Google Play product and store, entitlement and renewal status, subscription dates, Premium usage allowance, and requests for paid enrichment work. Payment-card details are handled by Google Play and are not provided to Resonate.

Device and notification data: device platform, push token, notification permission and delivery status.

Optional app analytics: on Android, Firebase Analytics stays disabled until you separately choose “Share analytics” after account creation or in Privacy settings. If enabled, bounded events describe feature surfaces, search result ranges, podcast and episode actions, playback milestones, queue and download actions, bookmarks, notifications, enrichment, and Premium flows. We deliberately do not put email, Resonate account IDs, transaction IDs, search text, podcast or episode names or identifiers, feed URLs, transcript text, bookmark notes, exact listening positions, or free-form errors into these events. Firebase may process app interactions, app-instance or device identifiers, device information, and coarse location inferred from network information under its own SDK behavior.

Search, podcast, and enrichment data: search text, podcast feed and media URLs, and public podcast audio or transcripts needed to return results, generate transcripts, create chapters, and resolve references. Providers receive the content needed for the task, but Resonate does not deliberately send them your email or Resonate account identifier.

Service and security data: request timestamps, basic network and device metadata, an in-memory hash derived from an IP address for abuse limits, and operational logs needed to secure and operate the service.

On-device data: cached library and podcast information, settings, queue state, artwork, and downloaded podcast audio are stored on your device so Resonate remains useful offline.

Why we use it

We use account, library, playback, device, and purchase data to provide and synchronize the app, restore access, deliver requested notifications, support offline listening, and complete account deletion.

If you consent, we use limited product analytics to understand activation, discovery, listening, feature adoption, enrichment, and Premium flows so we can improve Resonate. We use operational data to prevent abuse, diagnose failures, secure the service, and meet legal obligations.

Providing the account, playback, library, purchase, notification, and enrichment features you request relies on performing our contract with you. Optional Firebase Analytics relies on your consent. Security, fraud prevention, service reliability, and proportionate operational logging rely on our legitimate interests in protecting Resonate and its listeners. We also process data where needed to comply with law.

Where the data comes from

Most account, library, playback, bookmark, search, support, and analytics information comes from what you enter or do in Resonate and from the device running the app. Authentication providers tell us enough to sign you in, and Google Play and our subscription-management provider tell us whether Premium is active and the status of a purchase.

Podcast metadata, audio, transcripts, artwork, and related reference information can come from podcast publishers, media hosts, podcast directories, and public knowledge or media sources. Resonate can also create derived information such as playback progress, transcripts, chapters, and reference cards when you use the relevant features.

Service providers and sharing

Resonate uses specialist providers only where needed to operate the service. These categories include authentication, cloud database and storage, API and website hosting, background processing, subscription management, Google Play billing, Firebase Analytics, push delivery, and support-email delivery. Each provider receives only the account, device, purchase, operational, or analytics information needed for its role.

Podcast discovery and enrichment can involve podcast directories, publishers and media hosts, speech-to-text and AI providers, and public knowledge or media databases. Search or podcast content is shared only as needed to find, transcribe, enrich, or return the result you requested.

Some providers may process data outside Sweden or the European Economic Area. Where required, we rely on recognized transfer mechanisms such as an adequacy decision or approved contractual safeguards. Contact support@resonate-podcasts.com if you want information about the safeguard applicable to a particular transfer.

We may also disclose information when required by law, to protect listeners or the service, or as part of a business transfer with appropriate protections.

Resonate does not sell personal data, does not run third-party advertising, and does not use your listening activity for ad targeting.

Retention and deletion

Account-linked data is kept while your account exists and is removed when you delete the account. Deletion removes your sign-in, Resonate user row, subscriptions, private-feed association and any orphaned private feed, listening history, bookmarks and their notes, queue, per-show settings, push tokens, entitlement mirror, Premium usage and request records, and subscription-management profile.

Deleting a Resonate account does not cancel an active Google Play subscription. Google Play keeps its own purchase and subscription records under Google’s policies and legal duties, so cancel the subscription in Google Play first if you want future billing to stop.

Shared public podcast catalog data, transcripts, chapters, and reference cards may remain because they describe public podcast content and are not tied to your account. Delivery audit records may remain after their account link is removed where needed for security, fraud prevention, accounting, reliability, or legal compliance.

Firebase Analytics is not deliberately linked to your Resonate account. Resonate configures Firebase event-data retention to 14 months without resetting that period when new activity occurs. Firebase does not provide Resonate with a regional-storage choice for this Analytics property, and Google may process the data outside Sweden or the EEA under its safeguards. Withdrawing consent stops future collection on the current device and clears supported on-device Analytics state, but previously processed, non-account-linked Analytics cannot be located through your Resonate account or deleted through account deletion and may remain until Google’s retention period expires.

Legal-acceptance and analytics-consent audit rows are account-linked and are deleted with your Resonate account. Operational logs and backups may contain data for a limited period before normal rotation. Support email is kept only as long as reasonably needed to resolve the conversation and maintain necessary records.

Downloaded audio and other on-device data cannot be removed remotely. Remove downloads or uninstall/clear the app to erase that local copy.

Your choices and rights

You can change notification permissions in Android, change show settings in Resonate, grant or withdraw optional product analytics in Settings → Privacy, cancel a subscription in Google Play, and permanently delete your Resonate account in the app or on this website. An offline analytics change takes effect immediately on that device and synchronizes with your account after reconnecting. Declining or withdrawing analytics never limits app features.

An email address and authentication information are necessary to create an account and provide account synchronization; without them, we cannot provide signed-in features. Library, playback, search, notification, and enrichment data arise only when you use those features. Product analytics is optional.

Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal data. Email support@resonate-podcasts.com to exercise a right that is not available in the app. You may also complain to your local data-protection authority; in Sweden, this is the Swedish Authority for Privacy Protection (IMY).

Automated processing

Resonate uses automated systems to produce transcripts, chapters, search results, summaries, and reference cards and to operate security and abuse controls. These systems do not make decisions about you that produce legal or similarly significant effects. Premium access and usage checks apply the purchase and allowance rules described in the Terms of Service; contact support if you believe a status or allowance is wrong.

Security

Resonate uses HTTPS for app and API traffic, short-lived authentication tokens, access controls, secret separation, and restricted production access. No online service can guarantee absolute security, but we limit collection and provider access to what the product needs.

People under 16

Resonate is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child under 16 has created an account, contact support@resonate-podcasts.com so the account can be removed.

Changes to this policy

We may update this policy when Resonate or its providers change. The current version and update date will always appear on this page. Material changes will be communicated in the app or by another appropriate method when required.