Privacy policy
Curiosity without the creepiness.
The complete, plain-language account of what Resonate handles, why it is needed, and how you can remove it.
Last updated July 28, 2026
Who we are
Resonate is the developer and data controller for the Resonate podcast app and this website. Resonate is intended for people aged 16 and older.
You can contact us about privacy or support at support@resonate-podcasts.com.
Data we handle
Account and contact data: your email address, authentication provider, internal account identifier, optional display name, podcast storefront, and messages you choose to send to support. Supabase handles authentication credentials; Resonate does not store plaintext passwords.
Library and listening data: podcast subscriptions, notification choices, per-show settings, queue, playback position, completion and listening history. If you add a private podcast, its feed URL may contain access credentials and is treated as private account data.
Purchase and Premium data: your RevenueCat customer identifier, Google Play product and store, entitlement and renewal status, subscription dates, Premium usage allowance, and requests for paid enrichment work. Payment-card details are handled by Google Play and are not provided to Resonate.
Device and notification data: device platform, Expo push token, notification permission and delivery status.
App analytics: bounded Firebase Analytics events about Premium screens, product selection, purchase or restore outcomes, subscription management, and enrichment outcomes. We deliberately do not put email, Resonate account IDs, transaction IDs, podcast or episode names, feed URLs, transcript text, or free-form errors into these events. Firebase may process app interactions, app-instance or device identifiers, device information, and coarse location inferred from network information under its own SDK behavior.
Search, podcast, and enrichment data: search text, podcast feed and media URLs, and public podcast audio or transcripts needed to return results, generate transcripts, create chapters, and resolve references. Providers receive the content needed for the task, but Resonate does not deliberately send them your email or Resonate account identifier.
Service and security data: request timestamps, basic network and device metadata, an in-memory hash derived from an IP address for abuse limits, and operational logs needed to secure and operate the service.
On-device data: cached library and podcast information, settings, queue state, artwork, and downloaded podcast audio are stored on your device so Resonate remains useful offline.
Why we use it
We use account, library, playback, device, and purchase data to provide and synchronize the app, restore access, deliver requested notifications, support offline listening, and complete account deletion.
We use limited analytics and operational data to understand whether subscription and enrichment flows work, prevent abuse, diagnose failures, secure the service, and improve Resonate. We use data to meet legal obligations and enforce our rights where necessary.
Where applicable, these purposes rely on performing the service you request, our legitimate interests in operating a reliable and secure app, your choices and device permissions, and compliance with law.
Service providers and sharing
Resonate uses service providers only where needed to run the app: Supabase for authentication, database, and transcript storage; Railway and Vercel for API and website hosting; Trigger.dev for background work; RevenueCat and Google Play for subscriptions and purchase status; Firebase Analytics for app analytics; Expo for push delivery; and Cloudflare for support-email routing.
Podcast discovery and enrichment can use Podcast Index, Apple, podcast publishers and media hosts, Deepgram, OpenAI, Wikipedia/Wikimedia, Open Library, TMDB, and TheAudioDB. Search or podcast content is shared only as needed to return or create the requested result.
These providers may process data in countries outside Sweden or the European Economic Area under their contractual safeguards. We may also disclose information when required by law, to protect users or the service, or as part of a business transfer with appropriate protections.
Resonate does not sell personal data, does not run third-party advertising, and does not use your listening activity for ad targeting.
Retention and deletion
Account-linked data is kept while your account exists and is removed when you delete the account. Deletion removes your Supabase sign-in, Resonate user row, subscriptions, private-feed association and any orphaned private feed, listening history, queue, per-show settings, push tokens, entitlement mirror, Premium usage and request records, and RevenueCat customer profile.
Deleting a Resonate account does not cancel an active Google Play subscription. Google Play keeps its own purchase and subscription records under Google’s policies and legal duties, so cancel the subscription in Google Play first if you want future billing to stop.
Shared public podcast catalog data, transcripts, chapters, and reference cards may remain because they describe public podcast content and are not tied to your account. Delivery audit records may remain after their account link is removed where needed for security, fraud prevention, accounting, reliability, or legal compliance.
Firebase analytics is not deliberately linked to your Resonate account and may remain under Google’s configured retention controls. Operational logs and backups may contain data for a limited period before normal rotation. Support email is kept only as long as reasonably needed to resolve the conversation and maintain necessary records.
Downloaded audio and other on-device data cannot be removed remotely. Remove downloads or uninstall/clear the app to erase that local copy.
Your choices and rights
You can change notification permissions in Android, change show settings in Resonate, cancel a subscription in Google Play, and permanently delete your Resonate account in the app or on this website.
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal data. Email support@resonate-podcasts.com to exercise a right that is not available in the app. You may also complain to your local data-protection authority; in Sweden, this is the Swedish Authority for Privacy Protection (IMY).
Security
Resonate uses HTTPS for app and API traffic, short-lived authentication tokens, access controls, secret separation, and restricted production access. No online service can guarantee absolute security, but we limit collection and provider access to what the product needs.
People under 16
Resonate is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child under 16 has created an account, contact support@resonate-podcasts.com so the account can be removed.
Changes to this policy
We may update this policy when Resonate or its providers change. The current version and update date will always appear on this page. Material changes will be communicated in the app or by another appropriate method when required.