v2026-07-19
Privacy notice — draft
This notice describes what EpisodeBrief collects and how it is handled in the current pre-launch build.
Draft status
This is a working draft. Counsel-reviewed launch copy — including definitive controller identity, subprocessor list, retention schedule, and international-transfer basis — is set by prompt 20.
Account data
We store an email address, an optional name, sessions, linked sign-in methods, consent choices, and preference settings.
Security email
We send transactional messages that are necessary to operate your account (verification, sign-in link, password reset, security notifications). These are not marketing.
Deletion
You can request account deletion from account settings. Active data is scheduled for deletion within 24 hours. Some minimum billing / security / statutory records are retained separately.
YouTube import (data processed)
When you submit a public YouTube URL, EpisodeBrief validates the URL locally, records the 11-character video identifier, and asks Supadata for bounded public metadata plus a native or provider-generated transcript. The raw submitted URL, query string, cookies, referrer, request IP, and any YouTube credential are never stored in the YouTube import record and are never forwarded to Supadata. Provider text responses, content-free attempt metadata, and normalized transcripts each have a registered retention deadline; account or episode deletion cascades to the associated YouTube import rows. YouTube attribution is mandatory and cannot be disabled on owner views, provenance-bearing exports, or published episodes. EpisodeBrief does not warrant Supadata's or YouTube's availability, accuracy, or legal permission; provider-side retention is operator-audited and not asserted from a public page.
Data contact
Data-request contact details are set by prompt 20's launch gate. In pre-launch, use legal@episodebrief.com.