Legal
Privacy policy
Last updated: 23 July 2026
1.Who we are
Podkin is a peer discussion service operated as a sole trader based in London, United Kingdom. For UK GDPR purposes, the operator of Podkin is the data controller for the personal data described in this policy. Our full controller name and postal address are available on request — email hello@podkin.co.uk and we'll provide them. Contact us any time at hello@podkin.co.uk.
2.What we collect and why
2.1 Account and profile.
| Data | Source | Why |
|---|---|---|
| Name or display name | You | To identify you to your pod |
| Email address | You | Login, and service emails and receipts |
| Password | You (stored only as a secure hash) | To let you log in |
| Profile including bio, headline, expertise, location and interests | You (optional) | So your pod knows who they're sitting with |
| What you want to get better at | You | To match you to a suitable pod |
2.2 Membership and participation. Pods you request, join or leave; which sessions you attended; your credit balance and every credit transaction; notes, topics and resources you post; messages you send through the product; and votes or requests for new pods.
2.3 Payment. We take card payments through Stripe. We never see or store your full card number. We hold the fact of a payment, the amount, the date, your subscription status and renewal date, and identifiers Stripe gives us so we can match a payment to your account.
2.4 If you host. Bank account name, sort code and account number or IBAN, your payout share, and a record of amounts due and paid. We need these to pay you and keep them for as long as tax law requires.
2.5 Sessions, recordings and summaries. Sessions take place on Zoom. Where a session is recorded we hold the recording, any transcript, and any AI-generated summary. Recording only happens where everyone in the session has agreed — see clause 5.
2.6 Email. Which emails we sent you, whether they were delivered, bounces, and unsubscribe status.
2.7 Technical data. When you use the site or submit a form we automatically record the time, the page or form you came from, your browser and device string, and — for logged-in sessions — the IP address associated with the session. We use this for security, to prevent abuse, and to understand which parts of the site work. We also record the timezone reported by your browser, so we can show session times correctly for you.
2.8 Special category data. We don't ask for it. But pods are conversations, and you might mention your health, beliefs or other sensitive matters. Please share only what you're comfortable having recorded and summarised. If a session is recorded, that content is in the recording. You can ask us to delete it.
3.Lawful bases
| Purpose | Lawful basis |
|---|---|
| Running your account, seating you in pods, taking payment | Performance of a contract, Article 6(1)(b) |
| Service emails including confirmations, joining links, reminders and receipts | Performance of a contract |
| Marketing emails about Podkin | Consent, Article 6(1)(a), withdrawable at any time |
| Recording sessions and producing transcripts and summaries | Consent from every participant |
| Security, fraud and abuse prevention, product improvement | Legitimate interests, Article 6(1)(f) |
| Accounting, tax and payout records | Legal obligation, Article 6(1)(c) |
| Anything special category volunteered in a recorded session | Explicit consent, Article 9(2)(a) |
Where we rely on legitimate interests we have weighed our interest against your rights and use the minimum data needed. You can object — see clause 9.
4.Who processes your data for us
These are our processors. Each acts on our instructions under a data processing agreement.
| Service | What for | Where data is stored |
|---|---|---|
| Lovable | Application hosting, deployment, transactional email delivery, and the AI gateway described in clause 5.2 | United Kingdom, European Union and United States |
| Supabase | Database, authentication, file storage and scheduled jobs | European Union |
| Stripe | Card payments, subscriptions and receipts | European Union and United States |
| Zoom | Running sessions, and recordings where agreed | United States |
| Supplies the AI models used through Lovable's AI gateway | European Union and United States |
We do not sell your personal data and we do not share it with third parties for their own marketing. We may disclose data where the law requires it, but only to the minimum extent required.
5.Recordings, transcripts and AI
5.1 Recording. We tell you before a session is recorded. If anyone present objects, the session is not recorded. Recordings and transcripts are visible only to the members and host of that pod, and to us for running and supporting the service. We do not publish them or share them outside the pod. You can ask us to delete a recording you appear in and we will do so, subject to the interests of others in it.
5.2 AI processing. Podkin uses automated tools to draft agendas, summarise sessions, suggest reading and answer questions about your pods. To do that, relevant content — including session notes and things you write in the product — is sent through Lovable's AI gateway to Google's Gemini models, which process it on our behalf and under contract. Automated summaries can be inaccurate. No decision producing legal or similarly significant effects for you is made by automated means alone.
5.3 Retention of recordings. Recordings and transcripts are kept for 12 months after the pod ends, then deleted. Summaries may be kept for longer so members keep a record of their pod.
6.International transfers
Some processors are outside the UK, notably in the United States. Where personal data goes outside the UK we rely on UK-approved safeguards — the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision. You can ask us for details of the safeguards used for any particular transfer.
7.How long we keep things
| Data | Retention |
|---|---|
| Account and profile | While your account is open, then 12 months, then deleted |
| Pod membership, attendance and credit ledger | 6 years, to support billing queries and disputes |
| Payment and payout records | 6 years after the end of the relevant tax year, as legally required |
| Host bank details | While you host, then 6 years to support those payment records |
| Recordings and transcripts | See clause 5.3 |
| Marketing list | Until you unsubscribe, then removed within 90 days, and reviewed after 2 years of no contact |
| Email delivery logs | 12 months |
| Technical and security logs | 12 months |
You can ask us to delete your data sooner — see clause 9. Where we must keep records for tax or legal reasons we will keep only those and remove the rest.
8.Cookies and local storage
We use strictly necessary cookies and browser storage to keep you logged in and keep the site secure. These don't require consent and can't be turned off without breaking the site. We do not run advertising trackers or third-party marketing pixels.
9.Your rights
Under UK GDPR you can ask us to give you a copy of your data; correct anything wrong; delete your data; restrict how we use it; give it to you in a portable format; stop using it where we rely on legitimate interests; or withdraw a consent you gave — including consent to recording or to marketing email — at any time, with no cost. Withdrawing consent doesn't affect what we did before you withdrew it. Email hello@podkin.co.uk. We respond within one month, usually sooner, and there's no charge.
One limitation worth stating plainly: a session recording contains other people too. If you ask us to delete a recording you appear in, we will weigh your request against the rights of the others in it, and will explain what we can and cannot do.
10.Complaining
Please email us first — we'd like the chance to put it right. You also have the right to complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113.
11.Security
Data is sent over HTTPS. Passwords are stored hashed, never in plain text. Access to the production database and to member data is limited to the operator and any administrators we authorise, and protected by authentication controls. Card details are handled by Stripe and never touch our systems. Payout bank details are stored in our database with access restricted to administrators. We will tell affected people and the ICO without undue delay if a personal data breach requires it.
12.Children
Podkin is for adults. We don't knowingly collect data from anyone under 18. If you think a child has given us information, email us and we'll delete it.
13.Changes
We may update this policy as Podkin changes. Material changes will be emailed to members. The date at the top shows the current version.
14.Contact
hello@podkin.co.uk. The founder reads every email personally.