Privacy Policy

Last updated: February 21, 2026

1. Who We Are

DriftNote ("we", "us", or "our") operates the website at driftnote.net and the DriftNote podcast summarisation service. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our Service, and your rights in relation to that data.

For questions about this policy or your data, contact us at contact@driftnote.net.

2. Information We Collect

Account Information

When you create an account, we collect your email address and a hashed password. If you sign up or log in via Google, we receive your name, email address, and profile picture from Google.

Usage Data

When you use the Service, we store the Spotify episode URLs you submit, the podcast and episode titles associated with them, the AI-generated summaries produced, the status of each summary (completed or failed), and the timestamps of your activity. If you connect Notion, we also store the URL of the Notion page where a summary was saved.

Notion Connection Data

If you connect your Notion workspace, we store an encrypted OAuth access token, your Notion workspace ID and name, and a bot ID. This data is used solely to save summaries to your Notion workspace on your behalf.

Payment Data

If you subscribe to a paid plan, payments are processed by Stripe. We do not store your card details. We store your Stripe customer ID, subscription status, and billing period dates to manage your access to Pro features.

Technical Data

We collect standard technical information including your IP address, browser type, device information, and pages visited, via Vercel Analytics and Vercel Speed Insights. This data is aggregated and used to monitor performance and improve the Service.

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate your identity.
  • Process the podcast episodes you submit and return AI-generated summaries.
  • Sync summaries to your Notion workspace if you have connected it.
  • Process payments and manage your subscription.
  • Send transactional emails such as account confirmation and password reset.
  • Enforce usage limits based on your plan (Free: 5 summaries/month; Pro: unlimited).
  • Monitor and improve the performance, reliability, and security of the Service.
  • Respond to your support requests.
  • Comply with legal obligations.

We do not use your data to train AI models. We do not sell your personal data to third parties.

4. Third-Party Services

The Service relies on the following third-party processors. Each has its own privacy policy and data practices:

ServicePurposeData shared
SupabaseAuthentication & databaseEmail, hashed password, user data
Google (Gemini AI)AI summarisationPodcast transcript text
Google (OAuth)Sign in with GoogleName, email, profile picture (if used)
StripePayment processingEmail, billing information
NotionSaving summaries to NotionOAuth token, summary content (if connected)
PodcastIndexRSS feed discoveryPodcast name (search query)
Spotify / iTunesEpisode metadataEpisode URL / podcast name
Cloudflare TurnstileBot preventionBrowser signals, IP address
VercelHosting, analytics, performanceIP address, page views, load metrics

5. Cookies and Session Data

We use HTTP-only session cookies managed by Supabase to keep you logged in. These cookies are strictly necessary for the Service to function and do not track you across other websites.

We also use temporary cookies during the Notion OAuth flow to protect against CSRF attacks. These are deleted once the flow is complete.

Vercel Analytics may set analytics cookies or use local storage for performance measurement. These do not contain personally identifiable information.

6. Data Retention

We retain your account data and summaries for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial record-keeping purposes (for example, Stripe transaction records may be retained for up to 7 years in accordance with financial regulations).

You can delete individual summaries at any time from your dashboard. You can disconnect your Notion integration at any time from your account settings.

7. Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that inaccurate data be corrected.
  • Deletion — request that your personal data be deleted ("right to be forgotten").
  • Portability — request a machine-readable copy of your data.
  • Objection — object to certain processing of your data.
  • Restriction — request that processing be restricted in certain circumstances.

To exercise any of these rights, email us at contact@driftnote.net. We will respond within 30 days. If you are located in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.

8. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Data Security

We implement reasonable technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), HTTP-only session cookies, row-level security on our database, and encrypted storage of third-party OAuth tokens.

No method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

10. International Transfers

Our Service is hosted on Vercel and uses Supabase for data storage. Your data may be processed in the United States or other countries where our third-party processors operate. Where required by law, appropriate safeguards (such as Standard Contractual Clauses) are in place to protect transferred data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice in the Service. The "Last updated" date at the top of this page reflects the most recent revision.

Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

12. Contact

For any privacy-related questions, requests, or complaints, contact us at contact@driftnote.net.

You can also review our Terms of Service.