Privacy Policy
1. Who we are
Pibbl is a social media automation tool for podcast creators, operated by Medford Staffordshire Enterprises LLC d/b/a Pibbl. When this policy says "Pibbl," "we," "us," or "our," it refers to that entity.
Questions? Email us at [email protected].
2. What we collect and why
We collect only what we need to run the service:
| Data | What it is | Why we collect it |
|---|---|---|
| Account info | Email address and name provided at sign-up | Create and identify your account |
| Podcast RSS URL | The feed URL you add in settings | Fetch episode data to generate drafts |
| Episode metadata | Title, description, artwork URL, and episode link from your RSS feed | Generate social media drafts via AI |
| Episode audio | A copy of your episode audio, fetched from the URL in your feed at transcription time | Produce a transcript for drafts, Barks, and Content Packs |
| Episode transcripts | The text (and chapter/highlight markers) produced from that audio | Write drafts that reflect what was actually said |
| Media you upload | Images and videos you attach to an Instant Post, plus podcast cover art and shared assets | Attach them to the posts you publish |
| Platform OAuth tokens | Access and refresh tokens, webhook URLs, or instance credentials for connected accounts (Instagram, Facebook, Threads, LinkedIn, Bluesky, Pinterest, Mastodon, Discord, Telegram, Nostr, Lemmy) | Publish approved posts on your behalf |
| Platform identifiers | Username and account ID for each connected platform | Display connected account info and route posts correctly |
| Published post IDs | The ID returned by the platform after a post goes live | Track publishing history in your dashboard |
| Usage data | Pages visited, actions taken, timestamps | Diagnose bugs and improve the product |
3. How we use your data
We use your data to:
- Sync your RSS feed and detect new episodes
- Transcribe episode audio using Groq (Whisper) and AssemblyAI
- Generate AI draft posts using Anthropic's Claude API
- Publish approved posts to your connected social accounts
- Display your publishing history and account status in the dashboard
- Send transactional emails (e.g., account verification, billing receipts)
- Diagnose technical issues and improve the product
We do not use your data for advertising, behavioral profiling, or to train AI models. Episode metadata and, where a transcript exists, transcript text are sent to the Anthropic API and processed under Anthropic's API terms, which prohibit using API inputs to train their models. Episode audio is sent to our transcription providers under the same condition. We hold a copy of your audio only for as long as a transcription job is running; the resulting transcript is retained with your episode.
4. Third-party services
Pibbl uses the following third-party services to operate. Each receives only the data necessary for their function:
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database, file storage, and authentication | supabase.com/privacy |
| Anthropic | AI draft generation (receives episode title, description, and transcript text) | anthropic.com/privacy |
| Groq | Speech-to-text transcription (receives episode audio) | groq.com/privacy-policy |
| AssemblyAI | Full transcription for Barks and Content Packs (receives episode audio) | assemblyai.com/legal/privacy-policy |
| Inngest | Background job processing (draft generation, scheduled publishing) | inngest.com/privacy |
| Cloudflare | Hosting and edge delivery | cloudflare.com/privacypolicy |
| Sentry | Error monitoring (receives diagnostic data, which can include your account identifier) | sentry.io/privacy |
| Upstash | Rate limiting (receives account and request identifiers) | upstash.com/trust/privacy.pdf |
| Resend | Transactional email delivery | resend.com/legal/privacy-policy |
| Stripe | Payment processing (billing subscribers only) | stripe.com/privacy |
We do not sell, rent, or share your personal data with any third party for marketing or commercial purposes.
5. OAuth tokens and platform data
When you connect a social media account, we store the OAuth access token and refresh token returned by that platform. These tokens are encrypted at rest using AES-256. They are used exclusively to publish posts on your behalf and are never shared with any third party other than the platform that issued them.
You can disconnect any platform at any time from the Settings page. When you disconnect an account, its tokens are immediately and permanently deleted from our systems.
Pinterest specifically: Pibbl uses the Pinterest API to publish approved pins to your connected Pinterest account on your behalf. Pibbl is not endorsed by, affiliated with, or sponsored by Pinterest. When you disconnect your Pinterest account (or delete your Pibbl account), we immediately and permanently delete your Pinterest OAuth tokens, account identifiers, and any other Pinterest-derived data (such as board names and pin IDs) from our systems. We do not sell, rent, resell, or redistribute Pinterest content or Pinterest-derived data to any third party. It is used solely to operate the publishing features of the Service.
6. Data retention
We retain your data for as long as your account is active. If you delete your account:
- Your profile, podcast, episode, and draft data is deleted within 30 days
- OAuth tokens for all connected platforms are deleted immediately
- Billing records are retained for 7 years as required by tax law
To delete your account, email us at [email protected].
7. Your rights
Depending on where you are located, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Receive a copy of your data in a portable format
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Cookies and tracking
Pibbl uses session cookies issued by Supabase to keep you logged in. We do not use third-party advertising cookies, tracking pixels, or analytics that share data with ad networks. We may use a first-party analytics tool to understand feature usage in aggregate, without identifying individual users.
9. Security
We use industry-standard measures to protect your data: HTTPS for all data in transit, AES-256 encryption for stored OAuth tokens, and row-level security on our database so each user can only access their own data. No security measure is perfect. If you believe your account has been compromised, contact us immediately at [email protected].
10. Children
Pibbl is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice in the Pibbl dashboard at least 14 days before the change takes effect. The effective date at the top of this page always reflects the current version.
12. Contact
Medford Staffordshire Enterprises LLC d/b/a Pibbl
[email protected]