Effective 17 July 2026
Privacy Notice
This notice explains what personal data TLDR Pods uses, why we use it, who helps us provide the service, and the choices available to you.
1. Controller & contact
YORKECCAK LTD is the controller of personal data used by TLDR Pods. Our registered office is 21 Hornyold Avenue, Malvern, WR14 1QJ, United Kingdom. Privacy questions and rights requests can be sent to harveyyorke@proton.me.
2. Data we use
| Data | Purpose & lawful basis |
|---|---|
| Account details | Email address, name, avatar, authentication identifiers, and account settings. We use these to create and secure your account and provide the service under our contract with you. |
| Completion email delivery | Your verified account email address, delivery status, attempt timestamps, and the delivery provider's message identifier. We use these data to tell you that a Tldr you requested is ready, which is necessary to perform our contract with you. The message has the fixed subject "Your Tldr is ready" and a generic link to your library. We do not send the provider your question, Tldr, sources, job ID, or report ID. |
| Queries & Tldrs | Your questions, Tldr content, citations, and Tldr history. We use your question to create the Tldr you request and store it in your account. This processing is necessary to perform our contract with you. We also use this data where necessary to provide support, protect the service, and prevent abuse under our legitimate interests, or to comply with law. |
| Usage & technical data | Feature usage, Tldr counts, API-key metadata, timestamps, IP address, device and browser information, request logs, and security events. We use these for metering, troubleshooting, fraud prevention, service security, and understanding whether paid customers receive value and return to the service. This supports our contract and our legitimate interests in operating and improving the service. Product analysis uses counts and timing milestones, not Tldr questions, content, citations, or source URLs. |
| Billing data | Customer, subscription, invoice, payment status, and limited payment-method metadata. Our payment provider handles full card details. We use billing data to take payment, manage subscriptions, keep accounts, and meet tax and legal duties. |
| Messages & complaints | Support correspondence, feedback, rights requests, and copyright notices. We use these to respond, resolve disputes, protect rights, and meet legal obligations. |
We receive data directly from you, from our payment provider, and automatically when you use the service. We also process public podcast metadata and source material to create Tldrs. That source material is not your personal data unless you are featured in it.
An email address and authentication details are required to create and secure an account. Payment and billing details are required to buy a subscription. If you do not provide the required data, we cannot create the account, complete the purchase, or provide the paid service. Optional profile information can be omitted.
3. Your Tldrs & source material
Tldrs you create are stored against your account and are not placed in the public answer library. Our staff and service providers may access them only where reasonably necessary to provide support, investigate security or abuse, protect the service, or comply with law.
To create a Tldr, TLDR Pods temporarily processes podcast audio, metadata, and text from publicly available sources. We do not expose raw transcripts to customers, provide transcript downloads, or include raw transcripts in any Tldr.
Do not put health records, identification documents, financial account details, or other sensitive personal information into a query. TLDR Pods is not designed to receive this kind of data.
4. Who receives data
We share personal data only as needed with:
- hosting, database, authentication, networking, and security providers;
- payment and subscription-management providers;
- an email delivery provider, which receives the intended verified account address and a content-free completion message with a generic library link;
- language-processing and infrastructure providers that help create a requested Tldr;
- professional advisers, auditors, insurers, and authorities where reasonably necessary; and
- a buyer or successor in a genuine financing, reorganisation, or sale, subject to safeguards.
We do not sell personal data. We do not share your Tldrs with podcasters, publishers, or other customers. You can request a current list of material service providers by emailing us.
5. International transfers
Some providers may process data outside the United Kingdom. Where the destination is not covered by UK adequacy regulations, we rely on an approved transfer mechanism such as the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or another lawful safeguard. You may ask us for information about the safeguard used.
6. Retention
- Account details, Tldrs, and Tldr history are kept while your account is open and then deleted or anonymised when no longer needed, subject to backups and legal obligations.
- Account-linked product milestones are deleted with the account. Identifier-free cohort totals may be retained to keep historical service-improvement statistics accurate; they do not contain account, report, source, payment, or customer identifiers.
- Completion-email attempts are not started after the 23-hour delivery deadline. We clear the outbox copy of the verified address after the provider accepts the message, after delivery is abandoned, when account deletion drains outstanding delivery, or on the next delivery-worker pass after an outage or application rollback. An outage or rollback can therefore delay that final outbox cleanup beyond the delivery deadline.
- Temporary source audio is deleted after each processing attempt. If processing is interrupted, leftover audio is automatically deleted after it is at least 1 hour old. Temporary full source text becomes unavailable for reuse 7 days after creation and is then deleted automatically.
- Revoked API-key records and security logs are kept only as long as reasonably needed to protect the service, investigate incidents, and enforce limits.
- Billing, invoice, and transaction records may be kept for up to 6 years after the relevant accounting period to meet tax, company, and legal requirements.
- Support, dispute, and rights-holder records are kept for as long as needed to resolve the matter and establish, exercise, or defend legal claims, normally no longer than 6 years after closure.
Backup copies may remain for a limited rolling period before automatic deletion. We may retain data for longer where law requires it, a dispute is active, or a security investigation makes that necessary.
7. Cookies & local storage
TLDR Pods uses strictly necessary cookies and similar storage to keep you signed in, refresh your secure session, remember essential account state, and protect checkout and the service. These technologies are necessary to provide features you request and cannot be switched off through a consent banner.
We also use cookie-free web analytics to understand aggregate page views, referrers, broad location, browser, operating system, device type, and a small set of interactions across the public site and signed-in product. Those interactions record only fixed categories such as the marketing or sample action and position, public answer page views grouped by pillar and format, plan, billing period, whether checkout or billing could open, research depth, and whether a Tldr request was accepted, blocked, completed, failed, opened, copied, printed, or cancelled. The analytics service does not use third-party cookies or keep an identifier that follows you across websites or days. We configure it not to receive Tldr questions, report text, specific report or source URLs, account identifiers, payment identifiers, job or report identifiers, source titles, or private error text. Private page views are excluded, and fixed product events use only generic route categories. We use these statistics under our legitimate interest in understanding and improving the service.
We do not use advertising cookies or cross-site behavioural tracking. If that changes, we will update this notice and ask for consent before setting non-essential cookies where the law requires it. You can block cookies in your browser, but account and billing features may stop working.
8. Your rights
Depending on the circumstances, UK data-protection law gives you rights to access, correct, erase, restrict, or object to processing of your personal data, and to receive certain data in a portable form. Where processing relies on consent, you may withdraw it at any time. You may also object to direct marketing at any time.
Your right to object: where we rely on legitimate interests, you may object to that processing based on your particular situation. We will stop unless we can show compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.
We do not use solely automated decision-making that produces legal or similarly significant effects about you.
Email harveyyorke@proton.meto exercise a right. We may need to verify your identity. We normally respond within 1 month, subject to lawful extensions. You can complain to the UK Information Commissioner's Office at ico.org.uk, but we would appreciate the opportunity to resolve your concern first.
9. Security, children & changes
We use access controls, encryption in transit, restricted service credentials, and other technical and organisational measures appropriate to the service. No system is completely secure, so contact us promptly if you suspect unauthorised access.
TLDR Pods is for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data.
We may update this notice as the service or law changes. We will post the new effective date and provide reasonable notice where a change materially affects how we use personal data.