EarMark ← Back

Privacy Policy

Last updated: 20 June 2026

1. Who we are

EarMark (earmark-app.com) is a personal podcast service: it converts web articles, PDFs, and text you choose into spoken audio, delivered to a private podcast feed and to the EarMark apps. The service is operated by Earmark Ltd, a private company limited by shares, incorporated in England and Wales under the Companies Act 2006 (company number 17269833), with its registered office at Unit 4, Block E Holyrood Close, Poole, BH17 7FP, United Kingdom. In this policy, "EarMark", "we", and "us" refer to Earmark Ltd, which acts as the data controller for the personal data described here. You can reach us using the contact details in section 13.

2. What information we collect

We collect only what the service needs to work:

  • Account data. Your name, email address, and password. The password is stored only as a bcrypt hash — we never store or see the plaintext.
  • Content you submit. The article URLs you submit, PDFs you upload, text you paste, and audio files you upload. The text or document content of a submission is kept only while the episode is being generated and is deleted from our database as soon as the job completes or fails. The submitted URL, the generated audio, and episode metadata (title, duration, the voice used) are kept so your feed keeps working.
  • Usage and cost figures. Per-episode and cumulative processing costs (text-to-speech and text-cleanup spend), used to manage the shared service budget.
  • Devices (apps). If you sign in from the iOS or Android app, we store a per-device access token (only as a SHA-256 hash), the platform, an optional device label, and when it was last used. You can see and revoke each device in Settings.
  • Sharing. If you share an episode with another EarMark user, we record which episode was shared, by whom, and to whom, plus your list of trusted senders.
  • Feedback. The text of any bug report, feature request, or comment you send through the app.
  • Purchases (apps). If you buy credits or a subscription in the iOS or Android app, the purchase is processed by Apple or Google — we never receive your payment-card details. We keep a record of the purchase (a store transaction reference, the product, and the amount) and the credits it granted, tied to your account.
  • Technical data. When you request an email verification or password reset link we record the requesting IP address and browser user-agent alongside the short-lived token, as an abuse-prevention audit trail. The no-account sample on our landing page records a coarse network identifier for 24 hours to enforce its daily limit. Our servers also produce standard, short-lived operational logs.

3. How we use your information

We use this data to run EarMark for you: to generate your audio and deliver your personal feed, to keep you signed in, to send transactional email (email verification, password resets, password-change notices), to meter and bill text-to-speech usage (credits), to prevent abuse of the service, and to debug problems and keep the service running.

We do not sell your data, we do not show advertising, we do not profile you, and we use no analytics or tracking services. The only emails we send are the transactional ones listed above.

4. Legal bases for processing

Where UK or EU data-protection law applies, we rely on the following lawful bases:

  • Performance of a contract (Art 6(1)(b)) — for everything needed to provide the service you signed up for: your account data, the content you submit, the audio we generate, your devices, and episode sharing.
  • Legitimate interests (Art 6(1)(f)) — for keeping the service secure and operational and preventing abuse: the IP / user-agent audit trail on verification and reset requests, rate limiting, the landing-page sample limiter, and our short-lived server logs. We also rely on legitimate interests to stop repeated claims of the one-time free credit (we keep a one-way hash of your email so the same person can't claim it more than once). We've weighed these interests against your rights and consider them proportionate, and you can object at any time (see section 9).
  • Legal obligation (Art 6(1)(c)) — for the records of purchases we're required to keep under UK company and tax law.

We don't process your data for marketing, and we don't rely on consent for any current processing. If that ever changes, we'll ask for your consent first.

5. Cookies and local storage

EarMark uses a single essential cookie: the session cookie that keeps you signed in on the web. It is HTTP-only (inaccessible to scripts), marked Secure, restricted to same-site requests, and expires after 30 days. There are no advertising, analytics, or third-party tracking cookies.

Your browser's local storage holds a few interface preferences (for example, whether you've dismissed the welcome screen and your autoplay setting). These never leave your device. The iOS/Android apps store your device access token in the app's private preferences, and episodes you download for offline listening are stored in the app's private storage on your device — deleting a download, or the app, removes them.

6. Service providers and sub-processors

EarMark runs on a small set of service providers, each of which receives only what its job requires:

  • OpenAI — receives the extracted text of your submissions to clean it up for narration.
  • Inworld — the primary text-to-speech provider; receives the cleaned text to synthesise into audio.
  • Microsoft — provides the free fallback voice; receives the cleaned text when that voice is used.
  • Postmark — sends our transactional email; receives your email address and the message content.
  • Apple and Google — process in-app purchases of credits and subscriptions on iOS and Android. Payment happens entirely on the platform; we never see your payment details, only the purchase record described in section 2.
  • Hetzner — hosts our servers and storage; all data described in this policy lives on Hetzner infrastructure.
  • Cloudflare — sits in front of our servers for security and performance, and therefore processes your traffic (including your IP address) in transit.
  • Google Fonts — our web pages load fonts from Google's servers, which means your browser sends Google a standard font request (including your IP address). No other data is shared with Google.

7. Where your data is processed

Our servers and storage are in Germany (Hetzner, Nuremberg), inside the UK/EU-adequate area, so hosting itself involves no restricted transfer. Some of our other providers process data in the United States or globally — currently OpenAI, Inworld, Microsoft, Postmark, Cloudflare, and Google (web fonts). Where your data is transferred outside the UK, we rely, for each provider, on one of these safeguards:

  • the UK extension to the EU–US Data Privacy Framework (the "UK–US data bridge"), where the provider is certified under it; or
  • the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, where it isn't.

In each case we've satisfied ourselves — through a transfer risk assessment — that your data will get a level of protection broadly equivalent to that in the UK. You can ask us which mechanism applies to a particular provider using the contact details in section 13.

8. How long we keep your data

  • Submitted text and documents: deleted from our database the moment an episode finishes generating (or fails).
  • Generated audio: kept while storage allows. When storage fills, the oldest audio files are removed first; your episode history (titles, dates) remains in your feed view.
  • Sessions: expire after 30 days; expired sessions are purged hourly.
  • Email verification and password reset tokens (with their IP / user-agent records): valid for 48 hours and 30 minutes respectively, single-use, and purged hourly once expired.
  • Device tokens: kept until you revoke the device, reset your password, or delete your account.
  • Landing-page sample identifiers: deleted after 24 hours.
  • Purchase and financial records: kept for six years from the end of the financial year they relate to, as required by UK company accounting and tax rules.
  • Free-grant email hashes: a one-way hash of your normalised email, kept indefinitely as a fraud-prevention measure so the one-time free credit can't be claimed repeatedly. It cannot be reversed to your email and, by design, survives account deletion.
  • Everything tied to your account is deleted when you delete the account (see section 9).

9. Your rights and choices

You can view and change your account details, voice, and devices in Settings. You can delete your account and all associated data yourself, at any time, from Settings → Account → Delete account (in the apps and on the web). Deletion is immediate and removes your account, sessions, devices, episodes, shares, feedback, and tokens; generated audio files are removed from storage.

Where UK/EU law applies you also have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. You can also complain to us directly about how we handle your data, using the contacts in section 13 — we'll acknowledge your complaint within 30 days — before or instead of going to the ICO (ico.org.uk) or your local supervisory authority. For anything you can't do in Settings — including an export of your data — contact us (section 13) and we'll handle it directly.

10. Security

Passwords are stored only as bcrypt hashes. All traffic is encrypted in transit (TLS), and our origin servers accept traffic only via Cloudflare. Access tokens — device tokens, password-reset and email-verification tokens — are stored only as SHA-256 hashes, so a copy of our database does not contain usable credentials. Your podcast feed and audio are protected by per-user tokens, and each app device has its own revocable token. No system is perfectly secure, but EarMark is built to hold as little as possible and to protect what it holds.

11. Children's privacy

EarMark is not directed at children. You must be at least 16 years old to create an account, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, contact us and we will delete it.

12. Changes to this policy

If we change this policy, we'll update the date at the top. For material changes we'll also tell you in the app or by email before the change takes effect. The current version always lives at earmark-app.com/privacy.

13. Contact us

For privacy questions or data requests, email [email protected], or write to Earmark Ltd at the registered office address in section 1.

Terms of Service Home