Privacy Policy
Last updated: 20 June 2026
1. Who we are
EarMark (earmark-app.com) is a personal podcast
service: it converts web articles, PDFs, and text you choose into spoken audio, delivered
to a private podcast feed and to the EarMark apps. The service is operated by
Earmark Ltd, a private company limited by shares, incorporated in
England and Wales under the Companies Act 2006 (company number 17269833), with its
registered office at Unit 4, Block E Holyrood Close, Poole, BH17 7FP,
United Kingdom. In this policy, "EarMark", "we", and "us" refer to Earmark Ltd,
which acts as the data controller for the personal data described here. You can reach us
using the contact details in section 13.
2. What information we collect
We collect only what the service needs to work:
- Account data. Your name, email address, and password. The password is
stored only as a bcrypt hash — we never store or see the plaintext.
- Content you submit. The article URLs you submit, PDFs you upload,
text you paste, and audio files you upload. The text or document content of a
submission is kept only while the episode is being generated and is deleted from our
database as soon as the job completes or fails. The submitted URL, the generated
audio, and episode metadata (title, duration, the voice used) are kept so your feed
keeps working.
- Usage and cost figures. Per-episode and cumulative processing costs
(text-to-speech and text-cleanup spend), used to manage the shared service budget.
- Devices (apps). If you sign in from the iOS or Android app, we store a
per-device access token (only as a SHA-256 hash), the platform, an optional device
label, and when it was last used. You can see and revoke each device in Settings.
- Sharing. If you share an episode with another EarMark user, we record
which episode was shared, by whom, and to whom, plus your list of trusted senders.
- Feedback. The text of any bug report, feature request, or comment you
send through the app.
- Purchases (apps). If you buy credits or a subscription in the iOS or
Android app, the purchase is processed by Apple or Google — we never receive your
payment-card details. We keep a record of the purchase (a store transaction reference,
the product, and the amount) and the credits it granted, tied to your account.
- Technical data. When you request an email verification or password
reset link we record the requesting IP address and browser user-agent alongside the
short-lived token, as an abuse-prevention audit trail. The no-account sample on our
landing page records a coarse network identifier for 24 hours to enforce its daily
limit. Our servers also produce standard, short-lived operational logs.
3. How we use your information
We use this data to run EarMark for you: to generate your audio and deliver your personal
feed, to keep you signed in, to send transactional email (email verification, password
resets, password-change notices), to meter and bill text-to-speech usage (credits), to
prevent abuse of the service, and to debug problems and keep the service running.
We do not sell your data, we do not show advertising, we do not profile you, and we use no
analytics or tracking services. The only emails we send are the transactional ones listed
above.
4. Legal bases for processing
Where UK or EU data-protection law applies, we rely on the following lawful bases:
- Performance of a contract (Art 6(1)(b)) — for everything needed
to provide the service you signed up for: your account data, the content you submit,
the audio we generate, your devices, and episode sharing.
- Legitimate interests (Art 6(1)(f)) — for keeping the service
secure and operational and preventing abuse: the IP / user-agent audit trail on
verification and reset requests, rate limiting, the landing-page sample limiter, and
our short-lived server logs. We also rely on legitimate interests to stop repeated
claims of the one-time free credit (we keep a one-way hash of your email so the same
person can't claim it more than once). We've weighed these interests against your
rights and consider them proportionate, and you can object at any time (see
section 9).
- Legal obligation (Art 6(1)(c)) — for the records of purchases
we're required to keep under UK company and tax law.
We don't process your data for marketing, and we don't rely on consent for any current
processing. If that ever changes, we'll ask for your consent first.
5. Cookies and local storage
EarMark uses a single essential cookie: the session cookie that keeps you
signed in on the web. It is HTTP-only (inaccessible to scripts), marked Secure, restricted
to same-site requests, and expires after 30 days. There are no advertising, analytics, or
third-party tracking cookies.
Your browser's local storage holds a few interface preferences (for example, whether
you've dismissed the welcome screen and your autoplay setting). These never leave your
device. The iOS/Android apps store your device access token in the app's private
preferences, and episodes you download for offline listening are stored in the app's
private storage on your device — deleting a download, or the app, removes them.
6. Service providers and sub-processors
EarMark runs on a small set of service providers, each of which receives only what its job
requires:
- OpenAI —
receives the extracted text of your submissions to clean it up for narration.
- Inworld — the primary
text-to-speech provider; receives the cleaned text to synthesise into audio.
- Microsoft
— provides the free fallback voice; receives the cleaned text when that voice is
used.
- Postmark — sends our
transactional email; receives your email address and the message content.
- Apple and
Google — process
in-app purchases of credits and subscriptions on iOS and Android. Payment happens
entirely on the platform; we never see your payment details, only the purchase record
described in section 2.
- Hetzner —
hosts our servers and storage; all data described in this policy lives on Hetzner
infrastructure.
- Cloudflare —
sits in front of our servers for security and performance, and therefore processes
your traffic (including your IP address) in transit.
- Google Fonts — our
web pages load fonts from Google's servers, which means your browser sends Google a
standard font request (including your IP address). No other data is shared with
Google.
7. Where your data is processed
Our servers and storage are in Germany (Hetzner, Nuremberg), inside the UK/EU-adequate
area, so hosting itself involves no restricted transfer. Some of our other providers
process data in the United States or globally — currently OpenAI, Inworld, Microsoft,
Postmark, Cloudflare, and Google (web fonts). Where your data is transferred outside the
UK, we rely, for each provider, on one of these safeguards:
- the UK extension to the EU–US Data Privacy Framework (the "UK–US
data bridge"), where the provider is certified under it; or
- the UK International Data Transfer Agreement, or the EU
Standard Contractual Clauses with the UK Addendum, where it isn't.
In each case we've satisfied ourselves — through a transfer risk assessment — that your
data will get a level of protection broadly equivalent to that in the UK. You can ask us
which mechanism applies to a particular provider using the contact details in
section 13.
8. How long we keep your data
- Submitted text and documents: deleted from our database the moment an
episode finishes generating (or fails).
- Generated audio: kept while storage allows. When storage fills, the
oldest audio files are removed first; your episode history (titles, dates) remains in
your feed view.
- Sessions: expire after 30 days; expired sessions are purged hourly.
- Email verification and password reset tokens (with their IP /
user-agent records): valid for 48 hours and 30 minutes respectively, single-use, and
purged hourly once expired.
- Device tokens: kept until you revoke the device, reset your password,
or delete your account.
- Landing-page sample identifiers: deleted after 24 hours.
- Purchase and financial records: kept for six years from the end of the
financial year they relate to, as required by UK company accounting and tax rules.
- Free-grant email hashes: a one-way hash of your normalised email,
kept indefinitely as a fraud-prevention measure so the one-time free credit can't be
claimed repeatedly. It cannot be reversed to your email and, by design, survives
account deletion.
- Everything tied to your account is deleted when you delete the
account (see section 9).
9. Your rights and choices
You can view and change your account details, voice, and devices in Settings. You can
delete your account and all associated data yourself, at any time, from
Settings → Account → Delete account (in the apps and on the web). Deletion is
immediate and removes your account, sessions, devices, episodes, shares, feedback, and
tokens; generated audio files are removed from storage.
Where UK/EU law applies you also have the rights of access, rectification, erasure,
restriction, portability, and objection, and the right to complain to your supervisory
authority. You can also complain to us directly about how we handle your data, using the
contacts in section 13 — we'll acknowledge your complaint within 30 days — before or
instead of going to the ICO (ico.org.uk) or your local
supervisory authority. For anything you can't do in Settings — including an export of
your data — contact us (section 13) and we'll handle it directly.
10. Security
Passwords are stored only as bcrypt hashes. All traffic is encrypted in transit (TLS), and
our origin servers accept traffic only via Cloudflare. Access tokens — device tokens,
password-reset and email-verification tokens — are stored only as SHA-256 hashes, so a
copy of our database does not contain usable credentials. Your podcast feed and audio
are protected by per-user tokens, and each app device has its own revocable token. No
system is perfectly secure, but EarMark is built to hold as little as possible and to
protect what it holds.
11. Children's privacy
EarMark is not directed at children. You must be at least 16 years old to create an
account, and we do not knowingly collect data from anyone younger. If you believe a child
has created an account, contact us and we will delete it.
12. Changes to this policy
If we change this policy, we'll update the date at the top. For material changes we'll
also tell you in the app or by email before the change takes effect. The current version
always lives at earmark-app.com/privacy.
13. Contact us
For privacy questions or data requests, email
[email protected], or write to Earmark Ltd at the registered
office address in section 1.