Privacy Policy
Effective August 14, 2026
The Daily FM ("we") operates thedaily.fm and the Page to Pod with The Daily FM browser extension. This policy covers both.
What we collect
- Account information: your email address and a hashed password (or your identity from the sign-in provider you choose). Payment status for paid plans is handled by our payment processor; we never see or store card numbers.
- Content you submit: the sources you configure for your pods, and, when you use the browser extension, the page you choose to send (its URL, title, and article text).
- Usage data: privacy-friendly, aggregate site analytics and standard server logs (IP address, browser type) kept for security and debugging.
- Connected calendars: if you add a calendar briefing, we access your Google Calendar as described in "Google Calendar data" below.
The browser extension, specifically
- It reads a page only when you click "Send as episode." It does not run in the background, track your browsing, or read any page you don't explicitly send.
- What it sends to our servers is the page's URL, title, and text, which we use to generate your podcast episode.
- It authenticates with your existing thedaily.fm sign-in session and stores only your last-used pod and summary length, locally in your browser.
How we use it
To provide the service: generating your episodes (submitted content is processed by the AI text and speech providers that produce the audio), operating your account, billing, and support. We do not sell your data, share it for advertising, or use it to train models.
Google Calendar data
The calendar-briefing feature uses read-only access to Google Calendar. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- What we access: your Google account email, your list of calendars, and — for the calendars you select — each day's event details (title, time, location). Access is read-only; we never modify your calendar.
- How we use it: solely to generate the daily briefing episodes you set up. We do not use Google user data for advertising, do not sell it, and do not use it to train AI models.
- Sharing and disclosure: we do not share, transfer, or disclose Google user data to third parties, with two narrow exceptions needed to provide the service: the day's events are processed by the AI text and speech providers that write and voice your episode (as with every pod source, solely to produce your audio), and the service runs on our hosting provider's (Cloudflare's) infrastructure. Beyond that, we disclose data only if required by law.
- How we protect it: calendar data moves only over encrypted (TLS) connections. The OAuth refresh token that grants calendar access is encrypted at rest with AES-256-GCM before it is stored; the short-lived access tokens used to read events are held in memory only while an episode generates and are never stored.
- Deleting it: a briefing episode's script and audio contain the events it read out — delete the episode, its pod, or your account to remove them. Deleting your account also deletes the stored calendar connection, including the encrypted token. You can revoke our access at any time from your Google account permissions; revocation cuts off our access immediately.
How we protect data
All traffic to thedaily.fm is encrypted in transit (HTTPS/TLS). Passwords are stored only as bcrypt hashes and API tokens only as hashes; OAuth tokens are encrypted at rest as described above. Production data lives on Cloudflare's infrastructure, and access to it is restricted to the operator of the service.
Retention and deletion
You can delete episodes and pods at any time from the site. Deleting your account from the account page removes your data. Server logs and backups age out on a rolling basis.
Contact
Questions or requests: hello@thedaily.fm.