Privacy Policy
Effective: July 26, 2026 (v1.4) *(v1.3 effective July 23, 2026; v1.2 effective July 17, 2026; v1.1 effective July 5, 2026; v1.0 effective June 6, 2026. v1.4 is a factual clarification only: it extends the existing anti-abuse description to cover a limit on how many new accounts may begin generating from one network in a day, and an optional bot-verification check (Cloudflare Turnstile, an already-listed provider) on a new account's first generation. Both keep the same minimization — salted, one-way hashes; no raw addresses stored — and change no rights, obligations, or providers. v1.3 added the description of the IP-based fair-use and anti-abuse limits the Service enforces. v1.2 corrected the description of how text-to-speech synthesis runs — on Google Cloud's Vertex AI, which was already a listed provider.)*
This policy describes how D3SMC LLC, a Texas limited liability company doing business as Demades ("we," "us"), collects and uses information when you use the Demades website and app (the "Service"). We are the data controller for this information.
1. What we collect
- Account and identity. When you sign in, your identity provider (e.g., Google or Apple) supplies your email address, name, and profile picture. If you sign in with a phone number, we collect that number and verify it with a one-time code. Access to private collections is controlled by per-collection email allowlists.
- Guest sessions. Browsing without an account may create a device-scoped guest session identified by a random identifier; signing in links that activity to your account.
- Cookies. A session cookie (`nv_session`) keeps you signed in — it is strictly necessary and not used for advertising. Usage-analytics collection is governed by the consent control in Settings.
- Abuse prevention. To enforce fair-use and anti-abuse limits (for example, caps on how many episodes may be generated from one network in a day), we process your IP address at request time. Our rate-limit records store only a salted, one-way hash of the IP — the raw address is not written to those ledgers. (The free clip tool applies the same practice — see §5a.) The same limits also bound how many newly created accounts may begin generating from one network in a day; that record likewise stores only a salted, one-way hash of the IP and of the account identifier. On a new account's first generation we may additionally run a bot-verification check (Cloudflare Turnstile, see §3), which shares your IP address and a challenge token with Cloudflare for that check only; we do not store the result.
- Usage metrics. With your consent, we collect product usage events (pages viewed, plays, feature use) to improve the Service. You can withdraw consent at any time in Settings.
- Billing. Payments are processed by Stripe. We receive transaction metadata (amounts, last4, status) and maintain a credit ledger; we never see or store your full card number.
- Content you provide. Topics, sources, prompts, and the episodes generated from them; chats, comments, and ratings you post (including conversations with our AI assistants and support).
- Notifications. Your notification preferences and, on our native apps with your operating-system-level permission, a push token used to deliver notifications you've asked for.
- Creator profile. If you opt in as a creator, your public handle, public creator name, and published catalog are visible to anyone.
2. How we use it
To operate and improve the Service: authentication and access control, generating and delivering episodes, billing and fraud/chargeback handling, support, and (with consent) product analytics. We do not sell your personal information, and we do not use it for third-party advertising. Episodes and shows you publish publicly (with your public creator name) are visible to anyone and may be syndicated to third-party podcast platforms via RSS feeds. To avoid generating the same episode twice, we may compare the topic you submit against your own recent topics and against topics of episodes that are already published publicly, and open an existing episode instead of generating a duplicate; this comparison happens on our own systems, and it never surfaces anyone's private episode.
3. Service providers (sub-processors)
We share data with the providers below only as needed to run the Service:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing, fraud and dispute handling |
| Anthropic | AI research and script generation |
| Google Cloud Platform | Hosting, storage, infrastructure, and AI text-to-speech (voice), image, and embedding generation (Vertex AI) |
| Cloudflare | DNS, networking, content delivery, bot verification (Turnstile) |
| Resend | Transactional email |
| Expo (Expo Application Services) | Native push-notification delivery (relays to Apple and Google push services) |
| Twilio | SMS delivery of phone sign-in codes (when phone login is enabled) |
4. Retention
Account data is kept while your account is active. Generated episodes and audio are kept while published or until you delete them. Usage metrics are retained for up to 13 months. Billing and ledger records are retained as required for tax, accounting, and dispute-handling purposes. When you delete your account, associated personal data is deleted or de-identified within 90 days, except records we must keep by law.
5. Your rights
- Export: download your data anytime from Settings (Export).
- Delete: delete your account from Settings, or email us.
- Access / correction / consent withdrawal: email [email protected].
We honor applicable rights under the GDPR, CCPA/CPRA, and similar laws, and we do not discriminate against you for exercising them. California residents: we do not "sell" or "share" personal information as defined by the CCPA.
5a. Free clip tool (no sign-in)
> *Applies to the public, no-sign-in clip generator — see > Free Clip Tool Terms.*
The free clip tool lets anyone generate a short AI clip from a topic without an account or sign-in. Because there is no account, the data this flow processes is different from the rest of the Service:
- What we collect on the clip tool. The topic text you submit; your IP address and a session cookie, used only to rate-limit abuse and control cost; and anonymous, bounded usage events (e.g. a topic was submitted, a clip was generated, played, or shared) on the same consent-based, opt-out basis as elsewhere in this policy. We do not ask for your name, email, or any other identifier to use the clip tool, and we do not collect any personal identifier beyond your IP address in this flow.
- Why (legal basis). We process the IP address and session cookie for our legitimate interest in preventing abuse and runaway cost on a free, no-sign-in tool (and, where applicable, as strictly necessary to provide a service you requested). The session cookie is strictly necessary and is not used for advertising.
- IP minimization. We do not store your raw IP address for the clip tool's rate limiting — the rate-limit key is a salted, one-way hash of the IP and session, so the original address is not written to disk.
- Submitted topics. A topic and the clip generated from it may be retained to operate the tool, including caching popular topics so repeated requests are served instantly, and to improve the Service. Do not submit personal or confidential information in a topic — clips and their share pages are public.
- Retention. Clip-tool abuse-prevention data (hashed rate-limit keys, the spend ledger) is retained only as long as needed for that purpose and then deleted or rotated; anonymous usage events follow the up-to-13-month retention above; generated clips are kept while their public share page is available or until removed.
- Sub-processors. The clip tool uses Anthropic (script generation), Google Cloud Platform (AI text-to-speech synthesis via Vertex AI, plus hosting and storage), and Cloudflare (delivery) — all listed in §3. It does not involve Stripe (the tool is free) or account sign-in.
6. Security
Data is encrypted in transit; access to production systems is restricted. No system is perfectly secure — report concerns to [email protected].
7. Children
The Service is not directed to children under 13, and we do not knowingly collect their data.
8. Changes
Material changes will be posted here with a new effective date. The current version always lives at `/privacy`.
9. Contact
D3SMC LLC (d/b/a Demades) · Austin, Texas · [email protected]