Back to Earmail

Security & Privacy

Last updated: July 24, 2026

Forwarding a newsletter to Earmail means trusting us with the content of that email. Here's exactly what that trust covers.

How we protect your account

  • No reusable password. Earmail uses magic-link login only, so there is no reusable Earmail password to steal, guess, or reuse. A magic link is still a sign-in credential: your account security is bounded by your email security.
  • Revocable sessions. Logins are recorded as database sessions, not signed tokens. We can invalidate any session immediately if you ask us to.
  • HTTPS everywhere. All connections to and from Earmail use TLS.
  • Encrypted at rest. Our database, audio storage, and backups live on encrypted volumes.
  • Stripe handles payment. We never see card numbers, CVVs, or full bank details.
  • Private feeds. Your podcast feed URL contains a long random token. Only you have it; no public listing exists.

What we hold

  • Your email address (and optional display name).
  • The body of every newsletter you forward, while it's in your library.
  • The audio file generated for each episode.
  • Any follow-up questions you ask about an episode, and the answers we generate for them.
  • Anonymized usage counts (episodes generated, days active).

What we don't hold

  • A password. There isn't one to leak.
  • The contents of your inbox. We only see what you forward.
  • Your card details. Those live with Stripe.
  • Listening data from your podcast app. We can see that an episode was delivered (download events, with hashed IP addresses) — but not whether, or how much of it, you actually listened to. Playback in your podcast app never reports back to us. The one exception is when an episode is played in the browser rather than a podcast app: there we log anonymous playback events (play, pause, how far through) with the same pseudonymized IPs — never tied to an account, and never enough to identify a listener.

What you control

  • Delete an episode. Its audio and transcript (the original and cleaned text) are erased immediately; the remaining record is fully removed within 31 days.
  • Cancel a paid plan. You keep access through the end of the billing period. Your episodes and settings then remain available for a 30-day recovery window before deletion, in case you resubscribe.
  • Delete your account. Your personal information, content, transcripts, and audio are gone within 30 days of your deletion request. We give you that window in case the deletion was a mistake.
  • Opt out of translation. Settings → Episode extras. By default, non-English newsletters are auto-translated to English.

Admin access

For support, debugging, and quality control, Earmail can access the content of your episodes. That access is limited and logged internally; we don't read your content as a matter of routine, and we never use it to train AI models.

Where your content goes for processing

To turn a newsletter into a podcast episode, Anthropic first adapts the written content for listening; OpenAI then narrates the resulting text. The two third-party APIs are:

  • Anthropic (Claude) adapts written content for listening through cleanup, structure detection, translation, and the optional extras (weekly digests, reflection prompts, answers to follow-up questions). Anthropic does not train on data sent through their API.
  • OpenAI narrates the resulting text through its text-to-speech API. OpenAI does not train on data sent through their API.

Both relationships are governed by their no-training-on-data terms. Full third-party list is in our privacy policy. For what the AI does — and doesn't do — with the writing itself, see How Earmail uses AI.

Reporting a security concern

Found a bug or anything else that worries you? Email hello@earmail.app with the details and we'll get back to you fast.

Questions about anything on this page? Reply to any Earmail email or write to hello@earmail.app.