Privacy
We respect our users and their privacy.
This page explains how FeedCast handles information in the app and on feedcast.fm. Last updated September 11, 2026.
The FeedCast app
FeedCast Local works without an account. It stores your library, Up Next queue, playback progress, preferences, listening state, and recommendation signals on your device. Recommendations use your Subscribe and Follow choices, playback progress, and episode completion.
When a feature uses an external service, FeedCast sends the information needed to complete your request. Examples include searching Apple’s podcast directory, fetching feeds and artwork, streaming or downloading audio, and loading publisher-provided chapters or transcripts. Each service applies its own privacy policy.
On supported iPhones running iOS 26 or later, Transcript Beta can transcribe a downloaded episode you explicitly choose. The audio stays on device. A publisher-provided transcript remains the preferred source when available.
Optional accounts and Web Player Sync
The pre-release app offers an optional account. Auth0 handles sign-in, along with any identity provider you choose. Those providers process account and sign-in information under their own policies. FeedCast’s account service stores an account identifier, the sign-in provider’s account reference, registered-device identifiers and display names, your account region, and consent acknowledgments.
The current Google sign-in connection asks for basic and extended profile information. Auth0 stores and refreshes the attributes Google supplies, which may include your name, email and verification status, public-profile address, profile-picture address, country, language, and timezone. A profile-picture address is a link supplied by the sign-in provider; FeedCast does not request access to your iPhone’s photo library. The FeedCast listener service uses account identifiers rather than storing these name, email, or picture profile fields.
Signing in does not turn on Sync. When you choose Connect Web Player Sync, FeedCast stores your saved-show relationships, Up Next choices and order, playback progress and played state, portable playback preferences, selected discovery interests and feedback, and supported appearance settings on its servers so they can be used on your connected devices and the web player. Sync retains changes and operation receipts to reconcile updates and retries.
Hosted Sync is server-readable; it is not end-to-end encrypted. Downloads, raw listening events, local searches, transcript caches and timing adjustments, and the device’s derived recommendation profile remain local.
Disconnect Web Player Sync stops Sync on that device. Signing out removes its sign-in and offers a choice to keep or clear FeedCast Local. Neither action deletes the hosted account or the web player library. Complete account deletion is not yet available in the pre-release account flow. That remains a release requirement; contact [email protected] with questions about existing account data.
Private feeds
Private-feed URLs may contain credentials or access tokens, so FeedCast treats the complete URL as sensitive information. FeedCast keeps complete private-feed URLs and credentials out of sharing, logs, diagnostics, analytics, accessibility text, screenshots, and test data.
On iOS, the complete private-feed address and credentials are protected in Keychain. They are resolved for feed access, an explicitly authorized same-origin transcript request, or an OPML export you request. Private feeds are excluded from Web Player Sync by default.
If you separately choose Include Private Feeds, FeedCast uploads eligible complete feed addresses, including any embedded credentials, to an encrypted account vault. FeedCast’s server can decrypt them to fetch the feed, provide its catalog, and relay audio to your authenticated web player. This vault is not end-to-end encrypted. The browser receives opaque resource identifiers rather than the private feed address.
Remove Private Feeds from Web removes the account’s hosted private-feed access and media capabilities through the dedicated removal flow while keeping the private feeds and downloads on your iPhone. It is separate from deleting your account.
Service operation and feedback
FeedCast uses service providers, including Auth0, Cloudflare, and Railway, to authenticate accounts and deliver and protect its services. They may process request and security information such as IP addresses, request times, and browser or device information under their own policies. FeedCast retains operational logs such as request routes, status and failure categories, counts, platform, and request duration to protect and improve service reliability. Provider context and request correlation can associate this information with an account; it is not necessarily anonymous. FeedCast’s application logging excludes private-feed addresses, credentials, access tokens, and request bodies.
When you contact support, we receive the contact details and information you send. TestFlight also lets testers send feedback and diagnostic information through Apple. Please review attachments and avoid including private-feed addresses, credentials, or private listening details.
Hosted account data remains stored when you disconnect or sign out. This page does not promise an automatic account-erasure or backup-expiration period. Complete deletion, processor handling, and backup retention must be qualified and disclosed before an account-enabled public release.
This website
feedcast.fm uses no advertising trackers, analytics beacons, cookies, account forms, newsletter forms, third-party fonts, or embedded media. It collects no information through a form.
Hosting providers may process standard request information needed to secure and deliver the site, such as IP addresses, request times, requested pages, and browser information, under their own policies.
Questions
For privacy questions, email [email protected]. For product help, visit the Support page.
This page covers FeedCast and feedcast.fm. Podcast publishers and service providers apply their own privacy practices.