What CatchUpCast and CatchUpGist do with your email, and where it goes.
This policy covers both products. They are made by the same company and handle your mail the same way; where they differ, it is called out. CatchUpCast turns many newsletters into one spoken briefing. CatchUpGist summarizes each message on its own and emails the summaries back to you.
If you use your own API keys, your email never reaches us. Both products run on your own computer. They read your mail, summarize it, and produce the result without any of it passing through a server we operate.
If you subscribe to the hosted tier, the text of the emails being summarized is sent to our service so it can be summarized — and, for a CatchUpCast podcast, turned into audio. That text is processed and not stored. The details are below.
Almost every question about privacy here depends on which one you are running, so they are described separately.
We receive nothing. There is no account, no sign-up, and no server of ours involved in the work.
The only thing that can reach us on this tier is something you explicitly send: the feedback form, or the optional portable feed URL described below.
The app still runs on your computer and still reads your mail directly from Google. What changes is that the summarizing happens on our service instead of with your own keys — and, for CatchUpCast, so do the audio and the episode hosting.
| What we receive | What happens to it |
|---|---|
| The text of the emails being summarized, with formatting and markup stripped — a batch at a time for CatchUpCast, one message at a time for CatchUpGist | Sent to an AI provider to produce the digest — Google's Gemini, or a backup provider if Google's is unavailable (see below) — then discarded. We do not store it. While emails wait their turn to be summarized they sit in a queue, encrypted with a key only our service holds, for at most two hours. The AI provider's infrastructure may also hold it briefly in a cache; see below. |
| The digest text that gets produced (CatchUpCast only) | Held, encrypted, until your app collects it (usually seconds, and never more than six hours), then converted to audio and discarded. The audio is kept (below). |
| The summaries that get produced (CatchUpGist only) | Held, encrypted, until your app collects them (usually seconds, and never more than six hours), then deleted here. Your app emails them to you. |
| The previous episode's text, if you turn on continuity (CatchUpCast only) | Sent with the request so the new episode does not repeat it, then discarded. We do not store it. |
| The audio episode (CatchUpCast only) | Stored in our Cloudflare R2 bucket so your podcast app can download it, and deleted after your retention window (14 days by default). |
| Your email address, a hashed subscription token, and usage totals | Kept for as long as the subscription exists, to run the account and enforce the fair-use allowance. Your email address is stored encrypted, so it cannot be read from our database on its own. |
| Any prompt customization you write | Instructions you add, or a prompt you write to replace ours, stay on your computer and are sent with each run, the same way the email text is — we do not store them. |
| How often your prompt changes | We keep a fingerprint of your current prompt — a one-way code, not the words — and a count of how many times it changed today, so we can spot a subscription being used to attack the service. The fingerprint cannot be turned back into what you wrote, and it is not used for anything else. |
| Status check-ins from your machine: timestamps, your schedule and timezone, how many emails a run handled, and any error message the app produced | Kept so we can tell you if your summaries stop arriving. No email content is included. |
What we never receive, on any tier: your Gmail password or App Password, your Google account credentials, the contents of your mailbox beyond the specific messages you labelled for summarizing, or anything from emails you did not label.
On the hosted tier, these companies process data on our behalf, and their own privacy terms apply to what they handle:
When you subscribe, we store a Stripe customer reference (an identifier, not a card), what you pay per month, and when your billing period starts and ends. We keep a running total of what serving you has cost us during the current period — tokens summarized, characters of audio produced, bytes stored. That total is how the fair-use allowance described in the terms is calculated, and you can see it on your account page at any time.
You subscribe, and check on your subscription, by signing in with Google. From that sign-in we keep Google's identifier for your account (a number, not your password) and your email address, encrypted, so the app can show you which account you are signed in as. A sign-in lasts 30 days on a device before it asks again, or until you sign out, which deletes it straight away. “Sign out everywhere” deletes the sign-ins on all your devices at once.
When you press Subscribe, we store a random reference linked to that account, and send only the reference to Stripe. It comes back when your payment completes, and that is how the subscription is attached to you without us sending Stripe anything about your Google account. After 24 hours the reference no longer attaches anything.
None of that includes the content of your email. It is counted, not kept.
We do not sell your data, and we do not share it with anyone for advertising. There is no analytics or tracking on this website — no Google Analytics, no pixels, no third-party scripts.
Four things here store anything at all:
Podcast apps generally cannot log in, so a private feed is protected by an unguessable address rather than a password. Anyone you give that URL to can listen to your episodes. It is not published or indexed, but treat it like a password: if you share it, you have shared your digests. You can rotate it at any time from your own dashboard, which immediately invalidates the old one.
| Item | Default |
|---|---|
| Audio episodes | 14 days, then deleted |
| Digest text on your own machine | 30 days |
| Processed emails, moved to a "done" label in your Gmail | 10 days, then Gmail deletes them |
| Email text sent to the hosted service | Not stored at all |
| Subscriber record and status check-ins | Life of the subscription. After it ends, kept so you can subscribe again with nothing to set up, until you ask us to delete it (reply to any of our emails) |
| Security records of rejected requests (see below) | 30 days |
Security records. When the hosted service turns away a request in a way that can indicate misuse — a subscription token that matches nothing, a forged payment notification, a wrong internal password — we record what kind of event it was, when, and a scrambled form of the network address it came from. The scrambling is one-way: it lets us tell that forty attempts came from the same place without keeping the address itself. We never record what you were sending, and ordinary use — including a subscription that has simply lapsed — is not recorded at all.
The first three are settings you control, and you can shorten or lengthen them from your own dashboard.
CatchUpCast is not directed at children under 13 and we do not knowingly collect their information.
Questions, or a deletion request: use the feedback form and include a reply address.
If this policy changes in a way that affects what we collect or how it is used, the date below changes and the change will be described here rather than made quietly.
Last updated: 6 October 2026.
© 2026 P3 Digital Services LLC