Skip to content

Privacy Policy reworked #139

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 81 additions & 33 deletions _i18n/en/general/privacy.md
Original file line number Diff line number Diff line change
@@ -1,57 +1,105 @@
AntennaPod is developed and maintained by individual volunteers and not represented by any legal entity. The community doesn't need your data, so the app and website are designed to be fully GDPR compliant. Read on to learn more.
AntennaPod is developed and maintained by individual volunteers and not represented by any legal entity.
The community has no interest in your data, and the app and website are fully EU-GDPR compliant for everyone.

## What data the AntennaPod app might collect, store and process
The app only records data strictly necessary for the app to function. This includes for example the list of podcasts you follow, the app settings, and authentication data provided for specific podcasts or services (such as synchronisation services). The app does not include any advertisement libraries or any 3rd party tracking (analytics) code, such as Google Analytics.
## App permissions
The app requests the following privacy-relevant Android permissions:

**All data provided and created when using the AntennaPod app is stored locally on your device. AntennaPod does not send or upload your data anywhere, except where strictly necessary for the functioning of the app.** Please see the second next section for the cases in which your data may be provided to third parties.
- Read from/write to Storage (Photos/Media/Files)
The storage permission is used and only requested when opening files not downloaded directly from within the app.
It can also be used to import app settings or OPML files.

The only case where your data from 3rd parties is handled, is when using a synchronisation service if enabled via the settings. In that case, the app may receive subscriptions and playback events provided by the service.
- Full network access, to download or stream content, or interface with services.
- Prevent the device from suspending
- View network connections.
- View Wi-Fi connections.
- Ryn at startyp
- Connect to Bluetooth devices.
- Control vibration.
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could link to the relevant code here.


## App permissions
The app requests the following privacy-relevant Android permissions:

- Read from/write to Storage (Photos/Media/Files): The storage permission is used to open files that are not downloaded directly from within the app. It can also be used to import app settings or OPML files. The permission is only requested if you perform an action that requires reading from storage.
## Data the AntennaPod app itself (not third-party services) collects, stores and processes locally
Other than third-parties, only data strictly necessary for the app to function is recorded, and only on the device.
This includes podcasts you follow, the app settings, and login data provided for specific podcasts or services (such as syncing services).
The app itself (not third-party services) does not insert advertisement libraries, or third-party tracking (analytics).

**Except for third-party services, all data provided and created when using the AntennaPod app is stored locally on your device.
This means your data is not sent or uploaded anywhere, except when the you search, or turn on third-party services in the app.**
When interfacing with third-party services, the app itself receives subscriptions and playback events provided by the respective services.

## What app data other parties might collect, store and process
## App data third-parties collect, store and process

- Podcast hosters: When provided in the podcast settings, a host will receive authentication data you provided. Any web servers that provide the podcast feeds might collect additional data, such as your IP address, access time and what is being accessed. This includes the episodes you are downloading or streaming. Please refer to their respective privacy policies for details. You can view the URL of a podcast by opening the podcast and pressing the info icon. AntennaPod does not allow remote servers to set cookies. The servers can detect the fact that you are using AntennaPod and which version of AntennaPod you are using (HTTP User-Agent). If multiple podcasts are hosted on the same server, the server can detect the list of podcasts that you subscribed to and that are hosted on that server. This might happen if publishers use feedburner, podtrac or similar services to distribute their feeds.
- Discovery and search services: When opening the Discover screen in the app, it sends a call to Apple to collect podcast suggestions. They may store the query, including country (which by default is the device's country). These suggestions can be disabled by choosing "off" in the region selector. When using the search feature in AntennaPod, the services PodcastIndex.org, iTunes, fyyd and gpodder.net may store your query, including the sear terms. Discovery and search queries also include IP address, time, and app name "AntennaPod". After subscribing, the feed is served from the podcast hoster, meaning the discovery/search service is no longer involved.
- Synchronisation services: When enabled via the settings, AntennaPod synchronises your data. This data may include login credentials, subscribed podcasts, listened episodes, play, pause & favorite actions with date & time stamps and IP address. For more information, see your provider's privacy policy (e.g. [gpodder.net's privacy policy](https://gpodder.net/privacy), or the one of your Nextcloud host).
- Google: If you have activated backup & reset in your phone settings (Settings → Backup & Reset → Back up my data), you should be aware that Android itself will periodically save a copy of your phone's data in Google's servers. This backup contains private information, including your WiFi passwords, messages and call history. It may also include data from AntennaPod and from other apps you use. The developers of AntennaPod do not have access to this data. For more information, see [Google's privacy policy](https://policies.google.com).
- Discovery and search services: When opening the Discover screen in the app, it sends a call to Apple to collect podcast suggestions.
They may store the query, including country (which by default is the device's country).
These suggestions can be disabled by choosing "Off" in the region selector.
Copy link
Author

@comradekingu comradekingu Feb 17, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can't find this in 2.4.2 from F-Droid, and I would advice making it a default "Off".

  • I found out how to turn off covers, but that is very nondescript, and the app doesn't open with the settings, but presents the search first (?)

When using the search feature in AntennaPod, the services PodcastIndex.org, iTunes, fyyd, gpodder.net, mzstatic.com, and podnews.net, and omnycontent.com
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
When using the search feature in AntennaPod, the services PodcastIndex.org, iTunes, fyyd, gpodder.net, mzstatic.com, and podnews.net, and omnycontent.com
When using the search feature in AntennaPod, the services PodcastIndex.org, iTunes, fyyd, and gpodder.net

Don't really know what the ones I added do, but they do (try to) connect when searching. I didn't try it on a clean install, so it might be from podcasts I added.

may store your query, including the search terms.
Discovery and search queries also include the IP address, time, and the app name "AntennaPod".
After subscribing, the feed is served from the podcast hoster, meaning the discovery/search service is no longer involved.
- Syncing services: When turned on via the settings, AntennaPod syncs your data.
This data may include login credentials, subscribed podcasts, listened episodes, play, paused and favorite actions with date- and timestamps and your IP address.
Consult your provider's privacy policy (e.g. [gpodder.net's privacy policy](https://gpodder.net/privacy), or the one of your Nextcloud host).
- Podcast hosters: When provided in the podcast settings, a host receives the authentication data you provided.
Servers providing the podcast feeds might collect data in so doing, like your IP address, access time and content you download or stream.
Please refer to their respective privacy policies for details.
You can view the URL of a podcast by opening the podcast and pressing the 'Info' icon.
AntennaPod does not allow any remote servers to set cookies.
The servers can detect the fact that you are using AntennaPod and which version of AntennaPod you are using (HTTP user-agent).
If multiple podcasts are hosted on the same server, the server can detect the list of podcasts hosted on that server you are subscribed to.
This might happen if publishers use FeedBurner, Podtrac or similar services to distribute their feeds.
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
This might happen if publishers use FeedBurner, Podtrac or similar services to distribute their feeds.
This happens if publishers use FeedBurner, Podtrac or similar services to distribute their feeds.

?

- Backups: (If turned on in "Settings → System → Advanced" in the device settings) Android saves copies of device data on the server of your chosen provider.
This will contain private info, including your Wi-Fi passwords, messages and call history.
It also includes data from AntennaPod and from other apps you use.
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could make a summary of what this includes for AntennaPod.

AntennaPod developers do not have access to this data.

## What data might be collected, stored and processed from AntennaPod online services
- The donation system: AntennaPod uses Open Collective, offered by Open Collective Inc (USA) & Open Collective Europe ASBL (Belgium). When you make a donation, these entities get access to certain data. For more information, see [Open Collective's privacy policy](https://opencollective.com/privacypolicy).
- The website: AntennaPod's website is hosted via GitHub Pages. [GitHub's privacy policy](https://docs.github.com/en/github/site-policy/github-privacy-statement#github-pages) notices that "GitHub may collect User Personal Information from visitors to your GitHub Pages website, including logs of visitor IP addresses, to comply with legal obligations, and to maintain the security and integrity of the Website and the Service." The website does not store any cookies on your machine, and no 3rd party tracking (analytics) or other services are used.
- The forum: AntennaPod's forum uses the Discourse software, hosted by the core team. Please see the [forum's privacy policy](https://forum.antennapod.org/privacy) for which data is concerned.
## Data collected, stored and processed by third-party services linked to in AntennaPod
- The donation system: AntennaPod uses Open Collective, offered by Open Collective Inc (USA) and Open Collective Europe ASBL (Belgium).
When you make a donation, these entities get access to certain data. There is more info in [Open Collective's privacy policy](https://opencollective.com/privacypolicy).
- The website: Since the AntennaPod website is hosted via GitHub Pages it is subject to [GitHub's privacy policy](https://docs.github.com/en/github/site-policy/github-privacy-statement#github-pages). "GitHub may collect User Personal Information from visitors to your GitHub Pages website, including logs of visitor IP addresses, to comply with legal obligations, and to maintain the security and integrity of the Website and the Service."
No cookies are stored on your machine, and no third-party tracking (analytics) or other services are used.
- The forum: AntennaPod's forum uses the Discourse software, hosted by the core team.
The [forum's privacy policy](https://forum.antennapod.org/privacy) details how data is treated there.

## What data the AntennaPod core team may have access to
The developers of AntennaPod do **not** have access to any of your information, except when you
## Data the AntennaPod core team has access to
The developers of AntennaPod do **not** have access to any of your info, except when you

- actively share debugging information (either via email using the 'Crash Report' function, or via the Android crash reporting functionality of Google):
- device type
- Actively share debugging info (either via e-mail using the 'Crash Report' function, or via the Android crash reporting functionality of Google):
- Device type
- Android version
- AntennaPod version
- actively share a review in the Google Play store:
- public profile information
- Actively share a review in the Google Play store:
- Public profile info
- AntennaPod version
- device type
- device language
- Device type
- Device language
- Android version
- visit or participate on our forum: as described in the [forum's privacy policy](https://forum.antennapod.org/privacy)
- actively make a financial contribution via Open Collective (unless you make an [incognito](https://docs.opencollective.com/help/financial-contributors/payments#profile) contribution):
- public profile information (name, company, description, image, Twitter, GitHub, website)
- email address

- Visit or participate on our forum: as described in the [forum's privacy policy](https://forum.antennapod.org/privacy)
- Actively make a financial contribution via Open Collective (unless you make it [incognito](https://docs.opencollective.com/help/financial-contributors/payments#profile)):
- Public profile info (name, company, description, image, microblog, VCS profile link, website)
- E-mail address
- Actively interface with the GitHub version-control system (where the source code is stored):
- Star any of the the repositories
- Fork any of the repositories
- Open an issue
- Submit a PR
- Leave comments
- Participate in discussions
- Contribute to [the translation on Hosted Weblate](https://hosted.weblate.org/projects/antennapod/), subject to https://hosted.weblate.org/legal/
- (No more than what is publicly accessible on the platform, except in a pre-formatted list)

## Updates of this Privacy Policy
The developers may update this policy in the future. It is advisable to check the policy periodically for any changes. Changes to this Privacy Policy are effective when they are made on this document.
The developers may update this policy in the future.
It is advisable to check the policy periodically for any changes.
Changes to this Privacy Policy are effective when they are made on this document.

This Privacy Policy was last updated on 2022-02-13.
This Privacy Policy was last updated on 2022-02-18.
* Reworked and clarified all sections, added more info.
If you have questions, open an issue on GitHub or our forum.

<!-- mdpo-disable-next-line -->
{% if site.lang != 'en' %}

This privacy policy is translated from English to help you understand how AntennaPod deals with the topic. In case of conflict between the the original and the translated version, the English one will prevail.
This privacy policy is translated from English to help you understand how AntennaPod deals with the topic.
The English version is authorative, meaning translated versions are only provided as a convenience.

<!-- mdpo-disable-next-line -->
{% endif %}