1. Who We Are
Magnolia Apps
Email: [email protected]
2. Data We Collect
Account and app data
- Email address and display profile details, if provided.
- Account user ID used for sign-in, synchronization, and permitted product measurement.
- Podcast subscriptions, listening history, playback positions, queue, and favorites.
- Premium status and subscription state.
- Diagnostic information used to identify and fix software defects.
Device and security data
- Device tokens for delivering push notifications.
- App installation and non-advertising device identifiers used for app functionality, security, and permitted product measurement.
- Firebase App Check attestations and anti-abuse signals.
- Device model, operating-system version, app version, locale, and other diagnostic context.
Purchase data
- Store transaction receipts, product IDs, timestamps, and expiration state.
- Verification metadata produced by our backend validation workflow.
AI feature data
- Episode metadata including title, description, podcast name, chapters, and duration.
- Transcript text available from feeds or generated in app workflows.
- Your AI chat prompts and AI responses.
- Audio URL references for AI transcription generation.
Shared transcript cache note
When a transcript is generated with our primary Gemini 3 Flash transcription path, it may be stored in a shared cache keyed to episode or audio identity, not your account identity, so other users can reuse it and reduce duplicate processing.
Product measurement and diagnostics
First-party product measurement is default-disabled. At session start, our server returns only allowed, gated, or unknown after a transient network-region check; it does not return or persist a country. Collection is enabled only for allowed. Offline, unknown, malformed, or service-failure results leave collection disabled.
- When allowed, user ID, app/device ID, purchase history, product interactions, and other diagnostic data are linked to the account or app installation for app functionality and product analysis.
- Product events may include categorical feature or error codes, screen or action names, counts, durations, and length metrics. They do not include raw search queries, prompts, text, email addresses, error messages, exceptions, stacks, tokens, URLs, or request/response bodies.
- Crash reports are used only to diagnose app failures. They are not linked to the account and may contain technical crash details such as a stack trace and device/app context. The Crashlytics SDK's automatic collection is disabled. The app retains reports locally at first, keeps them across sessions whose region is not yet resolved, sends eligible queued reports only after a later allowed session, and deletes them when a session resolves to a consent-required region.
We do not use this information for advertising, ad measurement, data brokerage, or tracking across other companies' apps or websites.
3. How We Use Data
- Provide core playback, synchronization, account, and subscription functionality.
- Deliver AI summaries, key moments, transcript generation, and episode chat.
- Improve recommendation quality and product reliability.
- Detect abuse and unauthorized use.
- Comply with legal obligations and enforce our Terms.
4. Service Providers
- Google Firebase for authentication, Firestore, Cloud Functions, push delivery, first-party product measurement, crash reporting, and backend infrastructure.
- Google AI (Gemini API) for summaries, transcript generation, and chat responses.
- Apple App Store / StoreKit and Google Play Billing for subscriptions and receipt validation.
- Google Sign-In and Sign in with Apple for optional account sign-in.
- Podcast discovery providers such as Podcast Index and Apple Podcasts fallback APIs.
Processor privacy links: Firebase, Google, Apple, Podcast Index.
5. Recommendations
Recommendation features use your in-app activity (the podcasts you subscribe to and the episodes you play) to surface relevant content inside the app. You can adjust recommendation behavior in app settings.
6. Data Retention
- Account and sync data: retained until account deletion.
- Recommendation data: up to 90 days unless a shorter operational window applies.
- AI transcript, summary, and chat artifacts: generally up to 180 days.
- Shared transcript cache entries: generally up to 180 days.
- Purchase verification records: retained per store and compliance requirements, typically up to 1 year.
- Product measurement and diagnostic records: retained under our configured provider retention settings; unsent crash reports are retained across sessions whose region is not yet resolved and deleted when a session resolves to a consent-required region.
7. Data Storage and Transfers
- Local app data is stored on-device.
- Cloud data is stored in Firebase and Google Cloud infrastructure.
- Data may be processed outside your country, including outside the EU/EEA where permitted with appropriate safeguards.
8. Your Rights and Choices
- Access, correction, export, and deletion requests.
- Delete account in-app or via /delete-account.
- Manage notification preferences in app settings.
- Contact us at [email protected] for privacy requests.
9. Security
- Transport encryption using HTTPS/TLS.
- Authentication and access controls for cloud data.
- App integrity and anti-abuse safeguards.
- Reasonable administrative and technical protections.
No internet transmission or storage system is 100% secure.
10. Children
The app is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
11. Changes to this Policy
We may update this policy. Material updates will be reflected by a new last-updated date and may be announced in-app.
12. Contact
Questions or privacy requests: [email protected]