Privacy Policy
Last updated: 2026-07-21
1. Introduction
Narrate(“we”, “us”, or “our”) operates the platform at narrate.audio (the “Platform”). This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data.
By using the Platform you agree to the practices described here. If you do not agree, please stop using the Platform.
2. Data We Collect
2.1 Account data (creators only)
The Platform is invite-only for creators. When you sign in via Google OAuth we receive your name, email address, and profile picture from the identity provider. We store only what is necessary to operate your account.
2.2 Session cookies
We use Auth.js to manage authentication. The following cookies are set after a successful sign-in. Auth.js may also set short-lived transient cookies (state, PKCE) during the OAuth flow; these are discarded once sign-in completes.
- authjs.session-token — a signed, HTTP-only session token. Expires when you sign out or after 30 days of inactivity.
- authjs.csrf-token — a CSRF protection token. Session-scoped.
These cookies are essential for the Platform to function and do not require consent; no advertising, tracking, or analytics cookies are set at this time.
2.3 Usage data (listeners)
Listeners can access published episodes without an account. Beyond what your browser sends in standard HTTP requests (IP address, User-Agent), we collect privacy-friendly, aggregate usage statistics through Vercel Web Analytics and Vercel Speed Insights (see Section 4.9), together with anonymous page-performance timings, such as how quickly pages load; at this time they are cookieless and fingerprint-free — we do not use them to build an individual profile of you or to track you across other websites.
3. How We Use Your Data
- Authentication: your name and email are used to identify your creator account and display your profile inside the dashboard.
- Episode generation: the guiding question and topic keywords you provide are sent to third-party AI services (described below) to research and script your episode. We do not sell or share this content with other users.
- Published episodes: episode titles, transcripts, and audio are made publicly accessible. Do not include personal data in episode content that you do not wish to be public.
4. Third-Party Services
To deliver the Platform’s features we send data to the following third-party processors. Each processor’s privacy policy governs their use of your data.
4.1 Anthropic (script generation)
Episode scripts are generated by Anthropic’s Claude models. Your guiding question and keywords are sent to the Anthropic API. Anthropic’s Privacy Policy applies.
4.2 Tavily (research)
To research episode topics we send queries to the Tavily search API. These queries are derived from the guiding question you enter. Tavily’s Privacy Policy applies.
4.3 Exa (research, optional)
When Exa is configured as the active research provider, search queries derived from the guiding question you enter are sent to the Exa API. Exa’s Privacy Policy applies.
4.4 ElevenLabs (text-to-speech)
The episode script is sent to ElevenLabs to synthesise audio. ElevenLabs’ Privacy Policy applies.
4.5 OpenAI (text-to-speech, optional)
When OpenAI is configured as the active TTS provider, episode scripts are sent to OpenAI for audio synthesis. OpenAI’s Privacy Policy applies.
4.6 Deepgram (text-to-speech, optional)
When Deepgram is configured as the active TTS provider, episode scripts are sent to Deepgram for audio synthesis. Deepgram’s Privacy Policy applies.
4.7 Cloudflare R2 (audio storage)
Generated audio files are stored in Cloudflare R2 object storage. Audio for published episodes is publicly accessible via signed URLs. Cloudflare’s Privacy Policy applies.
4.8 Vercel (hosting)
The Platform is hosted on Vercel. Vercel’s infrastructure processes all incoming HTTP requests. Vercel’s Privacy Policy applies.
4.9 Vercel Web Analytics and Vercel Speed Insights (analytics)
We use Vercel Web Analytics and Vercel Speed Insights to understand aggregate traffic to the Platform — for example page views, referrers, and approximate country — together with anonymous page-performance timings, such as how quickly pages load. The measurement scripts load from our own domain rather than a third-party one, and at this time they are cookieless and fingerprint-free: they do not identify you individually, build a profile of you, or track you across other websites. The resulting aggregate measurements are processed by Vercel as our processor, so Vercel’s Privacy Policy applies.
Overseas disclosure (APP 8). Most of the processors listed above are located outside Australia, primarily in the United States. By using the Platform you acknowledge that personal data — such as the guiding questions you provide and the IP address and User-Agent your browser sends — may be disclosed to, and stored or processed by, these recipients overseas. We take reasonable steps to engage reputable processors, but overseas recipients may be subject to laws different from those in Australia.
5. Data Retention
Creator account data is retained for as long as your account exists. Episode data (scripts, audio, metadata) is retained until you delete the episode or your account is removed. Session cookies expire as described in Section 2.2.
6. Your Rights
Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), to the extent they apply to us — and, where applicable, other privacy laws such as the GDPR or CCPA — you may have the right to access, correct, or erase your personal data, and to object to or restrict certain processing. To exercise any of these rights, please contact us at notices@narrate.audio. We will respond within a reasonable time and in any case as required by applicable law.
7. Children
The Platform is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us at notices@narrate.audio and we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Platform after an update constitutes acceptance of the new policy.
9. Contact
Questions or concerns about this Privacy Policy should be directed to notices@narrate.audio.