On Record

PRIVACY POLICY · UPDATED 22 SEPTEMBER 2026

Privacy Policy

Written to be read rather than to be survivable in court, on the reasoning that a document nobody understood is the one that fails in court.

This explains what On Record does with personal data.

Data about you, our customer

We hold:

  • Your name, email and sign-in identity.
  • What you tell the Service — interview answers, stories, your writing, your goals — and the voice profile built from it.
  • What you have published through us, and engagement on it.
  • Billing details, held by our payment provider rather than by us.
  • Ordinary technical logs: IP address, browser, timestamps.

We use it to run the Service for you, and for nothing else. We do not sell it. We do not use it to train general-purpose AI models.

Data about people who are not our customers

This is the part worth reading properly, because most tools like this one gloss it.

People we write to about their own posts. On Record contacts some people itself, about something they published on LinkedIn. We keep their name, headline, the post, what we wrote, and a work address only if it is published somewhere we can point to. A person approves every message before it goes; each carries a way to stop, and stopping is permanent. Our lawful basis is legitimate interests: one professional note, and at most one follow-up, about something they chose to publish. Ask and we delete what we hold about you.

People who engage with your posts. When you connect a platform, we read who reacted to and commented on your posts, and store a name, headline, company and a platform reference. This is so you can see who is paying attention. It is your audience, and it is deleted when you close your account. Disconnecting a platform stops us reading any more; what has already been collected stays until you close the account or ask us to remove it.

Somebody you invite into a recording room. A guest joins by link and needs no account. Their side is recorded on their own machine and uploaded to us, and the audio is transcribed by OpenAI, our transcription provider, so the episode notes can be written from what was said. It is stored against your voice, counts against your account, and is deleted when your account is — or when you remove the file, which you can do at any time. The live video between you passes directly between the two machines and is not recorded or stored by us. Tell them, before they press record: they are your guest, not our customer, and we have no other way to reach them.

Somebody you tag in a post. Naming a person means looking them up on your own connected LinkedIn account, which is the only way to produce a tag LinkedIn accepts. We keep what you typed, their name, their profile id, their headline and when we found them, so the next post does not have to look them up again and so two people with the same name can be told apart. Resolving a profile that way counts as a profile visit. We ask LinkedIn not to announce it, and cannot promise they do not — assume they may see that you looked at them.

Journalists, podcast hosts and news desks. We hold a name, outlet, beat and a published or role-based email address, plus where we got it and when. We hold these because you are pitching them.

People a customer talks about. An interview is somebody describing their working life, and other people are in it — a colleague, a client, a patient, a candidate. Where that happens we hold what they said: the transcript, the story we made of it, and the drafts written from it. Nothing identifying reaches a published post without the customer clearing it first, and where a story is held back we keep a list of the details that identify you so that they cannot appear anywhere by accident.

People a customer might want to write to. Where a customer turns on outbound sourcing, we hold the name, role, profile link and the text of a public post somebody wrote. No address is held for them, nothing is ever sent to them by us, and they are visible only to the one customer whose desk they landed on.

If you think you are in somebody’s post, write to legal@onrecord.tech. You do not need an account, and you do not need to know whose customer they are — the details in the post are enough for us to find it. Withholding your name from future posts is not the same as deleting what we hold, and you can ask for either or both.

Three things we deliberately do not do:

  • We license one database, and only for podcasts. No journalist database is licensed — Cision, Muck Rack and ProfNet are all refused. Rephonic is licensed, for finding shows and the booking contact they hold. A contact shared across customers may only be a role address (press@, tips@) or one the person published themselves; anything from a vendor, Rephonic included, belongs to the single customer who obtained it and is not visible to anybody else. This is enforced in the database, not by policy.
  • We do not scrape LinkedIn ourselves. Where a public profile or a public post is collected for research, it is collected by a third-party runner under their own terms and never by us. What we keep from it is a name, role, profile link and the text of a post its author published. The exception is when you tag somebody in a post: that lookup runs on your own connected LinkedIn account, because that is the only way to turn a name into the tag LinkedIn will accept. Resolving a profile that way counts as a profile visit, so the person you are tagging may see that you looked at them. We keep their name and profile id so we do not have to look them up again.
  • We do not guess addresses from name-and-domain patterns.

Our lawful basis for holding a journalist’s published professional contact details is legitimate interests — contacting somebody in their professional capacity about something in their stated beat. We record the source and date for every one.

If you have been contacted through this Service

You can tell us to stop and we will, permanently. Reply to the message and say so — “unsubscribe”, “remove me”, “stop contacting me” are all understood automatically — or write to legal@onrecord.tech.

Because that reading is automatic it can be wrong in the other direction too, and stop mail you wanted. Where a pattern rather than a person made the decision, the sender whose outreach produced your reply can reverse it, with a written reason recorded against their name, and twenty-four hours to correct a mis-click where a person made it. Beyond that the only lift we will ever make is to repair a stop recorded wrongly against a contact several customers share, and every lift is kept on the record with the name and reason behind it.

It applies across every customer of this Service, not just the one who wrote to you, and no customer can override it. We keep a one-way hash of your address so that we can honour it without keeping the address itself. A hash is still treated as personal data, and it is kept only for that.

Your rights, whoever you are

These apply to everybody named on this page — our customers, people who engaged with a post, journalists we wrote to, and anybody described in somebody else’s story. You do not need an account with us and you do not need to have heard from us.

You can ask for a copy of what we hold about you, ask us to correct or delete it, or object to us holding it at all. Write to legal@onrecord.tech and we will answer within 30 days.

Two honest notes about erasure. A post that has already been published to LinkedIn is on LinkedIn, and we cannot remove it from there — we can delete our copy and the material behind it, and the person who posted it is the one who can take it down. And some records of what happened, without the detail that identifies you, are kept because the law requires us to be able to show what we did.

Who else processes it

The Service runs on these, and no others:

  • Supabase — database and authentication.
  • Vercel — application hosting, and anonymous page-view counts.
  • Sentry — error reports. Stack traces and error messages, with request bodies, headers and any token in a URL stripped before they are sent. We do not record sessions and we do not send your content.
  • Anthropic and OpenAI — the models that draft and analyse, and OpenAI also transcribes audio. Neither trains on data sent through their APIs.
  • Unipile — the authenticated LinkedIn session used to publish and read engagement.
  • Resend — sending email, both notifications and pitches.
  • Reddit — for customers who choose communities to watch, our Reddit app reads public threads there and passes us each thread’s title, link, age and a short excerpt, never who wrote it. We never post, comment or vote on Reddit for anybody.
  • Hunter.io — looking up a work email address somebody has published, for our own outreach only. We keep an address only when Hunter can show the public pages it appears on, and we keep those pages with it; an address Hunter inferred from a company’s naming pattern is refused. Anybody who tells us to stop is suppressed permanently.
  • Twilio — text messages, WhatsApp and phone calls, for people who link a phone to their account. It holds your number and the messages exchanged. We text you only after you prove the number and only about your own account; frequency varies, and message and data rates may apply. Reply STOP to stop, or HELP for help. We do not sell or share your mobile number, or your consent to be texted, with anybody for their marketing. How opting in and stopping work is on our text messages page.
  • Inngest — running background work. Overnight jobs sent to a model in bulk keep their text there while they wait for the answer.
  • Slack — when you connect a workspace, so it can answer questions in a channel and receive what you send it. We hold the workspace’s name and token, which channels are bound to which voice, and the Slack user ids of people who have linked themselves. What you type in the channel reaches us; what we answer reaches Slack.
  • Apify — a marketplace runner. Where a customer turns on outbound sourcing, we send it a search term and a job title, and what comes back is the text of a public post with its author’s name, headline and the post’s own link. For our own outreach it also reads the recent public posts of somebody we have already written to, so a single follow-up can mention what they said since. Two further actors are wired but not in use: one that takes LinkedIn handles and returns a name, headline, company and location, and one that takes X handles and returns a name, bio and follower count. We will say here before either is switched on.
  • Rephonic — the licensed podcast database used to find shows worth pitching and, where a show publishes no address in its feed, the booking contact Rephonic holds for it. The show’s own site is read only when neither has one. Its concierge flag means verified by Rephonic, not published by the show. We send it a search term, never anything about you.
  • Apple — the public podcast directory, searched the same way and for the same reason. No account, and nothing about you is sent.
  • Bluesky — read, not posted to, for journalists publicly asking for sources. We read public posts under a tag; nothing about you is sent.
  • Stripe — payments. Card details go to them and never to us.
  • Google — Search Console, when you connect it, to read how often people search for your name. Read-only, and only the property you choose.
  • X — when you connect it, to publish on your behalf and read engagement on what you posted.
  • HubSpot — when you connect a CRM, to write outcomes into it as notes. Nothing is ever read back.
  • Ghost, WordPress or beehiiv — when you connect a destination, to deliver a long-form piece to your own site or newsletter.

Some are outside the UK and EEA. Transfers rely on Standard Contractual Clauses or an equivalent. We will update this list before adding anybody to it.

One thing your browser does rather than we do. If you SPEAK an answer instead of typing it, your browser may transcribe it where you are, using a service built into the browser itself — Google’s in Chrome, Microsoft’s in Edge. That audio goes to them under their terms and not ours, and they are not on the list above because the Service does not run on them: your browser does. Safari has no such service and sends the recording to OpenAI, our transcription provider, instead. Typing avoids it entirely, and every interview can be typed.

How long we keep it

  • Your content: at the first daily sweep (02:00 UTC) after 30 days from closing your account — the app names the exact moment. Media, documents and anything you captured on your phone can be deleted as you go, file and all — the one exception is a file a published episode is still playing, which needs the episode taken down first. A post you have already published lives on the platform you published it to, and only you can take it down there; our record of it goes when the account does. Stories and interview transcripts currently go when the account does, or when you ask us.
  • Audience contacts: until you close your account, or ask us to remove them. Disconnecting a platform stops us collecting more.
  • Media contacts: their details are removed the moment they ask us to stop, and otherwise kept while the person who found them is still working with them.
  • Suppressions: permanently. That is the point of them.
  • Audit and billing records: as long as the law requires.

Security

Data is encrypted in transit and at rest. Access is scoped per voice and per role, and every action is attributed to the person who took it — including ours. The one person who runs On Record can read your account when you ask for help or we are looking into a fault, and that is written to the same audit log as everything else. Credentials for connected platforms are held encrypted and are never shown back in the interface, to you or to us.

Cookies

We set a session cookie so you stay signed in. We do not use advertising or cross-site tracking cookies.

Changes, and how to reach us

If we change this materially we will tell you before it applies. Earlier versions are available on request.

On Record is operated by an individual and is not incorporated, so there is no registered company. The controller of the data described here is the person who runs it. The postal address we are required to publish is carried in the footer of every marketing message we send — not on a sign-in link or a note about your own account, which the law that requires it does not cover. It is: 120 19th St N Ste 201, PMB 972419, Birmingham, AL 35203-3219.
Data questions: legal@onrecord.tech.
In the UK you can complain to the Information Commissioner’s Office; in the EEA, to your local supervisory authority.

Privacy Policy — On Record