This Privacy Policy explains how Live Pod (operated by Connection Marketing LTD, company number 16678162, registered in England and Wales) collects, uses, and protects your data when you use our service at livepod.io.
We've written this in plain English. If anything is unclear, email hello@cordeliakate.com and we'll explain.
1. Who we are
Live Pod is a research and idea management tool for live show creators. It is operated by Connection Marketing LTD, a company registered in England and Wales under company number 16678162, whose registered office is C/O Approved Accounting Ltd, Office 43, 1000 Lakeside, Portsmouth, Hampshire, England, PO6 3EZ. For the purposes of UK GDPR, Connection Marketing LTD is the data controller for the personal information described in this policy.
Contact: hello@cordeliakate.com
2. What we collect
From you directly
- Email address. Used to log you in (we send a one-time "magic link" rather than storing a password).
- Your name and the name of your show.
- Knowledge files you upload. Includes vision PDFs, audience notes, brand positioning documents, channel performance CSVs, and any other files you choose to add to your client knowledge base.
- Chat messages with the in-app assistant ("Larry").
- Your accept/reject decisions on AI-suggested episode topics.
From third parties (only when you authorise it)
- Airtable. If you connect Airtable, we receive an access token that allows us to list your bases and tables and create rows in the table you select. We never read records you didn't create through Live Pod.
- YouTube Data API (public data). We use YouTube's public API to fetch information about videos and channels for research purposes. This data is public and is not personal information about you.
- Your YouTube channel (only if you connect it). If you choose to connect your YouTube account, we receive OAuth tokens from Google and use them as described in the "Your YouTube connection" section below.
Automatically
- One authentication cookie after you log in, so we know it's you on subsequent page loads.
- Basic server logs (IP address, request path, response code) for security and debugging. Retained for up to 30 days.
2a. Your YouTube connection
Live Pod uses YouTube API Services. If you connect your YouTube account, you do so through Google's own sign-in and consent screen, and by using this part of the service you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
With your permission, we access and store:
- OAuth tokens issued by Google, which let Live Pod act on your channel on your behalf. Stored encrypted at rest, used only for the features below, and deleted when you disconnect.
- Your channel's identity — channel ID, channel name, and avatar — so the app can show which channel is connected.
- Your channel's analytics (views, watch time, subscriber counts and similar reports), fetched from the YouTube Analytics API and shown to you inside the app.
- Videos and live streams you ask us to create. When you use Live Pod to schedule a Short or set up a live stream, we send that content and its details (title, description, publish time) to YouTube on your instruction. We act only when you ask — never automatically posting without an action you took.
We do not read your YouTube comments or messages, and we never share your YouTube data with advertisers or data brokers. Your YouTube data is shared with our processors only as needed to run the feature (hosting on Vercel, storage on Neon), and analytics figures may be included in AI-generated summaries produced for you (see the Anthropic entry below).
You can disconnect at any time with the Disconnect button inside the app — which deletes the stored tokens and asks Google to revoke our access — or from Google's side via the Google security settings page. Stored analytics summaries are deleted on request, and everything is deleted when your account closes.
Live Pod's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Why we collect it
- To operate the service and let you log in.
- To provide the research, knowledge management, and chat features.
- To send AI-generated content suggestions back to you.
- To push your accepted ideas to systems you connect (such as Airtable).
- To investigate problems and prevent abuse.
Our legal basis under UK GDPR is performance of a contract (you've signed up to use the service) and our legitimate interest in keeping the service secure and working properly.
4. Who we share it with
We share data with a small number of carefully chosen service providers strictly as needed to run Live Pod. We do not sell your data or hand it to data brokers. The single exception to advertising is Meta, described below, and only for people who agreed to it on our cookie banner.
- Vercel (hosting). Your requests pass through Vercel servers (United States and Europe).
- Neon (database). Your account information and uploaded knowledge are stored in a Neon-managed Postgres database (eu-west-2, London).
- Anthropic (Claude AI). Your knowledge files, chat messages, and steering brief content are sent to Anthropic's Claude API to produce research, briefs, and replies. Anthropic does not train its models on this data.
- Resend (email delivery). Your email address is sent to Resend when we send you a magic-link login email.
- Airtable (only if connected by you). We send your accepted episode title and take to the table you nominate.
- Google (YouTube API Services). We send search queries (not your personal information) to YouTube's API for research. If you connect your channel, we also exchange your OAuth tokens with Google to fetch your analytics and to schedule the videos and live streams you ask for.
- Meta (advertising, public pages only, consent required). If you accept cookies on our webinar or Vision Call page and then register or pay, we send Meta a one-way scrambled (SHA-256 hashed) copy of your email address, and your phone number and first name if you gave them, so it can tell us which advert led to the sign-up. Meta cannot read the originals from the scrambled versions; it can only compare them against accounts it already holds. This never happens if you decline cookies, and never happens inside the members' area. See our Cookie Policy.
5. How long we keep it
- Account data. For as long as your account is active. Deleted on request.
- Knowledge files and AI-generated content. Until you delete them or close your account.
- Chat history with Larry. Stored against your client record until you or we delete it.
- Server logs. Up to 30 days.
- Airtable tokens. Until you click Disconnect, or we receive an invalidation signal from Airtable.
- YouTube (Google) tokens. Until you click Disconnect in the app or revoke access from your Google account — either way, our stored tokens are deleted (see "Your YouTube connection" above).
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (the "right to be forgotten").
- Export your data in a machine-readable format.
- Withdraw consent for any third-party connection (such as Airtable) at any time, by clicking Disconnect inside the app or revoking access from inside that third party's settings.
- Lodge a complaint with the UK's Information Commissioner's Office (ico.org.uk) if you believe we've mishandled your data.
To exercise any of these rights, email hello@cordeliakate.com. We aim to respond within 30 days.
7. Security
Data is encrypted in transit (HTTPS) and at rest in the database. Access tokens and other secrets are encrypted at rest. Access to the system is limited to the operator. Magic-link login URLs are short-lived (10 minutes) and tied to your email address.
No system is perfectly secure. If we ever become aware of a breach affecting your data, we'll notify you within 72 hours where required by law.
8. International transfers
Some of our service providers (Vercel, Anthropic, Resend) are based in the United States. When your data is transferred outside the UK and EEA, the transfer is protected by Standard Contractual Clauses or equivalent safeguards, as required by UK GDPR.
9. Cookies
Inside the app we use one strictly necessary cookie: an authentication cookie set after you log in, so the app knows you.
On our public marketing pages we also ask, before anything is stored, whether we may keep three things: which link brought you to us, a note that stops one visit being counted twice, and the Meta advertising pixel. You can say no, and you can change your answer later from the footer of those pages. We use no advertising cookies or third-party trackers anywhere inside the app itself. Our Cookie Policy lists every item individually.
10. Children
Live Pod is not intended for use by anyone under the age of 16. We do not knowingly collect data from children. If you believe a child has used the service, contact us and we'll delete the account.
11. AI-generated content
Some content in the app (research summaries, episode suggestions, chat replies) is generated by Claude, an AI model from Anthropic. AI output can be wrong, biased, or out of date. You should treat it as a starting point and apply your own judgement before publishing or acting on it.
12. Changes to this policy
We may update this policy occasionally. The "last updated" date at the top of this page tells you when it last changed. Material changes will be flagged inside the app.
13. Contact
Email hello@cordeliakate.com with any questions about this policy or how we handle your data.