Privacy Policy

Last updated: 17 July 2026

BondCasts is built to respect your privacy. In short: it does not track you, does not show ads, and does not sell your data to anyone.

Data we don't collect

BondCasts has no analytics SDKs, no advertising identifiers, and no third-party tracking. We never receive your listening history - what you play, your positions, or your queue. Our services do receive the limited information described below when you search the website, submit a feed, request a cached feed, or enable new-episode notifications. We do not use that information to profile you or associate it with an Apple Account.

Web companion

You can search for podcasts and preview verified RSS feeds on the BondCasts website without signing in. Search terms go first to the BondCasts web service, which forwards them to Apple's public podcast directory and may keep the returned results in memory for up to five minutes. When you select or paste a feed, its address is sent to our service and fetched from the podcast host so we can verify its title, artwork, privacy marker, and final address. Non-private parsed results may be kept in memory for up to fifteen minutes; locked feeds and addresses containing query tokens are not cached. Responses are marked not to be stored by browsers or intermediary caches. We do not persist a search history or associate these requests with an Apple Account. Like any web request, they necessarily include your IP address and standard request information while the request is being served. The production web companion does not have Application Insights or HTTP diagnostic exports enabled, so BondCasts does not retain those individual requests, IP addresses, search terms, or submitted feed addresses in developer-accessible logs. Azure exposes aggregate service measurements, such as request and error counts, without giving us an individual request history through the logging configuration we use.

If you choose to sign in with iCloud, Apple presents and processes the sign-in. CloudKit JS keeps a session token in your browser so the session can persist, and the page temporarily processes followed-show records in browser memory. Those reads and changes travel directly between your browser and your private CloudKit database. BondCasts servers do not receive your password, CloudKit session token, Apple Account identifier, or a copy of your private library. Signing out ends the browser's CloudKit session.

New-episode notifications

If you turn on new-episode notifications, a small service we run checks your chosen shows' public RSS feeds so your devices don't have to. To do that, the app registers the web addresses of those feeds - and nothing else - under a random identifier, never your identity. Private or password-protected feeds are never sent to this service. Turning notifications off for a show (or entirely) removes the registrations, and any registration a device hasn't refreshed in about 30 days expires on its own. Shows followed from the website start with server notifications off, so an unclassified or private feed cannot enter this registry; you can review that setting later in the app. You don't have to take our word for any of this: the service is open source, so you can read exactly what it collects and does - see the code on GitHub.

Data Apple collects as the platform

Because BondCasts is distributed through the App Store, runs on Apple's platforms, and uses Apple's CloudKit JS service on the website, Apple processes the information needed to deliver those services. This includes standard information such as App Store download and purchase metrics, and - only if you opt in to sharing with developers - aggregate crash and usage analytics. This collection is performed by Apple under Apple's privacy policy, not by us, and we only ever see anonymized, aggregate reports.

Data stored on your device and in iCloud

Your subscriptions, queue, playback positions, downloads, and settings are stored on your device. If you are signed in to iCloud and have the feature enabled, this data syncs across your devices using Apple's iCloud (CloudKit) in your own private iCloud account. Our servers cannot access that private database. The BondCasts app, and the web companion after you sign in, access it as clients authorized by your Apple Account.

Your controls, retention, and deletion choices

Web session and followed shows

Use the Apple-provided Sign Out button on the web companion to end its CloudKit browser session. The session data remains in that browser until you sign out, it expires, or you clear the site's browser data; BondCasts servers never receive it. Choosing Unfollow in the app or on the web companion removes the matching followed-show record from your private CloudKit database. Unfollowing does not erase separate playback history, queue, settings, or other BondCasts records.

New-episode notifications

You can turn new-episode notifications off for an individual show, or turn them off entirely in BondCasts Settings. Each installed device then removes its public feed registrations when it next reconciles with CloudKit. If a device cannot remove one immediately, the registration expires after it has not been refreshed for about 30 days. Removing the app without first turning notifications off has the same approximately 30-day backstop.

Delete all BondCasts data from iCloud

To remove the private BondCasts data that we cannot access, first turn off iCloud for BondCasts on every device so a remaining local copy is not synced back. On iPhone or iPad, open Settings > [your name] > iCloud > See All > BondCasts. Then open Settings > [your name] > iCloud > Storage (or Manage Account Storage), choose BondCasts, and use Apple's delete-data option. The wording can vary by OS version; Apple also explains how to delete third-party app data from iCloud. Delete BondCasts from your devices as well if you also want to remove local settings, downloads, and cached data. Because your private CloudKit database is accessible only through your Apple Account, we cannot perform that deletion for you.

Retention summary

Email privacy@bondcasts.com with privacy or deletion questions. We can help you find the controls above and address developer-accessible information, but private iCloud data must be deleted using your Apple Account controls.

Podcast content

When you play a podcast, the app downloads the audio directly from the podcast host you chose, which may receive your device's IP address and standard request information as part of delivering it, subject to their own privacy policy.

To load and check for new episodes, the app may fetch a show's public RSS feed through our own caching service rather than contacting each host directly, so your devices do less work. When it does, our service receives the feed's public web address and your device's IP address in order to answer the request. We use these only to serve the feed and operate the service, we don't tie them to your identity, and there is no account involved. It is the same open-source service described under New-episode notifications, and private or password-protected feeds are never sent to it.

Transcripts and on-device features

Any transcription and audio-processing features run on your device using Apple frameworks. Audio is not uploaded to us for processing.

Questions about privacy? Email privacy@bondcasts.com.