Privacy Policy
Last updated: July 10, 2026
The short version: we ask before we measure anything. No accounts, no payments, and nothing we sell or show you. Google Analytics runs only if you accept the consent banner; if you decline, or ignore it, the script is never fetched and no request reaches Google. We do keep a few whole-number counters on our own server — no IP, no cookie, nothing that is about you rather than about the site — and section 3 lists every one of them. We also keep whatever you type into the feedback box in the footer, if you use it: your words, the page you were on, and the time. No name, no address, no IP, nothing that ties one message to another or to you. The one thing that reaches a third party is a YouTube channel, if you choose to add one: that plays inside Google's own player, under Google's rules, and section 3 says exactly what that means. This page exists to say all of it precisely enough for the GDPR.
1. Controller
The operator of sleepcast.pro — [email protected].
2. On your device only
Feeds, settings and listening history live in your browser's storage and never reach us. Clearing the site's data erases everything.
3. What our servers see
- Feed relay — feed URLs are fetched through our relay so your browser can reach them; processed in memory, not logged. Basis: performance of our service to you (Art. 6(1)(b) GDPR).
- Hosting logs — our host (Fly.io) keeps standard technical logs (IP, user agent) briefly for security. Basis: legitimate interest (Art. 6(1)(f)).
- Feedback you send — the footer has a box you can type into. If you use it, we store exactly three things: the text you wrote, which page you were on when you wrote it, and the time. Nothing else is attached — no IP, no user agent, no cookie, no identifier, and no way for us to tell that two messages came from the same person. Your address is briefly used in memory to limit how many messages one connection can send, and is never written down. A person reads these by hand; nothing automated acts on them. Please don't put anything about yourself in the box — if you type your name or email, we will have it, because we keep what you wrote. Basis: legitimate interest in improving the service (Art. 6(1)(f)). To have a message removed, email [email protected] with enough of its wording to find it.
- Aggregate counters — whole numbers only, with no
IP, no cookie, no identifier and nothing joined to a visitor or a
session. Exhaustively, we count: which page bucket was served
(
/,/app,/colophon,/legal, other, not-found, and whether a not-found came from a known crawler, from one of our own links, or from neither); which external site linked here, as a bare hostname; which named crawlers visited, from a fixed allowlist — an unrecognised user agent, which is to say every human's, is discarded without being recorded; and a short allowlist of UI events the app reports. In full, those are: a returning listener seeing the welcome screen; each of the three ways a night can be started; the answer to "did you sleep well?"; the three outcomes of the 3am check-in; and, if you use the YouTube feature, that a channel was added, that a night played one, and that the embedded player had to be tapped to begin. Each is a single running total. Nothing here can be traced back to a person, including by us. One counter records an address rather than a number, and only this one: when a page on this site links to something that no longer exists, we record that broken address so it can be fixed. It is recorded only when the browser says the link came from one of our own pages, so the only addresses that can ever appear are ones we published ourselves. Anything typed into the address bar is never recorded, no query string is ever kept, and the list stops at thirty entries. Basis: legitimate interest in knowing whether the site works (Art. 6(1)(f)).
Podcast audio itself is streamed by your browser directly from whoever hosts it — those hosts see your IP, as any website you visit does. It does not pass through us.
3a. If you add a YouTube channel
You can add a YouTube channel as if it were a podcast. Nothing below happens unless you do, and none of it applies to a night of ordinary podcast feeds.
- YouTube publishes no audio file we could play, so the video plays inside Google's own embedded player. Your browser loads that player from Google and talks to Google directly: Google sees your IP address and whatever else a visit to a Google page reveals, exactly as visiting YouTube would.
-
We use
youtube-nocookie.com, Google's reduced-tracking host, which does not set advertising cookies. It is not no-storage and it is not no-tracking — it is Google's product operating under Google's privacy policy, not ours. - Google may show ads in that player. We do not place them, receive anything for them, or have any way to mute, skip or hide them.
-
The channel's list of videos is fetched through our relay like any
other feed, so that request carries our server's address rather
than yours. The same is true when you paste an
@namelink: our server loads that channel's page to find its id, keeps only the id, and remembers it for a day so the next person asking for the same channel costs nobody a request. The handle you typed is not logged.
3b. Google Analytics, only if you accept
A banner asks once whether we may use Google Analytics to see which
pages get used. Your answer is stored on your device as a
localStorage entry named sc-consent so we
stop asking.
- If you decline, or never answer, the Google Analytics script is never downloaded. No request is made to Google, so Google does not see your IP address and no analytics cookies exist. Declining costs you nothing: every part of the site and the player works the same.
- If you accept, we load Google Analytics 4
(measurement ID
G-DPQWL1XFMD). It then sets its own cookies under Google's domains and sends Google the usual measurement data: pages viewed, approximate location derived from your IP, device and browser type, and a randomly generated identifier that lets Google recognise the same browser across visits. That data is processed by Google, under Google's privacy policy, and we cannot see or delete it for you individually. -
Advertising signals stay off either way. We set Consent Mode v2
with
ad_storage,ad_user_dataandad_personalizationdenied, and never grant them. - Changing your mind means clearing
sc-consentfrom this site's site data in your browser, which brings the banner back.
The whole-number counters in section 3 are separate, first-party, and run whatever you choose here.
4. Transfers & retention
Providers operate in the US under Standard Contractual Clauses / Data Privacy Framework. We retain nothing that identifies you; hosting logs expire within 30 days. The aggregate counters in section 3 are kept indefinitely, because a running total of page hits is not personal data and there is nothing in it to expire. Feedback messages are kept until they have been acted on or are no longer useful, and are deleted on request — they are your words, so the only thing that can make one personal is what you chose to put in it.
5. Your rights
You hold the GDPR rights (access, erasure, portability, objection, complaint to your supervisory authority) — though nearly all your data is already in your own hands, in your browser. Anything else: email us; we answer within a month.
6. Cookies & children
We set one cookie-equivalent of our own: a localStorage entry
named sc-consent recording whether you accepted or declined
analytics, so we stop asking. That is stored whichever way you answer.
If you accept, Google Analytics sets its own cookies under Google's
domain. If you decline, it is never loaded. An embedded YouTube player,
if you add a channel, stores things under Google's domain rather than
ours — see 3a. Not directed at children under 16.