Privacy Policy

Last updated: August 2, 2026.

1. Who we are

Mr. Podcast is operated by MPriet, CVR 32212263, Vermlandsgade 70, st. tv, 2300 København S, Denmark ("MPriet", "Mr. Podcast", "we", "us" or "our"). MPriet is the data controller for the processing described in this policy unless a different controller is clearly identified. Contact us at [email protected].

This policy covers our websites, branded app, programmes, communities, Mr. Podcast Suite, assessments, support, business outreach and related services. It applies to customers, users, prospects, podcast guests and people who contact or interact with us.

2. Personal data and sources

Depending on the relationship, we may process:

  • Account and contact data, including name, email, company, user IDs, login and access status.
  • Business and podcast data, including offer, audience, revenue range, podcast name, website, podcast URL, RSS feed, public directory data and planned-podcast information.
  • Programme and progress data, including completed Steps and videos, assignments, deadlines, assessments, feedback, rewards and access history.
  • Content and production data, including audio, video, transcripts, manuscripts, show notes, graphics, social posts, connected-channel identifiers and publication status.
  • Community and support data, including forum posts, comments, private messages, support requests, reports, moderation actions and approved AI-assisted replies.
  • Transaction and guarantee data, including product, amount, payment status, invoices and evidence submitted for a voluntary refund guarantee. We normally do not receive full payment-card details.
  • Technical and security data, including IP address, device and browser data, timestamps, event and webhook identifiers, cookies, logs, diagnostics and suspected abuse.
  • Marketing and prospect data, including professional contact details, public podcast and business information, campaign source, consent or objection status and engagement.

We collect data from you, your use of our services, authorised integrations, payment and publication platforms, public podcast directories and professional data sources such as Rephonic. If you give us data about a guest or another person, you must have a lawful basis to do so.

3. Purposes and legal bases

We process personal data to:

  • Create accounts, provide programme and software access, publish authorised podcast and marketing assets, deliver support and fulfil our agreement. The legal basis is performance of a contract or steps requested before a contract.
  • Record progression, assess assignments, prepare podcast assessments and administer a voluntary refund guarantee. The legal basis is contract performance and our legitimate interest in consistent programme administration and fraud prevention.
  • Operate communities, moderate content, investigate reports, secure systems, deduplicate events and maintain reliable services. The legal basis is our legitimate interests and, where relevant, legal obligations.
  • Send operational messages, unlock notifications and approved support replies. The legal basis is contract performance or our legitimate interest in supporting users.
  • Send marketing where permitted. The legal basis is consent where required, or another lawful marketing basis. You can opt out at any time.
  • Conduct proportionate business-to-business outreach using professional and public podcast data. The legal basis is our legitimate interest in relevant B2B marketing, balanced against the rights of the recipient. Objections and suppression records are respected.
  • Keep accounting, tax, dispute and compliance records. The legal basis is legal obligation and establishment, exercise or defence of legal claims.
  • Improve content and systems using minimised or aggregated information. The legal basis is our legitimate interest in improving the service.

Where we rely on legitimate interests, you may request information about the relevant balancing assessment.

4. AI-assisted processing and human review

We use AI to classify messages, retrieve relevant Mr. Podcast knowledge, draft replies, evaluate whether assignment questions have genuinely been attempted, analyse podcast material and perform a preliminary check of voluntary refund-guarantee evidence.

  • AI does not decide whether a viewpoint is correct or whether a person is an attractive customer. A Reward Funnel answer is evaluated only for a genuine attempt to answer each required question. A failed check can delay progression, but the user can submit a new answer or contact us.

A refund-guarantee result is not finally rejected solely by AI. Failed, uncertain or low-confidence checks are eligible for human review, and the customer may provide missing evidence or request review at [email protected]. We record the model or system version, evidence, confidence and decision history where proportionate.

  • AI inputs may include relevant messages, transcripts, programme records, public podcast data and evidence submitted for the task. We minimise inputs and do not intentionally use guarantee documents to train public models.

5. Recipients and suppliers

We use the following recipients and supplier categories. A service is only used when relevant to the user or workflow, and not every service receives data about every person.

Cloudflare: hosting, security, Workers, databases, object storage, queues, browser automation, AI and AI gateway services.

Passion.io: branded app, programme access, community, messages and notifications.

HighLevel or LeadConnector: websites, forms, contacts, email, CRM, access and progression records.

Google Workspace and authorised Apps Script integrations: documents, spreadsheets and operational records.

Google APIs, YouTube, Spotify and Google Gemini or other authorised Google AI services: customer-authorised publishing, account connection, distribution and public metadata, plus selected assessment and analysis fallback tasks where enabled.

Slack: internal Messenger Center review, support approval and operational alerts.

Zapier: authorised automation between systems.

Cloudflare Workers AI, Anthropic and AssemblyAI: language-model processing, retrieval, embeddings, transcription and AI gateway services. Cloudflare Workers AI may run configured third-party model families, including Meta Llama and BAAI embedding models, within Cloudflare's service.

Descript and ElevenLabs: customer-authorised recording, transcription, voice and audio-production workflows.

Captivate: customer-authorised podcast hosting, RSS publication and analytics workflows.

Ayrshare, Publer and connected social platforms: customer-authorised scheduling and publication. Publer may appear in legacy Podcast Profit Accelerator workflows; Mr. Podcast Suite is the current implementation and audit route for the Podcast Profit Accelerator Implementation Guarantee.

Placid: generation of authorised visual assets.

VideoAsk or Typeform, Sendspark and Vimeo: form or video collection, personalised video and video hosting or delivery.

Stripe and relevant checkout providers: payment, invoicing, fraud prevention and transaction records.

Instantly: business outreach campaigns and suppression handling.

Rephonic: professional and public podcast discovery and enrichment.

HYROS and Google Tag Manager or related Google measurement services: consent-based attribution, analytics and advertising measurement where enabled.

Meta and Apple podcast services: advertising, connected publication, distribution or public podcast metadata, depending on the feature selected.

Bunny Fonts: delivery of website fonts and associated technical request data.

We also read public podcast data from directories and platforms such as Apple Podcasts, Amazon Music, Spotify, Acast, Podtail, Podimo, Podcast Addict, Podfriend, Hubhopper and similar services. In that context they are normally public sources or independent platforms, not processors acting on our instructions.

Some payment, advertising, app-store, social, hosting and connected publication platforms act as independent controllers for parts of their processing under their own terms. We may also disclose data to professional advisers, authorities or counterparties when required by law, necessary to protect rights or safety, or as part of a business reorganisation with appropriate safeguards.

Our current operational supplier and data-flow register is available at See the Suppliers and data flows section below. It identifies services found in active production workflows and distinguishes processors from connected or public platforms. Supplier roles, subprocessors and locations can change; we review material changes and update the register.

6. International transfers

Some suppliers or their subprocessors process data outside Denmark or the European Economic Area. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures, or another lawful transfer mechanism. We maintain a supplier and transfer register and review relevant subprocessors and processing locations. You may ask for information about the applicable safeguards.

7. Retention

We apply the following general retention rules unless law, an active dispute or a documented exception requires a different period:

Active account, programme, production and support data: for the relationship and normally up to 3 years afterwards.

Community content: while the community and account are active, then deletion or anonymisation where reasonably possible, subject to moderation, legal and other users' conversational context.

Security, webhook and diagnostic logs: normally up to 12 months.

Unsuccessful B2B prospect records: normally up to 12 months after the last relevant contact; a minimal suppression record may be kept longer to respect an objection.

Marketing consent and objection evidence: while used and afterwards for as long as necessary to demonstrate compliance.

Voluntary guarantee claim evidence and decision records: normally up to 5 years after the end of the financial year in which the claim was resolved, where needed for accounting, fraud prevention or legal claims.

Accounting material: the current financial year and the legally required period afterwards, generally 5 years from the end of the relevant financial year.

We delete, anonymise or restrict data when the purpose ends. Backup copies expire through controlled retention cycles.

8. Community content and messages

Community posts and comments are visible to users with access to the relevant area. Private messages are not public, but may be processed by authorised systems and staff for support, moderation and security.

Users can use available reporting and blocking controls. We may review, preserve, restrict or remove material involving harassment, unlawful content, infringement, spam, abuse or violations of our Terms. Do not publish sensitive or confidential data that is unnecessary for the discussion.

9. Cookies, analytics and connected platforms

Essential technologies are used for login, security, forms and service delivery. Non-essential analytics, attribution, advertising or tracking technologies are not to be activated before the consent required in the relevant jurisdiction. Where enabled after consent, these may include HYROS and Google Tag Manager or related Google measurement services. Refusing or withdrawing non-essential consent must not prevent access to essential service functions.

The consent interface must identify the relevant purposes and make rejection or withdrawal as accessible as acceptance. Connected third-party platforms may set their own technologies when you deliberately open or connect them under their policies. Server logs and security signals necessary to deliver and protect a requested service are handled separately from optional marketing tracking.

10. Security and incidents

We use proportionate technical and organisational measures, including access controls, secret management, encrypted transport, environment separation, event deduplication, audit records, rate limiting and human approval for sensitive actions. Access is limited by role. No service can guarantee absolute security.

We assess personal-data incidents and notify the competent authority and affected people when legally required.

11. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection. You may withdraw consent without affecting earlier lawful processing. You may also object to direct marketing at any time and request human review of a significant automated result.

Email [email protected]. We may verify your identity. You may complain to Datatilsynet or another competent supervisory authority.

12. Account deletion

Use the account deletion form below.

13. Children

The services are intended for adult business users and are not directed to children. We do not knowingly collect personal data from people under 18.

14. Changes

We update this policy when processing, suppliers or law changes. The current version and date are published here. Material changes are communicated reasonably.

15. Contact

MPriet · CVR 32212263

Vermlandsgade 70, st. tv, 2300 København S, Denmark

Supplier and Data-Flow Register

Verified against active Cloudflare Worker bindings on July 22, 2026. This is an operational register, not a substitute for reviewing each supplier's DPA, subprocessor list, processing regions and transfer mechanism.

Core platform and operations

  • Cloudflare — hosting, Workers, D1, R2, KV, Queues, Durable Objects, Workflows, Browser Rendering, Workers AI, Vectorize, security and AI Gateway. Data: account, content, messages, transcripts, technical and security records.
  • Passion.io — native/web app, courses, access, community, private messages and notifications. Data: account, progress, community and message data.
  • HighLevel / LeadConnector — CRM, forms, websites, email, contact identity, progression, access and guarantee workflow. Data: contact, programme, business, campaign and claim status.
  • Google Workspace / Apps Script — operational documents, sheets, assessments and approved automation. Data depends on the workflow.
  • Google Workspace, Google APIs and Gemini — OAuth, Docs, Drive, Calendar, YouTube publication, configured model fallback and related user-authorised Google connections.
  • Google Gemini / Google AI services — language-model fallback for selected assessment and analysis workflows routed through an authorised gateway. Data: only the minimised prompt, transcript excerpt or assessment material required for that task.
  • Slack — internal Messenger Center approval, support and operational alerts. Data: relevant message excerpts, drafted replies and operational metadata.
  • Zapier — event automation between authorised systems. Data: the minimum event payload required by each Zap.

AI, audio and content production

  • Cloudflare Workers AI — assignment classification, message analysis and retrieval/embedding tasks inside Cloudflare, including configured Meta Llama and BAAI models.
  • Anthropic — language-model analysis and drafting routed through configured gateways.
  • AssemblyAI — transcription and LLM gateway processing.
  • Descript — user-authorised recording, transcription and production source workflow.
  • ElevenLabs — authorised synthetic-voice and audio production. Data can include scripts, recordings, voice samples and generated audio.
  • Placid — generated visual assets.
  • VideoAsk / Typeform — assessment, form or video-form collection where the relevant flow is enabled.
  • Sendspark — personalised video workflow.
  • Vimeo — video hosting and delivery.

Podcast, promotion and distribution

  • Captivate — podcast hosting, RSS publication and analytics workflows.

  • Ayrshare — scheduling and publication to user-connected social platforms.

  • Publer — customer-authorised social scheduling where a legacy Podcast Profit Accelerator workflow or connected customer account still uses it. Publer is not the current audit route for the Podcast Profit Accelerator Implementation Guarantee; Mr. Podcast Suite is.

  • Spotify — user-connected or public podcast distribution and metadata.

  • YouTube / Google — user-connected video publication, discovery and Google Workspace services.

  • Apple Podcasts / iTunes directory — public podcast metadata and RSS discovery; generally a public data source or independent platform, not an instructed processor for this use.

  • Meta — advertising and user-connected social distribution where enabled.

Website analytics, attribution and delivery

  • HYROS — consent-based marketing attribution where enabled. Data can include page, campaign, device, transaction and contact-matching signals.
  • Google Tag Manager and related Google measurement services — consent-controlled loading of analytics or advertising tags where configured.
  • Bunny Fonts — website-font delivery and ordinary technical request metadata.

Non-essential analytics and advertising tags must not load before valid consent. The live page and tag configuration, not merely the Privacy Policy, determines whether this requirement is met.

Sales, payment and B2B outreach

  • Stripe — payment, invoicing, fraud prevention and transaction status where used.
  • Instantly — relevant B2B outreach, reply state and suppression.
  • Rephonic — professional and public podcast discovery and enrichment.

Public directories and independent platforms

  • The Workers can read public metadata or construct user-facing links for Apple Podcasts, Spotify, YouTube, Amazon Music, Acast, Podtail, Podimo, Podcast Addict, Podfriend, Hubhopper and similar directories.
  • These services are normally public sources or independent platforms in that use, not MPriet processors.
  • A platform may have a different role if a user separately connects an account for publication or advertising.

Active Worker evidence

  • `instantly-ghl-worker-v1`: HighLevel, Instantly, Cloudflare.
  • `mp26-worker-0-podcast-finder`: Rephonic, HighLevel, Slack, Cloudflare.
  • `mp26-worker-6-message-center`: Passion, HighLevel, Slack, Google Workspace, Anthropic, AssemblyAI, Cloudflare Workers AI and Cloudflare data services.
  • `mr-podcast-cold-funnel-sentinel`: Cloudflare and internal service bindings.
  • `mr-podcast-suite`: HighLevel, AssemblyAI, Ayrshare, Captivate, Placid, Spotify, YouTube and Cloudflare AI/data/browser services; Descript is a user-level connected production source where enabled.
  • `mrpodcast-legal`: Cloudflare hosting only.
  • `podcast-profit-assessment-worker-v1`: VideoAsk, HighLevel, Google Workspace, Instantly, Anthropic, AssemblyAI, Google Gemini fallback and Cloudflare.
  • `rephonicv16-lifecycle-category`: Rephonic workflow, HighLevel, Instantly, Anthropic and Cloudflare.
  • `video-pipeline-worker-v2-native`: HighLevel, Sendspark, Vimeo and Cloudflare.
  • `w7-growth-engine`: HighLevel, Instantly, Meta, Slack, Stripe, Vimeo, Zapier, AssemblyAI and Cloudflare.

Required controller actions

  • Obtain and retain a current DPA for each processor.
  • Record whether each supplier is processor, subprocessor, joint controller or independent controller for each use case.
  • Record countries and remote-access locations, not only the supplier's registered address.
  • For transfers outside the EEA, record adequacy status or SCC module, transfer-impact assessment and supplementary measures.
  • Subscribe to subprocessor change notices and review changes before they take effect where possible.
  • Record purposes, categories, recipients, access roles, security measures and deletion schedule in the Article 30 record.
  • Remove unused credentials and stop sending data to retired integrations.
  • Run a documented annual review and an event-driven review when a Worker gains a new external binding.

Account deletion request

Request deletion of your Mr. Podcast account and associated data.

REQUEST ACCOUNT DELETION

You can start deletion of your Mr. Podcast account without logging in. Submit the form below using the email address associated with your account.

WHAT WILL BE DELETED

After we verify your identity, we will delete your Passion account, your GoHighLevel contact data, and associated community posts, private messages and AI or support records where legally and technically possible. We retain only records that we are required to keep by law.

HOW IT WORKS

1. Enter and confirm your account email in the form below.

2. Confirm that you understand the request.

3. We contact you to verify your identity.

4. After identity verification, we wait six days before removing the account. You may withdraw the request during that period by emailing [email protected].

5. We normally complete the verified request within 30 days.

Deleting your account is permanent and may remove access to programmes and content. Submitting this request does not immediately delete the account; identity verification and the six-day waiting period come first.

NEED HELP?

Email [email protected].

DATA CONTROLLER

MPriet · CVR 32212263

Vermlandsgade 70, st. tv, 2300 København S, Denmark

[email protected]

Mr. Podcast avatar

Double your sales. Triple your fun. Run all your marketing in two hours a month.

Mr. Podcast

All your marketing. 2 hours a month. Powered by one real conversation.

MPriet · CVR 32212263 · Vermlandsgade 70, st. tv, 2300 København S, Denmark.

Results vary. Mr. Podcast provides education, software and implementation support, not guaranteed earnings.

© 2026 Mr. Podcast. All rights reserved.