Introduction and scope
This Privacy Policy explains how Caloroga Shark Media LLC ("Linnet," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the Linnet platform at linnetmedia.com and the Linnet application (the "Service").
We are the controller of your personal information under this policy. To contact us about privacy matters, email privacy@linnetmedia.com or write to Caloroga Shark Media LLC, Attn: Privacy, 353 Lexington Avenue, 4th Floor, Ste 476, New York, NY 10016.
This policy applies to registered users, visitors to our website, and people whose information is processed in connection with their use of the Service. The Service is intended only for users aged 18 and over.
International data transfers. Where we transfer personal data from the EEA, UK, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) as our primary transfer mechanism. See Section 5.
Linnet is offered to users internationally, and this policy is written to address that.
Information we collect
2.1Information you give us
Account information: name, email address, password (stored hashed), and any profile details you provide.
Billing information: when you subscribe, our payment processor collects and processes your payment details. We receive limited billing information such as your plan, billing status, renewal history, and partial card details (for example card brand and last four digits). We do not store full card numbers.
Content you provide: prompts, scripts, text, audio, images, and other material you upload or input, and the settings and choices you make when producing an episode.
Connected credentials (BYOK): if you connect your own third-party provider key, we store that credential in encrypted form to operate the feature you connected.
Communications: information you provide when you contact support or correspond with us.
2.2Voice data
Because the Service offers voice features, we process two categories of voice-related data: (a) text-to-speech, where we generate synthesized narration from text you provide using preset synthetic voices; and (b) transcription, where audio you upload is converted to text. The Service does not offer user voice cloning and does not create voice prints or cloned-voice models of any person. We do not sell voice data and do not use it for AI training.
2.3Automatically collected information
Device and technical data: IP address, device type, operating system, browser type and version.
Usage data: features accessed, session activity, timestamps, error logs, and usage patterns.
Approximate location: derived from IP address at city or country level. We do not collect precise location unless you enable a feature that requires it.
Cookies and similar technologies: see Section 11.
2.4Information from connected third parties
If you connect third-party services (such as distribution platforms or storage providers), we may receive information from them as authorized by your permissions with those services.
2.5Information about guests and recorded participants
If you record or include another person through the Service, we may process that person’s voice and any details you provide about them. You are responsible for obtaining any consents required by applicable law before recording any third party.
How we use your information
3.1Purposes of processing
We use personal information to:
- provide, operate, secure, and maintain the Service, including generating and editing content and publishing to destinations you choose;
- process payments and manage subscriptions and usage limits;
- authenticate you and protect your account;
- provide support and respond to your requests;
- monitor for and address abuse, fraud, prohibited content, and violations of our Terms;
- understand and improve the Service using aggregated, de-identified data that cannot reasonably identify you;
- comply with legal obligations and enforce our agreements;
- send you service-related messages and, with your consent where required, marketing communications you can opt out of at any time.
3.2No AI training on your content
We do not use your content to train our own AI models, and we do not sell or share your content with advertisers.
3.3Your choices
Most processing described in Section 3.1 is necessary to provide the Service under our contract with you and cannot be opted out of without terminating your account. Where we process your personal information for purposes that are not strictly necessary for the Service, such as marketing communications, we will obtain your consent before doing so, and you may withdraw that consent at any time by contacting privacy@linnetmedia.com or using the unsubscribe mechanism in any marketing communication.
If we wish to use your personal information for a purpose materially different from the purpose for which it was originally collected, we will notify you and obtain your consent before doing so. You may also request that we restrict our use of your personal information or not disclose it to third parties for their independent purposes by contacting privacy@linnetmedia.com.
3.4Legal bases for processing (EEA, UK, and Swiss users)
We process your personal information on the following legal bases:
Performance of contract (Article 6(1)(b) GDPR): account creation and management, payment processing, content generation and publishing, and all core Service features.
Legal obligation (Article 6(1)(c) GDPR): financial recordkeeping, responding to lawful requests from authorities, and compliance with applicable law.
Legitimate interests (Article 6(1)(f) GDPR): operating and improving the Service, detecting and preventing abuse and fraud, diagnosing technical issues, and maintaining security. We have assessed that these interests are not overridden by your rights and freedoms, having regard to the nature of the data and your reasonable expectations as a user of a professional AI production platform. Where we rely on legitimate interests, you have the right to object as described in Section 7.
Consent (Article 6(1)(a) GDPR): marketing communications and any other processing for which we seek your consent. You may withdraw consent at any time.
How we share your information
We do not sell your personal information. We do not share your personal information or voice data with advertisers or for cross-context behavioral advertising.
4.1Service providers and subprocessors
We share personal information with trusted third-party service providers who process it on our behalf only to provide services to us.
These providers include our hosting and infrastructure provider, database provider, payment processor, identity and authentication provider, AI language model providers (for script generation, transcription, and related features), voice synthesis provider, text-to-speech provider, image generation provider, stock footage and imagery provider, music library provider, email communications provider, podcast hosting and distribution provider, which distributes your published content to the major podcast and video platforms you select.
The names, locations, and applicable data transfer mechanisms for each provider are maintained at linnetmedia.com/subprocessors, updated with reasonable advance notice of material changes. We reserve the right to change service providers from time to time; any change will be reflected on the subprocessors page.
When you publish through the Service, your content is distributed onward by our podcast hosting and distribution provider, which distributes your content to the major podcast and video platforms. Those platforms receive your published content as downstream destinations under their own terms and are not Linnet’s processors.
User-connectable integrations. Certain services receive data only if you choose to connect your own account credentials. They are activated at your direction, not by default, and Linnet is not the data controller for those transfers. These services include alternative podcast hosts and alternative AI providers, including voice and transcription providers.
4.2Publishing at your direction
When you publish, we transmit your content and metadata to the distribution and hosting services you select, including through our podcast hosting and distribution provider, which distributes your content to the major podcast and video platforms. Each third-party platform handles your content under its own terms and privacy policy.
4.3Legal and safety disclosures
We may disclose personal information if required by law or legal process, or where we reasonably believe disclosure is necessary to protect rights, safety, or property, to investigate fraud or abuse, or to enforce our Terms. We will notify you of legal demands for your data where permitted by law.
4.4Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, your personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any choices you may have.
4.5Aggregated and de-identified data
We may share aggregated or de-identified data that cannot reasonably identify you, for example in industry reports or product analytics.
International data transfers
Caloroga Shark Media LLC is based in the United States. When you use the Service, your personal information may be transferred to and processed in the United States and in other countries where our service providers operate. These countries may not provide the same level of data protection as your home country. This section describes the mechanisms we use to protect your data when it is transferred internationally.
5.1Standard Contractual Clauses, primary transfer mechanism
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR (Commission Decision 2021/914) as our primary transfer mechanism, supplemented by the UK International Data Transfer Agreement (IDTA) or IDTA Addendum for UK transfers, and FDPIC-adapted SCCs for Swiss transfers. Our hosting and infrastructure provider maintains its own SCC-incorporating DPA that covers transfers through its platform, including AI gateway traffic. Subprocessors not covered by that DPA are subject to individual SCC agreements. Transfer mechanisms applicable to each subprocessor are listed at linnetmedia.com/subprocessors.
5.2Transfer impact assessments
In accordance with the Schrems II decision (C-311/18), we have conducted transfer impact assessments (TIAs) for transfers of EEA, UK, and Swiss personal data to US-based processors. Our TIAs assess US surveillance law, including FISA Section 702 and Executive Order 12333, the nature and sensitivity of the personal data transferred, the practical likelihood of government access to that data, and the supplementary contractual and technical safeguards in place. We have concluded that our transfer mechanisms provide effective protection in practice, having regard to the nature of the data processed through the Service (professional production content with limited sensitivity) and the contractual obligations imposed on our subprocessors. TIA documentation is maintained and available to competent supervisory authorities on request.
AI-specific disclosures
The Service uses artificial intelligence for script generation, voice synthesis, image generation, music selection, episode metadata. These systems process your inputs to deliver the results you request.
No training on your content. We do not use your content to train our models. Your inputs are used only to deliver the requested output to you.
AI output limitations. AI-generated output may be inaccurate, incomplete, or not unique. You are solely responsible for reviewing all AI-generated content before publishing or distributing it.
No IP clearance. We do not warrant that AI-generated output, including synthetic voices, music, images, or text, is free from third-party intellectual property rights. It is your responsibility to conduct any clearance or legal review necessary before using AI-generated content commercially.
AI content marking. Published audio is embedded with a machine-readable marker indicating it was AI-generated, applied at publication and logged. This marking is designed to assist platforms and regulators in identifying AI-generated content. It is not an absolute guarantee of detectability across all playback or processing environments.
Your privacy rights
This section describes your rights with respect to your personal information. The rights available to you depend on where you are located. We describe them in full below and will honor whichever rights apply to you based on your location. To exercise any right, contact us at privacy@linnetmedia.com with the subject line "Privacy Rights Request" and include your name, account email address, and a description of the right you wish to exercise. We may ask you to verify your identity before processing your request. We will respond within 30 days or such shorter period as applicable law requires.
7.1Rights for all users
Regardless of where you are located, you may:
- access the personal information we hold about you and receive a copy;
- correct inaccurate or incomplete personal information;
- request deletion of your personal information, subject to our legal retention obligations;
- receive your personal information in a portable format where technically feasible;
- opt out of marketing communications at any time;
- opt out of uses of your personal information for purposes materially different from those for which it was originally collected, or disclosure to third parties for their independent purposes.
7.2EEA, UK, and Swiss users, GDPR and revDSG rights
If you are located in the EEA, UK, or Switzerland, you have the following additional rights under the GDPR (and, for Swiss users, the revDSG):
Right of access (Article 15 GDPR). You may obtain confirmation of whether we process your personal data and, if so, a copy of that data together with the information set out in Article 15(1), including purposes, categories, recipients, and retention periods.
Right to rectification (Article 16 GDPR). You may obtain correction of inaccurate personal data and completion of incomplete personal data without undue delay.
Right to erasure (Article 17 GDPR). You may obtain erasure of your personal data where: it is no longer necessary for the purpose for which it was collected; you withdraw consent and there is no other legal basis; you object and there are no overriding legitimate grounds; it has been unlawfully processed; or erasure is required by law. This right does not apply where processing is necessary to comply with a legal obligation (such as our 7-year billing records retention) or for the establishment, exercise, or defense of legal claims.
Right to restriction (Article 18 GDPR). You may obtain restriction of processing where: you contest accuracy; processing is unlawful but you oppose erasure; we no longer need the data but you require it for legal claims; or you have objected pending verification of our legitimate grounds.
Right to data portability (Article 20 GDPR). Where processing is based on consent or contract and carried out by automated means, you may receive your personal data in a structured, machine-readable format and transmit it to another controller.
Right to object (Article 21 GDPR). You may object at any time to processing based on legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests or the processing is necessary for legal claims. You have an unconditional right to object to processing for direct marketing.
Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
We will respond to all rights requests within one month as required by Article 12 GDPR, with the right to extend by a further two months for complex or numerous requests, with notice within the first month.
7.3California users, CCPA/CPRA
If you are a California resident, you have the right to know what personal information we collect, use, and share; to access and delete your personal information; to correct inaccurate personal information; to limit use of sensitive personal information; and not to be discriminated against for exercising your rights. We do not sell your personal information and do not share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) browser signals as opt-out signals where required. To exercise your California rights, contact us at privacy@linnetmedia.com.
7.4Other US state residents
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Texas, Connecticut, and others, have rights including access, correction, deletion, portability, and the right to opt out of targeted advertising and profiling. Contact us at privacy@linnetmedia.com and we will respond within the timeframe required by your state’s law.
7.5Biometric and voice data rights (Illinois, Texas, Washington)
The Service does not currently create voice prints or cloned-voice models and does not collect biometric identifiers under laws such as BIPA (Illinois), the Texas Capture or Use of Biometric Identifier Act, or the Washington My Health MY Data Act. If we introduce a feature that creates such data, we will provide the required notice, obtain consent, and comply with applicable retention and deletion obligations before collecting any biometric data.
7.6Recourse and enforcement
If you are located in the EEA, UK, or Switzerland and believe we have processed your personal data in violation of applicable data protection law, you have the following recourse options in addition to the rights described in Sections 7.1 and 7.2:
Step 1, contact us directly. Email privacy@linnetmedia.com. We will investigate and respond within 45 days.
Step 2, supervisory authority cooperation. You may lodge a complaint with the data protection supervisory authority in your country of residence or place of work. A directory of EEA supervisory authorities is available at edpb.europa.eu. The UK supervisory authority is the Information Commissioner’s Office at ico.org.uk. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner at edoeb.admin.ch.
7.7Automated agents and appeals
You may use an authorized agent to submit a rights request where applicable law permits, with proof of authorization. If we deny a rights request, you may appeal by emailing privacy@linnetmedia.com with "Privacy Rights Appeal" in the subject line. You may also contact your state attorney general or data protection authority if you remain unsatisfied.
Data retention
We retain your personal information for as long as your account is active and as long as needed to provide the Service, subject to the following schedules. These periods reflect the storage limitation principle under Article 5(1)(e) GDPR and applicable US law.
Account and profile data: on account deletion, identifying fields (name, email address, profile image, and authentication credentials) are removed and the account record is marked deleted. A minimal anonymized record is retained to preserve system integrity and prevent account collision; this record is not personal data.
Content and project files: retained for the duration of your account, plus 30 days post-closure, after which they are permanently deleted.
Generated audio files: retained for the duration of your account and for 30 days following account closure, consistent with the lifecycle for other content and project files, after which they are permanently deleted.
Backup copies: purged within approximately 90 days of the original deletion date.
Billing and transaction records: retained for 7 years from the transaction date to comply with applicable accounting, tax, and financial recordkeeping obligations.
Support and communications data: retained for no longer than 3 years from last contact.
Legal hold: data subject to litigation, regulatory inquiry, or legal hold is retained for as long as required, after which standard deletion applies.
The retention periods above describe two distinct events. If your account lapses or is closed, your content and project files are retained for 30 days to allow for data export before permanent deletion. If you submit an affirmative deletion request through your account settings, your personal information is permanently deleted within approximately 7 days. When you delete your account, you are immediately signed out and your access is terminated.
Content you created while signed in to your account is removed as part of this process. Content created without being signed in is not linked to your account and cannot be removed through account deletion; it is deleted automatically on a time-based schedule.
Permanent deletion from our storage systems is completed within approximately 7 days of your account deletion request.
Content you have already published to third-party platforms is outside our control to delete.
Third-party service providers. When you delete your account, we will request deletion of your personal information from the service providers we use on your behalf. Most providers honor these requests as part of their standard data processing commitments. Where a provider cannot delete your data at the individual record level we will let you know when you make your deletion request, and your data with that provider will be handled under that provider’s own retention schedule. Where we anonymize data rather than delete it, the anonymized data is no longer personal data and is not subject to these retention periods.
Children
The Service is directed exclusively to adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. Under Article 8 GDPR, the age of consent for information society services varies by EEA member state between 13 and 16. Because our minimum age is 18, we do not rely on parental or guardian consent for any user and we do not process personal data of anyone under 18.
If we learn we have collected personal information from a person under 18, we will delete it promptly. If you believe a minor has registered for or used the Service, please contact us at privacy@linnetmedia.com.
Security
We implement reasonable and appropriate technical and organizational measures to protect your personal information against unauthorized or unlawful access, disclosure, alteration, loss, or destruction. These measures include encryption of data in transit using TLS, encryption of data at rest, access controls limiting data access to authorized personnel who need it to perform their responsibilities, and breach-response procedures designed to detect, contain, and notify affected individuals and authorities as required by law. We require our service providers to implement comparable measures.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security breach that affects your personal information, we will notify you and the relevant authorities as required by applicable law.
To report a potential security vulnerability or concern about your account, contact us at security@linnetmedia.com.
Cookies and similar technologies
We use cookies only to keep you logged in to the Service. We do not use analytics cookies, tracking cookies, or behavioral profiling cookies, and we do not use any third-party session recording tools. If you disable cookies through your browser settings, you will not be able to sign in. Because we use only strictly necessary cookies, no cookie consent banner is required under applicable EU, UK, or US law.
Data Protection Officer and EU/UK representative
Caloroga Shark Media LLC has assessed its obligations under Article 37 GDPR and has determined that appointment of a Data Protection Officer is not required. Data protection inquiries may be directed to privacy@linnetmedia.com.
EU and UK representatives. Caloroga Shark Media LLC is in the process of designating representatives in the European Economic Area and the United Kingdom as required by Article 27 GDPR and Article 27 UK GDPR. EEA and UK data subjects may in the meantime direct all data protection inquiries, including inquiries to a local representative, to privacy@linnetmedia.com. We will update this section to name the designated representatives once appointments are confirmed.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide notice through the Service or by email and update the effective date above. For material changes to how we handle voice or biometric data, we will obtain renewed consent before the new practice takes effect. Continued use of the Service after notice of a material change constitutes acceptance of the updated policy.
Contact us
For questions about this policy or to exercise your privacy rights: