Listenbox

Privacy policy

Listenbox uses account data and creator-owned content to run podcast hosting, managed YouTube publishing, migration, distribution, and user-requested episode preparation workflows.

Last updated: August 24, 2026.

Who we are

Listenbox is operated by Pneuma LLC, a New Mexico limited liability company. Pneuma LLC's mailing address is 1209 Mountain Rd Pl NE PMB 7944, Albuquerque, NM 87110. Privacy questions and requests can be sent to hello@listenbox.app.

Scope

This policy applies to Listenbox websites, accounts, podcast workspaces, publishing tools, managed YouTube publishing, support, and YouTube migration beta workflows. It does not apply to third-party podcast platforms, listening apps, payment providers, Google, YouTube, or other services that you choose to connect or use. Those services have their own privacy practices.

Information collected

Listenbox may collect account and workspace information, including your name, email address, login method, organization or workspace details, show names, episode records, support messages, and security or session data needed to operate the service.

If you choose Continue with Google, Listenbox receives the Google account identifier, name, and email address that Google provides so Listenbox can authenticate you and associate the sign-in with your Listenbox account. Listenbox does not receive your Google password.

If you connect a YouTube channel for managed publishing, Listenbox may access, collect, and store the following information through YouTube API Services:

  • Your encrypted Google refresh credential. Short-lived access tokens are used transiently for authorized operations.
  • The identifiers and names of the YouTube channel and playlists available to the connected account, and the playlist you select for a show.
  • The video file and the title, description, privacy setting, and other publishing details that you provide or approve for an upload.
  • The resulting YouTube video identifier, playlist membership, processing or publishing status, and API error details needed to complete the upload and show its status in Listenbox.

Google calls information accessed through an authorized YouTube API request "Authorized Data" or "API Data." Listenbox requests this data only when you connect YouTube or use a YouTube publishing feature.

For a direct YouTube import, Listenbox may collect creator-owned content and related data from the channel or playlist you select after you connect the Google account that owns or manages the source.

The migration data may include:

  • YouTube uploaded video media.
  • YouTube video metadata, including titles, descriptions, dates, thumbnails, and related episode fields available for the selected source.
  • YouTube channel data needed to confirm and describe the selected source.
  • YouTube playlist data needed to display and import the selected playlist.
  • Optional migration data only when implemented, requested, and authorized by you.

Listenbox may also collect technical information such as IP address, device and browser details, request logs, error logs, referral pages, and approximate location derived from network information. If paid features are available, payment details are handled by payment providers, and Listenbox may receive billing status, plan, invoice, and customer identifiers.

How information is used

Listenbox uses imported creator-owned content and related migration data to move your YouTube podcast playlist into Listenbox, create episode records and podcast-ready assets, and let you review, edit, publish, and distribute episodes.

For managed YouTube publishing, Listenbox uses your authorization and selected publishing settings to perform specific YouTube API operations. channels.list identifies the authorized channel; playlists.list displays existing playlists; videos.insert uploads user-provided media privately; videos.list monitors processing and verifies state; videos.update applies the approved metadata and final visibility; and playlistItems.list and playlistItems.insert prevent duplicates and perform optional playlist placement. videos.delete is used only to compensate an unpublished Listenbox-created back-catalog upload when that operation is cancelled. Listenbox does not access or modify ratings, comments, or captions.

Listenbox also uses information to create and secure accounts, operate workspaces, host media, generate RSS feeds and show websites, support publishing and distribution, provide customer support, prevent abuse, troubleshoot errors, analyze service reliability, comply with legal obligations, and enforce the terms.

If you choose transcript, copy, or chapter generation for imported media, Listenbox may use that imported media to create those requested assets. Listenbox uses imported media for AI-assisted features only when you request them for that media.

Ownership

Your imported videos, metadata, thumbnails, show information, and related episode materials remain your content. Connecting Google lets Listenbox confirm the YouTube source you control; it does not make that podcast content Google-owned content or Listenbox-owned content.

Google authorization, YouTube API Services, and limited use

Listenbox uses YouTube API Services for managed YouTube publishing. Google's Privacy Policy explains how Google handles information. Listenbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

For publishing, Listenbox requests only https://www.googleapis.com/auth/youtube.force-ssl. The narrower youtube.upload scope does not authorize videos.update or playlistItems.insert, so it cannot complete the user-approved publishing flow. Listenbox does not use the publishing scope to change or delete unrelated videos, post comments, rate videos, manage subscriptions, or take other unrelated actions on your YouTube account. Although youtube.force-ssl exposes video deletion, Listenbox uses videos.delete only to roll back an unpublished Listenbox-created upload after cancellation. Published videos are never deleted by Listenbox.

For direct YouTube imports, Listenbox uses read-only YouTube authorization to identify the connected channel and list the channels, playlists, and video metadata available to the selected source. The experimental import backend then retrieves media available for that source. Import authorization does not grant YouTube publishing access and is not used to import viewer subscriptions, watch history, or saved playlists.

Listenbox does not sell Google user data, YouTube API Data, imported creator-owned content, or YouTube migration data. Listenbox does not use that data for advertising, retargeting, credit or lending decisions, data broker or information reseller products, surveillance, or unrelated product development. Listenbox does not use Google user data or YouTube API Data to train generalized or personalized AI or machine-learning models.

Storage and retention

Imported creator-owned content and migration data from the direct-import pilot are stored in Listenbox infrastructure and object storage. Account, workspace, media, metadata, logs, and support records are retained while needed to provide the service, meet legal obligations, resolve disputes, maintain security, prevent abuse, or enforce agreements, unless deleted earlier by user action or retention policy.

Deletion from active systems may not immediately remove data from backups, logs, caches, distribution destinations, or third-party services. Backup copies are retained for a limited period and then overwritten or deleted according to operational retention schedules.

YouTube OAuth credentials are encrypted at rest and retained only while needed to operate a connection that you authorized. A daily scheduled workflow checks each active connection once its last successful validation is 25 days old. It refreshes the access token, confirms the authorized channel, refreshes current channel and selected-playlist details, validates stored delivery references, and deletes provider-derived caches before they can exceed the 30-day Authorized Data limit. Temporary timeouts, malformed responses, rate limits, network failures, and Google server errors are retried and do not cause disconnection or data deletion.

Content that you upload directly to Listenbox, metadata that you enter in Listenbox, and Listenbox's own episode and publishing records are not treated as data retrieved from YouTube merely because you later choose to publish that content to YouTube. Those records follow Listenbox's normal retention and deletion rules.

Sharing

When you publish to YouTube, Listenbox sends the video and publishing details you approved to Google and YouTube. Listenbox discloses Google user data and YouTube API Data only to Google and YouTube, service providers that supply infrastructure, security, storage, error monitoring, or support needed to operate the connection, and legal or security processes when required. Those providers may process the data only for Listenbox, only as needed to provide the user-facing service, and under appropriate confidentiality and security obligations. Listenbox does not disclose YouTube OAuth tokens to advertising, analytics, payment, email, or AI providers.

Other Listenbox data may be shared with service providers needed to operate the service, including hosting, object storage, database, analytics, error monitoring, support, email, payment, security, and AI processing providers. Listenbox may also share creator content with distribution targets you select and connected accounts you authorize. AI processing providers receive creator content only when you request an AI-assisted feature for that content; they do not receive your YouTube OAuth credentials.

Listenbox does not sell imported creator-owned content or YouTube migration data to data brokers or ad platforms. Listenbox does not share imported creator-owned content or YouTube migration data for cross-context behavioral advertising.

Security

Listenbox protects data with HTTPS in transit, encryption at rest for OAuth tokens and sensitive credentials, access controls that restrict data to people and systems that need it, and operational security reviews. No online service can guarantee absolute security. Security questions or incident reports can be sent to hello@listenbox.app.

Cookies and similar technology

Listenbox may use cookies, local storage, and similar technology on your device to maintain sessions, protect accounts, remember settings, prevent abuse, and measure service reliability. Listenbox does not use Google user data or YouTube API Data for personalized or interest-based advertising.

Deletion and revocation

You can delete imported episodes and media, delete a show, workspace, or account, and request support deletion at hello@listenbox.app.

You can disconnect YouTube through Listenbox's connected-account controls or revoke Listenbox's access through your Google Account security settings. When you disconnect through Listenbox, Listenbox requests immediate revocation of the Google authorization token. After Google confirms revocation—or reports that the token is already invalid—Listenbox removes the stored refresh credential and associated active YouTube Authorized Data in the same account cleanup operation. If Google revocation fails temporarily, Listenbox does not report success or delete the local credential; the operation can be retried deterministically. This behavior is designed to delete Authorized Data as soon as possible and within seven days of an in-app revocation request.

When you revoke Listenbox through Google Account settings, Listenbox detects the invalid authorization during the next authorized operation or scheduled validation. At that point it removes the unusable credential and related API Data, stops dependent publishing and import work, and notifies team members who can reconnect. Temporary timeouts, network failures, malformed responses, rate limits, and Google server errors are not treated as proof of revocation.

Deleting a Listenbox episode or podcast, removing a YouTube destination, disconnecting YouTube, or deleting stored YouTube API Data does not delete published YouTube videos. Manage or delete those videos in YouTube Studio. Data sent to another distribution destination is also subject to that destination's controls and policies.

Privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, export, restriction, or objection to certain processing of personal information. You may also have the right to withdraw consent where processing is based on consent, opt out of certain sharing or targeted advertising, and lodge a complaint with a regulator.

To make a privacy request, contact hello@listenbox.app or write to Pneuma LLC, 1209 Mountain Rd Pl NE PMB 7944, Albuquerque, NM 87110. Listenbox may ask for information needed to verify the request and protect the account.

International transfers

Listenbox may process and store information in the United States and other countries where Listenbox or its service providers operate. Those countries may have data protection laws different from your country.

Children

Listenbox is not directed to children under 13, and the YouTube migration beta is not intended for users under 18. Do not use Listenbox to submit children's personal information unless you have the rights and consents required by applicable law and platform rules.

Limited-use commitments summary

  • Listenbox does not sell Google user data, YouTube API Data, imported creator-owned content, or YouTube migration data.
  • Listenbox does not use imported creator-owned content or YouTube migration data for targeted ads, retargeting, lending, creditworthiness, or data broker or reseller products.
  • Listenbox does not use Google user data or YouTube API Data to train generalized or personalized AI or machine-learning models.

Updates

Listenbox may update this policy as the service, law, or operational practices change. Material updates will be posted on this page or provided through another reasonable notice.

Contact

Privacy questions and requests can be sent to hello@listenbox.app or Pneuma LLC, 1209 Mountain Rd Pl NE PMB 7944, Albuquerque, NM 87110.