Legal
Last updated 15 August 2026
Kiln is a podcast player made by Harigovind Valsakumar. This policy describes everything it collects, which is very little, and names the two cases where anything at all leaves your device to a server we run: new-episode alerts, which are free and off until you ask for them, and Kiln Plus.
There is no Kiln account. We operate no sign-up, no login of our own and no user records — there is no server of ours that holds anything about you as a person. Kiln does offer Sign in with Apple, which is optional and does one thing: it turns on iCloud sync. What Apple hands over stays on your device. See Signing in, and iCloud sync.
There is no tracking, no advertising, no analytics SDK, and nothing is sold or shared with anyone for marketing.
| What you use | What leaves your device | Where it goes |
|---|---|---|
| Kiln, free | Nothing but the podcast feeds you subscribe to | The publishers' own servers |
| Discover | Your search terms | Podcast Index, and Apple for chart order |
| Sign in with Apple | Nothing reaches us. Apple gives Kiln your identifier, name and email; they stay on this device | Your device's Keychain |
| iCloud sync, once signed in | Your library, positions and anything you generated | Your own iCloud account, which we cannot read |
| Transcripts | Nothing | Made on your device |
| Apple Intelligence | Nothing | Made on your device |
| Your own API key | The episode text you asked to summarise | The provider you chose, using your key. Never through us |
| New-episode alerts | The addresses of the shows you turned the bell on for, and your device's notification token | Kiln's server, so it can watch them for you. Addresses are stored encrypted |
| Kiln Plus | The episode text you asked to summarise | Kiln's server, then Google Gemini. Not stored |
Optional, and off until you use it. Nothing here involves a server we run.
Why it exists. Signing in with Apple is how Kiln turns on iCloud sync. That is the only thing it does — there is no Kiln account behind it, nothing to log in to, and no feature gated on being signed in other than sync itself.
What Apple gives Kiln. An identifier for you that is specific to this app, and — only the first time you authorise it — your name and email address, or Apple's private relay address if you chose to hide your real one.
Where that goes. Your device's Keychain, and nowhere else. It is never sent to us, never synced, and never joined to anything. We have no server capable of receiving it.
What sync does. Your subscriptions, positions, downloads, history and anything you generated are copied into your own private iCloud database. Apple stores it under your Apple Account; we cannot read it and are not a party to it. If your device has no iCloud account, Kiln carries on locally and says so.
A profile picture is one you choose from your own photo library, if you want one. It is stored on the device, downsampled, and is never uploaded anywhere.
Signing out erases the identifier, the name, the email and the picture from this device.
Your subscriptions, play positions, downloads, listening history, settings and any transcripts or summaries you generate live on your device. If you turn on iCloud sync they are stored in your iCloud account, which we cannot read.
If you add your own API key it is kept in your device's Keychain. It is sent only to the provider it belongs to, is never synced, and never reaches us.
Searching Discover sends your search text to Podcast Index to get results back. The Top Shows chart order comes from Apple's public podcast chart feed. Neither request carries any identifier for you or your device beyond the ordinary information any web request includes.
One of the two parts of Kiln that talk to a server we run — the other is new-episode alerts, below — and the only one that sends anything about an episode.
When you ask for a summary or chapters, the text of that episode is sent to Kiln's server, which passes it to Google Gemini and returns the result. Google's terms for the paid tier prohibit them from using it to train their models.
The episode text is not stored. Once the result comes back, the text is gone.
One row per request, containing:
That identifier is a random value. It is not derived from your name, your email, your Apple ID, your phone or your device. We cannot connect it to you, and it is the only thing tying any two requests together.
The episode, the show, the podcast, the text, your IP address, your location, your name or your email. We do not know what you listen to, and the log is not capable of telling us.
One honest qualification, because “our records do not contain it” and “nobody has it” are different claims and only the first is ours to make: Cloudflare, which runs the server your request passes through, sees the IP address that any web request carries, and keeps it briefly for abuse prevention. That is true of every website you visit. Kiln neither reads it nor stores it, and it appears in no record we hold.
To enforce the monthly allowance you bought, and to see total usage across all subscribers.
Generated summaries and chapters are cached so that if another subscriber asks about the same episode it doesn't have to be made twice. Those entries are stored against a one-way hash of the episode and carry nothing about any person.
Turning on the bell for a show means Kiln's server has to watch that show for you, so it needs the address of its feed. Your phone cannot do this reliably — iOS only wakes an app in the background when it feels like it, and stops entirely once the app has been force-quit, which is why an alert could arrive hours late or not at all.
What is stored: your device's push notification token, and the feeds of the shows you belled. Nothing else — not the rest of your library, not what you play, not how far through you are, and nothing connecting any of it to a Kiln Plus subscription or a payment. The alerts table holds a push token and no account identifier of any kind.
Feed addresses are encrypted. Some feeds are private: a premium or subscriber-only show gives you a personal address that acts as the key to it. Kiln therefore never stores an address in readable form. Each is kept encrypted, and identified by a value derived from it with a secret key, so a copy of the database on its own reveals neither which shows are being watched nor how to reach a private one. The server decrypts an address only at the moment it fetches the feed.
Notifications carry the show and episode title and nothing else.
Turning alerts off, for one show or all of them, deletes those rows. Deleting the app has the same effect: once Apple reports the device as gone, the record is removed on the next check.
Alerts are free and need no subscription. If you would rather nothing were stored, leave the bell off — Kiln still checks your feeds in the background and when you open it, just less punctually.
Your Apple identity: Settings → Sync → Sign out. The identifier, name, email and picture are erased from this device. There is nothing held anywhere else to delete, because none of it ever left. Your library stays where it is.
Kiln Plus usage: Settings → About → Delete my usage history. It removes every row described above, immediately.
Two things survive it, and both are stated plainly in the app:
Cancelling your subscription, or deleting the app, ends everything.
If you publish a podcast and would prefer generated summaries of your episodes were not cached, email the address below with your feed URL and they will be removed. Transcripts you publish yourself are never cached, altered or served — Kiln always uses yours in preference to making its own.
Kiln is not directed at children. Kiln Plus is not available to anyone under 18, because Google's terms for the Gemini API require it.
Kiln is not offered in the European Union.
For Kiln Plus subscribers only:
| Who | What they handle |
|---|---|
| Google (Gemini API) | Episode text, to produce a summary. Paid tier — not used for training |
| Cloudflare | Runs the server the request passes through |
| Supabase | Stores the usage rows described above |
| Apple | Handles the payment. We never see your payment details |
If this policy changes materially, the app will say so before the change takes effect.