Privacy Policy

Effective 8 September 2026

Supermix (“Supermix”, “we”, “us”) produces podcasts and other content for creators and companies, and runs the Supermix Studio our customers use to work with us. This policy explains what personal information we collect, how we use it, and who we share it with.

It covers supermix.io, the Supermix Studio (our app and customer portal), and the integrations we offer, including our YouTube publishing integration. Questions go to ops@supermix.io.

1. Information we collect

  • Contact details you give us when you enquire, book a call, email us or are invited to the Supermix Studio: your name, email address and company.
  • Billing details such as billing contacts, addresses and tax identifiers. Card details are entered directly with our payment provider and we do not store full card numbers.
  • Content you ask us to produce, including recordings, footage, transcripts and artwork, which may include personal information about hosts and guests.
  • Technical data such as your IP address and browser type, used to keep our website and Studio secure and working.
  • Information from services you connect, such as a YouTube channel. Section 3 describes this in detail.

2. How we use information

We use personal information to provide the services you ask for, including producing and publishing content on your behalf; to communicate with you about that work; to manage accounts and invoices; and to keep our systems secure. We do not sell personal information, and we do not use it for third-party advertising.

3. Connected accounts, Google user data and YouTube

Supermix uses YouTube API Services to publish videos to YouTube channels our customers connect. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy.

What we ask for

When a customer administrator connects a channel, we request two permissions from Google:

  • Upload videos (youtube.upload). Lets us upload videos, set their titles, descriptions, thumbnails and privacy status, and schedule them, on the channel you connect.
  • View your channel (youtube.readonly). Used only to look up the identity of the channel you connected (its ID, name, handle and avatar) so you can confirm the right channel is linked. We do not read your existing videos, comments, subscribers, watch history or analytics.

What we store

We store the channel ID, name, handle and avatar, the permissions Google actually granted, the OAuth access and refresh tokens Google issues, who connected the channel and when, and the connection’s health. Tokens are encrypted at rest. They are decrypted only inside our backend when publishing or refreshing the connection, are never shown to Supermix staff, and are never sent to a browser.

How we use it

We use this access only to publish content your team has asked us to publish, with the title, description, thumbnail, schedule and privacy status you approve, and to keep the connection working. We do not use Google user data for advertising, we do not sell it, and we do not use it to train machine-learning or AI models.

Who we share it with

Google user data is sent to Google to perform the actions you request and is stored with the infrastructure providers that host our systems. Your teammates in the Supermix Studio can see which channel is connected and what has been published to it. We do not otherwise share Google user data with anyone.

Revoking access

You can disconnect a channel at any time from the connections page in the Supermix Studio. When you do, we ask Google to revoke the grant and delete our copy of the tokens. You can also remove Supermix’s access from your Google Account permissions. After disconnecting we keep a non-sensitive record of the channel name so previously published posts remain readable in your history.

Google Calendar

Members of the Supermix team may connect their own Google Calendars to the Supermix Studio so colleagues can see their availability. This uses read-only calendar access together with basic profile information (name, email and photo). Tokens are handled the same way as described above, and calendar data is used only to display availability inside the Supermix Studio.

Limited Use

Supermix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we share information

We share personal information only as needed to run Supermix: with service providers that host and run our systems on our behalf and under our instructions; with the distribution platforms you connect or ask us to publish to, which receive the content you approve; with other members of your team in the Supermix Studio; and where the law requires it.

5. Retention and security

We keep personal information for as long as we are working with you and as long as tax and accounting law requires afterwards. Connected account tokens are deleted when you disconnect the account. We return or delete your content on request. We protect personal information with encryption in transit, encryption at rest for credentials such as OAuth tokens, and access controls that limit customer content to the people working on it.

6. Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct or delete it, or disconnect a connected account at any time. Email ops@supermix.io and we will respond within the timeframes required by applicable law.

7. Changes to this policy

We may update this policy from time to time. We will post the new version on this page and update the effective date at the top.

8. Contact

You can reach us at ops@supermix.io.