whatayarn (https://whatayarn.com (opens in a new tab)) is a voicemail link for podcasters and creators. This policy explains what data we collect, how we use it, who processes it for us, and the choices you have.
It covers three groups of people:
- Creators: you have a whatayarn account and a page where you receive voice messages.
- Senders: you leave a voice message on a creator’s page. You do not need an account.
- Visitors: you browse our site or a creator’s page.
1. The Data We Collect
If you send a voice message
| Data | Details | Why we collect it |
|---|---|---|
| Your recording | The audio you record or upload, stored as an MP3 | Delivering it to the creator’s inbox |
| What you type into the form | Your name and email if the creator asks for them (optional unless the creator has made them required), a title, a note, and answers to any questions the creator has added, such as an order number | Telling the creator who the message is from and what it is about |
| Source details | The website you came from (its address only, never the full page link), your browser, device type and operating system, and an approximate city, region and country estimated from your network. Creators can turn this off for their page (see section 2) | Shown to the creator with the message so they can see where their messages come from |
| Rate-limit key | Your IP address is read from the request and immediately reduced to a hash that expires within ten minutes. The address itself is not stored with your message | Stopping spam and abuse |
| Remembered details | After a successful send, your name and email are saved in your own browser’s local storage so you do not have to retype them next time. They stay on your device | Convenience |
We do not transcribe, analyse or listen to recordings ourselves. We store them and deliver them.
If you have a creator account
| Data | Details | Why we collect it |
|---|---|---|
| Account data | Name, email address and profile photo from Google, or the email address you sign in with | Creating your account, signing you in, and support |
| Your page | Page name, bio, image, links, colours and the questions on your send form | Publishing your page. This content is public by design |
| Billing data | Payment details, processed and stored by Stripe. We keep only your Stripe customer ID and current plan, and never see your full card number | Subscriptions and invoicing |
| Product feedback | The rating and comment you submit from the in-app feedback widget | Improving whatayarn |
If you visit our site or a creator’s page
| Data | Details | Why we collect it |
|---|---|---|
| Page views on creator pages | A random first-party visitor ID stored in your browser, the address of the site you came from, your browser’s user-agent string, the page path, and any UTM campaign tags in the link you followed | Powering the creator’s Insights: visits, sources and devices |
| Product analytics (PostHog (opens in a new tab)) | Product events such as “recording started” or “message sent”, browser and device type, approximate location estimated from your IP address (which PostHog then discards), and session replays in which anything typed, and every message and sender detail, is masked | Understanding how the product is used and fixing problems |
| Web analytics (Rybbit (opens in a new tab)) | Cookieless page views, the address of the site you came from, language, screen size, page performance timings, and clicks on a fixed list of public buttons such as “Start recording” | Site-level traffic statistics |
| Server logs (Vercel (opens in a new tab)) | IP address, user agent, request path and time, kept briefly by our hosting provider | Security and debugging |
Page views, product analytics and web analytics never include your recording, your name, your email or your form answers. PostHog creates a pseudonymous profile for visitors before sign-in, and if you sign in that activity is associated with your account. Session replay shows how our pages were used. Anything you type is masked, as is every message and sender detail shown in a creator’s inbox or on a listening page, and any text that looks like an email address. Replays exclude audio and video elements, remove query strings and private identifiers from the page address, and do not include console logs or network request bodies.
We do not intentionally collect sensitive categories of data (for example, health or political opinions) or data from children under 13 (see section 10).
2. Voice Messages You Send
When you leave a message on a creator’s page:
- Your recording is stored by whatayarn and delivered to that creator’s inbox. If the creator has notifications on, we also email them the message details, usually with the MP3 attached.
- Adding your name and email is optional, unless the creator has chosen to require it. The page tells you what is required before you send.
- Unless the creator has turned it off, they can see the website you came from, your browser, device type and operating system, and an approximate city, region and country. Location is estimated from your network, not GPS. A creator who turns Save message source details off in their settings receives only your recording and form answers, and the message is not linked to your visit.
- The creator can listen to, download and delete your message, and may use it in their own content, for example by playing it in a podcast episode. See our Terms of Service for details.
- A creator can share a message through a public listening link. That page shows your name and email if you gave them, the title, note and form answers, the recording, and when it was sent. It never shows where you came from or what device you used.
- If you want a message removed, contact the creator directly, or email us and we will help.
3. Questions Creators Add to Their Form
Creators can add their own questions to the send form, such as an order or customer number. The creator decides what to ask and why, and is responsible for that use, including telling their own customers about it where the law requires. whatayarn stores those answers with the message, shows them to the creator in their inbox and notification email, and does nothing else with them. We do not use form answers for analytics, marketing or any purpose of our own.
4. How We Use Your Data
- Provide the Service: store recordings, deliver them to inboxes, and keep you signed in.
- Process payments: through Stripe. We never see your full card details.
- Communicate with you: account notices, new-message notifications, and support replies.
- Improve and secure the Service: analytics, debugging, and spam and abuse prevention.
- Show and measure related products: present restrained links to other products we operate and understand whether those links are useful.
- Meet legal obligations: including under the Australian Privacy Act 1988 (Cth).
We may add optional processing of recordings in the future, such as automatic transcription, to make messages easier to read and search. If we do, it will only be used to provide the Service, and this policy will be updated before it launches.
5. Service Providers
We do not sell or rent your personal data. We share it only with the providers that run the Service. Each one processes data on our instructions and must keep it confidential.
| Provider | What it does | Sender data it receives | Creator and visitor data it receives |
|---|---|---|---|
| Supabase (opens in a new tab) | Database and sign-in | Message details: name, email, title, note, form answers and source details. Not the audio | Account data, page content, plan and page-view records |
| Vercel (opens in a new tab) | Hosting, file storage and request logs | Recordings, held in private storage and served only through whatayarn. Request logs with IP address and user agent, kept briefly | Page images and request logs |
| UploadThing (opens in a new tab) | Storage for files uploaded before September 2026 | Recordings received before we moved storage to Vercel, until they are deleted | Page images uploaded before that date |
| Resend (opens in a new tab) | The creator’s notification email: your name, email, title, note and form answers, usually with the MP3 attached | Creator email addresses, account emails, and emails sent to our support addresses | |
| Stripe (opens in a new tab) | Payment processing | None | Email address and billing details |
| PostHog (opens in a new tab) | Product analytics and session replay | Product events, browser and device type, an approximate location worked out from the IP address, which PostHog then discards, and session replays in which anything typed, and every message and sender detail, is masked. Never the recording, your name, your email or your form answers | The same, plus account email, name and plan for signed-in creators |
| Rybbit (opens in a new tab) | Web analytics | Page views, the address of the site you came from, language, screen size and page performance. IP address and user agent are used to estimate geography and filter bots | The same |
| Upstash (opens in a new tab) | Rate limiting | A hashed IP address, kept for at most ten minutes | The same |
If whatayarn is ever sold or restructured, your data may be transferred to the successor, who must continue to handle it under this policy.
6. Related-Product Links
Public pages may contain a promotional link to another product we operate, such as reroute.bio (opens in a new tab). When you view or click one of these links:
- We may record the promotion view or click as a whatayarn usage event through PostHog.
- If you follow the link, the destination receives the information ordinarily sent by your browser when opening a website, together with the campaign parameters included in the link.
- Your voice recordings and sender form responses are not transferred to the destination as part of that link.
7. Legal Bases (GDPR Visitors)
For EU/UK users, we rely on:
- Contractual necessity: to deliver the Service you signed up for.
- Legitimate interests: to keep the Service secure, understand how it is used, and improve it.
- Consent: where the law requires it, for example for marketing emails. You may withdraw it at any time.
- Legal obligation: to satisfy accounting or regulatory requirements.
8. Data Retention
| Data | Kept until |
|---|---|
| Account data | You delete your account. Deletion removes your pages, messages, recordings and sign-in record, cancels any subscription, and marks your analytics profile as deleted |
| Voice messages and form answers | The creator deletes the message, or deletes their account |
| Notification emails | Delivered emails, including any attached MP3, sit in the creator’s mailbox under their control. Resend keeps delivery records for a limited period |
| Page-view records | The creator’s page is deleted. They feed the creator’s Insights for as long as the page exists |
| Rate-limit keys | At most ten minutes |
| Server logs | Kept briefly by our hosting provider |
| Analytics events | Retained by PostHog and Rybbit under their retention settings. Profiles are pseudonymous unless you sign in |
| Financial records | 7 years, as required by law |
9. Your Rights & Choices
| Region | Your rights include |
|---|---|
| Australia | Access, correction, and complaint lodging under the Privacy Act 1988 |
| EU/UK (GDPR) | Access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority |
You can delete your account, and everything in it, at any time from your account settings. If you sent a message and do not have an account, you can still ask us to delete it or send you a copy. Tell us the creator’s page and roughly when you sent it. For anything else, email hello@whatayarn.com and we will respond promptly.
10. Children’s Privacy
The Service is not directed to children under 13. If you believe a child has provided personal data, please contact us so we can delete it.
11. Cookies & Local Storage
We do not use advertising cookies or ad networks. We use:
- Sign-in cookies from Supabase, so you stay signed in.
- Preference cookies that remember which page you were editing and whether the sidebar is open.
- Analytics identifiers set by PostHog in cookies and local storage.
- A first-party visitor ID in local storage on creator pages, so repeat visits count once in the creator’s Insights.
- A referral marker in local storage if you arrived through a link on a creator’s page, so we can credit that creator if you later sign up.
- Remembered sender details in local storage after you send a message, so you do not have to retype your name and email.
- Dismissed prompts in local or session storage, so we do not show you the same banner twice.
Most browsers let you refuse or delete cookies and site data, although disabling them may limit functionality, such as staying signed in.
12. Security
We use encryption in transit, role-based access controls and regular security reviews. Recordings are held in private storage and served only through whatayarn, either to the creator’s signed-in inbox or through unguessable listening links the creator chooses to create. Session replays mask anything typed and every message and sender detail, and a sender’s IP address is never stored with a message. No system is 100% secure, so we encourage using a strong, unique password with your sign-in provider.
13. Changes to This Policy
We may update this Privacy Policy periodically. If we make material changes, we will notify you, for example by email or a notice in the app, and post the update here with a new “Last updated” date. Continued use of the Service after changes means you accept the revised policy.
14. Contact
Questions or concerns? Email hello@whatayarn.com.