Security & trust

Podz is built for organizations that hold sensitive program and people data — including schools and community programs. This page summarizes authentication, hosting, subprocessors, incident response, deletion, and our current compliance posture.

Last updated: July 24, 2026. Related: Privacy Policy.

Authentication

Users sign in via Firebase Authentication (email, Google, and other supported providers). Sessions are validated on each API request. Organization-scoped data is enforced server-side — not only in the UI.

Access control

Data is scoped to organizations. Staff and admin roles control who can manage mandates, commitments, billing, and integrations within an org. The authenticated app routes are not indexed by search engines.

Infrastructure & hosting

Podz runs on Google Cloud. The API is served on Cloud Run; object storage holds static assets and uploads. Production traffic uses HTTPS. Primary production compute is in us-central1 (United States). Media and static assets may be delivered via CDN (including Bunny.net).

Subprocessors

We use the following third-party providers to operate Podz. Optional integrations are connected only when your organization authorizes them.

ProviderRoleNotes
Google Cloud PlatformHosting, storage, schedulingCore infrastructure
Google FirebaseAuthenticationCore infrastructure
Bunny.netCDN / media deliveryStatic and uploaded media
SendGridEmail delivery and inbound parseTransactional / product email
StripeBilling and paymentsWhen you purchase a plan
Google AnalyticsProduct and marketing analyticsLoaded only after cookie consent; IP anonymization enabled
TwilioSMSOptional — org must enable SMS
SlackWorkspace messagingOptional — org must connect Slack
Google (Gmail / Workspace APIs)Email automationOptional — org must connect Gmail
OpenAIOptional AI assist (Cora)Optional — only when AI features are used
Google GeminiOptional AI assistOptional — only when AI features are used

We do not sell personal data. Service providers may process data only to provide services to Podz. For education customers, we recommend leaving SMS, Slack, Gmail automation, and AI assist disabled unless your IT or privacy office has approved those subprocessors.

Breach notification

If we confirm a security incident that results in unauthorized access to, or acquisition of, Customer Data, we will notify the affected organization’s designated admin contacts without undue delay and within 72 hours of confirmation (or sooner when required by applicable law).

Notification will describe, to the extent known: the nature of the incident, categories of data involved, approximate scope, mitigation steps underway, and a contact for follow-up. We will cooperate with organizational notification obligations under applicable law, including FERPA and state student-privacy requirements for education customers under a DPA.

Report a suspected security issue immediately to info@podz.ai.

Deletion & retention

Organization admins can remove people and work records in-product (some records are soft-deleted and hidden from normal use). Individuals and organizations may also request access or erasure by emailing dpo@podz.ai.

  • We acknowledge verified privacy requests within 10 business days and complete production-data erasure for verified requests within 30 days (or sooner when required by law), unless a longer period is legally required (for example, billing records we must retain).
  • Residual copies in encrypted backups are removed on the normal backup rotation, typically within 90 days after production deletion.
  • Disconnecting an optional integration stops new sync; historical copies already stored in Podz remain until deleted in-product or via a verified erasure request.

Compliance posture

  • SOC 2: Podz is not currently SOC 2 Type I or Type II certified. We operate with the controls described on this page and will share audit roadmap updates with customers on request.
  • FERPA / schools: For K–12 and higher-education customers, we will sign a Data Processing Agreement (DPA) that addresses student data handling and “school official” style obligations where applicable. Download our standard DPA template or contact dpo@podz.ai.
  • COPPA: Podz is not directed to children under 13. We do not knowingly create accounts for children under 13. Schools that need under-13 use must contact us in writing before onboarding so we can confirm contractual and parental-consent requirements.
  • GDPR / CCPA: Privacy rights requests are handled as described in our Privacy Policy.

Education & classroom use

When Podz is used in a school or classroom context, we commit to the following (and will reflect these terms in education DPAs on request):

  • We do not sell student personal data.
  • We do not use student personal data to deliver third-party advertising.
  • We do not use Customer Data from education organizations to train generalized foundation models. Optional AI features send prompts to the model provider only when those features are used; schools may leave AI disabled.
  • Google Workspace API data (when Gmail is connected) is not retained to develop, improve, or train generalized AI/ML models, consistent with Google’s Limited Use requirements.
  • Recommended classroom configuration: dedicated school organization; collect only name and school email; leave birthday and personal phone blank; keep SMS, Slack, Gmail automation, and AI assist off until IT approves.

Integrations

Optional integrations (Slack, Gmail, SMS via Twilio, Stripe for billing, AI assist) connect only when authorized by your organization. Integration credentials are stored securely and scoped to the connecting org.

Contacts

  • Security incidents and vulnerability reports: info@podz.ai
  • Privacy, education, DPA, and data-subject requests: dpo@podz.ai
  • Standard Data Processing Agreement template (including education / FERPA schedule): podz.ai/dpa.html
We only use cookies to store your preferences and to keep you logged in. By continuing to use this website, you agree to our use of cookies.