Security & trust
Podz is built for organizations that hold sensitive program and people data — including schools and community programs. This page summarizes authentication, hosting, subprocessors, incident response, deletion, and our current compliance posture.
Last updated: July 24, 2026. Related: Privacy Policy.
Authentication
Users sign in via Firebase Authentication (email, Google, and other supported providers). Sessions are validated on each API request. Organization-scoped data is enforced server-side — not only in the UI.
Access control
Data is scoped to organizations. Staff and admin roles control who can manage mandates, commitments, billing, and integrations within an org. The authenticated app routes are not indexed by search engines.
Infrastructure & hosting
Podz runs on Google Cloud. The API is served on Cloud Run; object storage holds static assets and uploads. Production traffic uses HTTPS. Primary production compute is in us-central1 (United States). Media and static assets may be delivered via CDN (including Bunny.net).
Subprocessors
We use the following third-party providers to operate Podz. Optional integrations are connected only when your organization authorizes them.
| Provider | Role | Notes |
|---|---|---|
| Google Cloud Platform | Hosting, storage, scheduling | Core infrastructure |
| Google Firebase | Authentication | Core infrastructure |
| Bunny.net | CDN / media delivery | Static and uploaded media |
| SendGrid | Email delivery and inbound parse | Transactional / product email |
| Stripe | Billing and payments | When you purchase a plan |
| Google Analytics | Product and marketing analytics | Loaded only after cookie consent; IP anonymization enabled |
| Twilio | SMS | Optional — org must enable SMS |
| Slack | Workspace messaging | Optional — org must connect Slack |
| Google (Gmail / Workspace APIs) | Email automation | Optional — org must connect Gmail |
| OpenAI | Optional AI assist (Cora) | Optional — only when AI features are used |
| Google Gemini | Optional AI assist | Optional — only when AI features are used |
We do not sell personal data. Service providers may process data only to provide services to Podz. For education customers, we recommend leaving SMS, Slack, Gmail automation, and AI assist disabled unless your IT or privacy office has approved those subprocessors.
Breach notification
If we confirm a security incident that results in unauthorized access to, or acquisition of, Customer Data, we will notify the affected organization’s designated admin contacts without undue delay and within 72 hours of confirmation (or sooner when required by applicable law).
Notification will describe, to the extent known: the nature of the incident, categories of data involved, approximate scope, mitigation steps underway, and a contact for follow-up. We will cooperate with organizational notification obligations under applicable law, including FERPA and state student-privacy requirements for education customers under a DPA.
Report a suspected security issue immediately to info@podz.ai.
Deletion & retention
Organization admins can remove people and work records in-product (some records are soft-deleted and hidden from normal use). Individuals and organizations may also request access or erasure by emailing dpo@podz.ai.
- We acknowledge verified privacy requests within 10 business days and complete production-data erasure for verified requests within 30 days (or sooner when required by law), unless a longer period is legally required (for example, billing records we must retain).
- Residual copies in encrypted backups are removed on the normal backup rotation, typically within 90 days after production deletion.
- Disconnecting an optional integration stops new sync; historical copies already stored in Podz remain until deleted in-product or via a verified erasure request.
Compliance posture
- SOC 2: Podz is not currently SOC 2 Type I or Type II certified. We operate with the controls described on this page and will share audit roadmap updates with customers on request.
- FERPA / schools: For K–12 and higher-education customers, we will sign a Data Processing Agreement (DPA) that addresses student data handling and “school official” style obligations where applicable. Download our standard DPA template or contact dpo@podz.ai.
- COPPA: Podz is not directed to children under 13. We do not knowingly create accounts for children under 13. Schools that need under-13 use must contact us in writing before onboarding so we can confirm contractual and parental-consent requirements.
- GDPR / CCPA: Privacy rights requests are handled as described in our Privacy Policy.
Education & classroom use
When Podz is used in a school or classroom context, we commit to the following (and will reflect these terms in education DPAs on request):
- We do not sell student personal data.
- We do not use student personal data to deliver third-party advertising.
- We do not use Customer Data from education organizations to train generalized foundation models. Optional AI features send prompts to the model provider only when those features are used; schools may leave AI disabled.
- Google Workspace API data (when Gmail is connected) is not retained to develop, improve, or train generalized AI/ML models, consistent with Google’s Limited Use requirements.
- Recommended classroom configuration: dedicated school organization; collect only name and school email; leave birthday and personal phone blank; keep SMS, Slack, Gmail automation, and AI assist off until IT approves.
Integrations
Optional integrations (Slack, Gmail, SMS via Twilio, Stripe for billing, AI assist) connect only when authorized by your organization. Integration credentials are stored securely and scoped to the connecting org.
Contacts
- Security incidents and vulnerability reports: info@podz.ai
- Privacy, education, DPA, and data-subject requests: dpo@podz.ai
- Standard Data Processing Agreement template (including education / FERPA schedule): podz.ai/dpa.html