Terms and Conditions

Welcome to CoHost Podcasting!

These terms and conditions outline the rules and regulations for the use of Quill Inc's Website, located at https://www.cohostpodcasting.com.

By accessing this website we assume you accept these terms and conditions. Do not continue to use CoHost Podcasting if you do not agree to take all of the terms and conditions stated on this page.

The following terminology applies to these Terms and Conditions, Privacy Statement and Disclaimer Notice and all Agreements: "Client", "You" and "Your" refers to you, the person log on this website and compliant to the Company's terms and conditions. "The Company", "Ourselves", "We", "Our" and "Us", refers to our Company. "Party", "Parties", or "Us", refers to both the Client and ourselves. All terms refer to the offer, acceptance and consideration of payment necessary to undertake the process of our assistance to the Client in the most appropriate manner for the express purpose of meeting the Client's needs in respect of provision of the Company's stated services, in accordance with and subject to, prevailing law of Netherlands. Any use of the above terminology or other words in the singular, plural, capitalization and/or he/she or they, are taken as interchangeable and therefore as referring to same.


Cookies

We employ the use of cookies. By accessing CoHost Podcasting, you agreed to use cookies in agreement with the Cohostpodcasting’s Privacy Policy. 

Most interactive websites use cookies to let us retrieve the user's details for each visit. Cookies are used by our website to enable the functionality of certain areas to make it easier for people visiting our website. Some of our affiliate/advertising partners may also use cookies.

‍‍

License

Unless otherwise stated, Cohostpodcasting and/or its licensors own the rights to collect data for all the podcasts hosted on CoHost Podcasting. All intellectual property rights are reserved. You may access this from CoHost Podcasting for your own personal use subjected to restrictions set in these terms and conditions.

You must not:

    • Republish material from CoHost Podcasting

    • Sell, rent or sub-license material from CoHost Podcasting

    • Reproduce, duplicate or copy material from CoHost Podcasting

    • Redistribute content from CoHost Podcasting

This Agreement shall begin on the date hereof February 1st, 2022

Parts of this website offer an opportunity for users to post and exchange opinions and information in certain areas of the website. Cohostpodcasting does not filter, edit, publish or review Comments prior to their presence on the website. Comments do not reflect the views and opinions of Cohostpodcasting,its agents and/or affiliates. Comments reflect the views and opinions of the person who posts their views and opinions. To the extent permitted by applicable laws, Cohostpodcasting shall not be liable for the comments or for any liability, damages or expenses caused and/or suffered as a result of any use of and/or posting of and/or appearance of the comments on this website.

Cohostpodcasting reserves the right to monitor all comments and to remove any comments which can be considered inappropriate, offensive or causes breach of these Terms and Conditions.

You warrant and represent that:

    • You are entitled to post the comments on our website and have all necessary licenses and consents to do so;

    • The comments do not invade any intellectual property right, including without limitation copyright, patent or trademark of any third party;

    • The comments do not contain any defamatory, libelous, offensive, indecent or otherwise unlawful material which is an invasion of privacy

    • The comments will not be used to solicit or promote business or custom or present commercial activities or unlawful activity.

You hereby grant Cohostpodcasting a non-exclusive license to use, reproduce, edit and authorize others to use, reproduce and edit any of your Comments in any and all forms, formats or media.‍

Hyperlinking to our Content

The following organizations may link to our Website without prior written approval:

    • Government agencies;

    • Search engines;

    • News organizations;

    • Online directory distributors may link to our Website in the same manner as they hyperlink to the Websites of other listed businesses; and

    • System wide Accredited Businesses except soliciting non-profit organizations, charity shopping malls, and charity fundraising groups which may not hyperlink to our Website.

These organizations may link to our home page, to publications or to other Website information so long as the link: (a) is not in any way deceptive; (b) does not falsely imply sponsorship, endorsement or approval of the linking party and its products and/or services; and (c) fits within the context of the linking party's site.

We may consider and approve other link requests from the following types of organizations:

    • commonly-known consumer and/or business information sources;

    • dot.com community sites;

    • associations or other groups representing charities;

    • online directory distributors;

    • internet portals;

    • accounting, law and consulting firms; and

    • educational institutions and trade associations.

We will approve link requests from these organizations if we decide that: (a) the link would not make us look unfavorably to ourselves or to our accredited businesses; (b) the organization does not have any negative records with us; (c) the benefit to us from the visibility of the hyperlink compensates the absence of Cohostpodcasting; and (d) the link is in the context of general resource information.

These organizations may link to our home page so long as the link: (a) is not in any way deceptive; (b) does not falsely imply sponsorship, endorsement or approval of the linking party and its products or services; and (c) fits within the context of the linking party's site.

If you are one of the organizations listed in paragraph 2 above and are interested in linking to our website, you must inform us by sending an email to alison@quillit.io. Please include your name, your organization name, contact information as well as the URL of your site, a list of any URLs from which you intend to link to our Website, and a list of the URLs on our site to which you would like to link. Wait 2-3 weeks for a response.

Approved organizations may hyperlink to our Website as follows:

    • By use of our corporate name; or

    • By use of the uniform resource locator being linked to; or

    • By use of any other description of our Website being linked to that makes sense within the context and format of content on the linking party's site.

No use of Cohostpodcasting's logo or other artwork will be allowed for linking absent a trademark license agreement.

Content Liability

We shall not be held responsible for any content that appears on your Website. You agree to protect and defend us against all claims that are rising on your Website. No link(s) should appear on any Website that may be interpreted as libelous, obscene or criminal, or which infringes, otherwise violates, or advocates the infringement or other violation of, any third party rights.

Your Privacy

Please read Privacy Policy

Reservation of Rights

We reserve the right to request that you remove all links or any particular link to our Website. You approve to immediately remove all links to our Website upon request. We also reserve the right to amend these terms and conditions and it's linking policy at any time. By continuously linking to our Website, you agree to be bound to and follow these linking terms and conditions.

Removal of links from our website

If you find any link on our Website that is offensive for any reason, you are free to contact and inform us any moment. We will consider requests to remove links but we are not obligated to or so or to respond to you directly.

We do not ensure that the information on this website is correct, we do not warrant its completeness or accuracy; nor do we promise to ensure that the website remains available or that the material on the website is kept up to date.

Disclaimer

To the maximum extent permitted by applicable law, we exclude all representations, warranties and conditions relating to our website and the use of this website. Nothing in this disclaimer will:

    • limit or exclude our or your liability for death or personal injury;

    • limit or exclude our or your liability for fraud or fraudulent misrepresentation;

    • limit any of our or your liabilities in any way that is not permitted under applicable law; or

    • exclude any of our or your liabilities that may not be excluded under applicable law.

The limitations and prohibitions of liability set in this Section and elsewhere in this disclaimer: (a) are subject to the preceding paragraph; and (b) govern all liabilities arising under the disclaimer, including liabilities arising in contract, in tort and for breach of statutory duty.

As long as the website and the information and services on the website are provided free of charge, we will not be liable for any loss or damage of any nature.

PII DATA

Cohostpodcasting recognizes its need to maintain the confidentiality of Personal Identity Information (PII) and understands that such information is unique to each individual. The PII covered by this policy may come from various types of individuals performing tasks on behalf of the company and includes employees, applicants, independent contractors and any PII maintained on its customer base. The scope of this policy is intended to be comprehensive and will include company requirements for the security and protection of such information throughout the company and its approved vendors both on and off work premises.

Departments named in this policy have delegated authority for developing and implementing procedural guidance for ensuring that their departmental responsibilities under this policy are communicated and enforced.

Key Elements 

Personal Identity Information (PII): Unique personal identification numbers or data, including:

  • Full name
  • Email

As is standard practice on many corporate websites, Cohostpodcasting also logs non-personally identifiable information which includes, without limitation, IP address, profile information, aggregate user data, device type and browser type at login for security purposes. Cohostpodcasting will not use the information collected to market directly to that person. This non-personally-identifiable information may be shared with third-parties to provide more relevant services and advertisements to users. User IP addresses are unlinkable to the personally identifying information of any particular user.

Cohostpodcasting may use pixel tags (tiny graphic images) to tell us what parts of the Cohostpodcasting Websites (an upcoming feature), Cohostpodcasting embeds and Cohostpodcasting Campaigns (an upcoming feature) have been visited or to measure the effectiveness of searches users perform. Pixel tags also enable us to send email messages in a format users can read, and they also tell us whether emails have been opened to assure that we’re only sending email messages that are of interest to our users. Cohostpodcasting stores all of this information in the AWS RDS database.

We also use Google Analytics, a web analytics service. Google Analytics uses cookies to help us analyze how visitors use our main website as well as the application website. The information generated by cookies about your use of the Cohostpodcasting Products and Services (including your IP address) will be transmitted to and stored by a Google server in the United States. Google uses this information for the purpose of evaluating your use of our platform, compiling reports on site activity for site operators, and providing site operators with other services relating to site activity and Internet usage. You can prevent the storage of data relating to your use of Cohostpodcasting products by downloading and installing the browser plug-in available here. You can obtain additional information on Google Analytics’ collection and processing of data and data privacy and security at the following links: How Google Uses Information From Sites Or Apps That Use Our Services and Analytics Help.

PII may reside in hard copy or electronic records; both forms of PII fall within the scope of this policy.

Vendors: Individual(s) or companies that have been approved by the Contracts Department as a recipient of organizational PII and from which the Contracts Department has received certification of their data protection practices conformance with the requirements of this policy. Vendors include all external providers of services to the company and include proposed vendors. No PII information can be transmitted to any vendor in any method unless the vendor has been pre-certified for the receipt of such information.

PII Retention: Cohostpodcasting understands the importance of minimizing the amount of PII data it maintains and retains such PII only as long as necessary. A joint task force comprising members of the Legal, Finance, IT, Contracts and Human Resources departments maintains organizational record retention procedures, which dictate the length of data retention and data destruction methods for both hard copy and electronic records. In case a user decides to move away from the platform, PII data is retained for 14 days after which all the electronic data related to the user is removed from our database.

PII Training: All new hires entering the company who may have access to PII are provided with introductory training regarding the provisions of this policy. Employees in positions with regular ongoing access to PII or those transferred into such positions are provided with training reinforcing this policy and procedures for the maintenance of PII data and shall receive annual training regarding the security and protection of PII data and company proprietary data

PII Audit(s): Cohostpodcasting conducts audits of PII information maintained by the company in conjunction with fiscal year closing activities to ensure that this policy remains strictly enforced and to ascertain the necessity for the continued retention of PII information. Where the need no longer exists, PII information will be destroyed in accordance with protocols for destruction of such records and logs maintained for the dates of destruction. The audits are conducted by Finance, IT, Contracts and Human Resources departments under the auspices of the Legal department.

Data Breaches/Notification: Databases or data sets that include PII may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, the company will notify all affected individuals whose PII data may have been compromised, and the notice will be accompanied by a description of action being taken to reconcile any damage as a result of the data breach. Notices will be provided as expeditiously as possible and in no event be later than the commencement of the payroll period after which the breach was discovered.

The Legal department will handle breach notifications(s) to all governmental agencies to whom such notice must be provided in accordance with time frames specified under these laws. Notices to affected individuals will be communicated by Human Resources after consultation with the Legal department and within the time frame specified under the appropriate law(s).

Data Access: Cohostpodcasting maintains multiple IT systems where PII data may reside; thus, user access to such IT systems is the responsibility of the IT department. The  IT department has created internal controls for such systems to establish legitimate access for users of data, and access shall be limited to those approved by IT. Any change in vendor status or the termination of an employee or independent contractor with access will immediately result in the termination of the user’s access to all systems where the PII may reside.

Data Transmission and Transportation

1. Company Premises Access to PII: The Finance, Human Resources and IT departments have defined responsibilities for on-site access of data that may include access to PII; IT has the oversight responsibility for all electronic records and data access capabilities. Finance and Human Resources have the operational responsibility for designating initial access and termination of access for individual users within their organizations and providing timely notice to IT.

2. Vendors: Cohostpodcasting may share data with vendors who have a business need to have PII data. Where such inter-company sharing of data is required, the IT department is responsible for creating and maintaining data encryption and protection standards to safeguard all PII data that resides in the databases provided to vendors. Approved vendor lists will be maintained by the Contracts department, and Contracts have responsibility to notify IT of any changes to vendor status with the company.

3. Portable Storage Devices: Cohostpodcasting reserves the right to restrict PII data it maintains in the workplace. In the course of doing business, PII data may also be downloaded to laptops or other computing storage devices to facilitate company business. This data is protected through data obfuscation and encryption. The IT department has responsibility for maintaining data encryption and data protection standards to safeguard PII data that resides on these portable storage devices.

4. Off-Site Access to PII: Cohostpodcasting understands that employees may need to access PII while off site or on business travel, and access to such data shall not be prohibited, subject to the provision that the data to be accessed is minimized to the degree possible to meet business needs and that such data shall reside only on assigned laptops/approved storage devices that have been secured in advance by the IT department.

Regulatory Requirements: It is the policy of the company to comply with any international, federal or state statute and reporting regulations. Cohostpodcasting has delegated the responsibility for maintaining PII security provisions to the departments noted in this policy. Cohostpodcasting Legal department shall be the sole entity named to oversee all regulatory reporting compliance issues. If any provision of this policy conflicts with a statutory requirement of international, federal or state law governing PII, the policy provision(s) that conflict shall be superseded.

Employee Hotline: If an employee has reason to believe that his or her PII (please refer to what constitutes PII) data security has been breached or that company representative(s) are not adhering to the provisions of this policy, an employee should contact support@cohostpodcasting.com, cc: abhinav@quillit.io immediately.

Confirmation of Confidentiality: All company employees must maintain the confidentiality of PII as well as company proprietary data to which they may have access and understand that such PII is to be restricted to only those with a business need to know. Employees with ongoing access to such data will sign acknowledgement reminders annually attesting to their understanding of this company requirement.

Violations of PII Policies and Procedures: Cohostpodcasting views the protection of PII data to be of the utmost importance. Infractions of this policy or its procedures will result in disciplinary actions under the company’s discipline policy and may include suspension or termination in the case of severe or repeat violations. PII violations and disciplinary actions are incorporated in the company’s PII onboarding and refresher training to reinforce the company’s continuing commitment to ensuring that this data is protected by the highest standards.

Security Policy

HTTPS and HSTS for secure connections 

Cohostpodcasting forces HTTPS for all services using TLS (SSL), including our public website and Cohostpodcasting Application.

We regularly audit the details of our implementation, including the certificates we serve, the certificate authorities we use, and the ciphers we support. We use HSTS to ensure that browsers interact with Cohostpodcasting only over HTTPS. Cohostpodcasting is also on the HSTS preloaded lists for both Google Chrome and Mozilla Firefox.

Encryption of sensitive data and communication 

All passwords are encrypted at rest with Argon 2. Decryption keys are managed using AWS KMS and rotated every 60 days. We use AWS RDS for storing our data which is encrypted at rest. For temporary data storage, we use AWS Elasticache which is protected at rest and at transit. All our critical servers (database, key management, document store etc.) lie behind a bastion server which can be only accessed through a specific location and SSH key. Only our app servers are exposed to the internet and can be only accessed via a load balancer. 

Reporting vulnerabilities 

Vulnerabilities should be reported directly to the CTO at abhinav@quillit.io with the subject line Vulnerability detected - {short description of the vulnerability}

Ineligible Vulnerabilities

Cohostpodcasting does not consider the following to be eligible vulnerabilities:

Account squatting by preventing users from registering with certain email addresses

Attacks requiring MITM or physical access to a user’s device

Best practice reports without a valid exploit (for example, use of “weak” TLS ciphers)

Clickjacking on pages with no sensitive actions

Comma Separated Values (CSV) injection without demonstrating a vulnerability

Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS

Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions

Denial of service

Disclosure of server or software version numbers

Hypothetical subdomain takeovers without supporting evidence

Issues that require unlikely user interaction

Missing best practices in Content Security Policy

Missing best practices in SSL/TLS configuration

Missing email best practices (invalid, incomplete or missing SPF/DKIM/DMARC records, and so on)

Missing HttpOnly or Secure flags on cookies

Open redirect - unless an additional security impact can be demonstrated

Perceived security weaknesses without concrete evidence of the ability to compromise a user (for example, missing rate limits, missing headers, and so on)

Previously known vulnerable libraries without a working Proof-of-Concept

Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis

Rate limiting or bruteforce issues on non-authentication endpoints

Reports exploiting the behavior of, or vulnerabilities in, outdated browsers

Reports of spam

Self-XSS

Session invalidation or other improved-security related to account management when a credential is already known (for example, password reset link does not immediately expire, adding MFA does not expire other sessions, and so on)

Social engineering

Software version disclosure / Banner identification issues / Descriptive error messages or headers (for example, stack traces, application or server errors)

Tabnabbing

Unconfirmed reports from automated vulnerability scanners

User/merchant enumeration

Vulnerabilities only affecting users of outdated or unpatched browsers (less than 2 stable versions behind the latest released stable version)

Operational security

Security at Cohostpodcasting is at the heart of any feature development on the platform

Vulnerability management

Cohostpodcasting uses various open source softwares to scan for vulnerabilities on a regular basis. Our Nginx proxy is constantly updated to follow the latest guidelines and our code is scanned regularly using SAST methodologies. We subscribe to OWASP top 10 security bulletin as well as Rails specific CVE alerts.

Malware prevention

An effective malware attack can lead to account compromise, data theft, and possibly additional access to a network. All files uploaded to Cohostpodcasting are scanned using ClamAV software for malware.

Monitoring

Cohostpodcasting’s security monitoring program is focused on information gathered from internal network traffic, employee actions on systems, and outside knowledge of vulnerabilities. Internal traffic is inspected for suspicious behavior, such as the presence of traffic that might indicate botnet connections, at many points across our global network, using an open-source software.

We Obey The Law

We may also share your data to third parties as necessary to comply with applicable laws or to protect the security of Cohostpodcasting services, its corporate parents, affiliates and subsidiaries.

If you listen to a podcast through an app or a third-party website, your data may also be collected by that app or website, and you should check the privacy policy of the podcast app/website that you use.

Sub-Processors

Quill may engage sub-processors to process Customer Data. A list of sub-processors currently engaged by Quill and authorized by Customer is available upon request. Quill shall notify Customer in advance of any changes to the list of sub-processors, thereby giving Customer the opportunity to object to the engagement of new sub-processors.

Read more on how we track and measure downloads for your podcast here.

YouTube Data Usage and Revocation Policy

At CoHost, we take your data privacy seriously, especially when it involves third-party data access and sharing.As part of our podcast publishing workflow, we integrate with YouTube to allow creators to distribute their podcasts in video format directly to their YouTube channels. When you choose to connect your YouTube account to CoHost, we only request the minimum required access, which is clearly listed in the OAuth permissions screen provided by Google.We are fully compliant with YouTube’s Terms of Service and Google’s Privacy Policy.

What Data We Access

We access the following data from your YouTube account:

  • Basic account information (e.g., channel ID, playlist ID and title)
  • Video upload and management permissions
  • Analytics related to podcast videos

We do not share this data with third parties, and we only use it to support the podcast publishing experience within your CoHost account.

How to Delete Your YouTube Data

You can request deletion of all YouTube-related data stored in your CoHost account at any time. You may do so using one of the following methods:

In your CoHost Dashboard:

Click your name on the top right corner > Select Settings > Integrations > YouTube, and click “Disconnect & Delete Data.”

Via Google Security Settings:

Visit https://security.google.com/settings/security/permissions, find “CoHost Podcasting”, and click “Remove Access.” This revokes our app’s access to your YouTube account.

Contact Us:

Email us at support@cohostpodcasting.com with the subject line “Delete YouTube Data - #{SHOW NAME},” and we will delete all associated data within 48 hours after confirming your identity.

If you have any questions regarding the above, we’d love to help. Contact us today at support@cohostpodcasting.com.


Welcome to CoHost Podcasting!

These Terms and Conditions outline the rules and regulations for the use of Quill Inc.’s websites and services, including but not limited to:

  • The CoHost marketing website located at https://www.cohostpodcasting.com
  • The CoHost Podcasting web application, hosted on subdomains of cohostpodcasting.com
  • Autogenerated podcast websites hosted under cohostpodcasting.com as root domain (e.g., cohostpodcasting.com/show-name)
  • The analytics platform accessed via domains prefixed with cohst.app
  • Tracking links and embedded assets that may operate under any of the domains above

By accessing any of these websites, subdomains, or related services (collectively, the “Platform”), you agree to be bound by these Terms and Conditions in full. If you do not agree with any part of these terms, you must not use the Platform.

The following terminology applies to these Terms and Conditions, our Privacy Policy, Disclaimer Notice, and all related agreements:

“Client,” “You,” and “Your” refers to you, the person accessing the Platform and agreeing to the Company’s terms and conditions.

“The Company,” “Ourselves,” “We,” “Our,” and “Us” refers to Quill Inc.

“Party,” “Parties,” or “Us” refers to both the Client and the Company.

All terms refer to the offer, acceptance, and consideration of payment necessary to undertake the process of assisting the Client in the most appropriate manner for the express purpose of meeting the Client's needs in respect of the Company’s stated services, in accordance with and subject to the applicable laws of the Province of Ontario, Canada.

Any use of the above terminology—or other words in the singular, plural, capitalized, or as he/she/they—is considered interchangeable and refers to the same.

Cookies

We use cookies solely on the CoHost Podcasting Platform—including our main marketing site, web application, and autogenerated podcast websites hosted under cohostpodcasting.com—to improve user experience, track platform usage, and ensure functionality.

By continuing to use CoHost Podcasting, you consent to our use of cookies in accordance with our Privacy Policy. If you do not agree, you may disable cookies through your browser settings; however, this may affect your ability to use certain features of the Platform.

Cookies are used to:

  • Maintain session and login states
  • Store user preferences
  • Analyze traffic and interaction patterns using tools such as Google Analytics and Microsoft Clarity

We do not use cookies on our analytics platform (cohst.app) or within tracking links.

Some third-party services integrated with the Platform (e.g., Google Analytics, Microsoft Clarity) may also place cookies to help us understand and optimize user behavior.

License

Unless otherwise stated, Quill Inc. and/or its licensors own all intellectual property rights for the CoHost Podcasting Platform, including but not limited to the main website, web application, autogenerated podcast websites, embedded players, tracking link infrastructure, and analytics dashboards.

All rights are reserved. You may access the Platform for your own personal or business use, subject to the restrictions set forth in these Terms and Conditions.

You must not:

  • Republish material from the Platform without permission
  • Sell, rent, or sub-license Platform content
  • Reproduce, duplicate, or copy material from the Platform
  • Redistribute content, except where functionality (e.g., embeds, tracking links) is explicitly provided to do so

Quill Inc. staff, contractors, or affiliates may not use client-uploaded content for internal demonstrations, training materials, or marketing purposes without the client’s prior written consent. This includes use in presentations, sample assets, mockups, or public-facing documentation.


The Platform allows users to create, manage, and distribute podcasts, publish tracking links, and access analytics and marketing tools. While Quill Inc. provides the infrastructure, the content uploaded by users - including podcasts, metadata, and linked content - remains their responsibility.

Hyperlinking to Our Content

The following organizations may link to our Platform without prior written approval:

  • Government agencies
  • Search engines
  • News organizations
  • Online directory distributors that list businesses
  • System-wide accredited businesses, excluding non-profit fundraising groups and unsolicited charities

These organizations may link to our homepage, podcast websites, or other publicly available pages, provided the link:

  • Is not misleading
  • Does not falsely imply sponsorship, endorsement, or approval by Quill Inc. or the CoHost Platform
  • Fits within the context of the linking party’s site

We may also approve link requests from:

  • Common consumer or business information sources
  • Tech or podcast community sites
  • Educational institutions or trade associations
  • Online media companies or analytics providers

To request permission, email support@cohostpodcasting.com with your organization name, contact info, linking URLs, and target URLs. Please allow 2–3 weeks for a response.

Approved entities may hyperlink using:

  • Our corporate name
  • The direct URL being linked to
  • A context-appropriate label (e.g., “CoHost Podcasting – Show Hosting Platform”)

Use of any logos, artwork, or trademarks from Quill Inc. or CoHost Podcasting is prohibited without a formal trademark license agreement.

Users may freely share autogenerated podcast websites, embedded players, and tracking links created through the Platform, as these are intended for public distribution.

Content Liability

Quill Inc. shall not be held responsible for any content that appears on your podcast, embedded player, tracking link, autogenerated website, or other areas made available through the CoHost Podcasting Platform. You agree to defend and indemnify us against all claims arising from content you publish using the Platform.

No content shared via the Platform should appear in any context that may be interpreted as:

  • Libelous, defamatory, obscene, or otherwise unlawful
  • Infringing on any third-party intellectual property or privacy rights
  • Promoting violence, discrimination, or illegal activity

User-Generated Content

You are solely responsible for all content you upload, publish, or distribute through the Platform, including:

  • Podcast audio files, descriptions, and images
  • Show and episode metadata
  • Autogenerated podcast websites
  • Tracking links
  • Embedded players

We do not pre-screen or monitor user-generated content. However, we reserve the right to remove or disable access to any content that, in our sole discretion, violates applicable laws, infringes rights, or breaches these Terms.

Ownership and Consent

You retain all intellectual property rights and ownership over the content you upload to the Platform, including podcast episodes, metadata, images, and related assets. Quill Inc. does not claim ownership of any user-generated content.

Your content will not be published or distributed beyond the scope of your selected platform features (e.g., autogenerated websites, tracking links, YouTube integration) without your explicit consent. You are solely responsible for determining the visibility and distribution settings for your content.

Quill Inc. disclaims all liability for user-generated content that appears automatically on public-facing assets (e.g., websites, tracking links, embedded players).

Quill Inc. will not duplicate, clone, or create derivative works based on your uploaded content - such as variations for testing, localization, or promotional material—without your prior approval.

Internal Testing and Staging

By using the Platform, you grant Quill Inc. a limited, non-exclusive license to duplicate your uploaded content in staging or test environments solely for the purpose of quality assurance, debugging, feature development, and performance testing. These duplicates will remain internal to the Company and will not be publicly visible, indexed, or distributed without your explicit approval. Content used in this way may appear under a different show name or identifier, but only within staging infrastructure not accessible to the public.

Staging Environment Disclosure and Safeguards

While staging environments are intended to be private and restricted, you acknowledge that test environments may occasionally be accessible over the internet for development or debugging purposes.

We commit to implementing industry-standard access controls and monitoring to prevent unauthorized access or accidental exposure of duplicated content.

In the event of an unintentional leak from a staging environment, Quill Inc. will:

  • Notify affected clients within 5 business days
  • Remove exposed content immediately upon discovery
  • Investigate the root cause and apply remedial safeguards
  • Limit liability to the extent permitted under applicable law

Clients may request a report detailing where their uploaded content is currently stored or accessed across CoHost’s production and staging environments. Upon request, Quill Inc. will provide such information within a reasonable timeframe and assist in removing content from staging systems upon client request.

Takedown Requests

If you believe that any content on the CoHost Podcasting Platform infringes your rights or violates applicable laws, you may submit a formal takedown request by emailing support@cohostpodcasting.com with the subject line:

“Takedown Request – [Podcast Title or URL]”

Your request must include:

  • A description of the content in question and the specific URL(s) where it appears
  • The basis for your request (e.g., copyright infringement, defamation, privacy violation)
  • Your full name, contact information, and a statement under penalty of perjury that your claim is accurate
  • Proof of ownership or legal rights (e.g., copyright registration, license agreement, trademark certificate, or a signed declaration if you're the rights holder)

We will investigate all valid requests in accordance with applicable laws, including:

  • Canada’s Notice-and-Notice regime (under the Copyright Modernization Act)
  • The U.S. Digital Millennium Copyright Act (DMCA), where applicable
  • Any other international regulations relevant to intermediary liability and online content hosting

Where legally required, we will provide notification to the user responsible for the content and, if necessary, remove or disable access to the material.

Privacy

By using the CoHost Podcasting Platform, you acknowledge and agree to the collection, use, and disclosure of your information as outlined in our Privacy Policy.



Reservation of Rights

We reserve the right to request the removal of any link to our Platform at our sole discretion. You agree to promptly comply with such a request upon notification.

We also reserve the right to amend these Terms and Conditions, our linking policy, and related policies at any time without prior notice. Your continued use of the Platform after any changes constitutes your acceptance of the revised terms.

We may update, suspend, or discontinue any part of the Platform, including services, features, or access to content, at any time and for any reason, without liability to you or any third party.

You are responsible for reviewing these Terms periodically to stay informed of any updates. The current version will always be accessible on our website.



Removal of links from our website

If you find any link on the CoHost Podcasting Platform that you believe is offensive, inappropriate, or in violation of applicable laws, you are welcome to notify us at support@cohostpodcasting.com.

While we are not obligated to remove links or respond to every request, we will review and consider all legitimate reports in good faith. We reserve the right to remove or restrict access to content or links at our sole discretion and without prior notice.

We do not guarantee that information, URLs, or external references appearing on the Platform will be accurate, up-to-date, or uninterrupted. Quill Inc. is not liable for any damages or losses that may result from relying on outdated or incorrect links or embedded content.



Disclaimer

To the fullest extent permitted by applicable law, we exclude all representations, warranties, and conditions relating to your use of the CoHost Podcasting Platform, including any implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

Nothing in this disclaimer will:

  • Limit or exclude our or your liability for death or personal injury resulting from negligence
  • Limit or exclude our or your liability for fraud or fraudulent misrepresentation
  • Limit any of our or your liabilities in a way that is not permitted under applicable law
  • Exclude any liabilities that cannot be excluded under applicable law

Platform Performance & Limitations

We are committed to maintaining high availability, data accuracy, and service continuity across the Platform. However, we cannot guarantee uninterrupted access or flawless performance at all times. Occasional disruptions may occur due to system maintenance, third-party service interruptions (such as Clearbit, Google Analytics, or Microsoft Clarity), or other unforeseen technical issues.

We are not responsible for any indirect or incidental damages that may arise from:

  • Temporary downtime or feature outages
  • Delays in data delivery, reporting, or podcast publication
  • Errors or omissions in third-party integrations or analytics tools

If any major feature of the Platform is to be sunset or materially changed, we will provide users with at least 30 days’ advance notice to prepare for the transition and, where applicable, export their data.

Use of the Platform is at your own discretion and risk. All services are provided "as is" and "as available," without warranty of any kind unless expressly stated otherwise.

Personal Identifiable Information (PII) and Data Privacy

Quill Inc. is committed to protecting the privacy of both users and listeners across the CoHost Podcasting Platform. We collect and process Personal Identifiable Information (PII) in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the EU General Data Protection Regulation (GDPR) where applicable.

This section describes how we collect, use, store, and protect data across two categories of individuals:

  • Platform users (e.g., podcast creators, collaborators, and team members)
  • Podcast listeners (individuals downloading or streaming podcast episodes)

A. Data We Collect

From Platform Users

We collect the following personal data when you create or use an account:

  • Full name
  • Email address
  • Device type, browser type, and IP address (for security)
  • Login timestamps and activity metadata
  • Team, account, and workspace associations
  • Billing or subscription preferences (if applicable)

We also log non-personally identifiable data such as usage frequency, referral source, and interactions with key features (e.g., analytics tools, embedded players).

From Podcast Listeners

To comply with IAB Podcast Measurement Guidelines, we collect limited technical data from listeners who access content hosted on the Platform:

  • IP address
  • User agent (browser/device information)
  • Timestamp of download or stream
  • Referrer (when available)

This data is not associated with individual user accounts and is stored for measurement, reporting, and fraud prevention purposes only.

B. How We Use the Data

We use collected data for the following legitimate purposes:

  • To operate and secure the Platform
  • To manage user accounts and permissions
  • To enable team collaboration and tracking features
  • To generate podcast download analytics
  • To enrich data with business intelligence tools (e.g., Clearbit)
  • To provide aggregated U.S.-based demographic reports to creators (available through paid plans)

We do not use personal data for direct marketing purposes without consent, and we never sell personal information.

C. Third-Party Services and Enrichment

We may use the following services to process or enrich user and listener data:

  • Google Analytics — web usage insights
  • Microsoft Clarity — session interaction data
  • Clearbit — company identification for listener IPs
  • Demographics partners — aggregate reports on listener attributes

Only anonymized or aggregated insights are shared with podcast creators. Enrichment partners are contractually obligated to comply with applicable privacy standards.

D. Data Storage and Security

All data is stored in encrypted databases within AWS cloud infrastructure:

  • Primary storage: AWS RDS, encrypted at rest and transit
  • Temporary data: AWS ElastiCache, protected in transit and at rest
  • Passwords: Hashed using Argon2
  • Keys: Managed and rotated via AWS Key Management Service (KMS)

Access to personal data is restricted to authorized personnel on a need-to-know basis. Employees receive annual PII protection training and must sign confidentiality agreements.

E. Vendors and Sub-Processors

We may share data with pre-approved vendors or sub-processors for infrastructure, analytics, or enrichment purposes. No PII is transmitted to any vendor unless they are contractually bound to maintain privacy protections equivalent to those required by PIPEDA and GDPR.

A current list of sub-processors is available upon request.

F. Retention and Deletion

Platform user data is retained for the duration of the user’s account. If an account is closed, all associated personal data is deleted within 14 days.

Listener data is retained only for as long as needed to support podcast analytics and reporting. Aggregated listener metrics are stored indefinitely without identifiable metadata.

You may request access, correction, or deletion of your personal data by emailing support@cohostpodcasting.com.

G. Breach Notification

In the event of a data breach affecting PII:

We will notify affected individuals within 10 business days or by the next payroll period, whichever comes first

We will disclose what data was compromised, how it was accessed, and what steps we are taking to resolve it

Our Legal and HR departments will manage regulatory and user communications as required

H. Your Privacy Rights

If you are subject to PIPEDA, GDPR, or similar data protection laws, you have the right to:

  • Access the data we hold about you
  • Request corrections to inaccurate data
  • Withdraw consent or request deletion of your data
  • Ask how your data is used, processed, or shared

To exercise these rights, contact us at support@cohostpodcasting.com.

Security Policy

We take the security of your data seriously and implement industry-standard safeguards to protect the confidentiality, integrity, and availability of the CoHost Podcasting Platform and its underlying infrastructure.

A. Secure Connections

All connections to the Platform use HTTPS and are protected by TLS encryption. We enforce HTTPS across all services, including:

  • The CoHost web application
  • Autogenerated podcast websites
  • Embedded players
  • Tracking links
  • The prefix (cohst.app)

We use HSTS (HTTP Strict Transport Security) to ensure browsers interact with our services securely. CoHost Podcasting is included in the HSTS preload lists for modern browsers such as Google Chrome and Mozilla Firefox.

B. Encryption

  • All user data is encrypted at rest in AWS RDS and in transit using TLS 1.2 or higher.
  • Passwords are hashed using Argon2, a secure, modern hashing algorithm designed to prevent brute-force attacks.
  • Encryption keys are securely stored and rotated via AWS Key Management Service (KMS) on a 60-day schedule.

C. Infrastructure Protection

Our backend systems—including databases, key stores, and caching layers—are hosted behind a bastion server and are not publicly accessible. Only the application layer is exposed to the internet and routed through load balancers.

Access to internal systems is restricted to authorized personnel with role-based permissions and secured via SSH keys and IP-based whitelisting.

D. Vulnerability Management

We perform regular vulnerability scanning, dependency checks, and infrastructure audits using both open-source and commercial tools. We subscribe to security advisories such as:

  • OWASP Top 10
  • Rails CVE Bulletins
  • AWS and container-level alerts
  • Our infrastructure (e.g., NGINX reverse proxy) is kept up to date with the latest security patches.

E. Malware Protection

All user-uploaded files are automatically scanned using ClamAV, an open-source antivirus engine, to detect and block malicious content. Suspicious or non-conforming files are flagged or blocked before processing.

F. Monitoring and Response

We continuously monitor internal network activity and user behavior for signs of:

  • Unauthorized access attempts
  • Anomalous traffic patterns
  • Botnet or scraping activity

Security incidents are logged and reviewed by our internal response team. In the event of a breach, we follow the notification protocols outlined in our PII Data section.

G. Reporting Vulnerabilities

If you discover a potential security vulnerability, please report it by emailing support@cohostpodcasting.com with the subject line:

“Vulnerability Detected – [Short Description]”

We appreciate responsible disclosure and will respond to verified reports promptly.

Ineligible Vulnerabilities

We value the security community and welcome responsible disclosure of potential vulnerabilities. However, not all reported issues qualify for investigation or remediation. The following categories are considered ineligible vulnerabilities, meaning they do not represent meaningful risks to our users or infrastructure:

A. General Exclusions

  • Reports requiring Man-in-the-Middle (MITM) attacks or physical device access
  • Missing security headers (e.g., X-Frame-Options, Content-Security-Policy) without demonstrated exploitability
  • Reports based on outdated browser behavior or unpatched environments
  • Self-XSS (attacks requiring the user to paste code into their own console)

B. Application & UI Behavior

  • Clickjacking on pages without sensitive actions
  • Open redirects without additional security impact
  • CSV injection without a working proof of concept
  • Tabnabbing or cosmetic UI issues (e.g., text injection that doesn’t modify DOM logic)
  • Disclosure of software version numbers, stack traces, or error messages

C. Platform-Specific Exclusions

  • Account creation collisions (e.g., preventing certain usernames or emails)
  • Missing or “weak” rate limiting on non-authentication endpoints
  • Reports of spam behavior not caused by system misconfiguration
  • Session expiration or logout issues

D. Library and Dependency Reports

  • Use of known vulnerable libraries without a working exploit
  • Public zero-day vulnerabilities that have had official patches released within the last 30 days
  • Missing or invalid email security records (e.g., SPF/DKIM/DMARC)

Notes on Evaluation

We evaluate vulnerabilities based on actual impact, exploitability, and alignment with industry best practices. If you believe an issue listed above does present a real security risk, you’re encouraged to include a working proof-of-concept and details about how it could harm platform users or infrastructure.

All valid reports will be acknowledged and triaged accordingly.

Legal Compliance and Law Enforcement

We operate in compliance with all applicable laws and regulations in the jurisdictions in which we do business, including:

  • Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
  • EU General Data Protection Regulation (GDPR)
  • U.S. Digital Millennium Copyright Act (DMCA)
  • IAB Podcast Measurement Guidelines

A. Lawful Requests for Data

We may disclose user or listener data to third parties when required to do so by applicable law, regulation, subpoena, court order, or other legal process. This includes:

  • Criminal investigations or national security requests
  • Civil or regulatory proceedings
  • Consumer protection or copyright enforcement matters

We will only disclose the minimum amount of data required to comply with such lawful requests and will notify affected users when permitted to do so by law.

B. International Data Transfers

If personal data is transferred outside of Canada (e.g., to processors in the U.S. or EU), we ensure that appropriate safeguards are in place to protect it, including:

  • Data Processing Agreements (DPAs)
  • Standard Contractual Clauses (SCCs) for GDPR compliance
  • Contractual privacy guarantees with our vendors and sub-processors

C. Platform Use Restrictions

The CoHost Platform must not be used to:

  • Violate local, national, or international laws
  • Host or distribute illegal or infringing content
  • Circumvent data privacy regulations or broadcast restrictions
  • Interfere with lawful investigations or legal process

We reserve the right to suspend or terminate access to the Platform if we believe that your use violates applicable laws or these Terms.

YouTube Data Usage and Revocation Policy

As part of the CoHost Podcasting workflow, we allow users to connect their YouTube accounts to automate the distribution of podcast content in video format to their YouTube channels.

We take this integration seriously and comply with the YouTube Terms of Service and Google Privacy Policy, as well as applicable data privacy laws including PIPEDA and GDPR.

A. What Data We Access

When you connect your YouTube account to CoHost, we request access through Google’s OAuth process. The following information may be accessed:

  • Basic account metadata (e.g., channel ID, playlist ID, channel title)
  • Permissions to upload and manage video files related to your podcast
  • Podcast-specific YouTube analytics (e.g., video performance metrics)

We only request the minimum level of access required to publish your podcast content and display related analytics within the Platform.

B. How We Use This Data

Your YouTube data is used for the sole purpose of:

  • Uploading and managing podcast episodes to your connected YouTube channel
  • Monitoring video-level performance and analytics
  • Managing content linked to your show or episode releases

This data is not shared with third parties, and we do not use it for advertising, marketing, or profiling. We store only the tokens and metadata needed to manage your podcast distribution and maintain synchronization with YouTube.

C. How to Disconnect and Delete Your YouTube Data

You may revoke our access and delete YouTube-related data at any time. You can do this using one of the following methods:

Option 1: In Your CoHost Dashboard

  • Navigate to Settings > Integrations > YouTube
  • Click “Disconnect & Delete Data”

Option 2: Via Your Google Security Settings

  • Visit https://security.google.com/settings/security/permissions
  • Find “CoHost Podcasting” and click “Remove Access”

Option 3: Email Request

Send a request to support@cohostpodcasting.com with the subject line:

“Delete YouTube Data – [Show Name]”

We will confirm your identity and remove all associated data within 48 hours.

D. Compliance Statements

We adhere to:

  • The YouTube API Services Developer Policies
  • Google’s Limited Use requirements under their API Services User Data Policy
  • Our own Privacy Policy

We do not share, sell, or use YouTube data beyond the scope of the podcast publishing features you opt into.

Contact and Final Provisions

If you have any questions about these Terms and Conditions, your account, your data, or any of the services described herein, please contact us:

Quill Inc.

Email: support@cohostpodcasting.com

Legal inquiries (e.g., takedown notices or data access requests): support@cohostpodcasting.com

Entire Agreement

These Terms and Conditions, along with our Privacy Policy and any other referenced documents, constitute the entire agreement between you and Quill Inc. in relation to your use of the CoHost Podcasting Platform.

No waiver or failure to enforce any part of these Terms shall be deemed a waiver of any other provision or right.

If any provision of these Terms is found to be unenforceable or invalid under applicable law, that provision shall be deemed removed without affecting the validity and enforceability of the remaining Terms.

Last Updated

These Terms and Conditions were last updated on June 11, 2025.