Data and privacy
White Bastion · measurement documentation

What is recorded

White Bastion records what a download request itself carries:

  • the time of the request
  • the IP address it came from
  • the user agent, and the other headers sent with the request
  • which episode was requested
  • network metadata from the connection

This is request metadata — the same class of information any server receives when a file is requested from it.

What is not recorded

White Bastion issues a redirect and never sees the host's response. It does not know whether a download completed, how many bytes were delivered, or what the host returned.

There are no cookies, no accounts, and no identifiers beyond what a request already carries. Nothing is placed on a listener's device.

How it is used

Request data is used to count downloads and to classify traffic.

Where listener numbers are reported they are estimates, derived from masked and hashed forms of the request data rather than the raw values. A podcast download carries no login: several people on one network can appear as one listener, and one person moving between networks can appear as several. Listener figures are reported as estimates everywhere they appear.

Where the numbers go

The audit report is produced per show and delivered to the account holder — the agency running the campaign. There is one document, not a publisher version and a buyer version.

Retention, deletion and data processing agreements

Questions about how long data is held, deletion requests, or a data processing agreement: support@whitebastion.com.