Privacy policy
Draft updated
This notice covers the Cast app, website, waitlist and support service. It also covers personal information in podcast content that Cast processes.
EU launch draft — not yet in force. These pages include proposed procedures and identify details and controls that we must confirm before publication.
Who is responsible
Daniel McKenzie, a UK sole trader trading as Cast, is the controller of the personal information described here. This means I decide why and how Cast uses it. Contact danny@usecast.app about this notice or your rights.
Before this draft takes effect: we must add our public business contact address and the name and contact details of our EU data protection representative. A representative under data protection law has a separate role from a representative under the Digital Services Act.
Information we collect and its sources
- From you: email, sign-in details, profile information, interests, searches, follows, saved episodes, playlists, feedback, private-feed links, questions, chat history, waitlist signups and messages to support.
- From your use of Cast: playback position, listening history and statistics, downloads, preferences, app and device identifiers, feature events, connection details and error records. An account ID or hashed IP address can still be personal information.
- From voice features: microphone audio processed on your device and the recognised text of your question. The text, rather than a microphone recording, forms part of an AI request.
- From sign-in and purchase providers: the account details your sign-in provider shares, App Store transaction and subscription status, and identifiers that link Cast+ to your account. Apple handles payment-card details.
- From podcast feeds, publishers and directories: episode details, artwork, audio, transcripts and related content. These can contain personal information about speakers and people discussed, even when the source is public.
- From content reports and appeals: contact details, links, reasons, evidence, decisions and correspondence. Reports may concern people who do not have a Cast account.
Why we use information and our legal grounds
- Provide the service you request: create and secure your account, sync your library, resume listening, provide requested AI answers and check Cast+ access. We rely on performing our contract with you only where the use is necessary for that service.
- Protect and support Cast: investigate faults, prevent misuse, answer support requests and defend legal claims. We rely on our legitimate interests in running a secure, reliable service, subject to a check that your rights do not outweigh those interests.
- Optional app analytics: understand how people use features through Mixpanel. The proposed EU launch basis is consent. This draft cannot take effect until Cast offers a working choice before collection and an equally easy way to withdraw it.
- Waitlist messages: send the launch news and beta invitations you request when you join. We rely on your consent for those messages. Email us to leave the list. We use signup timestamps and hashed IP addresses to prevent abuse, based on our legitimate interests in protecting the signup service.
- Meet legal duties: handle valid legal orders, required content notices and records that tax or other law requires. We rely on the relevant legal obligation, rather than treating every request from an authority as compulsory.
Uses still under review: we must complete and record the legal grounds for personalised recommendations and processing personal information in sourced podcasts before this draft takes effect. Public availability does not remove privacy rights. Sensitive information and criminal allegations require a separate legal assessment; a general legitimate-interest claim is not enough.
You do not have to join the waitlist, give optional profile details or send a voice question. Without information needed for an account, purchase or requested AI answer, we may be unable to provide that feature. Reading this notice or accepting terms does not give consent to optional tracking.
AI, recommendations and device permissions
Ask Cast sends your question, relevant chat history, episode context and listening position to OpenAI. Voice input uses on-device recognition. If your device cannot provide it, you can type your question; Cast does not fall back to cloud transcription. The recognised question is still sent for an AI answer. Other AI features can process podcast content and listening patterns. Do not include passwords, private-feed access tokens or sensitive information that an answer does not need.
Cast prepares transcripts for selected public shows and the public shows starred by Cast+ members. It first checks transcripts from the publisher, then sends episode audio to Groq when it needs to generate one. Cast stores completed transcripts in Supabase for listeners to use with Ask Cast. You can request coverage for a show; Cast records the show and your account ID to count requests.
The terms explain recommendations and the feedback that affects them. Podcast ranking helps choose what to display. It does not decide eligibility for employment, credit or similar matters.
You can change microphone and notification permissions in your device settings. A microphone permission does not itself give permission for third-party AI sharing or optional analytics. The app must explain and obtain any separate permission needed before sharing.
Who receives information
- Supabase: accounts, synced app data and server processing.
- Apple and Superwall: purchases, subscription access and paywall events.
- OpenAI: questions, relevant context and podcast material for AI features, plus text used to generate spoken answers. Cast does not send microphone recordings for cloud transcription.
- Groq: public podcast episode audio for scheduled transcript generation. This does not include your microphone recordings.
- Mixpanel: feature events, searches and episode interactions linked to an app or account identifier. The current app uses its EU endpoint; that does not make events anonymous.
- Vercel and Resend: website hosting and email delivery. Expo and Apple help deliver notifications when enabled.
- Podcast publishers and hosts: connection details when your device requests feeds, artwork or audio. These services control their own handling of those requests, including any ads in their audio.
- People handling a report, advisers and authorities: information needed to assess a complaint, protect rights or meet a legal duty. We do not routinely disclose a reporter's identity to the person reported; we do so only where necessary and lawful.
Some suppliers act on our instructions; others, including Apple for its own purchase records and podcast hosts for their requests, have duties of their own. Their privacy notices provide further information. Using a supplier does not remove Cast's responsibility for processing that Cast controls.
International transfers
Information may pass outside the UK and European Economic Area. An EU server endpoint alone does not establish where every copy, support operation or subprocessor is located.
Before this draft takes effect: we must identify the destination countries and the transfer safeguard for each supplier. This may be an applicable adequacy decision or approved contractual safeguards with the assessments and extra protections needed. We will publish the arrangements that actually apply and explain how to obtain a copy. This draft does not claim that those checks or contracts are complete.
Your rights and how to use them
Email danny@usecast.app to request access, correction, erasure, restriction or a portable copy of eligible data. You can object to uses based on legitimate interests and to direct marketing. You can withdraw consent without affecting the lawfulness of earlier processing. These rights have legal conditions and exceptions.
You do not need a Cast account or legal wording to make a request. Tell us enough to locate the information. We will ask for further proof of identity only where reasonably needed; do not send identity documents unless we ask for them securely.
For requests under EU GDPR, we respond without undue delay and within one month. If complexity or the number of requests permits an extension, we explain why within the first month; the extension can be up to two further months. Requests are normally free. If we cannot act, we explain the reason and how to complain or seek a court remedy.
You can complain directly to the UK Information Commissioner's Office or an EU data protection authority, including in the country where you live, work or believe a breach occurred. You do not have to contact Cast first.
Storage, children and changes
The data policy explains account deletion, local files, supplier records and the retention work still needed. A request about information in a podcast does not depend on deleting a listener account; use the content reporting process or contact us about your privacy rights.
Before EU launch: we must confirm the intended age group, align the App Store age rating and access controls, and assess safeguards for children who may use Cast. This draft does not claim that a minimum age or parental-consent check is already enforced.
We date revisions and notify you of material changes through the app or another suitable direct channel. If a new use needs consent, a policy update alone will not supply it.
Contact Cast
Cast is operated by Daniel McKenzie, a UK sole trader trading as Cast. For privacy, data, billing or support requests, email danny@usecast.app.
You can use this address to ask about your data, request access, correction or deletion, object to a use of your information, or leave the waitlist. We may ask for enough information to confirm that the request relates to your account.
