Effective July 20, 2026

privacy, without the mystery.

This policy explains what Cast handles, why it is needed, and how to remove it.

Data we handle

  • Account identity, email or phone number, username, profile name, settings, public profile photo, and private identity selfie.
  • Your age-range attestation, AI-generation consent record, generated posts, reactions, comments, device push token, blocks, and reports.
  • Contacts only after permission. Names and photos stay on the device. Phone numbers are sent over TLS, converted to keyed hashes, and only those hashes are stored.
  • Account-linked product events, device and app context, approximate region derived from your network address, and diagnostics used to operate and improve the service.

Cast does not store address-book names or photos and does not create accounts for unregistered contacts.

Profile photo and visibility

Your Cast profile photo is visible in the app and may appear on your public invite page. A separate private identity selfie is used to include you in generated posts while your consent is active; it is not displayed to other users.

You can replace either photo or revoke generation consent in Settings. Revocation removes both photos, disables future casting, and removes posts containing you from the service.

Face data: collection, use, sharing, storage, and retention

What we collect. Cast collects the public profile photo you select or capture, the private identity selfie you capture, and the facial likeness visible in generated posts. Cast does not extract or store face geometry, facial landmarks, depth data, faceprints, biometric templates, or face-recognition identifiers.

How we collect and use it. After you tap “Allow Face Data Use,” Cast safety-screens both photos, displays the profile photo publicly, stores the identity selfie privately as the sole identity reference for fictional generated posts, and screens generated output before publication. Face data is never used for authentication, advertising, marketing, analytics, user profiling, or identifying anonymous people.

Where it is stored and shared. Convex stores the photos and generated posts and runs the product workflow. OpenAI receives both photos for safety screening. Vercel AI Gateway and OpenAI receive the curated base image, operator prompt, request metadata, and private selfies needed for generation; Google may receive the same generation data only if OpenAI refuses the request for safety. No face data is shared with PostHog, advertisers, data brokers, or information resellers.

How long it is retained. In Convex, a current profile photo and identity selfie remain until you replace them, revoke consent, or delete your account; replaced files are deleted once unreferenced. Generated posts remain until consent revocation, account deletion, or service removal. OpenAI’s moderation endpoint retains no customer content. OpenAI may retain generation customer content in abuse-monitoring logs for up to 30 days, and Google may retain fallback-generation prompts, images, and output for abuse monitoring for up to 55 days; either may retain data longer when legally required or necessary to prevent harm.

How data is used

We use this data to authenticate you, safety-screen public profile photos and private identity selfies, find friends, form pairwise-mutual groups, generate operator-curated posts, deliver media and notifications, power the widget, and operate safety controls.

Before either photo leaves the device for AI use, Cast obtains explicit, versioned permission. OpenAI screens the public profile photo and private identity selfie; generation sends the private selfie through Vercel AI Gateway to OpenAI, or to Google only if OpenAI refuses the request for safety. You can withdraw permission in Settings; withdrawal stops future use and removes both photos and posts that include you.

Cast posts are fictional, AI-edited images and must not be presented as real events. Base images and prompts are selected and curated by Cast operators. Cast sends the public profile photo and private identity selfie directly to OpenAI’s moderation endpoint for safety screening. For generation, it sends the curated base image, operator prompt, depicted people’s private selfies, and request metadata through Vercel AI Gateway to OpenAI; only after an OpenAI safety refusal may it send the same generation data through the Gateway to Google Gemini. Cast configures no-prompt-training and does not opt in to provider model training. Generated outputs are screened again before automatic publication. OpenAI’s moderation endpoint has no abuse-monitoring retention. OpenAI may retain generation customer content for up to 30 days, and Google may retain fallback-generation content for up to 55 days, or longer when legally required or necessary to prevent harm.

Details: AI & likeness.

Posts, sharing, and providers

Inside Cast, posts are shown only to the people depicted in them. A depicted person may save or share a post outside Cast. Blocking either direction removes in-app shared-post access. Copies shared outside the service are controlled by the person who shared them, not by Cast.

Convex provides authentication, product data, realtime updates, file storage, and workflows; Twilio receives the phone number and verification metadata needed to deliver and validate one-time codes; Vercel provides hosting and AI Gateway; OpenAI screens profile photos, identity selfies, comments, and generated output, and generates images and reaction suggestions; Google may generate an image only after an OpenAI safety refusal; Expo provides push delivery; PostHog provides analytics and diagnostics; Superwall is installed for future purchases but no paywall is currently presented.

Cast requires its processors to protect personal data consistently with this policy and applicable law, and does not authorize them to use it for advertising or model training. Review the Twilio privacy notice, Vercel privacy notice, OpenAI privacy policy, Google privacy policy, and PostHog privacy policy.

PostHog receives account-linked, allowlisted product activity and diagnostics, plus person profile fields needed for support (name, username, email, and public profile photo URL). It does not receive private identity selfies, generated media, prompts, contacts, address-book names, or other private media URLs. Session replay and touch or text capture are disabled.

Cast may ask for App Tracking Transparency permission on iOS. With or without that permission, Meta, TikTok, and Google/Firebase receive standard app install and conversion events (for example app open, completed registration, and onboarding completion) so Cast can measure advertising performance. Device advertising identifiers are used only when you allow tracking. Face data is never used for advertising. Review the Meta privacy policy, TikTok privacy policy, and Google privacy policy.

Retention and your choices

Contact hashes remain until your next sync, Contacts permission revocation, or account deletion. Current photos remain until replacement, consent revocation, or account deletion. A reported profile photo or post copy is retained only while its report is open or under review, then deleted when the report closes. Posts remain until consent revocation, account deletion, or service removal.

Settings lets you revoke generation consent, change notification choices, block users, and permanently delete your account. Deletion immediately locks the account and begins durable removal of authentication, profile, contacts, relationships, devices, reactions, comments, reports, both photos, posts containing you, and linked PostHog people, events, and recordings. Processor deletion may complete asynchronously. Limited records may remain when required by law, safety, fraud prevention, or backup rotation.

Age and safety

Cast is not intended for children under 16. Users aged 16–17 must attest that a parent or legal guardian permits their use and AI-likeness processing. Reports are reviewed by operators. Operators can inspect reported media, remove a post or profile photo, and suspend or restore an account with an audit history. Blocking remains available to every user.

Contact

Cast is a product of Undefined Software, Inc.. Email alon@undefinedinc.io for privacy, deletion, safety, or support questions. Also review our safety policy.