Who we are
cast0 (cast0.ai) is a text-to-podcast service operated by Tomas Pavlin (the "operator", "we"). We are the data controller for the personal data described in this policy. Contact: [email protected].
What we collect
- Account data: email address, name, and profile picture (when you sign in with Google or GitHub), plus a password hash if you sign up with email and password.
- Security data: IP address and browser user agent for each login session, used to keep sessions secure and prevent abuse.
- Content you submit: podcast settings (name, voice, music) and the text you send us to turn into episodes, together with the generated audio files.
- API keys: the cast0 API keys we issue to you, and optionally your own OpenAI API key if you add one in settings. Your OpenAI key is stored encrypted (AES-256-GCM) and is only decrypted to make TTS requests on your behalf.
- Billing data: your subscription plan, Stripe customer and subscription identifiers, and a ledger of usage charges. Card details are handled by Stripe and never touch our servers.
- Waitlist data (cast0 daily): the email address and preferences you enter in the setup flow (such as first name, city, topics, teams, tickers, schedule, and timezone).
- Usage data: product analytics events, page views, and session replays (see Cookies and analytics below), plus standard server logs.
How we use it
- Providing the service (contract): generating audio from your text, hosting episodes, serving your RSS feed, managing your account and API keys.
- Billing (contract): metering usage against your plan and processing subscriptions through Stripe.
- Transactional email (contract): verification emails and occasional service emails about your account, sent via Resend.
- Security and abuse prevention (legitimate interest): session management, bot protection on sign-up (Cloudflare Turnstile), and rate limiting.
- Product analytics (legitimate interest): understanding how the product is used so we can improve it.
- Advertising measurement (consent where required): measuring whether our ads on Reddit and Meta platforms lead to sign-ups.
We do not sell your personal data, and we do not use your content to train AI models.
Who we share it with
We use a small number of processors to run the service. Each receives only what is needed for its job:
- OpenRouter / Google (Gemini TTS) and OpenAI (TTS): receive the episode text you submit, to convert it to speech. If you bring your own OpenAI key, those requests run under your own OpenAI account.
- Hetzner (Germany): hosts our servers and database.
- Cloudflare: network security and content delivery, audio file storage (R2), and bot protection on sign-up.
- Stripe: subscription payments. Receives your email and subscription details.
- Resend: sends our transactional emails. Receives your email address and name.
- Mixpanel (EU data residency): product analytics and session replay.
- Reddit and Meta (Facebook/Instagram): advertising measurement. Receive conversion events with a hashed email address, IP address, browser user agent, and ad click identifiers.
- Google / GitHub: only if you choose them to sign in.
Where processors are located outside the EU (for example in the US), transfers rely on EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
Cookies and analytics
- Session cookies: required to keep you signed in to the dashboard.
- Ad attribution cookies: a Reddit click ID cookie (30 days) and a short-lived sign-up correlation cookie (15 minutes), plus cookies set by the Reddit and Meta pixels.
- Mixpanel: uses browser localStorage, records page views, product events, and session replays. Text you type into inputs is masked in replays, and sensitive values (episode text, API keys, passwords) are excluded from analytics events.
You can opt out of analytics and advertising cookies at any time via the Cookie preferences link in the site footer; opting out stops Mixpanel and the Reddit/Meta pixels in your browser. Blocking them with browser settings or extensions also works. Core functionality is unaffected either way (except session cookies, which are required to stay signed in).
Public content
RSS feeds and episode audio are served from public URLs so podcast apps can fetch them. The URLs contain unguessable tokens and are not listed anywhere by us, but anyone you share a feed or episode link with can access it. Do not submit text you would not want to become audible to people with the link.
AI assistants and the MCP server
You can connect cast0 to AI assistants (such as Claude or ChatGPT) through our MCP server. In that case the assistant sends us the text to publish and we return the episode status and links; we receive only what the assistant platform sends to our API and use it solely to provide the service, as described above. What the assistant itself stores or logs is governed by that platform's own privacy policy.
How long we keep it
- Account data: for as long as your account exists.
- Episode text and audio: until you delete the episode or podcast, or your account is deleted.
- Billing records: kept as long as required for accounting and tax purposes.
- Waitlist data: until the product launches or you ask us to remove you.
- Sessions and verification tokens: expire automatically.
Your rights and controls
You can delete episodes, podcasts (including their audio files), and your stored OpenAI key directly in the dashboard. To delete your account entirely, export your data, or exercise any GDPR right (access, rectification, erasure, portability, restriction, objection), email [email protected] and we will handle it within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Security
All traffic is encrypted in transit (TLS). Stored OpenAI keys are encrypted at rest. Our database is not reachable from the public internet, and administrative access is restricted. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.
Children
cast0 is not directed at children under 16, and we do not knowingly collect their data.
Changes
We may update this policy as the service evolves. Material changes will be announced on this page with an updated date, and by email when appropriate.