Effective: April 6, 2026
Privacy Policy
This Privacy Policy explains how Expandcast ("we," "us"), operated at expandcast.com, collects, uses, and protects your information. By using the Service, you consent to the practices described below.
1. What We Collect
- Account info: Email, name, and OAuth profile data when you sign in (e.g., via Google, Instagram, TikTok).
- Uploaded content: Audio/video files and metadata (titles, descriptions) you provide.
- Generated content: AI outputs (blog posts, threads, thumbnails, etc.) stored in your account.
- Usage data: Pages visited, features used, browser type, device info, IP address.
- Payment info: Processed by Stripe. We do not store your card details — we only receive transaction IDs, plan type, and billing status.
2. How We Use It
We use your information to:
- Operate and provide the Service (transcription, AI generation, storage).
- Process payments and manage subscriptions.
- Send transactional emails (verification, receipts, subscription reminders).
- Improve the Service using aggregated, anonymized data.
- Detect fraud, abuse, and security issues.
- Comply with legal obligations.
3. Third-Party Services
We share data with the following providers, each under their own privacy policies:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Auth, database, file storage | Account info, uploads, generated content |
| Groq | Audio/video transcription | Uploaded audio/video files (processed in transit, not retained) |
| OpenRouter | AI text generation | Transcripts and prompts |
| Hugging Face | AI image generation (thumbnails) | Text prompts |
| Stripe | Payment processing | Email, billing info, transaction data |
| Vercel | Hosting & CDN | Standard HTTP request data (IP, headers) |
4. Cookies
- Essential: Authentication and session management. Required.
- Preferences: Theme settings (dark/light mode).
- Analytics: Usage patterns to help us improve the Service.
You can manage cookies via your browser settings. Disabling essential cookies may prevent the Service from working.
5. Data Retention
- Account data: Kept while your account is active. Deleted within 30 days of account closure.
- Uploaded & generated content: You can delete individual episodes anytime. All content is removed when your account is closed.
- Usage logs: Kept up to 12 months, then anonymized or deleted.
- Payment records: Retained as required by tax/financial regulations.
6. Your Rights
Depending on your jurisdiction, you may:
- Access a copy of your personal data.
- Correct inaccurate data.
- Delete your data (subject to legal requirements).
- Export your data in a portable format.
- Object to certain processing, including marketing.
To exercise any right, email contact@expandcast.com. We respond within 30 days.
The Service is not intended for anyone under 16. If we learn we've collected data from a child under 16, we will delete it promptly.
7. Security
We use encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is 100% secure, but we take reasonable measures to protect your data.
Your data may be processed in countries other than your own (including the United States) where our providers operate. We rely on appropriate safeguards for international transfers where required.
8. Changes
We may update this policy. Material changes will be communicated via email or in-app notice, and the effective date above will be updated.
9. Contact
Questions about your privacy? Reach us at contact@expandcast.com.