Effective August 4, 2026
privacy, without the mystery.
This policy explains what Cast handles, why it is needed, and how to remove it.
Data we handle
- Account identity, email or phone number, username, profile name, settings, public profile photo, and private identity selfie.
- Your age-range attestation, AI-generation consent record, messages, reactions, replies, blocks, reports, device push token, and delivery or seen status.
- Photos, videos, GIFs, captions, thumbnails, filtered captures, generated media, game results, and the friends or group chats you choose as recipients.
- Phone numbers from your contacts when you grant Contacts access. Address-book names and photos stay on your device. If you grant Contacts access, phone numbers are sent to our servers over TLS in E.164 form, keyed-hashed server-side, and only those hashes are stored for friend matching.
- Account-linked product events, device and app context, approximate region derived from your network address, and diagnostics used to operate and improve the service.
Cast does not store address-book names or photos and does not create accounts for unregistered contacts.
Profile photo and visibility
Your Cast profile photo is visible to other users in the app. A separate private identity selfie is used to include you in generated media while your consent is active; it is never displayed to another user.
You can replace either identity photo or revoke generation consent in Settings. Revocation removes both identity photos, disables future likeness use, and removes generated media containing you from the service.
Face data: collection, use, sharing, storage, and retention
What we collect. Cast collects the public profile photo you select or capture, the private identity selfie you capture, and the facial likeness visible in generated media you create, receive, or appear in. Camera effects may detect facial or hand landmarks on your device while in use. Cast does not store that live landmark data or create face geometry, depth data, faceprints, biometric templates, or face-recognition identifiers.
How we collect and use it. After you tap “Allow Face Data Use,” Cast safety-screens both identity photos, displays the profile photo publicly, and stores the identity selfie privately as the sole identity reference for fictional generated media. Cast operators may start curated generations, and an eligible mutual friend may choose you for a Cast-authored group-generation experience while your consent remains active. Generated output is safety-screened before it can be sent. Face data is never used for authentication, advertising, marketing, analytics, user profiling, or identifying anonymous people.
Where it is stored and shared. Convex stores identity photos and generated media, enforces mutual-friend and consent checks, and runs product workflows. OpenAI receives both identity photos for safety screening. Vercel AI Gateway and the configured OpenAI or Google Gemini model receive the prompt, request metadata, composition image, and private identity selfies needed for an operator-, self-, or mutual-initiated generation. A mutual friend can select your public profile but never receives your private selfie. No face data is shared with PostHog, advertisers, data brokers, or information resellers.
How long it is retained. In Convex, a current profile photo and identity selfie remain until you replace them, revoke consent, or delete your account; replaced files are deleted once unreferenced. Generated media remains until consent revocation, account deletion, sender removal, or service removal. OpenAI’s moderation endpoint retains no customer content. OpenAI may retain generation customer content in abuse-monitoring logs for up to 30 days, and Google may retain generation prompts, images, and output for abuse monitoring for up to 55 days; either may retain data longer when legally required or necessary to prevent harm.
How data is used
We use this data to authenticate you, safety-screen identity photos, find mutual friends, provide group chats and first-party camera experiences, create requested AI media, deliver photos, videos, messages, games, and notifications, power the widget and profile archive, and operate safety controls.
Before either identity photo leaves the device for AI use, Cast obtains explicit, versioned permission. OpenAI screens the public profile photo and private identity selfie. While permission is active, Cast operators may include you in curated media, and mutual friends may select you in Cast-authored experiences that generate group photos or other media. Cast verifies the mutual relationship, active consent, and block status before resolving a private identity selfie on the server; the friend never receives the selfie. Generation sends only the references needed for that request through Vercel AI Gateway to the configured OpenAI or Google Gemini model. You can withdraw permission in Settings; withdrawal stops future use and removes both identity photos and generated media that includes you from the service.
AI-generated or AI-edited Cast photos and videos are fictional and must not be presented as real events. AI instructions and templates are fixed and curated by Cast; users choose only an offered experience and eligible mutual friends. Cast sends the public profile photo and private identity selfie directly to OpenAI’s moderation endpoint for safety screening. Operator-curated generation sends the base image, prompt, request metadata, and depicted people’s private selfies through Vercel AI Gateway to OpenAI, with Google Gemini available after a safety refusal. Cast-authored group-generation experiences may send the selected mutuals’ private selfies, a fixed composition template, and a fixed prompt through the Gateway to the configured OpenAI or Google Gemini model. The selecting friend never receives the private selfies and cannot supply the generation instructions. Cast configures no-prompt-training and does not opt in to provider model training. Generated output is screened before sending. OpenAI’s moderation endpoint has no abuse-monitoring retention. OpenAI may retain generation customer content for up to 30 days, and Google may retain Gemini generation content for up to 55 days, or longer when legally required or necessary to prevent harm.
Camera, microphone, speech-recognition, photo-library, motion, Contacts, and notification access is requested only when a feature needs it and depends on your device permission. Live camera effects may process frames, face or hand landmarks, and motion on the device. Captured media is uploaded only when you choose to send it.
Details: AI & likeness.
Messages, media, sharing, and providers
Inside Cast, messages and media are limited to their intended mutual-friend recipients and shared group chats. Sent media may also appear in a sender’s profile archive to mutual friends who share the underlying chat. A recipient or depicted person may save or share media outside Cast. Blocking either direction removes in-app shared-post access. Copies shared outside the service are controlled by the person who shared them, not by Cast.
Convex provides authentication, product data, realtime chats, file storage, and workflows; Twilio receives the phone number and verification metadata needed to deliver and validate one-time codes; Vercel provides hosting and AI Gateway; OpenAI screens identity photos, user-sent images and video thumbnails, and generated output, and generates some images and reaction suggestions; Google Gemini generates media for configured experiences and may provide operator-generation fallback; Expo provides push delivery; PostHog provides analytics and diagnostics; Superwall is installed for future purchases but no paywall is currently presented. Private chat text is not sent to an automated moderation provider.
Cast requires its processors to protect personal data consistently with this policy and applicable law, and does not authorize them to use it for advertising or model training. Review the Twilio privacy notice, Vercel privacy notice, OpenAI privacy policy, Google privacy policy, and PostHog privacy policy.
PostHog receives account-linked, allowlisted product activity and diagnostics, plus person profile fields needed for support (name, username, email, and public profile photo URL). It does not receive private identity selfies, generated or user-captured media, prompts, message text, contacts, address-book names, or private media URLs. Session replay is disabled and PostHog does not record screen, touch, or text capture.
Cast may ask for App Tracking Transparency permission on iOS. With or without that permission, Meta, TikTok, and Google/Firebase receive standard app install and conversion events (for example app open, completed registration, and onboarding completion) so Cast can measure advertising performance. Device advertising identifiers are used only when you allow tracking. Face data is never used for advertising. Review the Meta privacy policy, TikTok privacy policy, and Google privacy policy.
Retention and your choices
Contact hashes remain until your next sync, Contacts permission revocation, or account deletion. Current identity photos remain until replacement, consent revocation, or account deletion. Sent messages, media, results, and delivery metadata remain until sender removal, account deletion, service removal, or the applicable chat is deleted. A reported profile or media copy remains only while its report is open or under review, then is deleted when the report closes. Generated media containing you is removed after consent revocation.
Settings lets you revoke generation consent, change notification choices, block users, and permanently delete your account. Deletion immediately locks the account and begins durable removal of authentication, profile, contacts, relationships, devices, reactions, replies, messages, reports, identity photos, created media, generated media containing you, and linked PostHog people and events. Processor deletion may complete asynchronously. Limited records may remain when required by law, safety, fraud prevention, or backup rotation.
Age and safety
Cast is not intended for children under 16. Users aged 16–17 must attest that a parent or legal guardian permits their use and AI-likeness processing. User-sent images and video thumbnails are screened after delivery and removed if they fail safety checks; AI-generated output is screened before sending. Reports are reviewed by operators. Operators can inspect reported media, remove media or a profile photo, and suspend or restore an account with an audit history. Blocking remains available to every user.
Contact
Cast is a product of Undefined Software, Inc.. Email alon@undefinedinc.io for privacy, deletion, safety, or support questions. Also review our safety policy.