Privacy Policy of the Application "CASTMINT"
Binding language: English. Effective from July 20, 2026.
This Privacy Policy (the "Policy") contains information on the processing of your personal data in connection with the use of the "CASTMINT" application, operating at castmint.app(the "Application"). Any capitalized terms not otherwise defined here have the meaning given to them in the Terms and Conditions.
Personal data Controller
The Controller of your personal data is Lidia Bućko, conducting business activity under the name "TestPoint Lidia Bućko" (place of business: ul. Maratońska 87 lok. 72, 94-007 Łódź, Poland), entered into the Central Register and Information on Business Activity (CEIDG), NIP: 7752621292, REGON: 540507749(the "Controller").
Contact with the Controller
In all matters related to the processing of personal data, you can contact the Controller via:
- e-mail — at: support@castmint.app;
- traditional mail — at: ul. Maratońska 87 lok. 72, 94-007 Łódź, Poland.
Personal data protection measures
The Controller applies modern organisational and technical safeguards to ensure the best possible protection of your personal data and processes them in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"), the Polish Act of 10 May 2018 on the Protection of Personal Data and other data-protection regulations.
Information on the personal data processed
The use of the Application requires the processing of your personal data. Below are the purposes, legal grounds and retention periods.
| Purpose | Personal data | Legal basis & retention |
|---|---|---|
| Conclusion and performance of the Account Service Agreement | name (optional), e-mail address | Art. 6(1)(b) GDPR. Necessary to create and operate the Account. Retained until limitation of claims under the Agreement. |
| Conclusion and performance of the Application Use Agreement | name, e-mail; for paid plans: billing data (name, address, country); optionally company name and NIP (for Entrepreneurs) | Art. 6(1)(b) GDPR. Necessary to provide the Service. Retained until limitation of claims. |
| Conducting a complaint procedure | name, e-mail address | Art. 6(1)(c) GDPR (Art. 7a Consumer Rights Act; digital-content conformity liability). Retained for the duration of the procedure and until limitation of claims. |
| Reporting/verification of unlawful content and appeals (DSA) | name / business name, contact details incl. e-mail | Art. 6(1)(c) GDPR (Art. 16 and 20 DSA). Retained for the duration of the procedure and until limitation of claims. |
| Handling queries (contact form) | name, e-mail, other data contained in the message | Art. 6(1)(f) GDPR (responding to the inquiry). Until an effective objection or the purpose is achieved. |
| Service reviews / Opinions | name, optionally other data in the Opinion | Art. 6(1)(f) GDPR (information/promotion). Until an effective objection or the purpose is achieved. |
| Fulfilling tax obligations (invoicing, accounting records) | name / company, address of residence/registered office, NIP | Art. 6(1)(c) GDPR (tax law). Retained for 5 years from the end of the year in which the tax payment deadline expired. |
| Compliance with data-protection obligations | name, contact details provided | Art. 6(1)(c) GDPR. Until limitation of claims for breach of data-protection law. |
| Establishing, exercising or defending claims | name / company, e-mail, address, PESEL, NIP | Art. 6(1)(f) GDPR. Until limitation of the relevant claims. |
| Application administration (server logs) | IP address, server date and time, browser and operating-system information (saved automatically) | Art. 6(1)(f) GDPR (ensuring proper operation and security of the Application). Until an effective objection or the purpose is achieved. |
| Abuse prevention (free-account limits) | IP address, device fingerprint | Art. 6(1)(f) GDPR (detecting and limiting fraudulent or repeated free-account creation). Retained for a short period necessary for this purpose. |
Processor role (B2B Users)
Where a User who is an Entrepreneur enters into the Application personal data of their own customers or third parties (as part of their User Content), the Controller acts, with respect to that data, as a processoron behalf of that User (who is the controller of such data). The scope of the parties' rights and obligations is governed by a data-processing agreement (DPA) concluded with that User; such a DPA is available on request before the first entrustment of processing and forms an annex to the Terms and Conditions.
Recipients of personal data
The recipients of personal data are the following external entities cooperating with the Controller (each acting under a data-processing agreement and only as necessary to provide the Service):
- Hosting and infrastructure: Vercel Inc. (application hosting), Neon Inc. (database), Cloudflare, Inc. (media storage — R2);
- Payments & billing (Merchant of Record): Dodo Payments Inc. (United States) — processes payments, acts as seller of record, and handles invoicing and tax remittance;
- AI providers: OpenAI (text/scripts), fal.ai (images/video), ElevenLabs (voiceover);
- Transactional e-mail: Resend (e-mail delivery);
- Sign-in: Google (Google sign-in, where chosen by the User);
- Publishing (only when the User connects a channel): YouTube/Google, TikTok, Meta (Instagram);
- Session replay (only with your marketing consent): Content Square SAS (France) — records page interactions so we can diagnose interface problems; data for EU customers is stored in the EU;
- Accounting services (accounting provider).
In addition, personal data may be transferred to public or private entities where required by generally applicable law, a final court judgment or a final administrative decision.
Transfer of personal data to a third country
Some of the providers listed above are based in the United States, so your personal data may be transferred there. The basis for such transfers is:
- the EU–US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) for providers certified under that framework; and/or
- Standard Contractual Clauses in line with Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with supplementary safeguards, for providers not so certified.
You can obtain from the Controller a copy of the data transferred to a third country.
Google user data (YouTube integration)
This section describes specifically how the Application handles data obtained through Google APIs when a User connects their YouTube channel, in addition to the general rules above. It applies to the YouTube Data API scopes youtube.upload and youtube.readonly, which the Application requests only if and when you choose to connect a channel.
- Data we access.Through Google OAuth we receive and process: (a) OAuth access and refresh tokens for your channel; (b) your channel's name, shown so you can confirm the correct channel is connected; and (c) for videos that the Application itself published to your channel, aggregate engagement statistics — view count, like count and comment count. We do not access your watch history, your subscriptions, your private or other existing videos, viewers' personal data, or any content you did not create with the Application.
- How we use it.We use the upload authorisation solely to upload — at your request, each time — a video you generated in the Application to your own channel, with the title, description and visibility you choose. We never upload anything without you asking for that upload. We use the read-only authorisation solely to display your connected channel's name and to show real engagement figures for your published videos on your Statistics page. We do not use Google user data for advertising and we do not build user profiles from it.
- What we share, and with whom. Google user data is stored in our database (Neon) and processed only by our application hosting (Vercel) and our rendering worker (Render) to provide these features, each acting as a processor under a data-processing agreement. We do not sell Google user data. In particular, we do not transfer Google user data — including your tokens, your channel information or your YouTube statistics — to any third-party artificial-intelligence or machine-learning provider, and we do not use it to train, retrain or improve any AI or ML model. The AI providers referred to in this Policy (OpenAI, fal.ai, ElevenLabs) generate your video from your own prompts and inputs before any upload takes place and never receive data obtained from Google.
- How we protect it.Your Google OAuth tokens are encrypted at rest using AES-256-GCM before they are stored, and all communication with Google's APIs takes place over encrypted TLS connections. The authorisation flow is bound to your signed-in session to prevent forgery, and access to your data is scoped to your account.
- How long we keep it, and deletion. We keep your Google tokens only while your channel remains connected. Disconnecting the channel in Dashboard → Socialimmediately deletes the stored tokens; deleting your account deletes them together with the rest of your data. Engagement statistics for a published video are retained with that video and removed when the video or your account is deleted. You can additionally revoke the Application's access at any time in your Google Account security settings (myaccount.google.com/permissions). See our Data Deletion page for details.
CASTMINT's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your rights
In connection with the processing of personal data, you have the right: of access (and to a copy — the first free of charge); to rectification; to erasure (in the cases provided by the GDPR); to data portability; to withdraw consent at any time (where processing is based on consent, without affecting prior lawfulness); to restriction of processing; to object to processing based on the Controller's legitimate interest; and to lodge a complaint with the President of the Personal Data Protection Office (PUODO) if you believe the processing violates the GDPR. To exercise these rights, use our contact form or the contact details above.
Cookies
- The Application uses "cookies" — small text files installed on your end device.
- The Application uses strictly necessary cookies, required for the proper operation of the Application (e.g. maintaining your session and sign-in, security/CSRF protection, and remembering your interface preferences such as the theme). These cookies do not allow the Controller to identify you and do not require your consent.
- Since August 2, 2026 the Application additionally uses an optional marketing tool — Meta Pixel (Meta Platforms Ireland Ltd.) — solely to measure the effectiveness of the Controller's advertising campaigns. It is activated only after you give consent via the cookie banner; you can withdraw or change your choice at any time on the Cookie Policy page. The Application does not use analytics cookies (e.g. Google Analytics). If further such tools are introduced, consent will be requested the same way and this Policy will be updated accordingly.
Final provisions
To the extent not regulated by this Policy, generally applicable data-protection law applies. The Policy is effective from July 20, 2026.