Effective date: April 10, 2026
Copycastr (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and the choices you have.
Account information: When you register as an Agency, we collect your email address and display name. Company accounts are identified by the email address provided by your inviting Agency.
Interview data: Voice and text input collected during client interviews is stored as a transcript in our database. This data is used solely to generate website copy on your behalf.
Usage data: We collect standard server logs including IP addresses, browser type, and pages accessed. This data is used to monitor service health and diagnose errors.
Payment data: Credit card and billing information is processed directly by Stripe. Copycastr does not store full card numbers or sensitive payment credentials.
Providing the service: Account and interview data are used to operate Copycastr — conducting interviews, generating copy, and displaying results to authorized users.
Improving the service: Aggregated, anonymized usage statistics help us identify performance issues and plan product improvements. We do not use individual interview transcripts for this purpose.
Communications: We may send transactional emails (account activation, billing receipts). We do not send marketing emails without your explicit consent.
AI model training: Interview transcripts are never used to train or fine-tune AI models. All AI inference is performed at inference time using your transcript as context.
Copycastr does not sell, rent, or trade your personal information or your clients' interview data to third parties.
Sub-processors: We use the following sub-processors to operate the service — Supabase (database and authentication), Vercel (hosting and edge functions), Stripe (payment processing), and OpenRouter (AI inference API). Each sub-processor is contractually bound to handle data in compliance with applicable privacy law.
Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of Copycastr, its users, or the public.
Interview transcripts and generated content are retained for as long as your agency account is active. You may request deletion of a specific client's data at any time by contacting support.
Closed accounts: Upon account closure, your data is retained for 30 days in case of accidental deletion, then permanently removed from our systems.
All data is transmitted over HTTPS. Database access is governed by row-level security policies that restrict each agency to viewing only their own data.
Authentication is managed by Supabase Auth, which implements industry-standard session management and token rotation.
API keys and secrets are stored as environment variables and never exposed to the browser.
Despite our precautions, no system is completely secure. We encourage you to use a strong, unique password and to report any suspected vulnerabilities via our support page.
Access and portability: You may request a copy of the data we hold about you or your clients at any time.
Correction: If any data we hold is inaccurate, please contact us and we will correct it promptly.
Deletion: You may request deletion of your account and associated data. Processing takes up to 30 days.
If you are located in the European Economic Area, you have additional rights under the GDPR. Contact us via our support page to exercise any of these rights.
Copycastr uses a single first-party cookie (copycastr-color-scheme) to remember your light/dark mode preference. We do not use third-party tracking cookies or advertising cookies.
Copycastr is not directed at children under the age of 13 and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
We may update this Privacy Policy from time to time. Material changes will be communicated via the email address on your account at least 14 days before taking effect. Continued use of Copycastr after that date constitutes acceptance of the revised policy.
Questions about this Privacy Policy can be directed to us via our support page.
Also see our Terms of Service. Questions? Contact support