Legalv2.4 · Effective Jan 15, 2026

Privacy policy.

A founder shouldn't have to read a 40-page document to know what happens to their writing. So here it is plainly — and then the legal detail if you want it.

We don't train on your data.

Your research, drafts, voice, analytics — never used to train any model. Not ours, not OpenAI's, not anyone's.

Encrypted at rest and in transit.

AES-256 at rest, TLS 1.3 in flight. Per-customer encryption keys on Scale.

You can export anything, anytime.

JSON, Markdown, or CSV — including research history, voice profiles, and every draft you've ever generated.

Delete everything with one click.

Settings → Danger Zone → Delete Workspace. We purge inside 30 days; backups inside 90.

We don't sell your data.

We don't sell, rent, or trade personal data. Full stop.

Opt out of analytics anytime.

Settings → Privacy → Anonymous analytics off. Nothing tied to your identity.

01What we collect

Category
Why
Retention
Account info — name, email, password hash
Sign you in, bill you
While account active
Content — research, drafts, voice profiles
The product
Until you delete
Usage logs — API calls, button clicks
Debug, improve UX
13 months
Billing info — last 4 of card, address
Process payment via Stripe
7 years (tax)
Support tickets
Help you
3 years

02How we use it

We use your data to run and improve the service. Specifically:

  • Account & auth — to sign you in, manage your subscription, and send transactional emails
  • Content data — exclusively to power the features you use. Never for training.
  • Usage logs — to debug issues, improve performance, and understand how features are used
  • Billing — processed by Stripe. We never store your full card number.

03Cookies

We use a minimal set of cookies: strictly necessary session cookies, CSRF tokens, and — by default — anonymous product analytics via PostHog. No advertising pixels. No cross-site tracking. You can disable analytics in Settings → Privacy.

04Data sharing

Subprocessors only — vendors who help us run the service. Each has a signed DPA:

  • AWS — infrastructure hosting (US-East, EU-West)
  • Anthropic, OpenAI, Google — foundation models (zero-retention APIs, no training)
  • Stripe — payment processing
  • Postmark — transactional email

We respond to lawful law enforcement requests only with a valid subpoena, and we'll notify you unless prohibited.

05Storage & security

All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Data is hosted on AWS in US-East by default, with EU-West available on request. We conduct annual third-party security audits. Our SOC 2 Type II report is available under NDA — email privacy@deepcast.ai.

06Your rights

Regardless of where you are, you have the right to access your data, correct it, export it, delete it, and object to certain processing. Exercise any of them from Settings → Privacy, or email privacy@deepcast.ai. We respond within 14 days.

For EU/UK residents: Deepcast, Inc. is the data controller. Our lawful basis for processing is performance of contract (account data) and legitimate interests (usage analytics). You have rights under GDPR/UK GDPR including the right to lodge a complaint with your supervisory authority.

07Children

Deepcast is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@deepcast.ai and we will delete it promptly.

08Contact

Data Protection Officer: privacy@deepcast.ai
Deepcast, Inc. · 548 Market Street #88234 · San Francisco, CA 94104

LAST UPDATED JANUARY 15, 2026