Privacy Policy
Last updated: August 13, 2026
This policy describes how Eschaton Labs ("we") handles your information when you use Crosscast at crosscast.io (the "Service"). The short version: we store what the Service needs to publish and measure your content, we don't sell any of it, and you can delete all of it.
Information we collect
- Account information. Your email address, name, and password hash when you sign up.
- Connected platform accounts. When you connect a TikTok, Instagram, or YouTube account we store the OAuth tokens those platforms issue, the account's public identity (handle, display name, avatar), and the scopes you granted. Tokens are encrypted at rest and used only to perform the actions you initiate.
- Content. Videos, captions, cover selections, and schedules you upload or create via the API.
- Analytics data from platforms. Performance metrics (views, likes, comments, shares, watch time, follower counts) that the platforms' APIs report for your own posts and accounts.
- Usage and log data. Standard operational logs (IP address, browser type, timestamps) kept for security and debugging.
How we use it
- To publish content to the platform accounts you connected, on the schedules you set.
- To fetch and display analytics for your posts and accounts.
- To operate, secure, and improve the Service.
- To contact you about the Service (account notices, breaking changes). No marketing without opt-in.
Platform data
Data received from TikTok, Instagram (Meta), and YouTube (Google) APIs is used only to provide the Service's features to you, is never sold, never used for advertising, and never shared with third parties except the subprocessors below. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke Crosscast's access at any time from each platform's security settings or by disconnecting the account in your dashboard, which deletes its stored tokens immediately.
Storage and subprocessors
Data is stored with our hosting provider (Railway Corp., United States) — application database and object storage for your uploaded videos. Uploaded videos are staged at time-limited signed URLs solely so the platforms can ingest them, then those URLs expire.
Retention and deletion
- Uploaded videos: deleted from storage 30 days after their last scheduled post completes, or immediately when you delete them.
- Platform tokens: deleted immediately when you disconnect an account or delete your workspace.
- Analytics snapshots: kept while your workspace exists.
- Deleting your workspace (Settings → Danger zone, or by emailing support@crosscast.io) removes all of the above within 30 days, including backups.
What we don't do
- We don't sell or rent your data. To anyone.
- We don't use your content or platform data to train models.
- We don't read, repost, or modify your content beyond what you schedule.
- We don't use third-party advertising or tracking pixels on the Service.
Security
Transport is TLS everywhere. Platform tokens are encrypted at rest. API keys are stored hashed and displayed once. Access to production systems is limited to Eschaton Labs operators.
Your rights
Depending on your jurisdiction (including GDPR and CCPA), you may have rights to access, correct, export, or delete your personal information. Email support@crosscast.io and we'll handle it within 30 days.
Changes
We'll post changes here and, for material changes, email account holders before they take effect.
Contact
Eschaton Labs — support@crosscast.io