Privacy Policy
Last updated: July 30, 2026
Who we are
Crosscast (“we”, “us”) is a service for publishing and scheduling videos to social platforms, operated at crosscast.app. For any privacy question or request, contact privacy@crosscast.app.
Data we collect
- Account data: your email address and a hashed password, managed by our authentication provider (Supabase).
- Connected platform data: when you link a YouTube, TikTok or Instagram account we store the account's ID, display name, handle, avatar and the OAuth access/refresh tokens the platform issues. Tokens are encrypted at rest and used only to publish content you explicitly create and to show basic account information inside the app.
- Content: the video files, titles, captions and scheduling settings you upload. Files are stored with our storage provider (Cloudflare R2) until you delete them.
- Technical logs: standard server logs (IP address, timestamps, request metadata) kept for security and debugging.
How we use it
Solely to run Crosscast: authenticating you, storing your videos, publishing and scheduling posts to the platforms you connect, and showing you the status of those posts. We do not sell your data, we do not use it for advertising, and we do not use your content or platform data to train AI models.
Third-party platforms
Crosscast connects to third-party platforms only with your explicit authorization via each platform's official OAuth flow. You can revoke access at any time from the app (Accounts → Disconnect) or from the platform's own security settings.
- YouTube: Crosscast uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy. You can revoke Crosscast's access via Google security settings. Crosscast's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- TikTok: publishing uses TikTok's Content Posting API under TikTok's Terms of Service.
- Instagram: publishing uses the Instagram API with Instagram Login under Meta's Platform Terms. We request only the permissions needed to identify your connected account and publish the content you create. You can revoke access under Instagram's Settings → Apps and websites.
Service providers & international transfers
We process data ourselves and through a small number of providers acting on our instructions:
- Supabase — authentication and database.
- Cloudflare R2 — video file storage.
- Resend — transactional email, such as sign-up confirmation and alerts when a scheduled post fails.
Some of these providers, and every platform you connect, operate servers outside the European Economic Area. Where data is transferred internationally it is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
Legal basis
Where the GDPR applies, we process your account data and content to perform our contract with you (Art. 6(1)(b)) — without it we cannot run the service. Connecting a platform and publishing to it rests on your explicit authorization, which you can withdraw at any time by disconnecting the account (Art. 6(1)(a)). Security logging rests on our legitimate interest in keeping the service available and abuse-free (Art. 6(1)(f)).
How we protect your data
Google user data, and every other credential you entrust to us, is protected by the following measures:
- Encrypted in transit. Every connection to Crosscast — browser to app, app to Google, YouTube, TikTok and Meta — uses HTTPS with TLS 1.2 or above. We do not accept unencrypted connections; plain HTTP requests are redirected to HTTPS.
- Encrypted at rest. Databases and video storage are encrypted at rest with AES-256 by our infrastructure providers (Supabase and Cloudflare R2).
- OAuth tokens are separately encrypted. Access and refresh tokens for your connected accounts — including Google and YouTube tokens — are encrypted with an application key (Fernet, AES-128 in CBC mode with an HMAC-SHA256 signature) before they are written to the database, so they are not readable from the stored data alone. The encryption key is held in the application's runtime environment and is never stored in our source code or version control. API keys you add for third-party AI providers are protected the same way.
- We never handle your passwords. Authentication is delegated to Supabase Auth, which stores only a salted hash. When you connect a platform you authenticate on that platform's own site — Crosscast never sees, requests or stores your Google, TikTok or Meta password.
- Access is scoped to your account. Every query for videos, posts, tokens and settings is restricted to the signed-in user's own records, and every API request must present a valid signed session token.
- Video files are not publicly readable. The storage bucket denies public access. Files are reached only through short-lived signed links that expire, generated per request for the account that owns the file.
- Least privilege. We request the minimum OAuth scopes needed to upload and schedule content on your behalf, and nothing that would let us read your private data beyond that. Disconnecting an account deletes its tokens immediately.
- Restricted operator access. Crosscast is run by a single operator, and administrative access to production systems is used only to keep the service running or to investigate a fault you have reported. We do not view the content of your videos except where you ask us to investigate a specific problem with one.
No system is perfectly secure, but if we become aware of a breach affecting your personal data we will notify affected users and, where required, the competent supervisory authority without undue delay and within 72 hours of becoming aware of it.
Storage & retention
Videos and post data are kept until you delete them or delete your account. When you disconnect a platform account, its OAuth tokens and the cached profile details are deleted immediately. When you delete your Crosscast account, all associated videos, posts, tokens and profile data are permanently removed within 30 days.
Step-by-step instructions are on our data deletion page.
Your rights
Depending on your location (including under the GDPR), you may have the right to access, correct, export or erase your personal data, and to object to or restrict processing. Email privacy@crosscast.app and we will respond within 30 days.
Changes
We will update this policy as the service evolves and note the date at the top. If a change is material, we will notify you by email or in-app before it takes effect.