Privacy Policy

Last updated: February 2026

CastProof ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use the CastProof platform at castproof.com.

1. Information We Collect

1.1 Account Data

When you create an account, we collect your name, email address, role (Model or Creator), and any other information you provide during registration.

1.2 KYC Data

Models are required to complete identity verification. We collect government-issued ID documents, selfie verification images, date of birth, and address information. KYC data is processed by our third-party verification provider and retained only as long as required by law and platform integrity needs.

1.3 Likeness Assets

Models upload photos, videos, and other likeness assets for use in AI-generated content. We store these assets securely and use them solely for the purposes described in our Terms of Service.

1.4 Usage Data

We automatically collect information about how you interact with the Service, including IP address, browser type, device information, pages visited, features used, generation history, and timestamps.

1.5 Payment Information

Payment card details and billing information are collected and processed by our payment processor, Stripe. CastProof does not directly store full credit card numbers.

2. How We Use Information

We use the information we collect to:

  • Provide, maintain, and improve the Service.
  • Process transactions and send related notices.
  • Verify identity and prevent fraud.
  • Facilitate likeness licensing between Models and Creators.
  • Generate AI content in accordance with approved usage requests.
  • Enforce our Terms of Service and protect platform integrity.
  • Communicate with you about updates, security alerts, and support.
  • Comply with legal obligations.

3. Data Sharing

We do not sell your personal information. We share data only in the following circumstances:

3.1 Stripe (Payment Processing)

Payment and payout information is shared with Stripe to process subscriptions, credit purchases, and model payouts. Stripe's privacy policy governs their use of your data.

3.2 AI Vendors (Content Generation)

Likeness assets and generation prompts may be transmitted to third-party AI service providers solely for the purpose of generating content. We require all AI vendors to adhere to strict data protection agreements and to not retain or train on your data.

3.3 KYC Providers (Identity Verification)

Identity documents and verification data are shared with our KYC provider for the sole purpose of verifying your identity. Data is processed in accordance with their privacy policy and applicable regulations.

3.4 Legal Requirements

We may disclose your information if required by law, legal process, or government request, or to protect the rights, property, or safety of CastProof, our users, or the public.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention periods include:

  • Account data: Retained until account deletion, plus any legally required retention period.
  • KYC data: Retained for the duration of your account and for up to 5 years after account closure, as required by applicable regulations.
  • Likeness assets: Deleted within 30 days of account deletion or consent revocation.
  • Usage and generation data: Retained for up to 3 years for audit and compliance purposes.
  • Payment records: Retained for up to 7 years as required by tax and financial regulations.

5. User Rights

Depending on your jurisdiction, you may have the following rights:

5.1 Access

You may request a copy of the personal information we hold about you.

5.2 Deletion

You may request the deletion of your personal data. We will comply except where retention is required by law or necessary for legitimate business purposes (such as fraud prevention or existing license records).

5.3 Portability

You may request your data in a structured, commonly used, machine-readable format.

5.4 Correction

You may request that we correct inaccurate or incomplete personal data.

5.5 Objection & Restriction

You may object to or request restriction of certain processing activities.

To exercise any of these rights, contact us at privacy@castproof.com.

5A. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, the purposes for collection, the categories of sources, and the categories of third parties with whom we share your data.
  • Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions (e.g., legal compliance, ongoing transactions).
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: CastProof does not sell your personal information and does not share it for cross-context behavioral advertising. Therefore, there is no need to opt out.
  • Right to Limit Use of Sensitive Personal Information: We use sensitive personal information (such as biometric data) only for the purposes disclosed in this Privacy Policy and our Biometric Data Consent.
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

To exercise any of these rights, contact us at privacy@castproof.com or use the in-app account settings. We will respond to verified requests within 45 days.

Categories of personal information collected in the past 12 months: identifiers (name, email, phone), commercial information (subscription data, transaction history), biometric information (for Models — see our Biometric Data Consent), internet activity (usage data, IP address), professional information (KYC data), and audio/visual data (likeness assets, voice samples).

5B. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

Legal Bases for Processing

We process your personal data on the following legal bases:

  • Consent: For biometric data collection (see Biometric Data Consent), marketing communications, and non-essential cookies (see Cookie Policy).
  • Contractual Necessity: For account creation, subscription management, content generation, payment processing, and fulfilling our obligations under the Terms of Service.
  • Legitimate Interest: For fraud prevention, platform security, analytics, and improving the Service.
  • Legal Obligation: For tax reporting, law enforcement requests, and regulatory compliance.

Additional GDPR Rights

  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of processing prior to withdrawal.
  • Right to Data Portability: You may receive your data in a structured, commonly used, machine-readable format.
  • Right to Lodge a Complaint: You may file a complaint with your local data protection supervisory authority.

Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33 and 34.

Data Processing Agreement

For details on our sub-processors and data processing practices, see our Data Processing Agreement.

6. Cookies and Tracking

CastProof uses cookies and similar tracking technologies to operate and improve the Service. These include:

  • Essential cookies: Required for authentication, security, and core functionality.
  • Analytics cookies: Used to understand how users interact with the platform and to improve user experience.
  • Preference cookies: Used to remember your settings and preferences.

You can manage cookie preferences through your browser settings. Disabling essential cookies may impair your ability to use the Service.

7. Children's Privacy

CastProof is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a minor, we will take immediate steps to delete that information and terminate the associated account.

8. Security Measures

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Access controls and role-based permissions for internal systems.
  • Regular security audits and vulnerability assessments.
  • Secure, isolated storage for KYC documents and likeness assets.
  • Monitoring for unauthorized access or suspicious activity.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

9. International Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure that appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses and other mechanisms approved by applicable data protection authorities.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this page periodically.

11. Contact

If you have any questions or concerns about this Privacy Policy, please contact us at:

For biometric data inquiries specifically, please see our Biometric Data Consent. For cookie preferences, see our Cookie Policy.