Privacy Policy

Last updated: July 26, 2026

1. Overview

This Privacy Policy explains how Aliocast ("Aliocast", "we", "us") collects, uses, and protects information when you use our AI-generated video channel automation service (the "Service"). Aliocast is the controller of the personal data described here. You can reach us at me@mohitt.com.

2. Information we collect

We collect only what the Service needs to operate:

  • Account information from Google OAuth when you sign in: your name, email address, and profile picture. We never see your Google password.
  • Content you create in the Service: organizations, channel guides, characters, scripts, images, videos, schedules, and approval decisions.
  • Provider API keys you connect (for example Anthropic, Google Gemini, ElevenLabs), stored encrypted at rest and used only to run generations you initiate or schedule.
  • Social account tokens for platforms you connect (YouTube, TikTok, Instagram), stored encrypted and used only to publish content and read performance metrics on your behalf.
  • Billing information processed by Stripe: plan, subscription status, and invoice history. Full payment card details are held by Stripe, not by Aliocast.
  • Usage and log data: actions in the app, generation and publish events, IP addresses, and device/browser information used for security and troubleshooting.

3. How we use information

We use this information to:

  • provide and operate the Service, including running generation pipelines with your provider keys and publishing episodes on your instruction;
  • manage subscriptions, billing, and plan limits;
  • secure the Service, prevent abuse, and debug problems;
  • communicate with you about the Service, including transactional emails;
  • comply with legal obligations.

4. What we do not do

We do not sell personal data. We do not use your content or your provider keys to train models. We do not show advertising in the Service, and we do not use your data for third-party advertising.

5. Where your data lives

Application data is hosted on Supabase (managed Postgres, authentication, and storage), protected by row-level security so each organization's data is isolated. Provider API keys and social account tokens are encrypted at rest, and all traffic is encrypted in transit with TLS.

Social tokens are used exclusively to act on your behalf — publishing approved episodes and reading their metrics — and are never used to read unrelated account data or act without an instruction from you or an automation you configured.

6. Sharing and subprocessors

We share data only with services required to run Aliocast:

  • Supabase — database, authentication, and file storage.
  • Stripe — subscription billing and payment processing.
  • The AI providers you connect — they receive the prompts and content needed to run generations under your own accounts and keys.
  • The social platforms you connect — they receive the content and metadata you publish.
  • Authorities, where disclosure is required by law.

7. Google user data

Aliocast's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google account data is used only for authentication and, for connected YouTube accounts, only to publish content and read performance metrics at your direction.

8. Retention and deletion

We keep your data while your account is active. When you delete your account, or a specific connection or key, the corresponding data is deleted from our production systems within 30 days; residual copies in encrypted backups are purged on the backup rotation cycle. Billing records may be retained longer where required by tax and accounting law.

9. Your rights

Depending on where you live (including under the GDPR and CCPA), you may have rights to access, export, correct, delete, or restrict the processing of your personal data, and to object to processing or withdraw consent. You can exercise most of these directly in the app — including exporting your content and deleting your account — or by emailing me@mohitt.com. We respond to verified requests within the timelines required by applicable law, and we do not discriminate against you for exercising your rights.

10. Security

We apply industry-standard safeguards: encryption in transit and at rest, encrypted storage of provider keys and social tokens, row-level security in the database, scoped OAuth permissions, and least-privilege access to production systems. No method of transmission or storage is completely secure; if we learn of a breach affecting your data we will notify you as required by law.

11. Children

The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced through the Service or by email before they take effect. The date above reflects the latest revision.

13. Contact

For privacy questions or requests, email me@mohitt.com.