Privacy Policy
Effective Date: April 5, 2026
Last Updated: April 5, 2026
This Privacy Policy describes how CastNET ("we", "us", or "our"), operated by Brody McWilliams, collects, uses, and protects information when you use our services, including the public website at castnet.cc and the CastNET Content Engine platform. CastNET is the operating name; some legacy materials reference the founder's prior brand, FishINDY.
1. Who We Are
CastNET is a content automation platform for professional bass fishing anglers. We help anglers manage their social media content across Facebook, Instagram, and YouTube through automated clipping, formatting, captioning, and posting.
2. Information We Collect
2.1 Sign-In with Facebook (Public Account)
When you sign in to castnet.cc using Facebook, we receive and store the following from your Facebook profile:
- Facebook user ID — the numeric identifier Facebook assigns to your account
- Name — your public display name on Facebook
- Email address — the email associated with your Facebook account
- Profile picture URL — link to your public Facebook profile picture
- Profile link — a URL that points to your public Facebook profile (the
user_link field), shown on your CastNET account page so you and others can find you on Facebook
We do not request, receive, or store your Facebook password. We do not post anything to your Facebook account from this sign-in flow.
2.2 Information Anglers Provide (Content Engine)
- Account Information: Name, email address, and professional angler profile details
- Social Media Credentials: OAuth access tokens for Facebook, Instagram (via Facebook Graph API), and YouTube (via Google OAuth) that you authorize us to store and use on your behalf
- Content: Video clips, transcriptions, captions, thumbnails, and metadata you create or generate through the platform
2.3 Information Collected Automatically
- Platform Data: When you connect Facebook, Instagram, or YouTube accounts, we retrieve and store: Page IDs, Instagram Business Account IDs, YouTube channel IDs and titles, and content publishing permissions you grant
- Usage Data: Post history, engagement metrics, posting timestamps, and API response logs
- Technical Data: IP addresses, device identifiers, browser types, and access logs for security and debugging
3. How We Use Your Information
We use the collected information exclusively to:
- Post content (videos, photos, captions) to your connected Facebook, Instagram, and YouTube accounts on your behalf, as authorized by you via OAuth
- Retrieve engagement analytics and insights from your connected platforms
- Store and organize your video clips, transcriptions, and generated content
- Generate automated captions, hashtags, and platform-specific content formats matching your voice profile
- Provide you with approval workflows and a master clip library
- Monitor token health and notify you when re-authentication is needed
- Improve our services and troubleshoot issues
4. OAuth and API Data Handling
4.1 YouTube API Services
Our use of information received from YouTube APIs adheres to the YouTube API Services Terms of Service and the Google Privacy Policy.
Specifically, we:
- Only access YouTube data with your explicit OAuth consent
- Use YouTube data only for the content posting and analytics features you have authorized
- Do not share YouTube API data with third parties
- Allow you to revoke our access at any time via your Google Account security settings
- Delete YouTube API data from our systems upon your account deletion or revocation request
4.2 Facebook and Instagram
Our use of information received from Facebook and Instagram via the Meta Graph API adheres to the Meta Platform Terms and Developer Policies.
You can revoke our access at any time by removing our app from your Facebook Business Integrations settings.
5. Data Storage and Security
- Encryption at rest: All OAuth access tokens and refresh tokens are encrypted using Fernet (AES-128-CBC) symmetric encryption before being stored in our database
- Secure infrastructure: User data is stored in our managed Postgres database (Supabase) with restricted credentials. Internal admin services that handle this data are isolated on a private network and not exposed to the public internet.
- PIN-gated access: Our platform is protected by PIN authentication with rate limiting
- No third-party sharing: We do not sell, rent, or share your data with third parties for marketing purposes
6. Data Retention
We retain your data for as long as your account is active. Upon account termination:
- OAuth tokens are permanently deleted within 7 days
- Video clips and metadata are deleted within 30 days unless you request earlier deletion
- Logs are retained for 90 days for security and audit purposes, then purged
7. Your Rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Revoke OAuth permissions at any time via the respective platform (Facebook, Instagram, YouTube)
- Export your clip library and content metadata
To exercise any of these rights, email [email protected] or visit our Data Deletion Request page. If you connected via Facebook, you can also request deletion directly from your Facebook App Settings.
8. Third-Party Services
We use the following third-party services to provide our features:
- Meta Graph API (Facebook, Instagram) — for Facebook Login and content publishing
- YouTube Data API v3 — for video uploads and channel management
- Supabase — managed Postgres database for user accounts and account metadata
- Cloudflare — DNS, CDN, and reverse-proxy for the public website
Each service has its own privacy policy governing how they handle data. Automated processing (captioning, transcription, content analysis) is performed on self-hosted infrastructure controlled by the operator — not sent to external AI providers.
9. Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy at this URL with a new "Last Updated" date.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Brody McWilliams
CastNET
Email: [email protected]
Website: castnet.cc
← Back to Home | Terms of Service
© 2026 Brody McWilliams / CastNET. All rights reserved.