Privacy policy
Castrook is a social publishing service in developer beta. This policy describes the data used to connect accounts, publish and schedule content, manage supported comments, and operate the service. For privacy questions, contact support@castrook.com.
Data we process
- Account and workspace information, including your email address and workspace preferences.
- Connected social-account identifiers, names, granted permissions, and authorization tokens.
- Content you submit for publication, including captions, media URLs, schedules, destination settings, and delivery results.
- Comments and replies requested through the service, plus API request metadata and webhook delivery records.
How we use data
We use this information to provide the actions you request, maintain account security, diagnose failures, apply rate limits, and communicate about your account. Social platforms receive the content and actions you authorize. Their own policies apply to the data they process.
Service providers
We use service providers for identity, application hosting, data storage, and operational delivery. They process data needed to provide those services. Castrook does not sell connected-account data.
Retention
Product records remain available while your account is active. Request logs, cached comments, and webhook delivery attempts are retained for up to 30 days. Temporary media copies are retained for up to 48 hours. Disconnecting a social account clears the connection’s stored access credentials. Deletion requests remove associated account and product records, subject to any records that must be retained by law.
Your control
You can revoke API keys, disconnect social accounts, and revoke Castrook in each social platform’s connected-app settings. See data-deletion instructions to request deletion. Disconnecting Castrook does not delete posts already published to a social platform.
Security and changes
API key secrets are stored as hashes. Connected-account credentials are encrypted at rest and are not returned by the API. No service can guarantee absolute security. We may update this policy as the service changes; the update date above identifies the current version.