Privacy Policy
Last updated: 4 October 2026
This policy explains what Caspro (“we”, “us”) collects when you use the Caspro app and its backend service, why we collect it, and the choices you have. Caspro is in a closed beta run by an individual developer. Contact: yasindp2024@gmail.com.
What stays on your device
Caspro is local-first. The images, voiceovers, music, subtitles and rendered videos it creates are saved in a folder on your device (or in the app's own storage on phones). We do not keep copies of them, except as described under “Publishing” below.
What we collect
- Account details: your email address and display name. If you use “Continue with Google”, we receive your Google account's name, email address and profile picture from Google.
- Project metadata: brands, scripts, scene lists, settings, statuses, schedules and cost estimates. This is stored in Google Firebase (Cloud Firestore).
- AI provider API keys that you add (OpenAI, Anthropic, ElevenLabs). They are encrypted with AES-256-GCM before storage and are only decrypted by our backend to make the requests you start.
- Connected social accounts: when you connect YouTube, Facebook, Instagram or Threads, we store the access tokens those services issue (encrypted the same way) and basic channel or page details such as its name and ID.
- Crash reports: if the app crashes, Firebase Crashlytics sends a stack trace, device model, OS version, app version and your Caspro user ID, so we can fix the bug.
- Server logs: our backend logs requests (time, route, status, IP address and device/browser type) to keep the service running and secure. Logs do not contain your API keys or content.
How content flows to AI providers
When you generate a script, image or voiceover, the backend forwards your prompt and text to the provider you chose, using your own API key, and returns the result to the app. We do not store the prompt or the result on our servers. Each provider handles that data under its own terms and privacy policy, through your account with them.
Publishing
When you approve a video for posting, the final video file is uploaded once to a private Google Cloud Storage bucket. Our worker posts it to the accounts you selected, at the time you chose, and then deletes the file. If a post cannot be completed, the file is deleted shortly after its last scheduled time.
YouTube and Google user data
Caspro uses YouTube API Services. If you connect a YouTube channel, Caspro requests permission to read your channel's basic details and to upload videos that you approve. It does not read, change or delete your other videos, comments or subscriptions. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
Caspro's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use this data only to show which channel is connected and to post your videos. We do not sell it, use it for advertising, or let humans read it except to fix a problem you report or where the law requires.
You can revoke Caspro's access at any time on the Google security settings page, or by disconnecting the channel in Caspro.
Who we share data with
We do not sell personal data. We share it only with the services that run Caspro: Google Firebase and Google Cloud (hosting, database, storage, sign-in, crash reports), the AI providers you choose, and the social platforms you post to. We may disclose data if the law requires it.
Where data is stored
Project metadata is stored in Google Cloud's Singapore region (asia-southeast1). Staged videos for publishing are stored in the US (us-west1). Crash reports are processed by Firebase Crashlytics.
How long we keep it
We keep your account data until you delete your account. Staged videos are deleted after posting. Crash reports are kept for 90 days.
Deleting your data
You can delete your account in the app under Settings → Account → Delete account. This removes your profile, brands, projects, stored API keys, connected social accounts and any staged videos, then deletes your sign-in account. Files in your own library folder stay on your device. You can also email us to ask for a copy of your data or for deletion.
Children
Caspro is not meant for anyone under 18, and we do not knowingly collect data from children.
Changes
If we change this policy, we will update the date above and tell beta testers in the app or by email.