Privacy Policy
This Privacy Policy explains what information GrabCast collects, why, how long we keep it, who we share it with and the choices and rights you have. We designed GrabCast to be privacy-first: most tools run in your browser and never upload your files.
Who we are. GrabCast is operated by Digidot Marketing Agency L.L.C., a Wyoming limited liability company, 30 N Gould St Ste R, Sheridan, WY 82801, USA ("GrabCast", "we", "us"). We are the controller of personal data processed through grabcast.click, except where we process data on behalf of a workspace owner (see Team workspaces). Contact: privacy@grabcast.click.
The short version
- Files you open in our image, PDF, video, audio and transcription tools are processed on your device and are not uploaded.
- We collect only what a feature needs: your account email, what you choose to save or schedule, data from social, ad and storage accounts you connect, and pseudonymous usage statistics.
- Access tokens, refresh tokens and API keys are encrypted with AES-256-GCM and never shown in your browser.
- We don't sell your personal information, don't use data from connected platforms for advertising, and don't use your content to train AI models.
- You can export or delete your data at any time in Account → Data & privacy, or by following the data deletion instructions.
On this page
- Tools that run in your browser
- Features that use our servers
- Social Media Scheduler and connected accounts
- Ads manager (Meta ad accounts)
- Google user data and Limited Use
- Team workspaces and approval links
- AI features and your AI keys
- Media library and connected storage
- Account, usage and security data
- Cookies and browser storage
- Advertising
- Affiliate links
- Emails we send
- Who we share data with
- Legal bases (EEA/UK)
- International transfers
- How long we keep data
- Your rights
- US state privacy rights (California and others)
- Your privacy choices
- Security
- Children
- Changes to this policy
- Contact
1. Tools that run in your browser
Most of our tools (image converters, PDF tools, background remover, video and audio editors, AI transcription, QR codes, word counter, Base64, JSON, password generator and many more) run entirely in your browser. Your files are processed on your device and are never uploaded to our servers. Some of these tools download open-source code or AI models to your browser from public content-delivery networks (see third-party resources); those downloads don't include your files.
Some tools remember your options, and some keep the file you are working on in your browser for up to 3 days so a reload doesn't lose it. That data stays in your browser (see Cookie & Storage Policy).
2. Features that use our servers
- AI text features (for example the AI writer, translator, summarizer, email reply, content pack and document Q&A): where possible the reply is generated on your device (your browser's built-in AI, or an open model you chose to download, which then runs locally) and your text never leaves your device. If you added your own AI key, your text goes from your browser directly to that provider under its terms. Otherwise, when GrabCast's own server AI isn't available to you (it is reserved for site admins), your browser sends the text you enter to the free Pollinations.ai service to generate the reply (results made this way show a "☁ Pollinations" label); choose "On this device only" in AI settings or use your own key to avoid this. For site admins the text goes to our server, which forwards it to an AI provider (currently Groq, with Pollinations as a fallback). Each result shows which engine was used. A few image and text tools send your prompt from your browser straight to Pollinations. Replies may be kept in server memory for up to 30 minutes to answer identical requests faster. We don't store your prompts in our database, don't use them for advertising and don't use them to train AI models. If you add your own AI key, it is used only for your own requests (see AI features and your AI keys).
- Optional cloud transcription: if you choose to transcribe with your own OpenAI or Groq key instead of the in-browser model, your audio goes directly from your browser to that provider under your own account; it doesn't pass through our servers.
- Temporary email: messages sent to a temporary inbox are received and stored on our server until the inbox expires (24 hours for shared addresses, 72 hours for addresses on your own domain) or you delete them. Temporary inboxes aren't private — don't use them for anything sensitive.
- Problem reports you choose to send (your message, the page, your browser type and, if you give it, your email address) so we can fix the problem and reply.
- Accounts, sign-in and the features in the sections below.
Template Studio: saved designs and community templates
- GrabCast Studio (the video editor) processes media on your device. Imported clips, projects, version history and exports are stored only in your browser (IndexedDB / origin storage) and are never uploaded; clear this site's data to remove them. Sending an export to the Scheduler "on this device" also stays local.
- Saved designs ("My designs") contain only template data (text, colours, fonts, timing, music settings) — your photos, clips and logo stay on your device. They are private to you.
- Published community templates are public: the template, the display name you choose, its ratings and use/save/remix counts, "remix of" credits and a creator page listing your published templates. Your e-mail address and account details are never shown. Your handle is replaced with "@yourbrand" and links, e-mail addresses and phone numbers are blocked.
- Reviews, ratings and reports: we store the reviewers' votes and notes, your star ratings, reports (reason, optional message, and a salted hash of the network address when you're signed out) and, for anti-abuse, one "used" count per person per template per day. Reviewers and other users see only vote totals, never who voted; GrabCast moderators can see which account voted, rated or reported. To keep ratings fair we compare keyed hashes (HMAC) of the network (/24) and device identifier that sent a rating or published a template with those of the author — the same kind of abuse-prevention hash described in Account, usage and security data; the raw address and device identifier are not stored with them.
- Automated checks and community moderation run on the template text and thumbnail only (spam, near-copies, blocked words, blank thumbnails). Decisions (approve, decline, hide, remove, strikes) are logged and shown to the author in their account notifications.
GrabCast does not download or fetch videos, audio or other content from third-party websites. The only exception is a file you choose from your own cloud storage (Google Drive, Dropbox, OneDrive or Box) to add to a post — see Adding media from your phone and cloud storage. We never download from social or video platforms.
3. Social Media Scheduler and connected accounts
The Social Media Scheduler lets you draft, schedule and publish posts. Drafts you create without signing in are stored only in your browser on your device. If you sign in and connect an account, the following applies.
What we receive from each platform
- Facebook and Instagram (Meta): your app-scoped Facebook user ID; the ID, name and picture of each Facebook Page you choose and the tasks you can perform on it; the ID, username, name and picture of each linked Instagram professional account; access tokens; the list of permissions you granted; for posts published through GrabCast, their IDs, links and status. If you enable the extra features, we also receive: reaction, comment, share and view counts, reach and watch-time statistics for those posts; the comments on those posts (author name and ID, text, time, and whether a comment is hidden); your Page's follower count and Page-level views, reach, engagement and new followers (
read_insights); your Instagram account's follower and post counts and account-level reach, views, accounts engaged and interactions (instagram_manage_insights). - Threads (Meta): your app-scoped Threads user ID, username, name, profile picture, bio and verified badge; a long-lived access token (renewed automatically before it expires after 60 days); your posting quota (posts and replies used in the last 24 hours); for posts published through GrabCast, their IDs, links and status. If you enable the extra features, we also receive view, like, reply, repost, quote and share counts for those posts and your profile's follower count, views, likes, replies, reposts, quotes, link clicks and follower demographics (country, city, age, gender, when Threads provides them) (
threads_manage_insights); and the replies to posts you published through GrabCast (author username, text, time, whether a reply is hidden) (threads_read_replies). Replies are read when you open the Inbox and are not stored. - YouTube (Google): your Google account ID, name, email address and picture; if you grant read access, your channel ID, title and thumbnail; access and refresh tokens; for videos uploaded through GrabCast, their IDs, links and status. If you enable the extra features, we also receive: view, like and comment counts and watch time for those videos (
youtube.readonly,yt-analytics.readonly); your channel's subscriber, view and video counts and daily channel reports (views, watch time, subscribers gained and lost, likes, comments) from the YouTube Analytics API; the comments on videos you published through GrabCast and, if you add subtitle tracks from a subtitle pack, the IDs of the caption tracks GrabCast uploaded to those videos (youtube.force-ssl). - TikTok: your TikTok open ID, display name, username and avatar; the posting options TikTok allows for your account; access and refresh tokens; for posts published through GrabCast, their IDs, links and status. If you enable the extra features, we also receive view, like, comment and share counts for those posts (
video.list) and your follower, following, like and video counts (user.info.stats). TikTok doesn't offer a comments API to apps like GrabCast, so we never read or post TikTok comments; GrabCast links you to the post in TikTok instead. - Bluesky and Mastodon: your handle, display name, avatar and account ID, session or access tokens, and for posts published through GrabCast their IDs, links, status and counts. For Mastodon, if you use the Inbox features, we also read your notifications (mentions and replies) and can like, boost, mute or block only when you click those buttons. See Bluesky and Mastodon accounts.
- Google Drive, Docs and Sheets: your Google account ID and email, tokens limited to the
drive.filepermission, and the name, type, size and (for media) dimensions of the files you pick or GrabCast creates. See Media library and connected storage.
What you give us and how we use it
- What you give us: the posts you save (caption, title, first comment, link, times, time zone, per-platform settings such as privacy, "made for kids", AI-generated and commercial-content disclosures), the media you attach, notes and labels, and the time you confirmed publishing.
- How we use it: only to publish what you schedule or publish, to show you each post's status, statistics and comments, to create the reports you ask for, to warn you when an account needs reconnecting, and to let you manage or disconnect accounts. We never post anything without your explicit confirmation. We do not sell this data, use it for advertising, or use it to train AI models. We share it only with the platform you publish to and with the service providers that run GrabCast (see Subprocessors).
- Comments: comments are read from the platform when you open them and are not stored. Replying to, hiding, unhiding or deleting a comment happens only when you click that button, and only on posts you published through GrabCast; the only thing we keep is the ID of a comment you mark "done", which is deleted when you disconnect the account or the post is gone.
- Statistics: post statistics are saved as snapshots (1 hour to 30 days after publishing). Account-level statistics (followers, reach, channel analytics) are read live when you open Analytics, kept in server memory for up to 30 minutes to save API calls, and never written to our database.
- Security: access and refresh tokens are encrypted at rest (AES-256-GCM), are never shown in your browser and are never written to logs. Data travels over HTTPS.
- Media files: see Media library and connected storage. Platforms fetch the file to publish from a signed link that expires within 6 hours.
Adding media from your phone and cloud storage
In the Scheduler you can add photos and videos from your phone or from Google Drive, Dropbox, OneDrive and Box. In every case we access only the files you pick, never the rest of your storage.
- From your phone: your computer shows a QR code for a private link that works once, on one phone, for 15 minutes. The phone doesn't need to sign in; the files it sends go straight to our private storage (Cloudflare R2) and appear in your account. We store only a scrambled (hashed) form of the link, and delete the link record a day after it expires.
- Dropbox: you pick files in Dropbox's own window (Dropbox Chooser). Dropbox gives us a temporary link to each chosen file, which we use once to copy it; we don't receive or store a Dropbox login.
- OneDrive: you sign in with Microsoft in your browser to pick files. The Microsoft sign-in stays in your browser for that session and is never sent to or stored on our servers; we receive only a short-lived download link for each file you picked.
- Share links (Google Drive, Dropbox, OneDrive, Box): when you paste a link to your own file, our server downloads that one file and checks it's a photo or video. We keep the file name, type, size and which service it came from, not the link itself.
- Uploads that never finish are deleted within 6 hours.
Removing GrabCast from a platform
- YouTube: GrabCast uses YouTube API Services. By connecting YouTube you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy. You can revoke GrabCast's access at any time at Google security settings. We re-confirm our access every day and refresh your channel or profile details at least every 30 days. Data we store from YouTube API Services is deleted within 7 days after you disconnect or revoke access; statistics are deleted immediately when you disconnect.
- Facebook and Instagram: you can remove GrabCast at any time in your Facebook settings (Settings & privacy → Settings → Apps and websites). When you remove it, Meta notifies us: we delete the access tokens and statistics right away, cancel pending posts to those accounts, and delete the remaining account records within 7 days. If you send a data deletion request through Facebook, we immediately delete everything we received from Meta for your Facebook user: accounts, tokens, post IDs and links, statistics, ad-account connections, and posts and media that were only meant for those accounts. You then get a confirmation code to check the status. Deletion instructions: grabcast.click/data-deletion.html.
- Threads: content you publish through GrabCast is subject to the Threads Terms of Use and Meta's Community Guidelines. We post only content you confirm, with the reply settings you choose. You can remove GrabCast at any time in Threads under Settings → Account → Website permissions. When you remove it, Meta notifies us: we delete the access token and statistics right away, cancel pending Threads posts, and delete the remaining account record within 7 days. If you send a data deletion request through Meta, we immediately delete everything we received for your Threads profile and you get a confirmation code to check the status.
- TikTok: content you publish through GrabCast is subject to TikTok's Terms of Service and Community Guidelines. We post only content you confirm, with the privacy, interaction and disclosure settings you choose. We never pick a privacy setting for you. You can remove GrabCast in the TikTok app under Settings and privacy → Security and permissions → Apps and services permissions; we delete the stored data within 7 days of noticing.
- Disconnecting in GrabCast revokes our access at the platform (where the platform supports it) and immediately deletes that account's tokens, profile details, statistics and health checks, and cancels its pending posts. Your own post history in GrabCast (captions, times, status and links) stays until you delete those posts or use "Delete all social data", which removes connected accounts, saved posts, uploaded media, notifications and your activity log at once.
4. Ads manager (Meta ad accounts)
If the Ads manager is enabled for your workspace, an Owner or Admin can connect Meta ad accounts through a separate Facebook permission dialog (ads_read, and ads_management when boosting or campaign editing is on; business_management only when needed to list ad accounts owned by a business portfolio).
- What we receive: your app-scoped Facebook user ID and name; an access token (encrypted with AES-256-GCM); the granted permissions; for each ad account you can access: its ID, name, currency, time zone, status and disable reason, amount spent, spend cap, balance, owning business, a display string for its funding source (never card numbers or payment details), promotable Pages and pixels; campaigns, ad sets, ads and creatives with their settings, budgets, schedules, targeting and review status; and performance statistics (spend, impressions, reach, frequency, clicks, CTR, CPC, CPM, results, cost per result, purchase value and ROAS, video views), including aggregated breakdowns by age, gender, country, placement and device. We never receive information about the individual people who saw your ads.
- How we use it: only to show your ad accounts and their performance, to create and change the campaigns you ask for (always created paused, and started only after your confirmation), to run the optional rules and alerts you turn on, and to include paid results in reports you create. We don't use ads data for our own advertising, don't sell or share it, and don't use it to train AI models. If you click "Explain with AI", only aggregated numbers are sent to the AI provider.
- What we keep: statistics are cached for 15 minutes (ranges that include today) or 12 hours and then deleted. Ad-account details, the campaigns GrabCast created, your spending limits and rules, and an audit log of every change (who, when, what changed, IP address) are kept while the ad account stays connected to the workspace, so the workspace can see what was done.
- Deletion: disconnecting an ad-account connection deletes its token. Deleting your account first pauses the campaigns GrabCast started for you, then deletes your ads connections, accounts, objects, rules and cache; in other people's workspaces, the record of changes stays but no longer names you.
5. Google user data and Limited Use
GrabCast's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We request only what a feature needs:
youtube.upload, and only if you enable the extra featuresyoutube.readonly,yt-analytics.readonlyandyoutube.force-ssl(YouTube);drive.file(Google Drive, Docs and Sheets — access only to files you pick or that GrabCast creates); and your basic profile (name, email, picture) for Google sign-in. - We use Google user data only to provide the features you see in GrabCast: uploading and scheduling your videos; showing their statistics, your channel analytics and comments and letting you reply to or moderate comments; picking Drive files for posts; storing GrabCast files in your Drive; importing and syncing a content calendar from a Google Sheet you pick; reading a Google Doc you pick as a content source; and exporting reports to a new Sheet or Doc.
- We don't transfer Google user data to others except as needed to provide those features (for example to our hosting providers), for security, or to comply with the law; we don't use it for advertising, don't sell it, and don't use it to develop, improve or train AI or machine-learning models; and no person at GrabCast reads it unless you ask us to, it is needed for security or abuse investigations, or the law requires it.
- You can revoke GrabCast's access at any time at Google Account → Third-party apps & services.
6. Team workspaces and approval links
- Workspaces and members: when you create a workspace or accept an invite, we store the workspace name and color, who is a member and each member's role. Members of a workspace see each other's name and email address (Client approvers see names only). Social and ad accounts connected in a workspace belong to that workspace: its members can see them and, depending on their role, publish or manage ads with them. For content inside a workspace, the workspace owner decides what is stored and shared; we process it on their behalf.
- Invites: we store the invited email address, the role and when the invite expires (7 days). We only keep a one-way hash of the invite link. If email is set up, we send one invitation email; otherwise the person who invites copies the link.
- Content board: cards (ideas, captions, labels, checklists, due dates, assignees), comments with @mentions and every saved version of a caption, so reviewers can see what changed. Notifications about assignments, mentions, due dates and approvals are shown in the app and, if you keep email notifications on, sent by email.
- Audit log: each workspace keeps a log of who did what (for example "moved a card", "created an approval link", "changed a role"), with the time and IP address, visible to its Owner and Admins.
- Approval links and shared reports: anyone with the link can see the posts or report in it until it expires or is revoked (report links expire after 30 days by default). Links are not indexed by search engines and can have a password (we only store a hash of the link and of the password). When a reviewer approves, requests changes or comments, we store the reviewer's name and email address, their decision, comment, time and IP address, and show them to the workspace's members. Reviewers' name and email are remembered only in their own browser for next time.
- Retention: board data, versions, comments, reviews and the audit log are kept while the workspace exists and deleted when its owner deletes it. Leaving or being removed from a workspace removes your membership; comments you wrote stay with the workspace. To have reviewer details removed, contact the workspace that sent the link or contact us.
7. AI features and your AI keys (BYOK)
GrabCast's AI features run on your device when your browser supports it, or with your own key; GrabCast's own server AI is used only for site administrators. You can connect your own keys for AI providers (for example OpenAI, Anthropic, Google Gemini, Groq, OpenRouter, Mistral, DeepSeek, xAI, Hugging Face, Cloudflare Workers AI, Stability AI, fal.ai, Replicate, Ideogram, Black Forest Labs, Runway, Luma and ElevenLabs) and for stock media search (Pexels, Pixabay) in Account → Connections. When you use your own key, your prompts and inputs go to that provider under your own account and its privacy policy applies.
- Storage: keys are encrypted with AES-256-GCM before they are stored. The encryption key is held only on our servers, not in the database, and each stored key is bound to its own record and account. After you save a key we only ever show its last 4 characters (for Cloudflare also the first characters of your Account ID, which isn't secret); your data export lists keys the same way.
- Use: a key is used only for AI requests you start (such as writing captions or testing the key) and work you schedule (autopilot plans you turn on, image or video jobs). It is shared with teammates only if you turn on sharing for that key; then members of workspaces you own can make AI requests with it, without ever seeing it. We never sell keys or use them for our own work.
- Where requests go: only to that provider's official API address (a fixed list in our code), or to your own Cloudflare AI Gateway if you set one up. Keys are not written to our logs, and provider error messages are scrubbed of anything that looks like a key.
- Usage records: we count requests, failures and tokens per provider per day so you can see your usage and so fair-use limits work. We don't keep the prompt text; generated images and videos are stored in your media library like other uploads.
- Your control: you can see each key's usage, pause it or remove it at any time. Removing a key deletes it from our database immediately; encrypted database backups kept by our database provider expire on their own schedule. We recommend creating a dedicated key with a spending limit at the provider and revoking it there when you stop using GrabCast.
- Browser-only mode: for some text providers you can keep a key only in your browser; it then goes straight from your browser to the provider and never reaches our servers.
- AI key for GrabCast's tools (Account → Connected apps): this older, separate option keeps the key in your browser and sends it with each AI tool request; when you're signed in it is also saved encrypted on your account so your other devices can load it.
- Deletion: deleting your account, or "Delete all social data" in the Scheduler, deletes all your AI keys, AI usage records and AI settings.
8. Media library and connected storage
- Media library: photos and videos you upload to the Scheduler (and images or videos you generate there) are kept in your workspace's media library in private cloud storage (Cloudflare R2), or in a Google Drive you connect, until you delete them. Deleted files go to the Trash, where you can restore them for 30 days; after that they are permanently deleted. Optional cleanup rules (off by default) can delete published or unused files automatically. You can see, download and delete every file in Settings → Storage.
- Temporary copies: media that isn't kept in the library, and copies made only to publish (for example a file copied from Google Drive, Dropbox or OneDrive), are deleted automatically: 24 hours after the post is published or canceled (never later than 48 hours for Drive staging copies), 7 days after a failed post (so you can retry), and 7 days after upload if no post uses them. Posts set to repeat (evergreen) keep their media while repeating is on.
- Google Drive as storage: if you connect a Google Drive to store GrabCast files, we request only the
drive.filepermission (GrabCast can see only the files it creates or you pick) and read your Drive's name, email, picture and storage quota to show it in Settings. The refresh token is encrypted (AES-256-GCM) and never shown in your browser. You can disconnect it in GrabCast or revoke access at any time at Google security settings. Deleting your account revokes the token at Google and deletes our records; files already in your own Drive stay in your Drive. - Google Docs and Sheets: if you link a Google Sheet as a content calendar, we store the file's ID, name and link, your column mapping and, per row, a fingerprint used to sync changes both ways. If you use a Google Doc as a content source, we keep a cached copy of its text so the AI can use it. Exports create a new Sheet or Doc in your Drive. Unlinking a file, "Delete all social data" or deleting your account deletes these records; the files themselves stay in your Drive.
- App passwords and tokens for other services (for example a social network's app password or bot token you add to publish your own posts): they are encrypted at rest in the same way, never shown back to you, used only to publish what you schedule, and deleted when you remove them or delete your account.
- Bluesky and Mastodon accounts: for Bluesky you enter your handle and an app password. GrabCast uses the app password once to open a login session and does not store it; it keeps only the session tokens Bluesky returns, encrypted (AES-256-GCM). GrabCast refuses your main Bluesky password. For Mastodon you approve GrabCast on your own server's sign-in page (permissions: read your profile, posts and notifications; publish posts and media; like, mute and block when you click those buttons); the access token is stored encrypted. Disconnecting deletes the Bluesky session / revokes the Mastodon token at the service and deletes the tokens; you can also delete the app password in Bluesky or revoke GrabCast in your Mastodon settings at any time.
- Push notifications (optional, per device, only after you click "Turn on" and your browser asks): we store the push address your browser gives us (at Google, Mozilla, Apple or Microsoft's push service), its encryption keys, a device label like "Chrome on Mac" and your notification preferences. Messages contain only the notification text. Turning push off, removing the device, deleting all social data or deleting your account deletes them; addresses the push service reports as expired are deleted automatically.
- Link-in-bio page (optional): the page content you enter is public once you publish it. Visits and link clicks are counted as daily totals only — no IP address, cookie or device identifier is stored. The page is deleted with "Delete all social data" or account deletion.
9. Account, usage and security data
- Account data (if you sign up): your email address, username and a securely hashed password (or your Google account ID, name, email and picture link if you sign in with Google). New accounts confirm their email with a one-time link.
- Two-step verification (optional): if you turn it on, your authenticator secret is stored encrypted (AES-256-GCM) and your recovery codes and "remembered device" tokens only as one-way hashes; they are deleted when you turn two-step verification off or delete your account.
- Profile picture (optional): if you add one (by upload, or by choosing your Google profile photo), we store a small square copy that is re-encoded or cleaned so it contains no photo metadata such as location or camera details; it is shown on your account and to members of workspaces you share (anyone with the picture's link can view it), and it is deleted when you remove it or delete your account. When you sign in with Google we keep the link to your Google profile photo so you can choose it; we only download it when you ask.
- Settings sync: if you are signed in, your language, theme, favorites and tool option choices (like a format or quality setting — never files or text you type) sync to your account so they follow you across devices.
- Usage statistics: when you visit a page we record the page, the referring site, your country, a random device identifier your browser keeps for GrabCast, and your IP address. These raw records are kept for up to 45 days and then reduced to daily totals (pages, referring sites, countries, number of unique visitors) that don't identify you. We use them to understand which tools are used and to fix problems. We don't use third-party analytics such as Google Analytics, don't build advertising profiles and don't track you across other websites. Short-lived per-IP rate-limit counters (kept in memory) protect the Service from abuse.
- Anonymous error diagnostics: when something breaks (a script error, a failed download of one of our files, or a server error) your browser may send a small anonymous report to our own server so we can fix it: the type of error, a shortened technical message with anything that looks like an email address, number or quoted text removed, the first lines of the technical stack trace, the page address without its query string, the version of our code, and your browser and operating-system family (for example "Chrome on Windows"). Reports carry no account, IP address, device identifier, cookie or text you typed or files you opened, are limited in number per page and per tab, and are grouped into daily counts. They are kept for 30 days. Unhandled server errors are grouped the same way. We don't use a third-party error-tracking service.
- Abuse prevention (fair use): when you sign up or sign in we record, to stop one person from opening many free accounts, the random device identifier your browser keeps for GrabCast, a coarse browser summary (browser family, operating system, time zone, language and a rounded screen size — no canvas, audio or font fingerprinting), your IP address and its network prefix. We store these only as keyed one-way hashes (HMAC with a server secret), never in readable form, keep them for at most 90 days (also after you delete your account, so deleting and re-creating accounts can't be used to reset limits), and use them only to link accounts that share a device or network so they share one set of fair-use limits and to spot account farms. They are never used for advertising or shared with anyone. If your household or office shares a device or network and you need separate limits, contact us. Sign-up and password-reset forms are also protected by Cloudflare Turnstile, which checks that the request comes from a real browser.
- Security logs: we log sign-ins, security changes and Scheduler actions (with time and IP address) to protect your account and investigate abuse. The Scheduler activity log is kept for 30 days.
10. Cookies and browser storage
GrabCast itself doesn't use advertising or analytics cookies. We use browser storage (localStorage and sessionStorage) for things you'd expect a site to remember — your sign-in, language, theme, favorites, tool settings and drafts — and one short-lived security cookie on our API server during social-account connection. Details, and how to clear them, are in our Cookie & Storage Policy. If advertising is shown on a page, Google may set cookies as described in the next section. Ads are never loaded on account, sign-in, admin, Scheduler app or legal pages.
11. Advertising
To keep GrabCast free we may display advertising served by Google, including Google AdSense, on some content pages. In connection with this:
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to our sites and/or other sites on the Internet.
- You may opt out of personalized advertising by visiting Google Ads Settings. You can also opt out of some third-party vendors' use of cookies for personalized ads at aboutads.info/choices or youronlinechoices.eu (EU).
- If you are in the European Economic Area, the United Kingdom or Switzerland, we ask for your consent through a Google-certified consent message before any personalized advertising cookies are used, and you can change your choice at any time.
- We honor the Global Privacy Control browser signal and the switch in Your privacy choices: when either is on, we request only non-personalized ads.
For more information, see how Google uses cookies in advertising and how Google uses information from sites that use its services.
12. Affiliate links
GrabCast is free for everyone. There are no paid plans or subscriptions, and we never collect payment or card details. Some links (for example on the Recommended tools page and in some guides) are affiliate links: if you click one and later sign up or buy, we may earn a commission at no extra cost to you. When you click one, we count the click as a daily total per link, page and country (from our CDN's country header) and device type — we don't store your IP address, a cookie, a device ID or your account. The partner may use its own cookie or a link parameter to record that the visit came from GrabCast, under its own privacy policy; we don't share your files or account data with partners.
13. Emails we send
We send only service emails: account activation, password reset and security codes, invitations and notifications you've turned on (failed posts, approvals, reports, storage and ad alerts), replies to your fair-use or problem reports, and important notices about the Service or these policies. We don't send marketing newsletters. You can turn off optional notification emails in the Scheduler's settings or with the link in each email; account and security emails can't be turned off while you have an account. Emails are delivered through the email providers listed in Subprocessors; we keep a delivery log (masked address, status) for up to 45 days, and a hashed list of addresses that bounced or unsubscribed so we don't email them again.
14. Who we share data with
We don't sell personal information. We share it only:
- With service providers that host and run GrabCast for us under contract — hosting, database, file storage, email delivery and AI providers. The current list, with what each handles and where, is on our Subprocessors page.
- With the platforms you connect, when you publish, reply, run an ad or otherwise ask us to act on your behalf.
- With other members of your workspace, and with reviewers you send approval links to, as described in Team workspaces.
- For legal reasons: when required by valid legal process after we review its legality and scope, or when necessary to protect the rights, property or safety of our users, the public or GrabCast. Where the law allows, we tell the affected user first.
- In a business transfer: if GrabCast is merged, acquired or sold, subject to this policy.
Third-party resources loaded by some tools. Some in-browser tools load code, fonts or AI models from public networks (jsDelivr, cdnjs, Google Fonts, Hugging Face), and a few look up public data (currency rates from open.er-api.com, DNS lookups over Cloudflare or Google DNS-over-HTTPS, and the password checker, which sends only the first 5 characters of a hash of the password to Have I Been Pwned — never the password). Those services receive your IP address and browser details like any website you visit, but not your files.
15. Legal bases (EEA, UK and Switzerland)
If you are in the EEA, the UK or Switzerland, we process personal data on these legal bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Providing your account, the Scheduler, Ads manager, AI features, temporary email and other features you use | Account data, content you save, connected-account data, tokens | Performance of a contract (Art. 6(1)(b) GDPR) |
| Security, fraud and abuse prevention, fair-use limits | IP address, device identifier, hashed signals, security and audit logs | Legitimate interests in keeping the Service safe and free (Art. 6(1)(f)) |
| Usage statistics to improve the Service | Page, referrer, country, device identifier, IP address | Legitimate interests (Art. 6(1)(f)) |
| Personalized advertising and related cookies | Cookie identifiers set by Google | Consent (Art. 6(1)(a)), collected by Google's certified consent message |
| Optional features you switch on (push notifications, profile picture, notification emails) | As described above | Consent, which you can withdraw at any time by switching the feature off |
| Responding to legal requests, keeping required records | As needed | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, you can object (see Your rights).
16. International transfers
GrabCast is operated by a US company. Our main application servers run in the United States (Google Cloud, Iowa), and our other providers process data in the United States and, for content delivery and storage, in data centers worldwide (see Subprocessors for each provider's location). When personal data from the EEA, the UK or Switzerland is transferred to the United States or other countries, we rely on our providers' data processing terms, which include the European Commission's Standard Contractual Clauses (and the UK Addendum) or the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider participates. You can ask us for more information at privacy@grabcast.click.
17. How long we keep data
| Data | How long |
|---|---|
| Account, profile, settings, saved posts, board data | Until you delete them or your account |
| Connected-account tokens, profile details and statistics | Until you disconnect (deleted immediately), or within 7 days after you remove GrabCast at the platform; post statistics at most 400 days |
| Ads statistics cache | 15 minutes to 12 hours |
| Auto-moderation log (comment id, rule, action; never comment text) | 90 days; its rules until you delete them |
| Media library files | Until you delete them; then 30 days in Trash |
| Temporary media copies | 24–48 hours after publishing; 7 days after a failure or if unused; unfinished uploads 6 hours |
| Background jobs (for example imports and renders) | 7 days after they finish |
| AI replies cache | Up to 30 minutes, in memory only |
| Temporary email messages | 24 hours (shared addresses) or 72 hours (your own domain) |
| Raw usage statistics (IP address, device identifier) | Up to 45 days, then daily totals only |
| Anonymous error diagnostics (grouped daily counts) | 30 days |
| Abuse-prevention hashes | Up to 90 days |
| Scheduler activity log | 30 days |
| Email delivery log | Up to 45 days |
| Data-deletion confirmation codes | 90 days |
| Workspace audit logs, reviews and ad change logs | While the workspace or ad-account connection exists |
| Shared report links | 30 days by default (up to 365 days if you choose) |
| Template Studio: saved designs and published templates | Until you delete them (or unpublish) or your account; declined templates 30 days; removed templates 90 days |
| Template ratings; community review votes; template reports; "used" counts; community moderation log | Ratings while the template is published; review votes and closed reports 180 days after the decision; "used" counts 14 days (totals only after that); moderation log 180 days |
| Problem reports | Until the report is resolved and deleted; ask us to delete yours at any time |
| Database backups | Encrypted; overwritten on our database provider's short rolling schedule |
When you delete your account, we delete your account data right away, including connected social and ad accounts (access is revoked; campaigns GrabCast started are paused first), saved posts, media, AI keys, storage connections, push devices, link-in-bio page, Google Docs/Sheets links, background jobs, saved designs, published community templates and your template ratings, review votes and creator profile. Copies of your published templates that other people already saved stay with them under the CC0 public-domain dedication; your reports stay (without your account) as moderation records until they are closed and expire. Content you contributed to other people's workspaces (cards, comments, change history) stays with that workspace but no longer names you.
18. Your rights
Wherever you live, you can:
- Access and export your data: Account → Data & privacy → Download my data gives you a copy in a machine-readable format (JSON).
- Correct your account details in Account & Settings, or ask us to.
- Delete your data: see the data deletion instructions.
- Withdraw consent for optional features at any time by switching them off.
If you are in the EEA, the UK or Switzerland, you also have the right to restrict or object to processing (including processing based on legitimate interests), to data portability, and to lodge a complaint with your local data protection authority. We have not appointed a data protection officer because we are not required to; please contact privacy@grabcast.click.
EU and UK representative: [To be completed by the owner: name and address of our EU representative (Art. 27 GDPR) and UK representative (Art. 27 UK GDPR), if appointed.]
To make a request, email privacy@grabcast.click from the address on your account (or tell us how to identify you). We may ask for information to verify your identity, and will answer within one month (GDPR) or 45 days (US state laws); we may extend this where the law allows. You may use an authorized agent where the law allows; we may ask the agent for proof of authorization. We will not discriminate against you for exercising your rights. If we decline a request, you can appeal by replying to our decision; if you're unhappy with the appeal, you can contact your state attorney general or data protection authority.
19. US state privacy rights (California and others)
This section is our notice at collection and privacy notice for residents of California and other US states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas and Oregon).
| Category (CCPA) | Examples | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | Email, username, account ID, IP address, device identifier, platform account IDs | You, your browser, connected platforms | Providing the Service, security, fair use, statistics | Service providers; platforms you connect |
| Customer records | Name and email in your account or workspace | You | Providing the Service | Service providers; your workspace members |
| Commercial information | Ad-account spend, budgets and results (Ads manager) | Meta, when you connect | Showing and managing your ads | Service providers; Meta |
| Internet or network activity | Pages visited, referrer, post and ad statistics | Your browser, connected platforms | Statistics, providing the Service | Service providers; advertising partners (only if personalized ads are shown) |
| Geolocation (coarse) | Country from IP address | Your browser | Statistics, security | Service providers |
| Audio, visual and similar | Media you upload, profile picture | You | Providing the Service | Service providers; platforms you publish to |
| Inferences | None — we don't build profiles about you | — | — | — |
- Sensitive personal information: your account password and platform tokens are credentials; we use them only to provide the Service and not to infer anything about you. We don't otherwise collect sensitive personal information.
- Sale and sharing: we don't sell personal information for money and don't knowingly sell or share the personal information of anyone under 16. If personalized ads are shown, Google and its partners may use cookies on those pages, which some state laws treat as "sharing" for cross-context behavioral advertising or "targeted advertising". You can opt out below; we also treat a Global Privacy Control signal as an opt-out.
- Retention: see How long we keep data.
- Your rights: to know, access, correct, delete and port your data, to opt out of sale, sharing and targeted advertising, and to limit the use of sensitive personal information — see Your rights for how to exercise them.
20. Your privacy choices
Do Not Sell or Share My Personal Information / opt out of targeted advertising
Turn this on to receive only non-personalized ads on GrabCast in this browser. It is remembered in this browser only; repeat it in other browsers and devices, or turn on Global Privacy Control in your browser to send the signal everywhere.
You can also email privacy@grabcast.click, and opt out with Google at Google Ads Settings.
- Browser storage: clear this site's data in your browser settings to remove everything GrabCast stored on your device.
- Connected accounts: disconnect them in the Scheduler or remove GrabCast at the platform (see data deletion instructions).
- Notifications: turn off push or notification emails in the Scheduler settings.
- Your account: export or delete it in Account → Data & privacy.
21. Security
We protect data with HTTPS everywhere, AES-256-GCM encryption for tokens, keys and two-step secrets, hashed passwords and links, least-privilege permissions, role-based access in workspaces and audit logs. No method of storage or transmission is completely secure, so we can't guarantee absolute security. If we become aware of a breach that affects your personal data, we will notify you and the authorities as the law requires. More on our Security page.
22. Children
GrabCast is not directed to children under 13 (or under 16 where local law requires a higher age), and we do not knowingly collect their personal information. Connecting social or ad accounts requires you to be at least 18. If you believe a child has given us personal information, contact privacy@grabcast.click and we will delete it.
23. Changes to this policy
We may update this policy as GrabCast changes. We will post the new version here with a new "Last updated" date and, for material changes, tell signed-in users in the app or by email before they take effect.
Change log: September 30, 2026 — restructured with a table of contents; added the Ads manager (Meta ad accounts), Google Docs and Sheets, the media library and Trash, legal bases, international transfers, a retention table, US state privacy notice and "Your privacy choices" (Global Privacy Control), emails, and third-party resources; corrected usage statistics (raw records kept up to 45 days). September 29, 2026 — added AI provider keys (BYOK), connected storage, Bluesky/Mastodon, push notifications, link-in-bio and Threads.
24. Contact
Digidot Marketing Agency L.L.C. (d/b/a GrabCast), 30 N Gould St Ste R, Sheridan, WY 82801, USA. Privacy questions and requests: privacy@grabcast.click. Everything else: support@grabcast.click.