Privacy Policy
This policy explains what data Castfrom (“the Service”) collects, why, how long it is kept, and how you can have it deleted. Castfrom is operated by Social Marketing Inc., Bunkyo-ku, Tokyo, Japan (“we”, “us”). It applies to the website at castfrom.social-marketing.io and to the Castfrom application.
1. What Castfrom does
Castfrom lets you connect social media accounts that you own or are authorised to manage, publish posts to those accounts, and view performance metrics for the posts you published. Supported networks are X, TikTok, Instagram, Threads and YouTube. All access goes through each network’s official API.
2. Data we collect
| Category | What | Source |
|---|---|---|
| Account information | Your name, email address and organisation, used to create and secure your Castfrom login. | You |
| Connected-account data | The network’s user ID, username, display name and profile image of each account you connect; the access token and refresh token the network issues to Castfrom. | The network, after you authorise Castfrom |
| Content you create | Post text, media files, captions, hashtags, scheduling times and per-network settings (audience, comment/duet/stitch permissions, brand disclosure). | You |
| Post metrics | Performance data the network returns for posts you published through Castfrom or that belong to a connected account: for example views, likes, comments, shares, saves, reach, impressions, watch time, follower counts and aggregate audience statistics. | The network’s API |
| Comments and replies | Where the network provides them and you enable the feature, public comments or replies on your own posts, so that you can read and respond to them. | The network’s API |
| Technical data | Server logs (IP address, browser type, timestamps, pages requested) kept for security and troubleshooting. | Your browser |
Castfrom does not collect your network passwords. Authorisation happens on the network’s own login page, and the network gives Castfrom a limited token instead.
Castfrom does not read direct messages, does not collect personal data about your followers beyond the aggregate statistics the network exposes, and does not access accounts you have not connected.
3. How we use it
- To publish the posts you create to the accounts you selected, at the time you chose.
- To retrieve and display performance metrics for your posts.
- To show and let you respond to comments on your posts, where you enable it.
- To keep your login and connected accounts secure, and to refresh tokens so connections keep working.
- To provide support and to diagnose problems.
- To comply with the developer policies of each network.
We do not sell your data. We do not use connected-account data for advertising, for building profiles of your followers, or for training machine-learning models. We do not share it with anyone except as described in section 5.
4. Legal basis
We process your data to perform the service you asked for, on the basis of your consent given when you connect an account, and to meet our legal obligations. You can withdraw consent at any time by disconnecting an account (section 7).
5. Who we share data with
- The networks themselves. When you publish, the post content and settings are sent to the network you chose. Their handling of that content is governed by their own terms and privacy policies.
- Hosting and infrastructure. Castfrom runs on Amazon Web Services in the Asia Pacific (Tokyo) region. AWS processes data on our behalf under its data processing terms.
- Your organisation. If your Castfrom account belongs to a company or agency workspace, other members of that workspace can see the connected accounts, posts and metrics in it.
- Legal requirements. If required by law or a valid legal request.
6. Retention
- Access tokens are kept for as long as the account is connected, and are deleted when you disconnect it or when the network revokes them.
- Posts and metrics are kept for as long as the connected account remains in your workspace, and for up to 30 days after it is disconnected, then deleted.
- Your Castfrom login data is kept while your account exists and for up to 30 days after you close it.
- Server logs are kept for up to 90 days.
7. Your choices and rights
- Disconnect an account. In Castfrom, open the account and choose “Disconnect”. Its token is deleted immediately and its stored posts and metrics within 30 days.
- Revoke from the network. You can also remove Castfrom from the network’s side: X (Settings → Security and account access → Apps and sessions), TikTok (Settings → Security → Manage app permissions), Instagram and Threads (Settings → Website permissions / Apps and websites), YouTube (Google Account → Security → Third-party apps with account access). Revoking from the network stops Castfrom’s access at once.
- Delete everything. Email support@social-marketing.io from the address on your account and ask for deletion. We confirm within 7 days and complete deletion within 30 days, except for records we must keep by law.
- Access and correction. You can ask for a copy of the personal data we hold about you, or ask us to correct it, at the same address.
8. Platform-specific terms
YouTube
Castfrom uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy. Castfrom stores YouTube data (channel details, video metadata, and analytics for your own videos) only for as long as needed to show it to you, refreshes it at least every 30 days, and deletes it when you disconnect the channel. You can revoke Castfrom’s access at any time from the Google security settings page. Castfrom’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
TikTok
Castfrom uses the TikTok Login Kit, Content Posting API and Display API. Before each post you choose the audience and interaction settings yourself; Castfrom does not change them and does not add watermarks or branding to your content. Metrics are those TikTok exposes for your own videos.
Instagram and Threads (Meta)
Castfrom uses the Instagram Platform and Threads API provided by Meta. Publishing requires a professional Instagram account. Media you upload for publishing is placed temporarily on our servers so that Meta can fetch it, and is removed after publishing completes.
X
Castfrom uses the X API v2. Posts made through Castfrom may be labelled by X as coming from an automated source in line with X’s automation rules. Metrics are those X exposes for your own posts.
9. Cookies
The public website sets no tracking cookies. The Castfrom application uses a session cookie that keeps you signed in; it contains no tracking identifiers and expires when you sign out or after a period of inactivity.
10. Security
Tokens and personal data are encrypted at rest and in transit. Access within our team is limited to the people who operate the Service. If we learn of a breach affecting your data we will notify you without undue delay.
11. Children
Castfrom is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
12. International transfers
Data is stored in Japan. Where a network you connect processes data outside Japan, that transfer is governed by your agreement with the network.
13. Changes
If we change this policy in a way that affects your rights we will post the new version here with a new effective date, and notify you in the application before it takes effect.
14. Contact
Social Marketing Inc. (ソーシャルマーケティング株式会社)
Bunkyo-ku, Tokyo, Japan
support@social-marketing.io