← PointCast
Privacy

A small-data promise.

Effective September 21, 2026

What PointCast collects

Google sign-in supplies a stable account identifier, verified email address, display name, and profile image. PointCast uses that information only to create or link a PointCast account, keep the user signed in, and identify the verified account allowed to manage the live broadcast.

PointCast does not request access to Gmail, Google Drive, contacts, calendars, or any other Google service.

Spotify live signal

The shared Spotify live signal is available only to the authorized PointCast broadcaster and requests the user-read-currently-playing permission. For the broadcaster’s own station page it also requests user-read-recently-played, user-top-read and user-library-read (the saved-songs library: its size, the first save and the latest few). PointCast stores the resulting access and refresh credentials encrypted at rest.

The public signal contains only the current item’s title, artist or publisher, cover image, Spotify link, and playing or paused state. It never republishes audio and does not expose the Spotify account, playback device, progress, or other personal profile information.

The broadcaster’s station page (/station) publishes the broadcaster’s own play log by the broadcaster’s choice: tracks, the times they played, counts made from them, and Spotify’s top lists for that one account. It is kept until the broadcaster erases it, and disconnecting Spotify erases it too. This applies only to the broadcaster. A personal Spotify connection never has a play log and is never asked for listening history, and it is never added to the public play log or the shared broadcast signal. Separately, a signed-in visitor may choose, from their profile, to show the track they are playing as a label next to their Noun while they are in town. It is off by default; turning it off, pausing, or leaving removes the label.

The station can also read the broadcaster’s public listening history from ListenBrainz, an open scrobbling service, by the username the broadcaster enters. That data is already public there; PointCast holds no ListenBrainz credentials. A visitor may enter their own ListenBrainz username on their profile to show what they are playing: the username is kept only in that browser, the browser asks ListenBrainz directly, and PointCast’s servers never receive it.

The station’s request line is public. A request stores the Spotify track, the reason given, and a self-reported name, until the broadcaster removes it or it ages off the list of 120. To limit abuse, a one-way hash of the sender’s network address is kept for one hour and then expires.

GitHub sign-in

Optional GitHub sign-in verifies your public GitHub identity. PointCast keeps your stable account ID, username, display name, avatar, and verification time. It requests no repository or email permissions and does not fetch repositories or email addresses. Provider access and refresh tokens are never stored.

GitHub accounts are matched by their verified account ID, never by email. Linking GitHub to an existing PointCast account requires a recent sign-in and an explicit Link GitHub action. You can revoke PointCast in GitHub’s authorized OAuth apps settings or request account data deletion using the contact below.

Shopify catalog connection

Shopify connection is available only to the authorized PointCast broadcaster and requests the read-only read_products permission. The connection is intended for publishing selected product and catalog nouns in a PointCast shop window. PointCast stores the resulting expiring credentials encrypted at rest.

PointCast does not request customer, order, checkout, payment, or write access. A connected shop’s domain and authorization status are visible only to the broadcaster; public visitors see only whether a catalog is available.

Shwa and personal Spotify connections

Optional five-person Shwa rooms store chosen names, resource preferences, explicitly posted text and proposal votes on Cloudflare for 24 hours from room creation. Anyone with the invite link can join when a seat is open and read the board. Names are not verified identities. A random reconnect secret stays in this browser session; only its hash identifies a seat on the server. Room content is cleared at expiry. No AI keys, wallet credentials, Spotify metadata, microphone audio or private call transcript is broadcast to other participants. Selecting Discuss with Shwa adds the selected text to this browser’s OpenAI context for an eligible call. Choosing a resource route neither connects credentials nor grants spending authority.

In the Shwa room, signed-in people can optionally connect their own Spotify account with the user-read-currently-playing permission. These credentials are encrypted and bound to that PointCast user, separate from the public broadcaster. Current-track metadata is returned privately to that user's room and is not added to the public signal or sent to AI models. Disconnect Spotify from the Music panel; deletion can take time to propagate across storage locations.

Starting a Shwa call sends microphone audio to OpenAI. Live captions and room interactions can be processed by OpenAI to create notes and interactive cards. Image and research requests run when you select them. This room keeps captions, images, and canvas pieces in the current page, clearing them with a new call; it does not save a room history to your PointCast account. A manually pasted public Spotify link is remembered in this browser. Wallet transactions require your separate approval.

Storage, sharing, and deletion

Sign-in sessions expire after 30 days. Current Spotify metadata is refreshed when requested and any cached signal expires within 24 hours. Shopify credentials rotate through the provider’s expiring offline-token flow. PointCast does not sell this data or use it for advertising. Cloudflare provides the hosting, session storage, and encrypted secret storage needed to operate the service.

The broadcaster can disconnect Spotify or Shopify at any time from the PointCast dashboard. Disconnecting immediately deletes that provider’s stored credentials; Spotify disconnection also clears the cached live signal. Any user may request access to or deletion of their PointCast account data by emailing hello@pointcast.xyz.

Security and changes

PointCast uses secure, HttpOnly cookies for account sessions, verifies Google identity tokens, verifies Shopify state and signed callback parameters, and encrypts Spotify and Shopify credentials before storage. No online service can promise absolute security; material changes to this policy will be reflected on this page with a new effective date.