Privacy Policy
Castrix ("Castrix," "we," "us") is a browser-based teleprompter service operated by Jason Aron Media and available at castrix.app. This policy explains what we collect, where it is stored, how long we keep it, who else touches it, and how to get a copy or have it deleted.
The short version: we collect the minimum needed to run your account. Your scripts are saved to your Castrix account so they follow you between machines — they are stored on servers we operate in the United States. We do not read them, we do not train anything on them, and we do not sell or share anything with anyone for their own purposes. Your card details go directly to Stripe and never reach us.
An important change on August 14, 2026
Castrix used to keep your scripts only in your own browser. It no longer does. Scripts you write are now saved to your Castrix account and stored on our servers, so you can open the same library on a different computer. This is a real change in what we hold about you, and this policy was rewritten for it. If you would rather we did not hold your scripts at all, email us and we will tell you honestly what that does and does not leave you with.
What we collect
- Account information. Your name, email address, and a password (stored only as a salted PBKDF2 hash — we cannot see or recover your password), plus your plan, subscription status, trial end date, and the pairing key your own screens and remotes use to connect.
- Your scripts. The name and the text of every script you save, including formatting, notes and markers. Scripts are stored on our servers under your account. If you are on a team plan, everyone on that team's library can read and edit the scripts in it — see "Teams and shared libraries" below.
- Live sync data. When you run a show across paired screens, position and script content move between your devices. Where the network allows, that happens directly between your own devices and never reaches us. Where it does not, it passes through our relay, which briefly holds recent messages so a screen that reconnects can catch up. Those messages can include the full text of the script currently loaded.
- Payment information. Payments are processed by Stripe. Your card number and full payment details are collected and stored by Stripe, never by Castrix. From Stripe we receive your email, plan, subscription and payment status, and a customer identifier.
- Sign-up submissions. If you submitted an early-access or contact form, we store the name, email and plan preference you gave.
- Email preferences. Which categories of Castrix email you have switched off, and when you last changed that. See "Email we send you" below.
- Records of exports and deletions. When a script library is exported or deleted we keep a short administrative record — the account address, what happened, when, and how many scripts and bytes were involved. Never any script text or script name.
- Technical basics. Our hosting provider processes standard server logs — IP address, browser type, requested pages — to deliver and secure the service.
We do not run advertising trackers, third-party analytics, session recording, or any form of behavioural profiling.
Where your data is stored
Castrix runs on Netlify. Your account records, your scripts and the sync relay are held in Netlify Blobs storage in the AWS us-east-2 region (Ohio, United States), and the server code that reads and writes them runs in the same region. Backups and operational copies are held by Netlify under its own policies.
If you are outside the United States — including in the UK, EU or EEA — using Castrix means your data is transferred to and stored in the United States. See "International transfers" below for the safeguards we rely on.
How long we keep things
| What | How long |
|---|---|
| Account record | For as long as your account exists. Deleted on request — see "Your rights". |
| Scripts | Until you delete them, or until your account is deleted. Cancelling a subscription, letting a payment fail, or letting a plan lapse does not delete anything. Moving down to the Individual plan does, after 30 days — see the next row and "Moving down to Individual" below. |
| Your cloud script library, after you move down to Individual | 30 days from the day the plan actually changes, then permanently deleted. Individual is a one-machine plan, so we stop holding a cloud library for it. During those 30 days nothing changes for you except that we email you about it — twelve times, escalating, each one naming the exact deletion date. If you download the library and our server verifies you received every byte, you can have it deleted right away instead of waiting. |
| Deleted scripts | When you delete a script, its text is removed immediately and a small record of the deletion (name, size, date) is kept so your other devices don't re-upload it. That record is cleared automatically about 90 days later, the next time that library is opened. |
| Live sync messages in the relay | At most the last 80 messages for any one connection. Twelve hours after the connection was last used they stop being served to anything, and they are discarded the next time you use that connection. If you never use it again, that last batch can sit in storage until your library or your account is deleted — clearing them on a timer instead is on our build list, and we would rather tell you than round it down to "12 hours". They are deleted outright, not left to expire, whenever a cloud library is deleted. |
| The record that we deleted a library | Kept indefinitely, and deliberately empty of content. It holds the dates, how many scripts and bytes went, the name you gave the device that downloaded them, and a one-way digest — no script names, no script text, no identifiers of any individual script. It exists so we can prove to you what we deleted and when. It is attached to your account, so it goes when your account is deleted. |
| Our record of exports and deletions | 12 months. Every time a script library is exported or deleted we log the account address, what happened, when, the outcome, and counts. Never any script text, script name or script identifier. This is how we answer "did anyone touch my library, and when" — including when the answer is about us. Today this log is cleared by hand rather than on a timer; a scheduled sweep is on our build list. |
| Your email preferences | For as long as your account exists. We store only the categories you have switched off — a category you have never touched is stored as nothing at all. |
| Sign-in sessions | 30 days, or until you sign out. |
| Password reset links | Expire shortly after they are issued. |
| Early-access sign-up list | The most recent 2,000 entries. Removed on request. |
| Payment and tax records | Held by Stripe under its own retention rules, and by us where tax law requires it — typically several years. These survive account deletion because the law requires them to. |
Moving down to Individual: the 30-day window
This is the one thing in this policy that ends with us permanently deleting something you wrote, so it gets its own section rather than a line in a table.
The Individual plan is a single-machine plan and we do not hold a cloud library for it. If you have been on Pro, or on a trial (which gives you Pro-level access), you may have a library on our servers. If you then move down to Individual, that library is kept for 30 days and then permanently deleted.
- The clock starts the day the plan actually changes, not the day you ask. A downgrade requested mid-month does not take effect until the end of the period you have already paid for, so you keep Pro, and your library, for the balance of that period — and then the 30 days begin.
- You get twelve emails about it, spread across those 30 days and getting closer together as the date approaches. Every one of them states the exact date we will delete it.
- You can take it with you. You get the library as a single self-contained file you can open in any browser, years later, with no account and no Castrix. It is plain, readable text — so once it is on your machine, looking after it is on you. The one-click download inside Castrix is being built; until it is there, email us and we will send you the file, and we will not delete a library while that is the only way to get it.
- You can also have it deleted immediately. When you download, our server checks a cryptographic receipt proving every byte of every script reached your browser. Only after that can you ask us to delete the server copy, and you have to type the word DELETE to do it. We would rather make you confirm twice than delete someone's writing on a mis-click.
- Cancelling is not the same as downgrading. Cancelling a subscription, a failed payment, or a trial simply running out does not start this clock and does not delete anything. Only actually moving to the Individual plan does.
- What "deleted" means here. Every script and every deletion record in that library, the library's usage record, and the sync-relay messages belonging to the account — all removed, checked, and checked again. What is left behind is the content-free record described in the retention table above.
You cannot switch off the last warning. Reminders about your stored scripts are email you can unsubscribe from — but the final warning before we delete a library, and the receipt afterwards, are sent whatever your email settings say. Someone who muted the reminders and then permanently lost their writing was still owed those two.
If you are on a team, downloading only ever gives you your own library. A member of somebody else's team cannot download the shared library they have been working in, and the owner cannot delete a shared library while other members are still seated on it.
Who can see your scripts
- You, and any device you pair. Anyone holding a pairing link or an active session on your account can open your library. Treat those the way you treat a password.
- Us, only when we have to. Castrix is operated by one person. Administrative access to the storage that holds your scripts exists — it has to, or nobody could run backups, fix a corrupted record, or answer a support request. We do not read your scripts as a matter of course, we do not read them for product development, and we do not use them to train any model. We access script content only where you have asked us to help with a specific problem, or where we are compelled by law and permitted to comply.
- Netlify. As our hosting and storage provider, Netlify has the technical ability to access data held on its infrastructure, under its own contractual and security controls.
- Nobody else. We do not sell personal information, we do not share it for anyone else's marketing, and we do not disclose script content to third parties except as described here.
Teams and shared libraries
A team shares one script library. Every member can read, edit and delete every script in it, and the account owner controls who is a member. If your organisation puts confidential material into a shared library, membership of that library is the access control — decide who is in it accordingly.
Two consequences worth knowing before you invite anyone. The shared library is the owner's own library, so exporting or deleting it is the owner's to do, not a member's — a member who leaves takes only their own private library, which joining never touched. And the owner cannot delete a shared library while other members are still seated on it; we refuse rather than take an archive away from people still working in it.
Who processes your data
These are every third party that handles your data on our behalf. If we add or replace one, we will update this list.
| Provider | What it does | What it sees |
|---|---|---|
| Netlify (US) | Hosting, our database, script storage, the sync relay | Everything we hold: account records, script text, server logs |
| Stripe (US/IE) | Payments and subscription billing | Your name, email, card details, billing history. Never your scripts. |
| Resend (US) | Sends our account emails — password resets, welcome, billing notices | Your name, email address, and the contents of those emails. Never your scripts. |
| PeerJS public signalling and public STUN servers (incl. Google) | Helps your own devices find each other for a direct connection | Your pairing room code and your devices' IP addresses. Never your scripts. |
Business customers who need this in contract form should read our Data Processing Agreement.
Why we are allowed to hold your data
- To perform our contract with you — your account, your scripts, syncing your screens, taking payment. This is the basis for almost everything.
- Our legitimate interests — keeping the service secure, preventing abuse and fraud, and keeping records of what we did and when.
- Legal obligation — tax and accounting records.
We do not rely on consent for anything, so there is nothing here for you to opt in or out of, and no consent banner to click.
Cookies
We use a small number of strictly necessary cookies: a session cookie to keep you signed in, and a sign-out marker. No advertising cookies, no tracking pixels, no third-party analytics.
Email we send you, and what you can switch off
Castrix email is sorted into categories, and each one is switched on or off on its own. That is deliberate: one blanket unsubscribe button is how somebody mutes a nag in Gmail and, three weeks later, silently misses the warning that we are about to delete their scripts.
| Category | What is in it | Can you turn it off? |
|---|---|---|
| Sign-in and account access | Password resets, and notices that access to your account or to a shared library has changed. | No. These are how you get back into your account, and how you find out you have lost access to a shared library before a shoot rather than during one. |
| Payments and plan | Receipts, failed charges, plan changes, cancellations, the end of a subscription. | No. Every one of them is a record of something that happened to your money. A customer who stops receiving these cannot manage their own billing. |
| Your stored scripts | Reminders to download your cloud library while it is still there. | Yes — except two. The final warning before we delete a library, and the receipt confirming we have, always send. See the box below. |
| Trial and getting started | Your welcome email, trial reminders, setup nudges. | Yes. Nothing here is a record of anything. |
| Product news | New features, and anything promotional. | Yes. Off means off. |
Three kinds of email will reach you no matter what you switch off: account access, anything about a payment, and the final warning plus receipt when we are deleting your stored scripts. If you believe you have muted everything, those are the ones that will still arrive — and they are the ones you would most regret missing.
How to change it. Every email you can unsubscribe from carries an unsubscribe link in its footer, and the one-click unsubscribe header your mail app uses. Both land on our email preferences page, where you can see all of it in one place — signed in, or straight from the link in the email without signing in.
What that link is, technically. The link carries a short signed token naming one email address and one category, and nothing else. It cannot be edited to point at a different address or a different category, it cannot name a category that can never be switched off, and verifying it involves no lookup of any kind — so nobody can use one of these links to find out whether an address has a Castrix account. Any valid link can switch mail back on as well as off, because otherwise muting a category would leave you with no way to undo it: the only link that could is in the email you no longer receive.
We store only the categories you have explicitly turned off, as a field on your account record. We do not keep a separate mailing list, and unsubscribing does not create a record for an address that has no account.
International transfers
Castrix is operated from the United States and our providers are US-based, so if you are in the UK, EU or EEA your personal data is transferred to the United States. Where that happens we rely on the standard contractual clauses (and, where applicable, the UK addendum) incorporated into our agreements with those providers, together with their own technical safeguards. You can ask us for details of the safeguard relied on for any particular provider.
Your rights
Wherever you live, you can ask us to give you a copy of what we hold about you, correct it, export it, or delete it. If you are in the UK, EU or EEA these are statutory rights under the UK GDPR and GDPR, including the right to object, the right to restrict processing, and the right to complain to your data protection authority (in the UK, the ICO). If you are in California, the CCPA/CPRA gives you rights to know, delete, correct and limit — and note that we do not sell or share personal information as those laws define it, so there is nothing for you to opt out of.
How to use any of these rights: email jason@jasonamedia.com from the address on your account and say what you want. There is no self-serve button for this yet — we are building one, and until it exists a human handles every request by hand.
- Getting a copy of your data. We will send you your account record and every script in your library, as files you can keep, within 30 days.
- Deleting your account. We will delete your account record, your scripts, your device-pairing data, your sign-up entry and your sessions within 30 days, and email you when it is done. Deletion is permanent and we cannot undo it — take a copy first if you want one.
- What survives deletion. Payment and tax records held by us or by Stripe, where the law requires us to keep them, and any records we need to resolve a dispute or prevent fraud. Nothing else.
- Your own copies. Deleting your Castrix account does not reach copies of scripts held in your own browsers or on your own machines. Clear those yourself if you need to.
- If your plan has lapsed. Cancelling, a failed payment, or a trial running out does not delete your scripts. You can still ask us for a copy and we will send it whether or not you are paying — your writing is yours, and we do not hold it hostage to a bill. The one case where we do delete a library is moving down to Individual, and that is the 30-day window described above, with twelve warnings before it happens.
Security
All traffic to castrix.app is encrypted with HTTPS. Passwords are stored only as salted PBKDF2 hashes. Data at rest is encrypted by our storage provider. Every account's scripts and sync channels are namespaced to that account and checked against the signed-in caller on every request, so knowing another customer's pairing code does not reach their data. Administrative access is limited to what is needed to operate the service.
Castrix is a small operation and we would rather tell you the honest shape of it than imply a security organisation we do not have: there is no SOC 2 report, no penetration test on file, and no 24-hour security team. What there is, is a small system with a small attack surface, no third-party trackers, and a policy of fixing what we find and telling you if it mattered.
If something goes wrong
If we become aware of a breach affecting your personal data, we will investigate immediately, and where the law requires it we will notify the relevant regulator (within 72 hours of becoming aware, under the UK GDPR and GDPR) and notify you without undue delay if the breach is likely to put you at high risk. If your scripts were involved, we will tell you that specifically, because for our customers that is usually the part that matters most.
Children
Castrix is not directed to children under 13, is intended for adult professional use, and we do not knowingly collect personal information from children.
Changes to this policy
If we make material changes we will update the effective date above and, for significant changes, notify account holders by email before they take effect.
Who we are, and how to reach us
Castrix is operated by Jason Aron Media, United States, which is the controller of the personal data described in this policy. For any privacy question, or to use any of the rights above: jason@jasonamedia.com. We aim to reply within a few days and will always reply within 30 days.