Privacy Policy

Effective date: August 14, 2026

Castrix ("Castrix," "we," "us") is a browser-based teleprompter service operated by Jason Aron Media and available at castrix.app. This policy explains what we collect, where it is stored, how long we keep it, who else touches it, and how to get a copy or have it deleted.

The short version: we collect the minimum needed to run your account. Your scripts are saved to your Castrix account so they follow you between machines — they are stored on servers we operate in the United States. We do not read them, we do not train anything on them, and we do not sell or share anything with anyone for their own purposes. Your card details go directly to Stripe and never reach us.

An important change on August 14, 2026

Castrix used to keep your scripts only in your own browser. It no longer does. Scripts you write are now saved to your Castrix account and stored on our servers, so you can open the same library on a different computer. This is a real change in what we hold about you, and this policy was rewritten for it. If you would rather we did not hold your scripts at all, email us and we will tell you honestly what that does and does not leave you with.

What we collect

We do not run advertising trackers, third-party analytics, session recording, or any form of behavioural profiling.

Where your data is stored

Castrix runs on Netlify. Your account records, your scripts and the sync relay are held in Netlify Blobs storage in the AWS us-east-2 region (Ohio, United States), and the server code that reads and writes them runs in the same region. Backups and operational copies are held by Netlify under its own policies.

If you are outside the United States — including in the UK, EU or EEA — using Castrix means your data is transferred to and stored in the United States. See "International transfers" below for the safeguards we rely on.

How long we keep things

WhatHow long
Account recordFor as long as your account exists. Deleted on request — see "Your rights".
ScriptsUntil you delete them, or until your account is deleted. Cancelling a subscription, letting a payment fail, or letting a plan lapse does not delete anything. Moving down to the Individual plan does, after 30 days — see the next row and "Moving down to Individual" below.
Your cloud script library, after you move down to Individual30 days from the day the plan actually changes, then permanently deleted. Individual is a one-machine plan, so we stop holding a cloud library for it. During those 30 days nothing changes for you except that we email you about it — twelve times, escalating, each one naming the exact deletion date. If you download the library and our server verifies you received every byte, you can have it deleted right away instead of waiting.
Deleted scriptsWhen you delete a script, its text is removed immediately and a small record of the deletion (name, size, date) is kept so your other devices don't re-upload it. That record is cleared automatically about 90 days later, the next time that library is opened.
Live sync messages in the relayAt most the last 80 messages for any one connection. Twelve hours after the connection was last used they stop being served to anything, and they are discarded the next time you use that connection. If you never use it again, that last batch can sit in storage until your library or your account is deleted — clearing them on a timer instead is on our build list, and we would rather tell you than round it down to "12 hours". They are deleted outright, not left to expire, whenever a cloud library is deleted.
The record that we deleted a libraryKept indefinitely, and deliberately empty of content. It holds the dates, how many scripts and bytes went, the name you gave the device that downloaded them, and a one-way digest — no script names, no script text, no identifiers of any individual script. It exists so we can prove to you what we deleted and when. It is attached to your account, so it goes when your account is deleted.
Our record of exports and deletions12 months. Every time a script library is exported or deleted we log the account address, what happened, when, the outcome, and counts. Never any script text, script name or script identifier. This is how we answer "did anyone touch my library, and when" — including when the answer is about us. Today this log is cleared by hand rather than on a timer; a scheduled sweep is on our build list.
Your email preferencesFor as long as your account exists. We store only the categories you have switched off — a category you have never touched is stored as nothing at all.
Sign-in sessions30 days, or until you sign out.
Password reset linksExpire shortly after they are issued.
Early-access sign-up listThe most recent 2,000 entries. Removed on request.
Payment and tax recordsHeld by Stripe under its own retention rules, and by us where tax law requires it — typically several years. These survive account deletion because the law requires them to.

Moving down to Individual: the 30-day window

This is the one thing in this policy that ends with us permanently deleting something you wrote, so it gets its own section rather than a line in a table.

The Individual plan is a single-machine plan and we do not hold a cloud library for it. If you have been on Pro, or on a trial (which gives you Pro-level access), you may have a library on our servers. If you then move down to Individual, that library is kept for 30 days and then permanently deleted.

You cannot switch off the last warning. Reminders about your stored scripts are email you can unsubscribe from — but the final warning before we delete a library, and the receipt afterwards, are sent whatever your email settings say. Someone who muted the reminders and then permanently lost their writing was still owed those two.

If you are on a team, downloading only ever gives you your own library. A member of somebody else's team cannot download the shared library they have been working in, and the owner cannot delete a shared library while other members are still seated on it.

Who can see your scripts

Teams and shared libraries

A team shares one script library. Every member can read, edit and delete every script in it, and the account owner controls who is a member. If your organisation puts confidential material into a shared library, membership of that library is the access control — decide who is in it accordingly.

Two consequences worth knowing before you invite anyone. The shared library is the owner's own library, so exporting or deleting it is the owner's to do, not a member's — a member who leaves takes only their own private library, which joining never touched. And the owner cannot delete a shared library while other members are still seated on it; we refuse rather than take an archive away from people still working in it.

Who processes your data

These are every third party that handles your data on our behalf. If we add or replace one, we will update this list.

ProviderWhat it doesWhat it sees
Netlify (US)Hosting, our database, script storage, the sync relayEverything we hold: account records, script text, server logs
Stripe (US/IE)Payments and subscription billingYour name, email, card details, billing history. Never your scripts.
Resend (US)Sends our account emails — password resets, welcome, billing noticesYour name, email address, and the contents of those emails. Never your scripts.
PeerJS public signalling and public STUN servers (incl. Google)Helps your own devices find each other for a direct connectionYour pairing room code and your devices' IP addresses. Never your scripts.

Business customers who need this in contract form should read our Data Processing Agreement.

Why we are allowed to hold your data

We do not rely on consent for anything, so there is nothing here for you to opt in or out of, and no consent banner to click.

Cookies

We use a small number of strictly necessary cookies: a session cookie to keep you signed in, and a sign-out marker. No advertising cookies, no tracking pixels, no third-party analytics.

Email we send you, and what you can switch off

Castrix email is sorted into categories, and each one is switched on or off on its own. That is deliberate: one blanket unsubscribe button is how somebody mutes a nag in Gmail and, three weeks later, silently misses the warning that we are about to delete their scripts.

CategoryWhat is in itCan you turn it off?
Sign-in and account accessPassword resets, and notices that access to your account or to a shared library has changed.No. These are how you get back into your account, and how you find out you have lost access to a shared library before a shoot rather than during one.
Payments and planReceipts, failed charges, plan changes, cancellations, the end of a subscription.No. Every one of them is a record of something that happened to your money. A customer who stops receiving these cannot manage their own billing.
Your stored scriptsReminders to download your cloud library while it is still there.Yes — except two. The final warning before we delete a library, and the receipt confirming we have, always send. See the box below.
Trial and getting startedYour welcome email, trial reminders, setup nudges.Yes. Nothing here is a record of anything.
Product newsNew features, and anything promotional.Yes. Off means off.

Three kinds of email will reach you no matter what you switch off: account access, anything about a payment, and the final warning plus receipt when we are deleting your stored scripts. If you believe you have muted everything, those are the ones that will still arrive — and they are the ones you would most regret missing.

How to change it. Every email you can unsubscribe from carries an unsubscribe link in its footer, and the one-click unsubscribe header your mail app uses. Both land on our email preferences page, where you can see all of it in one place — signed in, or straight from the link in the email without signing in.

What that link is, technically. The link carries a short signed token naming one email address and one category, and nothing else. It cannot be edited to point at a different address or a different category, it cannot name a category that can never be switched off, and verifying it involves no lookup of any kind — so nobody can use one of these links to find out whether an address has a Castrix account. Any valid link can switch mail back on as well as off, because otherwise muting a category would leave you with no way to undo it: the only link that could is in the email you no longer receive.

We store only the categories you have explicitly turned off, as a field on your account record. We do not keep a separate mailing list, and unsubscribing does not create a record for an address that has no account.

International transfers

Castrix is operated from the United States and our providers are US-based, so if you are in the UK, EU or EEA your personal data is transferred to the United States. Where that happens we rely on the standard contractual clauses (and, where applicable, the UK addendum) incorporated into our agreements with those providers, together with their own technical safeguards. You can ask us for details of the safeguard relied on for any particular provider.

Your rights

Wherever you live, you can ask us to give you a copy of what we hold about you, correct it, export it, or delete it. If you are in the UK, EU or EEA these are statutory rights under the UK GDPR and GDPR, including the right to object, the right to restrict processing, and the right to complain to your data protection authority (in the UK, the ICO). If you are in California, the CCPA/CPRA gives you rights to know, delete, correct and limit — and note that we do not sell or share personal information as those laws define it, so there is nothing for you to opt out of.

How to use any of these rights: email jason@jasonamedia.com from the address on your account and say what you want. There is no self-serve button for this yet — we are building one, and until it exists a human handles every request by hand.

Security

All traffic to castrix.app is encrypted with HTTPS. Passwords are stored only as salted PBKDF2 hashes. Data at rest is encrypted by our storage provider. Every account's scripts and sync channels are namespaced to that account and checked against the signed-in caller on every request, so knowing another customer's pairing code does not reach their data. Administrative access is limited to what is needed to operate the service.

Castrix is a small operation and we would rather tell you the honest shape of it than imply a security organisation we do not have: there is no SOC 2 report, no penetration test on file, and no 24-hour security team. What there is, is a small system with a small attack surface, no third-party trackers, and a policy of fixing what we find and telling you if it mattered.

If something goes wrong

If we become aware of a breach affecting your personal data, we will investigate immediately, and where the law requires it we will notify the relevant regulator (within 72 hours of becoming aware, under the UK GDPR and GDPR) and notify you without undue delay if the breach is likely to put you at high risk. If your scripts were involved, we will tell you that specifically, because for our customers that is usually the part that matters most.

Children

Castrix is not directed to children under 13, is intended for adult professional use, and we do not knowingly collect personal information from children.

Changes to this policy

If we make material changes we will update the effective date above and, for significant changes, notify account holders by email before they take effect.

Who we are, and how to reach us

Castrix is operated by Jason Aron Media, United States, which is the controller of the personal data described in this policy. For any privacy question, or to use any of the rights above: jason@jasonamedia.com. We aim to reply within a few days and will always reply within 30 days.