CastBridge

Data Retention

Effective September 7, 2026

CastBridge uses data minimization. We retain only what is reasonably necessary to provide live streaming, recording delivery, billing, support, security, abuse prevention, and legal/audit evidence.

Retention matrix

Account and workspace records

Purpose: Authentication, workspace access, support, and deletion handling.

Storage: Postgres application tables and secure session cookies.

Retention: Kept while the account is active; minimized or disabled on deletion.

Deletion: Active sessions are revoked and user/workspace records are disabled or anonymized when deletion is confirmed.

Authorization confirmations

Purpose: Evidence that the customer accepted the rebroadcast and recording responsibility for a specific room/session.

Storage: Postgres stream_authorizations records.

Retention: Retained as legal/audit evidence for the relevant stream history.

Deletion: Not reassigned or rewritten; personal metadata is minimized where practical.

Clubhouse URLs and admission telemetry

Purpose: Compatibility checks, support, abuse review, reliability measurement, and incident diagnosis by session ID.

Storage: Postgres room/session, stream event, and admission diagnostic tables; provider runtime logs.

Retention: Retained for operational history unless removed by a future retention job or required for legal/support review.

Deletion: Historical records may be retained but direct personal metadata is minimized where practical.

YouTube connection and broadcast identifiers

Purpose: Connect a customer channel, create/manage broadcasts, and support stream lifecycle.

Storage: Encrypted OAuth tokens in Postgres; non-secret channel and broadcast identifiers in stream records.

Retention: OAuth tokens are kept only while connected; identifiers remain in historical stream records.

Deletion: Disconnect/deletion clears OAuth tokens and keeps non-secret historical IDs when needed for audit/support.

Recordings, replay metadata, and Telegram delivery

Purpose: Optional recording processing, replay delivery, support, and delivery status.

Storage: Postgres metadata plus configured CastBridge/Netreex storage or delivery systems.

Retention: Kept as needed for delivery, support, and audit; physical media removal depends on provider integration.

Deletion: Destination links/tokens are cleared; stored artifacts are removed where the active storage integration supports it.

Billing and financial records

Purpose: Subscription entitlement, reconciliation, accounting, refunds, fraud prevention, and support.

Storage: Stripe plus non-card Stripe identifiers and finance events in Postgres.

Retention: Retained as required for accounting, tax, dispute, and financial audit obligations.

Deletion: Raw card details are handled by Stripe, not CastBridge; financial records may be retained and minimized.

Support, takedown, abuse, and security records

Purpose: Respond to customer issues, rights complaints, abuse, and security incidents.

Storage: Support channel records, audit events, and relevant Postgres references.

Retention: Retained while needed to resolve the issue and preserve appropriate audit evidence.

Deletion: Sensitive complaint contents are not public; records may be retained when needed for safety/legal reasons.

Infrastructure logs and backups

Purpose: Operate Railway services, diagnose failures, recover data, and investigate incidents.

Storage: Railway/provider logs and database backup systems.

Retention: Controlled by provider settings and backup configuration.

Deletion: Deletion may not immediately remove data from immutable logs/backups; access is restricted and records expire through provider retention.

Data generally removed on account deletion

Account deletion revokes active sessions, clears Google/YouTube OAuth tokens, removes saved Telegram and RTMP destinations tied to the workspace, clears Clubhouse session credentials, disables account access, and removes CastBridge-controlled recording segments where the current storage model supports it.

Data generally retained or minimized

CastBridge may retain payment/accounting identifiers, security and fraud events, authorization confirmations, takedown-relevant stream records, diagnostic events, and non-secret historical broadcast metadata when needed for accounting, support, legal defense, abuse investigation, or platform integrity. Retained records are minimized where practical, including removal of common email fields from stored JSON metadata during deletion.

Current policy gaps

Questions

For retention or deletion questions, message @netreexid on Telegram.