CastBridge
Privacy Policy
Effective September 8, 2026 · privacy-2026-09-08
CastBridge helps authorized creators send compatible Clubhouse room audio to YouTube Live and, when selected, deliver recordings through Netreex to Telegram.
Information we handle
We process account email authentication, workspace information, Google/YouTube OAuth tokens, YouTube channel and broadcast identifiers, Clubhouse room URLs, authorization audit records, stream and session diagnostics, recordings when explicitly enabled, Telegram delivery information, and billing or subscription information handled through Stripe.
Session cookies keep users logged in and protect dashboard access. Operational records may include non-secret identifiers such as workspace IDs, session IDs, provider session hashes, admission outcomes, timing, browser/network profile labels, and delivery statuses. We do not intentionally collect payment card numbers or raw Clubhouse passwords in CastBridge application tables.
Google and YouTube data
With your permission, CastBridge uses Google/YouTube API data only to identify your connected YouTube channel, create and manage broadcasts for that channel, read the minimum channel or broadcast information required for the workflow, and refresh authorization for an active connection. OAuth access and refresh tokens are encrypted before database storage and are not displayed in the CastBridge interface.
How Google user data is shared or disclosed
CastBridge does not sell, rent, or share Google user data for advertising, marketing, or unrelated commercial purposes. Google user data is disclosed only when necessary to provide, secure, or support the CastBridge service, or when required by law.
Google OAuth credentials and YouTube account data may be processed by the infrastructure providers that host the CastBridge application, database, and related backend services strictly on our behalf and only as needed to operate the service. Data is also exchanged with Google/YouTube itself when CastBridge calls the YouTube APIs or refreshes OAuth authorization.
CastBridge does not send Google OAuth access or refresh tokens to Browserbase, Netreex, Telegram, or Stripe. Clubhouse browser capture and Telegram recording delivery are separate workflows and do not require disclosure of your Google OAuth credentials to those providers.
Data protection mechanisms
CastBridge uses technical and organizational controls designed to protect sensitive data. Connections to the CastBridge web application use HTTPS/TLS in transit. Google OAuth access and refresh tokens are encrypted before storage using server-side application encryption. Service credentials and encryption keys are kept on the server and are not exposed to the browser. Access to production data and administrative functions is restricted, service-to-service credentials are scoped to their intended functions, and audit records are maintained for security-sensitive operations.
We also minimize sensitive data exposure in application interfaces and logs. OAuth tokens are not displayed to users, and production diagnostics are designed to use non-secret identifiers or hashes rather than raw credentials. Users can disconnect YouTube from CastBridge, which disables the connection and the associated authorization for future API use.
Recording and delivery
Selected recordings may be transferred to Netreex for processing, splitting, and delivery from the CastBridge Netreex account to your verified Telegram destination. These services receive only the data needed for the selected recording workflow. This recording workflow does not require sharing your Google OAuth access or refresh tokens with Netreex or Telegram.
Data minimization
CastBridge retains only what is reasonably necessary to provide the service, operate securely, process billing, support users, and meet legal or audit obligations. We do not claim to retain no user data because the service does store account, billing, OAuth, audit, diagnostic, and recording-related data when those features are used.
Security, retention, and deletion
We use access controls, encrypted token storage, scoped service credentials, HTTPS/TLS, and audit records to protect the service. You can disconnect YouTube, remove destinations, and request account deletion from Settings. Some payment, security, authorization, and audit records may be retained when required and minimized where possible.
Service providers
CastBridge uses Railway for hosting and databases, Browserbase for managed browser sessions, Oxylabs for residential proxy routing when enabled for Clubhouse capture, Google/YouTube for OAuth and broadcasts, Stripe for billing, Resend for support/auth email when configured, Netreex for recording/replay processing, and Telegram for delivery where selected. These providers receive only the categories of information reasonably necessary for the services they perform. Google OAuth credentials are not shared with providers that do not need them for the YouTube connection workflow.
International processing
CastBridge and its providers may process data in regions different from your country. We use vendor access controls, HTTPS/TLS, encrypted token storage, and data minimization to reduce risk, but we do not claim enterprise compliance certifications that have not been externally verified.
Your choices
You can disconnect YouTube, remove saved destinations, request deletion from Settings, or contact support for an operator-assisted export or privacy question. Some records may be retained when needed for security, legal, accounting, backup, or abuse-prevention purposes as described in the Data Retention page.
Contact
For privacy or deletion questions, message @netreexid on Telegram.