CasTV.ai

Privacy Policy

Effective date: 21 July 2026  ·  Last updated: 21 July 2026

This Privacy Policy explains how CasTV.ai and its affiliates (“CasTV.ai”, “AURA”, “we”, “us”, or “our”) collect, use, disclose, and safeguard information in connection with the CasTV.ai digital-signage management platform, our websites, APIs, and the player/agent applications we provide for televisions and media devices (collectively, the “Service”). By using the Service you acknowledge the practices described in this Policy.

1. Who we are and scope

CasTV.ai provides a cloud platform that lets organizations (“Customers”) remotely manage screens, deploy content and playlists, monitor playback, and maintain a fleet of connected displays. The Service has three parts, all covered by this Policy:

  • The web dashboard and APIs used by Customer administrators and users.
  • The player/agent application installed on a television or media device (including our webOS, Tizen, Fire TV, Android, and desktop agents), which pairs with a Customer account and plays the content that Customer deploys.
  • The backend services that coordinate devices, store content and logs, and produce reporting.

Controller / processor roles. For account and platform data, CasTV.ai generally acts as a data controller. For content and operational data that a Customer configures and deploys through the Service, CasTV.ai generally acts as a data processor on that Customer’s behalf, and the Customer is the controller responsible for that content.

2. Information we collect

2.1 Account and workspace information

  • Identity and contact details of administrators and users: name, email address, and the organization/workspace they belong to.
  • Authentication data: hashed passwords, single-sign-on identifiers, and multi-factor authentication settings. We do not store passwords in plain text.
  • Role, permission, and audit information describing actions taken in the dashboard.
  • Billing and subscription details, which are processed by our payment provider; we do not store full payment-card numbers.

2.2 Device and player information

When a display is paired with the Service, the player/agent reports technical information needed to operate and support the fleet, which may include:

  • Device model, manufacturer, firmware/OS version, and application version.
  • Device and hardware identifiers, and a per-device certificate/credential that we generate to authenticate the device.
  • Network information such as IP address, connectivity status, and diagnostic metrics (heartbeat, uptime, playback position, synchronization drift, resource health).
  • Approximate location at the level provided by the Customer (e.g., the site or venue a screen is assigned to). We do not collect precise GPS location from displays.

2.3 Content and proof-of-play data

  • Records of what content played, when, and for how long (“proof-of-play”), used for reporting and verification.
  • Screen captures. To verify that the correct content is displayed and to support the fleet, the player may capture periodic screenshots of the content shown on the screen and transmit them to the backend. These images reflect the Customer-deployed content on the display; they are not captures of any camera or of persons in the room.

2.4 Usage, log, and technical data

  • Server, application, and security logs, including request metadata and error reports.
  • Product-usage and performance telemetry used to operate, secure, and improve the Service.

2.5 Cookies and similar technologies

The web dashboard uses strictly-necessary cookies and similar technologies for authentication, session management, security, and preferences. We do not use the dashboard to serve third-party advertising. You can control cookies through your browser, though disabling strictly-necessary cookies may prevent you from signing in.

3. How we use information

  • Provide, operate, secure, and maintain the Service and the connected fleet.
  • Authenticate users and devices and enforce access controls and tenant isolation.
  • Deploy, synchronize, and verify content playback, and generate reporting and proof-of-play.
  • Provide customer support, diagnose issues, and communicate service and security notices.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our agreements.
  • Improve and develop features, using aggregated or de-identified data where practicable.

4. Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: (a) performance of a contract to provide the Service; (b) our legitimate interests in operating, securing, and improving the Service, balanced against your rights; (c) compliance with legal obligations; and (d) consent, where required and separately obtained.

5. How we share information

We do not sell personal information. We share information only as follows:

RecipientPurpose
Service providers / sub-processorsCloud hosting, content delivery, object storage, key management, email, and analytics that operate the Service under contract and confidentiality obligations.
The Customer that operates a deviceDevice, playback, and proof-of-play data is made available to the Customer account that manages that display.
Legal and safetyWhen required by law, legal process, or to protect rights, safety, and the integrity of the Service.
Business transfersIn connection with a merger, acquisition, or sale of assets, subject to this Policy.

A current list of sub-processors is available on request at [email protected].

6. International data transfers

We may process and store information in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms as required by applicable law.

7. Data retention

We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Operational data such as logs, proof-of-play records, and screen captures is retained according to the retention period configured by the Customer or our default retention windows, after which it is deleted or de-identified.

8. Security

We apply administrative, technical, and organizational safeguards appropriate to the risk, including encryption of data in transit (TLS, and mutual-TLS for device connections), managed key storage, least-privilege access controls, tenant isolation, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights

Subject to applicable law, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing or withdraw consent. Residents of the EEA/UK (GDPR) and California (CCPA/CPRA) and other jurisdictions may have additional rights, including the right to non-discrimination for exercising them. To make a request, contact us at [email protected]. If you are an end user of a Customer’s displays, please direct requests to that Customer; we will assist them as processor. You may also lodge a complaint with your local data-protection authority.

10. Children’s privacy

The Service is a business tool intended for organizations and is not directed to children, and we do not knowingly collect personal information from children.

11. Third-party services

Content that Customers deploy, and any third-party sites or services it references, are governed by those third parties’ own terms and privacy policies. We are not responsible for the privacy practices of third parties.

12. Changes to this Policy

We may update this Policy from time to time. We will revise the “Last updated” date above and, where changes are material, provide additional notice. Your continued use of the Service after an update constitutes acknowledgment of the revised Policy.

13. Contact us

CasTV.ai
Privacy: [email protected]  ·  Website: https://castv.ai