Privacy Policy
Last updated: August 12, 2026
What HamCast is
HamCast ("we", "the service") is a social media management tool operated at hamcast.site. It lets authorized workspace members and their AI assistants publish content, read analytics, and manage engagement on social platforms and marketplaces the workspace owner has connected.
Information we collect
Sign-in data. When you sign in with Google or GitHub we receive your name, email address, and avatar from that provider. We use it only to identify you and decide workspace access. We do not see or store your Google or GitHub password.
Connected platform data. When the workspace owner connects a social or marketplace account (for example a Facebook Page, Instagram Business account, TikTok account, or Etsy shop), we store the OAuth access token that platform issues, the account's ID and display name, and — when features are used — content you ask us to publish, scheduled posts, analytics summaries, and engagement items (comments, mentions, reviews) fetched from the platform.
SmartLink analytics. Public link-in-bio pages record view counts and, per button click, a timestamp, the referring page, and the browser user-agent string. We do not use third-party tracking cookies.
How we use information
Solely to provide the service: publishing the content you request, showing analytics, listing engagement, and operating scheduled posts. We do not sell personal information, we do not use it for advertising, and we do not share it with third parties except the platforms you explicitly connected (and our hosting providers below).
Storage & security
Data is hosted on Vercel (application) and Neon (PostgreSQL database). OAuth access tokens are encrypted at rest with AES-256-GCM before being written to the database. Access to the workspace is restricted to an owner-approved list of email addresses, and the programmatic API requires a secret bearer key.
Data retention & deletion
Connected-account tokens are kept until the connection is removed. You can request deletion of your data at any time — including sign-in records, connected-account tokens, scheduled posts, and SmartLink analytics — by emailing kendallcorless@gmail.com with the subject "Data deletion request". We will delete the data within 30 days and confirm by reply. Disconnecting a platform in the dashboard immediately replaces its stored token.
This page (/privacy#data-deletion) serves as the data deletion instructions URL for platform app reviews (Meta, TikTok, and others).
Platform policies
Use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Meta, TikTok, X, and other connected platforms is handled per each platform's developer terms.
Changes & contact
We may update this policy; material changes will be reflected by the date above. Questions: kendallcorless@gmail.com.
