ClearCast manages social accounts for businesses, which means we hold sensitive access to your connected platforms. We treat that access as a responsibility, not a convenience. This page is the single home for our privacy, security, and compliance commitments — and we only claim what is actually true today.
All traffic is served over HTTPS/TLS. Your data and uploaded media are stored on managed infrastructure (Supabase / AWS) that encrypts data at rest.
Every request is scoped to the signed-in account; a signed-in customer cannot read or affect another customer's data, posts, media, or connected-account tokens.
OAuth tokens for your social accounts are stored server-side only and are stripped from every response sent to the browser.
Payments are processed by Stripe (PCI-DSS Level 1). ClearCast never stores full card numbers.
We use a single essential session cookie and no third-party advertising or analytics trackers. We don't sell or share your data, so there is nothing to opt out of.
We will not display a certification badge until we have actually earned it. The following are planned, not in place today:
Independent audit of our security controls over time. Planned as we scale.
Formal ISMS certification and recurring third-party testing.