← PointCast
Privacy

A small-data promise.

Effective July 25, 2026

What PointCast collects

Google sign-in supplies a stable account identifier, verified email address, display name, and profile image. PointCast uses that information only to create or link a PointCast account, keep the user signed in, and identify the verified account allowed to manage the live broadcast.

PointCast does not request access to Gmail, Google Drive, contacts, calendars, or any other Google service.

Spotify live signal

Spotify connection is available only to the authorized PointCast broadcaster and requests the user-read-currently-playing permission. PointCast stores the resulting access and refresh credentials encrypted at rest.

The public signal contains only the current item’s title, artist or publisher, cover image, Spotify link, and playing or paused state. It never republishes audio and does not expose the Spotify account, playback device, progress, listening history, or other personal profile information.

Shopify catalog signal

Shopify connection is available only to the authorized PointCast broadcaster and requests the read-only read_products permission. The connection is intended for publishing selected product and catalog nouns as a PointCast signal. PointCast stores the resulting expiring credentials encrypted at rest.

PointCast does not request customer, order, checkout, payment, or write access. A connected shop’s domain and authorization status are visible only to the broadcaster; public visitors see only whether a catalog signal is available.

Storage, sharing, and deletion

Sign-in sessions expire after 30 days. Current Spotify metadata is refreshed when requested and any cached signal expires within 24 hours. Shopify credentials rotate through the provider’s expiring offline-token flow. PointCast does not sell this data or use it for advertising. Cloudflare provides the hosting, session storage, and encrypted secret storage needed to operate the service.

The broadcaster can disconnect Spotify or Shopify at any time from the PointCast dashboard. Disconnecting immediately deletes that provider’s stored credentials; Spotify disconnection also clears the cached live signal. Any user may request access to or deletion of their PointCast account data by emailing hello@pointcast.xyz.

Security and changes

PointCast uses secure, HttpOnly cookies for account sessions, verifies Google identity tokens, verifies Shopify state and signed callback parameters, and encrypts Spotify and Shopify credentials before storage. No online service can promise absolute security; material changes to this policy will be reflected on this page with a new effective date.