Cascads
FeaturesPricingFAQ
Log inGet started

Privacy

Your work stays your work.

Effective and last updated: 15 August 2026

Who is responsible

Cascads is operated by Victor Laybats as part of the Ivryn product studio. For privacy questions or requests, email contact@cascads.com.

Data Cascads processes

  • Account: email address, optional name, optional password salt and one-way password hash, email-verification status, terms acceptance, one-time account-link hashes, account creation date and login sessions. If you choose Google sign-in, Cascads also stores Google's stable account identifier and the name and profile-photo URL Google returns.
  • Workspace: brand profiles, websites or text you ask Cascads to analyse, content instructions, edits, generated posts and media, schedules, job history and publishing results.
  • Connected services: the credentials, granted scopes, expiry information and account identifiers needed to provide the connection you request. Social credentials are encrypted at rest and are excluded from account exports.
  • Billing and credits: plan, subscription and trial status, trial eligibility or prior claim, welcome, trial and monthly credit use, purchased-credit balance, top-up references and Stripe customer or subscription identifiers. Cascads does not receive or store complete card details.
  • Affiliate programme: affiliate account, opaque referral code, aggregate click count, referred-account attribution, paid-invoice and refund references, commission rate, pending or paid balance and payout reference. Affiliates see a masked identifier for each referral, not the referred customer's full email address.
  • Minimal product measurement: only first-occurrence dates for completed signup, email verification, completed brand profile, completed generation, connected network, configured cadence, confirmed remote publication, received provider metrics, and the start or confirmed outcome of a subscription, trial or credit top-up. This ledger stores no content, payment amount, IP address, device identifier or social account identifier.
  • Account acquisition cohort: if you create an account from a measured public signup link, Cascads may store once the bounded source category, page placement, interface language and attribution time. It does not store the raw referrer URL, campaign name, query string, IP address, user agent or a visitor identifier in this account cohort.

Cascads uses one essential, secure session cookie to keep you signed in. If you deliberately follow an affiliate link, Cascads also stores an opaque first-party referral code for 180 days. An affiliate may add a short campaign label and choose a Cascads destination page; Cascads stores only the aggregate click count for that label. The click counter does not retain your IP address, device, fingerprint or referring page; the code is connected to your identity only if you create a Cascads account. Public marketing pages otherwise count aggregate page views and conversion actions without a tracking cookie, fingerprint or persistent visitor identifier. A signup link may carry only a bounded source category, page placement and language so that completed-account cohorts can be compared without keeping a raw referrer or campaign string. Query strings, email addresses and IP addresses are not written to the aggregate measurement store. After validation, a sanitised server-side copy is processed by PostHog US Cloud without a tracking cookie, stable visitor profile or session replay. Do Not Track or Global Privacy Control disables both measurement and this signup-link attribution. See the IVRYN portfolio measurement notice. Cascads has no advertising or behavioural profiling tracker.

Why the data is used

  • To create and secure your account, send required account and billing notices, generate requested content, run jobs, schedule and publish approved content, and provide subscriptions, as necessary to provide the service you request.
  • To reserve and debit production credits, prevent abuse, troubleshoot failures and keep the service secure, based on Cascads's legitimate operational and security interests.
  • To maintain payment and accounting records where required, in compliance with legal obligations.
  • To attribute referred accounts, calculate valid commission, prevent self-referral and affiliate fraud, and maintain payout records, for performance of the affiliate terms, Cascads's legitimate fraud-prevention interests and applicable accounting duties.

Cascads does not sell your personal data and does not use your workspace content for advertising.

Service providers and destinations

Primary application data is hosted on infrastructure operated by Ivryn in France. Only the providers needed for a feature receive the data required for that feature:

  • Anthropic may receive brand context and instructions when AI generation is requested.
  • Pexels receives stock-media search terms when visuals are sourced.
  • Stripe receives account, trial, subscription or credit top-up information when a payment method or paid billing is used.
  • Resend receives the email address and transactional message needed for account verification, account recovery or a required trial-renewal reminder.
  • Cloudflare Turnstile processes the technical information needed to prevent automated public registrations when public signup is enabled.
  • PostHog US Cloud processes sanitised public-page events with a fresh anonymous event identifier, a zeroed IP property and person-profile processing disabled.
  • Google verifies your identity and returns your email, name and profile photo when you choose “Continue with Google”. Cascads requests only the OpenID Connect identity scopes for this sign-in flow and does not retain Google's access or ID token from that flow.
  • YouTube receives the authorisation request and, when you expressly choose to publish, the selected video and the metadata and visibility settings you confirmed.
  • Connected social networks receive approved content, media and the authentication data required for publishing.

Some providers may process data outside the European Economic Area under their own terms and legal safeguards. You can avoid optional providers by not using the corresponding feature.

YouTube API Services

Cascads uses YouTube API Services only when you choose to connect a YouTube channel. Google handles the authorisation screen. Cascads never asks for or stores your Google or YouTube password. Google's own processing is described in the Google Privacy Policy.

  • Information accessed and stored: the OAuth access and refresh tokens, granted scopes and expiry time; the connected channel ID and displayed channel title; the video file, title, description, privacy setting and made-for-kids choice for an upload you approve; and, after publication, the returned YouTube video ID, publication result, view count, like count, comment count and the time those metrics were retrieved.
  • How it is used: to show the exact connected channel, upload the video with the metadata and visibility you chose, keep an authorised connection working, display the publication result and retrieve performance for that channel's published content. Cascads does not use YouTube API Data for advertising, behavioural profiling or training a general-purpose AI model.
  • Who can receive it: Google and YouTube receive the authorisation request and the upload you instruct Cascads to send. Cascads does not disclose YouTube Authorized Data to advertisers, other Cascads customers or unauthorised third parties.
  • Storage: credentials are encrypted at rest. While the connection remains authorised, YouTube API Data is kept only when needed for the requested features and is refreshed or deleted within 30 calendar days. Dated historical performance may be shown with the time at which it was retrieved.

Disconnecting and revoking access: use Disconnect in Cascads network settings to ask Google to revoke the token, immediately delete the YouTube Authorized Data stored for that connection and stop future YouTube API access. If Google cannot confirm remote revocation, Cascads tells you to revoke Cascads from your Google security settings. Cascads rechecks YouTube authorisations during daily maintenance. If a revoked token can no longer be refreshed, the associated YouTube Authorized Data is deleted as soon as detected and within seven calendar days of revocation.

Removing access does not delete videos already stored by YouTube. Use YouTube itself to delete a video or channel.

To delete YouTube-related data stored by Cascads without deleting content held by YouTube, delete your Cascads account, follow the data deletion instructions, or email contact@cascads.com. A verified request to delete stored YouTube Authorized Data is handled as soon as possible and within seven calendar days.

Retention

  • Account, brands, schedules, content and connections: until the account is deleted.
  • Login sessions: 30 days after the last use.
  • Single-use Google sign-in state: 10 minutes at most, removed on callback or expiry.
  • Email-verification links: 24 hours; password-reset links: one hour. Only a one-way hash of each single-use token is stored.
  • Unused original uploads: 24 hours.
  • Cascads usage and subscription history: 13 calendar months.
  • Sanitised public-page events processed by PostHog: 12 months under the current project setting.
  • Bounded account acquisition cohort: until the account is deleted.
  • Affiliate referral cookie: 180 days. Account attribution, commission, refund and payout records: for the programme relationship and then for the accounting or dispute period required by applicable law.
  • Purchased-credit balance and top-up references: until the credits are used and the related payment record is no longer required, or until the account is deleted, subject to legal accounting retention.
  • YouTube Authorized Data: while the connection remains authorised and the data is needed for a requested feature, with refresh or deletion within 30 calendar days. Disconnecting deletes the data stored for that connection immediately. A revoked authorisation detected by the daily maintenance check is deleted as soon as detected and within seven calendar days of revocation.
  • Job history: the latest 40 video jobs, 40 carousel jobs and 50 clipping jobs.
  • Encrypted local and remote backups: seven days at most. Deleted account data and revoked YouTube Authorized Data disappear from backup rotation within that period.

Payment providers and social networks may retain their own records under their policies or legal obligations.

Security

Passwords are salted and one-way hashed. Sessions use secure, HTTP-only cookies. Google sign-in uses a single-use anti-forgery state, PKCE, a nonce and server-side signature validation. Social credentials are encrypted at rest. Public media links created for supported social publishing are signed, restricted to one file and expire within one hour. Backups are encrypted.

No internet service can guarantee absolute security. Never email a password, API key or social access token to support.

Your rights

Depending on the circumstances, you may request access, rectification, erasure, restriction, objection or portability of your personal data. You can download a machine-readable account export and start account deletion from the account menu.

Email requests to contact@cascads.com. Include the email address attached to your Cascads account; additional proof may be requested to protect the account. Requests are answered within one month, subject to lawful extensions. You may also lodge a complaint with the CNIL, the French data protection authority.

Delete account dataContact support
© 2026 Cascads, a product from Ivryn TermsPrivacyData deletionSupport