BuildCaster public test · No real charges · Support · Legal notices
BuildCaster.

LEGAL · September 16, 2026

Cookie Notice

The cookies and browser storage used by the current BuildCaster test, with their purposes and controls.

Version 2026-09-16-test.3 · Invitation-only test

Operated by Hiltos LLC · Michigan, United States

1. Necessary sign-in cookie

The HTTPS service uses a cookie named __Secure-buildcaster.session_token to recognise a verified sign-in. It is HttpOnly, Secure, SameSite=Lax and limited to the host where you signed in. Team sign-in and portal sign-in do not depend on sharing cookies across unrelated domains.

The configured lifetime is seven days; normal session refresh can renew it and signing out removes it. Blocking this cookie prevents authenticated features from working. Public approved content remains readable without signing in.

Choosing Google sign-in also sets __Secure-buildcaster.state on the host where you started. This signed, HttpOnly, Secure, SameSite=Lax cookie binds the Google response to that browser, lasts up to five minutes, and is cleared when sign-in completes. The related server-side sign-in state expires after ten minutes; a portal handoff expires after one minute. These temporary values are necessary for the sign-in you requested, not advertising or analytics identifiers.

2. Idea draft storage

When you write an idea, its title and problem/desired outcome are saved in sessionStorage under a buildcaster-draft key scoped to the portal. This keeps the draft in the same browser tab while you sign in. Successful submission clears the saved draft; closing the tab normally ends the browser session, although browser restore features may retain it.

You can clear this through your browser’s site-data controls. Doing so may lose your unfinished idea. Similar-idea search sends the title to the current portal while you type. Draft storage is not used to track you across sites.

3. Measurement and optional tracking

BuildCaster does not currently set an advertising cookie, embed an external analytics script or use an analytics identifier stored in your browser. Basic landing/sign-in counts are held as aggregate server counters, and workspace activation milestones are associated with workspace records.

Postmark open tracking and link tracking are disabled for messages sent by this deployment. We still receive delivery, bounce, complaint and unsubscribe events to operate email safely. If optional tracking is introduced later, this notice and the applicable consent controls must be updated before it is used.

The application does not change its behaviour in response to a browser’s Do Not Track signal. It does not track visitors across third-party sites for advertising.

4. Other sites and network services

Cloudflare handles network/security for the main site and may set security or challenge cookies when those functions are used. The temporary test portal namespace currently reaches the application directly. Cookie behaviour can therefore differ by address and security challenge.

Stripe checkout and subscription management run on Stripe’s own pages and have their own cookie/privacy information. Choosing Google sign-in opens Google’s pages, which may use Google cookies and operate under Google’s policies. The Google mailbox used for support also operates under those policies. These services are not embedded advertising trackers supplied by BuildCaster.

5. Your controls

Use your browser’s cookie and site-data settings to inspect, clear or block storage. Signing out clears the current host’s authentication cookie; if you signed into several portal hosts, sign out on each host. Clearing cookies does not delete server-side workspace records or unsubscribe you from email.

For account deletion or email preferences, see the privacy policy or contact privacy@buildcaster.app.