1. Who is responsible
Hiltos LLC, based in Michigan, United States, operates BuildCaster. Contact privacy@buildcaster.app for privacy questions or requests.
BuildCaster determines how it handles its own account administration, sign-in, service security, support and billing records. A company operating a customer portal determines why it collects customer feedback and who it invites; BuildCaster stores and processes that workspace content to provide the service on the company’s instructions. In data-protection laws using these terms, these activities can make BuildCaster a controller for its own operations and a processor for workspace content.
BuildCaster is also the workspace operator for its own feedback portal. For another company’s portal, contact that company through its usual support channel about its handling of your contributions. We can help identify the relevant workspace and route a request without disclosing private tenant information.
2. Information we receive
We receive information directly from you, from people who invite you or import information into a workspace, from your browser when it contacts the service, and from the providers used to deliver the service.
- Identity and access: name, email address, verification state, sign-in and session records, workspace memberships, roles, invitation details and access changes. Session records can include IP address and browser information. If you choose Google sign-in, Google supplies your account identifier, name, email and email-verification status. We retain the provider identifier to recognise your account. We use Google access tokens only to complete sign-in and do not retain them in your account record.
- Workspace content: product name, logo and colours; ideas and drafts submitted to the server; votes, comments, follows and notification preferences; internal notes and imported provenance; decisions, releases, relationships and moderation history.
- Operational records: request-limit identifiers, timestamps, delivery attempts, recipient addresses, provider references, message hashes, bounce/complaint and unsubscribe records, domain verification and routing status, and security or support diagnostics.
- Billing tests: workspace identifiers, owner contact information, Stripe customer/subscription references and confirmed trial, renewal and cancellation state. Card details are entered on Stripe’s hosted pages; BuildCaster does not receive full card numbers or security codes.
- Support: the email address and content you send to support, and information needed to respond. Avoid sending secrets or unnecessary personal information.
- Browser drafts: an unfinished idea’s title and description are saved in this tab’s session storage to survive sign-in. Similar-idea search sends the current title to the portal’s search endpoint while you type; an unfinished draft should not be treated as entirely offline.
Optional Google sign-in
You can choose Continue with Google instead of requesting an email link. This sends you to Google to choose an account and authorise basic identity information (openid, email and profile). Google processes the sign-in request and related browser/network information under its own terms and privacy policy. We do not request permission to read your Gmail messages, contacts, calendar or Drive files.
A matching, previously verified BuildCaster email can connect to the same Google identity without creating a second BuildCaster account. Signing in does not grant a team role or bypass a private portal invitation. Google sign-in uses the central BuildCaster callback and returns you to the portal where you started, with a separate session for that host. You can continue using email links or remove BuildCaster’s connection through your Google account settings. Removing that connection does not itself delete your BuildCaster records or existing sessions.
3. Why we use information
We use information to verify identity, provide authorised access, show feedback to its intended audience, process votes and comments, moderate content, publish updates, deliver requested messages, manage test subscriptions, provide export/support, prevent misuse and investigate failures.
We count aggregate homepage/sign-in requests and record workspace activation steps, such as creating a workspace or publishing its first release. Landing counters do not contain an IP address or browser identifier. Workspace activation events are associated with a workspace. Internal and demo workspaces are excluded from workspace adoption measurements; these counts are not unique visitors or proof of paid adoption.
We do not sell personal information, use it for targeted advertising, or enrol people in marketing because they voted or signed in. The application has no integration that sends workspace feedback to an external analytics or AI service. We do not use automated profiling to make decisions with legal or similarly significant effects about individuals. Rate limits and access rules protect the service; product decisions remain with workspace teams.
4. Basis for handling information
Where a law requires a legal basis, we use account information as needed to provide a service requested under our agreement with you; for business users acting for an organisation, the organisation’s agreement and our legitimate interests in administering that relationship are relevant. Security, misuse prevention, troubleshooting and limited operational measurement support our legitimate interests in running and protecting the service. We consider the effect on the people concerned.
Following settings authorise the optional product notifications you select, and you can withdraw those choices at any time. Where consent is legally required, the processing depends on that consent. We may also use or retain information to comply with applicable legal obligations. A workspace operator is responsible for its own legal basis and required notices for customer content.
You can read approved public content without an account. A verified email and name are required to sign in and contribute. You may choose not to provide them, but authenticated features will then be unavailable.
5. Who can see workspace information
Anyone can read approved public ideas, public comments, display names, decisions and published releases on a public portal. Public information may be copied or indexed by third parties. Pending ideas are limited to their submitter and the workspace team. Invitation-only portals restrict content to their permitted audience.
Workspace owners and authorised team members can access administrative information according to their role. Owner exports include participant email addresses, private content, provenance and history. An editor in one workspace has no team permissions in another workspace.
Approved operational access may be needed to provide support, investigate incidents, maintain the service or respond to a lawful request. Public interfaces omit participant email addresses, internal notes and private source material. No security measure can guarantee that information will never be accessed improperly.
7. Where information is processed
The application and managed PostgreSQL database currently run in DigitalOcean’s New York region in the United States. Providers may process information in other countries, and Cloudflare uses a global network. Support and email processing can therefore involve countries outside your home country.
We do not offer a region-restricted hosting commitment in this test. The applicable contract and transfer safeguards depend on the workspace operator, the people involved and the providers. Before using the service for customer data subject to a required processing agreement or international-transfer mechanism, contact us to establish the appropriate arrangement. A provider’s certification is not a certification of BuildCaster.
8. Retention and deletion
Workspace content remains in the active database while the test workspace is in use and after trial expiry or cancellation, so authorised people can read history and the owner can export it. This deployment has no automatic workspace-deletion schedule. Requests to delete accounts or workspace data are handled manually after identity and authority checks.
When handling a request, we consider whether information is still needed to provide an active workspace, carry out the owner’s instructions, resolve a dispute, meet a legal obligation, investigate abuse, or preserve an unsubscribe/suppression choice. We will explain any material reason information must be retained. We do not treat an inactive workspace as permission to retain all personal information indefinitely.
Sign-in links are valid for 15 minutes and sessions normally last seven days, subject to refresh and sign-out. Expiry limits access; it does not by itself delete historical database or delivery records.
Daily application backups and managed-provider backups may contain earlier copies. Automatic rotation is not configured for the application’s logical backup files, so we cannot promise a fixed backup-erasure date. A deletion request must also consider these copies and prevent a later recovery from reintroducing deleted information. Providers retain their own operational records under their agreements and settings.
The public test should use sample or non-sensitive evaluation information. A fixed retention and backup-rotation policy must be established before a broader customer-data rollout.
9. Your choices and requests
Contact privacy@buildcaster.app to request access, correction, deletion, restriction or a copy of your personal information, or to ask how it is used. Depending on the law that applies, you may also have rights to portability, to object to processing based on legitimate interests, to withdraw consent and to complain to the relevant privacy regulator. These rights may be subject to lawful exceptions.
You can remove your vote and independently keep or remove an idea’s email follow. You can also adjust portal-wide notification preferences. Every product notification includes a way to unsubscribe. Withdrawing optional message preferences does not block a sign-in message you request or an administrative message needed for your account.
Include the email address you use and the relevant workspace address. Do not send passwords, magic links, card details or identity documents unless we request a necessary, proportionate verification step. We verify authority before releasing another person’s data and respond within any deadline applicable to the request.
For information controlled by a workspace operator, we may need to forward the request or act on that operator’s instructions. Account deletion can affect access to several workspaces. Public copies, recipients’ emails and other parties’ lawful records may not be retrievable by BuildCaster.
You may contact the Michigan Attorney General’s Consumer Protection Team about a consumer complaint, or a privacy or consumer regulator with authority where you live. Contacting us first is optional and does not limit a complaint or other legal remedy.
11. Changes to this notice
Effective September 16, 2026. This revision adds optional Google sign-in, the account information used for it, and its temporary sign-in cookie. Email-link sign-in remains available. Choosing either method does not enrol you in marketing or idea updates.
We identify revisions by version and date and will provide additional notice of material changes where required. An update does not silently authorise a new use that requires your consent. Contact support for an earlier notice or a question about a change.