Last updated · <TODO: effective date>

Privacy Policy

A plain-language note on what Tollcast collects, how voice-training inputs are stored and used to draft replies, and the third-party processors that touch creator data. Reviewer-editable — every section is a scaffold the team can adjust before ads go live.

01 · What we collect

What Tollcast collects at /start

When a creator signs up at /start, we ask for three things — and only three things — so we can train an on-brand voice profile and start watching the platforms that matter to them.

  • Email. Used for sign-in, the Monday brief, and any account-related comms (anomaly alerts, billing receipts, opt-out links). Never shared with third parties for marketing.
  • Creator handle. The public identity Tollcast watches on the creator’s behalf — so we know whose mentions to pick up and whose voice profile to match them against. Not displayed publicly.
  • Primary platform. The channel the creator leads with, so the queue can be tuned to where their audience actually lives. The creator can add or remove channels at any time from settings.

02 · Voice training & replies

Voice-training inputs and reply generation

Voice training is the heart of Tollcast — it’s how the drafts read on-brand instead of generic. We collect two streams of inputs and a queue of generated drafts:

  • Past-post samples. Posts you paste (or explicitly allow us to fetch) when building the voice profile. These are stored encrypted at rest and used solely to derive cadence, phrasing, and stylistic patterns. They never leave Tollcast and are never used to train models owned by anyone else.
  • Mention signals. Mentions, replies, quote-posts, comments, and tags picked up from the platforms the creator has connected. We score each against the voice profile; only the mentions worth replying to are forwarded to the draft step.
  • Generated drafts. On-brand reply drafts, each with a video script and a written fallback, queued for the creator to review. Nothing ships without reviewer approval. Drafts you don’t approve are retained for audit and the Monday brief, then aged out.

Retention window: voice-training samples and mention logs are kept while the account is active. Account deletion removes voice-training samples, mention logs, and unused drafts within 30 days.

03 · Third-party processors

Who else handles your data

We name every processor that touches creator or end-user data. We do not sell data, and we do not allow these processors to use creator data for their own purposes.

Auth

better-auth

Sign-in, sessions, and account state. Holds email and authentication credentials; nothing else.

Payments

stripe-billing

Subscription billing, invoices, and receipts. Card details are handled by Stripe directly; Tollcast never stores card numbers.

Reply generation

Polsia AI proxy

Routes model calls for draft generation. Receives the mention signal and the anonymized voice-profile parameters; no creator PII is forwarded to the model.

Hosting, storage, and transport are provided by Polsia’s managed runtime; data is encrypted in transit and at rest.

04 · Contact

Questions about this policy

We’re a small team and we read every line that lands in the inbox below. If anything in this policy is unclear, or you want to exercise access, correction, or deletion, write to us and we’ll be back within two business days.

tollcast@polsia.app

Reviewer note. Bracketed <TODO> markers are placeholders to fill in before the policy is referenced in ads or a DPA — typically an effective date and any jurisdiction-specific clauses.

Questions to tollcast@polsia.app.