Privacy Policy
Effective date: August 6, 2026
This policy explains what personal data BroadcastPilot collects, why, and what rights you have. It covers two situations: data about you as our customer (where we are the controller), and data about your station's listeners that we process on your behalf (where your station is the controller and we are the processor).
1. Data we collect about you (our customer)
- Account data: name, email address, password (stored as a secure hash, never in plain text), language preference, and optional two-factor authentication secrets.
- Billing data: your plan, invoices, and payment status. Card numbers are handled entirely by Stripe — we never see or store them.
- Content you create: stations, audio, scripts, playlists, schedules, brand strategy, and configuration.
- Usage and technical data: session and security logs (including IP address and device information) and an audit trail of account actions, kept to protect your account.
2. Data we process on behalf of your station
When listeners interact with your station — sending greetings or dedications, joining your mailing list, or using your public player — we collect what they submit (such as name, email, phone number, message, and technical data like IP address) and store it for you. Your station decides how this data is used; we process it only to provide the service and never sell it or use it for our own marketing.
3. What we use data for
- Operating the platform: streaming, generating content you request, sending the transactional emails the service requires (verification, receipts, alerts).
- Security: preventing fraud and abuse, protecting accounts.
- Billing and compliance with legal obligations.
- We do not sell personal data. We do not use your content or your listeners' data for advertising.
4. AI processing
To generate content you request, relevant text (such as prompts, scripts, and station context) is sent to our AI subprocessors (OpenAI for text, ElevenLabs and Inworld AI for voice synthesis). We send what is needed for the generation you asked for; we do not send your listeners' contact data to AI providers.
5. Subprocessors
- Stripe — payments and billing.
- Resend — transactional email delivery.
- OpenAI — AI text generation.
- ElevenLabs and Inworld AI — AI voice synthesis.
- Contabo GmbH — server hosting (European Union).
- Streaming infrastructure (AzuraCast) runs on our own servers, not a third party.
6. Where data is stored
Our servers are hosted in the European Union. Some subprocessors (such as Stripe, Resend, and the AI providers) process data in the United States under their own safeguards.
7. Retention
- Account and content data: kept while your account is active.
- Analytics: retained according to your plan's retention window, then aggregated or deleted.
- Backups: rotated automatically; old backups are overwritten on a fixed schedule.
- When you close your account, we delete your data within 30 days, except records we must keep for legal or accounting reasons (such as invoices).
8. Your rights
You may access, correct, export, or delete your personal data, and object to or restrict certain processing, as provided by laws such as the GDPR and the CCPA. Write to support@broadcastpilot.com and we will respond within 30 days. If you are a listener of a station hosted on BroadcastPilot, you can contact us or the station directly; we will assist the station in honoring your request.
9. Cookies
We use only essential cookies: session authentication and security. We do not use advertising or cross-site tracking cookies, which is why you do not see a cookie banner.
10. Children
BroadcastPilot accounts are for adults (18+). The service is not directed at children under 16, and we do not knowingly collect their data.
11. Changes and contact
We will notify you of material changes to this policy before they take effect. Questions or requests: support@broadcastpilot.com.