Privacy Policy
TaleCast is operated by Faelore Studios LLC, a Wyoming limited liability company, which is the data controller for the information described here. References to "we," "us," or "our" mean Faelore Studios LLC. We are committed to protecting your privacy, and this Privacy Policy explains how we collect, use, share, and protect information about you when you use our mobile application and services.
1. Information We Collect
Account Information
When you create a TaleCast account, we collect:
- Email address
- Username and display name
- Profile photo (optional)
- Date of birth (to verify age eligibility)
- Author biography and links (for author accounts)
Purchase & Transaction Data
When you purchase Gems or subscribe, we collect:
- Transaction amount and timestamp
- Gem balance and transaction history
Reading & Listening Activity
- Content you have unlocked or purchased
- Reading and listening progress (chapter, position)
- Titles, series, and authors you follow
- Ratings and reviews you submit
- Community posts and comments
Device & Technical Information
- Device type, operating system, and version
- App version
- IP address and approximate geographic region
- Crash and error reports (we do not collect performance or usage tracing)
- Push notification token (if you grant permission)
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account;
- Process purchases and deliver content you unlock;
- Track and display reading/listening progress;
- Send transactional emails (receipts, password resets);
- Send optional marketing and digest emails (with your consent — you may opt out at any time);
- Provide creator payout processing;
- Improve Platform features, performance, and recommendations;
- Detect and prevent fraud, abuse, and policy violations;
- Comply with legal obligations.
3. Third-Party Services
Supabase
We use Supabase for our database, authentication, and backend infrastructure. Your account data and content are stored on Supabase-managed servers. Supabase is SOC 2 Type II certified. For more information, see supabase.com/privacy.
Stripe
All payment processing is handled by Stripe, Inc. Payments are collected by Faelore Studios LLC, which operates TaleCast, and will appear on your card or bank statement as FAELORE STUDIOS LLC. When you make a purchase, your payment information is submitted directly to Stripe. TaleCast does not receive or store your full payment card details. Stripe's privacy policy governs their handling of your payment data: stripe.com/privacy.
ElevenLabs
Authors on TaleCast may use AI voice generation powered by ElevenLabs. When an author generates audio using this feature, the text content of the script may be transmitted to ElevenLabs' servers to produce the audio. TaleCast does not share listener or reader data with ElevenLabs. For more information: elevenlabs.io/privacy.
Google (Gemini)
Authors on TaleCast may use AI image generation — character art, backgrounds, and covers — powered by Google's Gemini models. When an author generates an image, the prompt they wrote, and any reference image they choose to supply, are transmitted to Google's servers to produce the image. TaleCast does not share listener or reader data with Google. For more information: policies.google.com/privacy.
Anthropic (Claude)
We use Anthropic's Claude models to run our automated content-safety checks. Content submitted to TaleCast is transmitted to Anthropic's servers and checked against our prohibited-content rules — sexual content involving minors, extremism, hate speech, non-consensual intimate imagery of real people, and instructions for serious crimes. Unlike the AI features above, this is not limited to authors: episode and chapter text, uploaded images (including profile pictures), the transcript of uploaded audio, community posts, comments, written reviews, and the text of a report you file about a marketplace listing are all reviewed this way. We send the content being reviewed and a short label describing what kind of submission it is — not your name, email address, or account ID. We also use Claude to power the in-app support assistant, which sends your side of that conversation to Anthropic. For more information: anthropic.com/privacy.
OpenAI (Whisper)
When an author uploads an audio episode, or uploads their own sound-effect or music file, that audio file is transmitted to OpenAI and converted to text using their Whisper speech-to-text model. We do this because audio cannot be safety-checked without first knowing what is said in it — the resulting transcript is what the Claude check above reviews. Only the audio file is sent; no account information goes with it. For more information: openai.com/policies/privacy-policy.
Copyscape
When an author publishes a novel or visual-novel chapter, the text of that chapter is transmitted to Copyscape, a plagiarism-detection service, which compares it against pages published on the public web and returns any that match. This runs when a chapter is submitted for publication, not while it is being drafted, and it applies only to written chapters — never to comments, reviews, or messages. For more information: copyscape.com/privacy.
AuthentiCast
AuthentiCast is a content-authenticity and piracy-detection service that we also operate. It is a separate product with its own systems and its own database, so we disclose it here rather than treat it as internal. Two things are sent to it. When an author uploads an audio episode, up to the first 5 MB of that audio file is sent to AuthentiCast, which turns it into an acoustic fingerprint and compares it against recordings it already knows, so a recording taken from another creator or another platform can be caught before it is published. When an author publishes a written chapter, that chapter's text is sent to AuthentiCast, which searches selected phrases from it against a web-search index; this text check runs alongside Copyscape so the two can be compared, and it does not currently affect whether anything is published. Content sent to AuthentiCast is identified by an internal episode reference, not by your name or account. For more information: authenticast.org/privacy.
Crash reporting (Sentry)
When the app crashes or hits an error, a diagnostic report is sent to Sentry so we can find and fix the problem. These reports include the error itself, the app version and basic device information. They are tagged with your account's internal user ID so we can tell whether a crash affects one person or everyone — they do not include your name or email address. We do not use Sentry for analytics or performance tracking, only errors. For more information: sentry.io/privacy.
Push notifications
If you turn on notifications, your device gives us a notification token — an identifier for that specific device, not for you personally. We store one token per device you sign in on, along with which platform it is, so a notification meant for you reaches the right device and does not follow you to a device you no longer use. Turning notifications off in your device settings stops them; deleting your account removes the tokens.
Expo / React Native
The app is built with Expo. Expo may collect anonymous usage and crash analytics about its own developer tooling. That data is not linked to your identity.
4. Cookies & Local Storage
TaleCast is a mobile application and does not use browser cookies. However, we use the following on-device storage mechanisms:
- On-device local storage for authentication tokens (session persistence);
- AsyncStorage for user preferences such as theme and notification settings;
- Cached content data to enable offline reading progress.
You can clear locally stored data by uninstalling the app or clearing app data in your device settings.
5. Data Sharing & Disclosure
We do not sell your personal data to third parties. We may share your information only in the following circumstances:
- With service providers who assist in operating TaleCast, under contractual data protection agreements — Supabase (hosting, database and file storage), Stripe (payments and creator payouts), Sentry (crash reporting), Resend (transactional email), ElevenLabs (AI voice generation), Google (AI image generation), Anthropic (automated content-safety review and the support assistant), OpenAI (speech-to-text transcription of uploaded audio), and Copyscape (plagiarism checking) — each described in Section 3 above;
- With AuthentiCast, a separate content-authenticity and piracy-detection service we also operate, which receives uploaded audio and published chapter text as described in Section 3 above;
- With law enforcement or government authorities when required by law or to protect the safety of our users;
- In connection with a merger, acquisition, or sale of assets, in which case we will notify users before data is transferred;
- With your consent for any other purpose.
Author usernames and published content are publicly visible on TaleCast. Community posts and comments you make are visible to other users.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services.
Deleting a story or episode. When you delete content, it stops being visible in the app straight away. You then have 7 days to change your mind — contact us within that window and we can restore it. After 7 days it is permanently deleted and can no longer be recovered by you or by us. The files that belong to it — uploaded and generated audio, cover images, narration and visual-novel assets — are erased in a routine cleanup that runs monthly.
Deleting your account. When you delete your account it is closed immediately: you are signed out and it can no longer be used. You then have 14 days to change your mind. Email support@talecastapp.com from the address on the account within those 14 days and we can reopen it with your content intact.
After the recovery window your account is queued for permanent deletion, which is carried out in a cleanup that runs monthly. In practice your profile, your solo content and the uploaded files behind it are destroyed within about 30 to 60 days of your request. Once that has run, nothing can be recovered.
What outlives deletion, and why.
- Financial transaction records are retained for 7 years where applicable law requires us to keep them.
- Content that other users have purchased or unlocked is retained so their purchases and access remain valid. It is removed from public view rather than destroyed.
- Reports you file for content moderation purposes are retained indefinitely with your identity permanently removed, to support platform safety even after account deletion.
- Content you contributed to a collaborative story remains on the Platform so your collaborators' work is unaffected. See the Terms of Service for how your credit is handled.
Backups are kept on a rolling basis and are overwritten in the normal course of operation. Deleted data may persist in a backup until that backup expires; it is not restored to the live service.
7. Your Rights (GDPR & CCPA)
Depending on your location, you may have the following rights with respect to your personal data:
- Right to Access — request a copy of the personal data we hold about you;
- Right to Correction — request that we correct inaccurate or incomplete data;
- Right to Deletion — request that we delete your personal data (subject to legal retention requirements);
- Right to Portability — request your data in a machine-readable format;
- Right to Object — object to processing of your data for direct marketing purposes;
- Right to Restrict — request that we limit how we use your data while a dispute is resolved;
- Right to Opt Out of Sale — we do not sell personal data; this right is automatically satisfied.
California residents under the CCPA have additional rights including the right to know what categories of personal information we collect and the right to non-discrimination for exercising these rights.
You can export a machine-readable (JSON) copy of your own data at any time from Settings → Export My Data in the app, which satisfies the Right to Access and Right to Portability directly.
To exercise any other rights, contact us at support@talecastapp.com. We will respond to verified requests within 30 days.
8. Children's Privacy
TaleCast is not directed at individuals under the age of 18 and we do not knowingly collect personal information from minors. If we become aware that a user is under 18, we will terminate their account and delete associated data. If you believe we have inadvertently collected data from a minor, contact us immediately at support@talecastapp.com.
9. Security
We implement industry-standard security measures to protect your personal data, including:
- Encrypted connections (TLS) for all data transmission;
- Supabase Row Level Security (RLS) to prevent unauthorized data access;
- Session tokens stored on-device and never transmitted except over TLS;
- Regular security audits and monitoring.
No system is completely secure. If you discover a security vulnerability, please disclose it responsibly to support@talecastapp.com.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notice. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of TaleCast after changes constitutes acceptance of the updated policy.
11. Contact Us
For all privacy questions, data requests, or general support: