Legal

Privacy Policy

Last updated August 20, 2026

AuthentiCast helps podcasters, audiobook producers, audio-drama creators, and authors detect when their work is copied or re-uploaded without permission — for audio, and for books, articles, and manuscripts. This policy explains what data we collect, how the detection actually works, and the choices you have. We've written it in plain language on purpose.

1. Who we are

AuthentiCast ("AuthentiCast", "we", "us") provides an audio content-authenticity and theft-detection service. You can reach us any time at [email protected]. This policy covers the AuthentiCast marketing site, the customer dashboard, and the AuthentiCast API.

2. Information we collect

Account information

Audio you submit

When you add a track to your catalog or run a check, you provide audio — either as an uploaded file or as a public URL we fetch. We compute an acoustic fingerprint (a compact numeric signature) and store it along with its duration and a reference label you choose (for example an episode name). We do not retain the original audio file after processing, and the fingerprint is not a reconstructable copy of your audio. We also use a "script match" detection method — comparing a short transcript of the opening portion of your audio against other content (your own catalog, the shared corpus, and other customers' catalogs, as described in Section 3) to catch work re-recorded in a different or AI-generated voice, which the fingerprint alone can't detect. We generate this transcript using a third-party transcription API (OpenAI — see Section 5); we store the transcript and a derived text-matching signature so future checks can be compared against it, and separately cache transcripts keyed to the audio's checksum (not to your account) to avoid re-transcribing identical audio — entries in that cache are automatically deleted 90 days after they are created, by a scheduled job that runs daily, and a cached transcript that has passed 90 days is never used even in the window before the job removes it. This method compares literal repeated word sequences — it's built to catch verbatim reuse of a script, not a paraphrased retelling of the same story.

Books, manuscripts, and other text you register

If you use AuthentiCast's book and text protection, you can register written works — published books, articles, or unpublished manuscripts — so we can detect copying of them. What we store depends on the registration mode you choose for each work:

Scanned documents and OCR. If a PDF you register has no readable text layer — a scan or a photographed page — we can only match it by first converting the image to text. When that happens, the document's contents are sent to Anthropic's API to be read back as text (see Section 5), and the resulting text then re-enters the ordinary pipeline above and is stored according to the registration mode you chose. This applies to unpublished manuscripts too, including hash-only ones: hash-only governs what we keep afterwards, not whether the document had to be read in the first place. OCR is spend-capped per account and per document, and runs only for accounts that have an OCR budget set — if yours doesn't, a scanned PDF is refused rather than silently sent anywhere.

What hash-only does and doesn't mean. It means we don't keep your text — the field is left empty, not encrypted. It is not a claim that your text is cryptographically protected: the fingerprints are fast, non-cryptographic hashes of short word sequences, chosen for matching speed, not secrecy. Someone holding the stored fingerprints couldn't read your work from them, but could check whether a phrase they already guessed appears in it. If that distinction matters to you, treat hash-only as "we do not store your text" rather than "your text is encrypted."

We claim no rights in what you register. You keep every right in any work you register with us. AuthentiCast claims no ownership of it, no license to publish, display, distribute, adapt, sell, or excerpt it, and no right to use it to train any model, ours or anyone else's. The only thing we do with your work is process it to detect copying of it, on your behalf, for as long as you keep it registered — and that permission ends the moment you delete the work or close your account. You may only register a work you own or are otherwise authorized to protect, as described in our Terms of Service.

Deleting a registered work. You can delete any registered work from your dashboard or via the API at any time, and you don't need to contact us. Deleting a work removes its stored text, its passages, its match history, and any search excerpts taken from it, immediately — and also removes it from the comparison corpus, so it can no longer be matched against. This immediate deletion applies to our live database; our infrastructure provider retains backups for disaster recovery for a limited period before they age out, the same as for every other type of data in this policy.

Content sources you ask us to watch

If you set up a "content source," you give us the titles and creator/show names you want us to watch for. We use these as search terms for the automated sweep described in Section 3.

Detection results

We store the matches we find for your account — what was matched, where, a similarity score, and when — so you can review them in your dashboard.

Billing information

Payments are processed by Stripe. We store a Stripe customer identifier, your plan, prepaid credit balance, and a record of purchases and renewals. We never receive or store your full card details — those go directly to Stripe.

Usage & technical data

3. How our detection works (and what that means for data)

Detecting stolen audio requires us to look beyond your own account. This is the part of our service most different from an ordinary app, so we want to be explicit about it.

AuthentiCast operates automated crawlers that scan publicly available sources to build a shared reference corpus and to look for possible unauthorized copies of customer audio:

Separately, when you register catalog content or a text work, or run a check, its fingerprint (or, for text, its passage-level signature — and, where script matching applies to audio, its derived text-matching signature) is also compared against every other AuthentiCast customer's registered catalog or works — not just the shared public corpus above — to catch cases where two customers' registered content appears to be the same work. Neither party's identity is revealed to the other from this comparison alone. If our review finds enough evidence that one party's content was copied from the other's, both parties are notified and can provide context or appeal before any final decision is made; only a confirmed, human-reviewed finding can result in permanent enforcement action. See our Terms of Service for what that enforcement can include.

The reference corpus (fingerprints from crawled legitimate hosts) is shared across all AuthentiCast customers — that shared library is what makes detection work. Your own catalog fingerprints and content sources are private to your account and are never shown to other customers directly. As described above, they are compared against other customers' catalogs to detect likely duplicate registrations — but no other customer ever sees your account details, and neither party's identity is revealed to the other unless and until a match is confirmed through review.

4. How we use your information

We do not sell your personal information, and we do not use your audio, text, or matches to train models for unrelated purposes.

5. Third-party services

6. Cookies & local storage

The dashboard uses your browser's local storage to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.

7. Data sharing & disclosure

We share personal data only: with the service providers above so they can perform their function; when required by law or valid legal process; to protect the rights, safety, and property of AuthentiCast, our customers, or the public; and in connection with a merger, acquisition, or sale of assets (you'll be notified). We never sell your data.

8. Data retention

Two kinds of data are deleted on a fixed schedule regardless of your account status:

Everything else — your account data, fingerprints, registered works, and match results — we keep for as long as your account is active. You can export your data or close your account at any time from the dashboard. Closing your account deactivates it — it cancels billing, deactivates your API keys, and stops all processing — but does not itself erase your stored data. To request full deletion of your personal data, email [email protected] and we'll act on it, subject to what we're required to keep for legal, tax, or fraud-prevention purposes.

Registered books, articles, and manuscripts work differently, and it's a stronger guarantee: as described in Section 2, deleting a registered work from your dashboard or via the API removes its stored text, passages, match history, and search excerpts immediately — you don't need to close your account or contact us to do it.

9. Your rights (GDPR & CCPA)

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. You can access and export most of your data yourself from the dashboard, or contact us at [email protected] and we'll respond within the time your law requires.

10. Security

We use encryption in transit, hashed passwords and API keys, scoped access to each customer's own data, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data and to limit what we collect in the first place.

11. Children's privacy

AuthentiCast is a business tool intended for creators and companies, and is not directed to children. We do not knowingly collect personal information from anyone under 16.

12. Changes to this policy

We may update this policy as the service evolves. We'll change the "last updated" date above and, for material changes, notify you by email or in the dashboard.

13. Contact us

Questions about privacy or your data? Email [email protected].