Privacy Policy
We collect only what Castalio needs to work, we never keep an image of your face, and you stay in control of your data.
Verzija 2026-09-21 · Povijest verzija
Samo predložak – sve pravne tekstove treba pregledati stručnjak.
This page is not yet available in your language; showing English.
Who is responsible for your data
The data controller is Castalio, which operates the Castalio platform.
Our person in charge of the protection of personal information is [responsable à nommer]. You can reach them at [email protected] with any question or request about your data. Address: [adresse à confirmer après l’immatriculation].
Representative in the European Union (Article 27 GDPR): [représentant à désigner avant l’ouverture dans l’UE]. Representative in the United Kingdom: [représentant à désigner avant l’ouverture au Royaume-Uni].
Castalio welcomes members worldwide. We use the European Union's General Data Protection Regulation (GDPR) as our baseline and add the requirements of each jurisdiction, including Québec's Law 25, Canada's PIPEDA, California's CCPA/CPRA and other US state laws, and Brazil's LGPD. When several regimes apply, we apply the one most favourable to you.
The data we collect
- Account: email address, password (stored only in hashed form that no one can read back), security settings such as two-factor authentication.
- Profile: photos, videos, audio, bio, location and travel areas, rates, role-specific details, availability, declared work preferences.
- Identity verification: a non-reversible biometric template, meaning a set of numbers computed from your face that cannot be used to rebuild it. The live capture is processed in memory and deleted immediately; only the encrypted template is kept. No photo of your face is kept for verification. This verification is never mandatory: a manual verification without biometrics is always offered. It will only be switched on after a privacy impact assessment and its prior declaration to Quebec's Commission d'accès à l'information, as required by the Act to establish a legal framework for information technology.
- Age verification: the result (above the threshold or not) and the level of check reached.
- Messages, references, castings, bookings and image releases signed on the platform.
- Payments: payments are handled by our payment providers. We never store your card number. We keep your subscription, invoice and refund history.
- Technical data: login logs, device, IP address, approximate country, security events.
- Cookies: according to your choices, see our Cookie Policy.
Why we use it and on what basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account, showing your profile, running messaging and search | Performance of the contract (the Terms of Service) |
| Identity verification using a biometric template | Your explicit, separate consent, collected before any capture; a manual, non-biometric check is offered |
| Age verification and enabling sensitive work categories | Legal obligation and explicit consent, timestamped for each category |
| Billing, taxes and refunds | Performance of the contract and accounting and tax obligations |
| Account security, fraud and abuse prevention | Legitimate interest in protecting members and the platform |
| Detecting and reporting illegal content | Legal obligation |
| Anonymous usage statistics | Your consent (analytics cookies) |
| Notifications and communications | Performance of the contract for essential messages; your preferences for the rest |
How long we keep it
Deletions are carried through to our backups according to our retention schedule.
| Data type | Retention | When you delete your account |
|---|---|---|
| Account and profile | While the account is active | Deleted |
| Media (photos, videos, audio) | As long as you keep them online | Deleted |
| Biometric template | Until its purpose is fulfilled, and no later than 3 years after your last interaction, whichever comes first | Destroyed, with a destruction record in our audit log |
| Image captured for verification | None: deleted immediately after the template is computed | Not applicable |
| Messages | While the account is active | Your link to the conversation is removed; content already exchanged may remain visible to the other person, without being re-attributable to you |
| Invoices and transactions | 7 years (accounting and tax obligations) | Kept for that period only, no longer linked to your deleted account |
| Security and login logs | 13 months | Deleted when the period ends |
| Reports and moderation decisions | 3 years after the decision | Kept, no longer linked to your deleted account |
| Data subject to a legal proceeding (legal hold) | For the duration of the proceeding | Kept despite the deletion request, for the proceeding only |
Our service providers
We rely on providers bound by contract, who may use your data only to provide their service to us.
| Provider | Role | Country (headquarters) |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Vercel | Website hosting and fast page delivery | United States |
| Stripe | Card payments, Apple Pay, Google Pay, tax calculation | United States |
| PayPal | Payment via a PayPal account (required for a subscription) | United States |
| NOWPayments | Cryptocurrency payments | Estonia / Netherlands |
| Cloudflare | Security, media delivery and detection of known illegal content | United States |
| Twilio | Text messages (two-factor authentication, security alerts, VIP perk) | United States |
| Resend | Sending emails | United States |
| Sentry | Technical error monitoring | United States |
| Identity and age verification provider | Live capture, fraud detection, age verification | Varies with the provider chosen |
| Known illegal content detection service (optional) | Hash matching against known illegal content databases, in addition to Cloudflare's filtering, if configured | Varies with the service chosen |
| Meilisearch (optional) | Profile search engine, only if enabled | France |
| Mux (optional) | Streaming video and audio transcoding, only if enabled | United States |
| Google / Apple | Sign in with your Google or Apple account | United States |
| Plausible or Umami | Privacy-friendly usage statistics, only if you accept them | Estonia (Plausible) or variable, Umami is self-hosted |
Transfers outside Québec and Canada
Some of our providers are based in or process data outside Québec and Canada, notably in the United States. As required by Québec's Law 25, we are telling you so explicitly.
Before any transfer, we assess the protection offered and cover the transfer by contract (for example the European Union's standard contractual clauses), with encryption in transit and at rest.
Location, profiling and artificial intelligence
We use no precise location technology and no advertising profiling. The only location signal is the approximate country derived from your IP address, used for your account security (new sign-in alerts) and legal compliance (geographic blocking). Your city is only visible if you add it to your profile yourself.
We do not sell your data, and we do not use your media or messages to train artificial intelligence models.
Your rights
- Access your data and get a copy.
- Have it corrected.
- Have it erased.
- Receive it in a readable format (portability).
- Withdraw your consent at any time, including for biometrics and cookies.
- Object to processing or ask for it to be restricted.
- Be informed of any decision based solely on automated processing (for example a verification result, the automatic suspension of an account matching known illegal content, or a suspicious message being blocked), know the information and main factors used, and submit your observations to a member of our team who can review the decision.
- Opt out of the sale or sharing of your data. We do not sell your data.
- Lodge a complaint with the competent authority, such as Québec's Commission d'accès à l'information, the Office of the Privacy Commissioner of Canada or your country's data protection authority.
How to exercise your rights
Most rights are self-service from your data management page: export your data, delete your account, view and change your consents.
You can also write to [email protected]. We answer within 15 days, for every member, whatever their country. We may verify your identity before answering, to protect your account.
Security
- Encryption of data in transit and at rest; stronger encryption for the biometric template.
- Two-factor authentication available to everyone, mandatory for staff.
- Access partitioning: each staff member can reach only what their task requires.
- No default access to private conversations or verification data. Any exceptional access requires a reason, is time-limited and is recorded in a log no one can alter.
- Login history visible to you, with one-click sign-out of all sessions.
If an incident occurs
Every incident involving personal information is recorded in our incident register. When it poses a risk to you, we notify you and the competent authority within the time required by law, explaining what happened and what you can do.
Minors
Castalio is for people aged 18 and over. If we learn that an account belongs to a minor, it is removed. Any content involving a minor is blocked, preserved as evidence and reported to the authorities. You can report such a case to [email protected].
Changes to this policy
If we change this policy, we notify you before significant changes take effect. The version history remains available, and the version you accepted is kept on record.