LEGAL

Privacy Policy

Last updated: March 1, 2026

Overview

Cast Laboratories Inc. ("Cast Labs," "we," "us") operates the CastOS platform. This Privacy Policy describes how we collect, use, and protect your information when you use our services.

Information We Collect

Account information

When you create an account, we collect your name, email address, company name, and role. Authentication is handled by a trusted third-party identity provider.

Manufacturing data

Data you enter into CastOS - jobs, estimates, production records, quality inspections, inventory, documents, and related business information. This data belongs to you.

Usage data

We collect standard usage analytics to improve the product: pages visited, features used, and performance metrics.

How We Use Your Information

  • To provide and maintain the CastOS platform
  • To process AI-assisted features within the platform
  • To communicate product updates and support
  • To improve the platform based on usage patterns
  • To comply with legal obligations

AI Data Handling

CastOS uses AI to power features like drawing takeoff, scheduling suggestions, and inspection pre-fill. When AI processes your data:

  • Your data is sent to AI providers solely to deliver results within CastOS
  • AI providers are contractually prohibited from using your data for model training
  • We do not use your manufacturing data to train any AI models
  • AI processing results are stored within your organization-scoped account

Data Sharing

We do not sell your data. We do not share your data with third parties for their marketing purposes. We share data only with service providers necessary to operate the platform:

  • Authentication and identity management
  • Database hosting and storage
  • File storage and content delivery
  • Application hosting and analytics
  • AI processing (your data is never used for model training)

Each provider processes data only as needed to deliver their service and is bound by their own privacy commitments.

Data Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Database access requires authenticated connections over SSL. Application access is controlled through role-based permissions scoped to your organization. Every data mutation is logged in an audit trail.

Data Retention and Deletion

We retain your data for as long as your account is active. You can request export or deletion of your data at any time by contacting us. Upon account termination, we delete your data within 30 days, except where retention is required by law.

Your Rights

You have the right to:

  • Access the data we hold about you and your organization
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a standard format
  • Withdraw consent for optional data processing

Cookies

We use essential cookies for authentication and session management. We collect anonymous usage metrics to improve the product. We do not use advertising cookies or third-party tracking.

Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email or through the platform. Continued use after changes constitutes acceptance of the updated policy.

Contact

For privacy-related questions or requests, contact us at privacy@castlabs.ai.