Legal
Last updated: 1 June 2026
Sanctcast ("we", "us", "our") is a free social media scheduling and management platform built for churches. We are operated as a community-supported project. If you have questions about this policy, contact us at privacy@sanctcast.app.
When you sign up, we collect your name and email address. If you create a password account, your password is stored as a salted bcrypt hash - we never store or log the plain-text password. If you sign in with Google, we receive your name and email address from Google and store no password at all. If you enable two-factor authentication, your authenticator secret is stored encrypted with AES-256-GCM.
Church name, address, website, and team member details you enter in the Settings section. Team member email addresses are used only for internal team management and are not shared with third parties.
When you connect a social media account (Facebook, Instagram, YouTube, TikTok, X/Twitter), we receive and store an OAuth access token. All tokens are encrypted at rest using AES-256-GCM encryption before being written to our database. Tokens are never accessible to other users, never logged, and never transmitted in any response to your browser.
Posts you create, schedule, and publish through Sanctcast - including text, images, and videos - are stored in our database to enable scheduling and team review workflows. Approved posts are transmitted to the relevant social media platform at publish time.
We maintain an audit log of significant actions (post approvals, rejections, platform connections) for security and accountability purposes. Logs include the actor's user ID, role, action type, and IP address. Logs are retained for 12 months.
We do not use your data for advertising. We do not sell your data to any third party. We do not train AI models on your church's content.
Sanctcast uses the following sub-processors:
| Service | Purpose | Data shared |
|---|---|---|
| Neon (Postgres) | Database | All app data (tokens encrypted at rest) |
| Cloudflare R2 | Media file storage | Images and videos you upload for posts |
| Vercel | Hosting & CDN | Request logs, IP addresses |
| Resend | Transactional email | Email address, notification content |
| Optional "Sign in with Google" | Email, name (only if you use it) | |
| Anthropic | AI post generation (optional) | Post text you choose to generate |
| Meta (Facebook/Instagram) | Publishing posts | Post content, access token used server-side |
| Google (YouTube) | Publishing videos | Video content, access token used server-side |
| TikTok | Publishing short videos | Video content, access token used server-side |
| X Corp (Twitter) | Publishing tweets | Post text, access token used server-side |
If you are based in the UK or European Union, you have the following rights:
To exercise any of these rights, email privacy@sanctcast.app. We will respond within 30 days.
We use the following cookies:
We do not use tracking, advertising, or analytics cookies.
We take security seriously. Key measures include:
We may update this policy as the product evolves. We will notify you of material changes by email and by posting a notice in the app at least 14 days before they take effect. The date at the top of this page always shows the most recent version.
Questions or complaints: privacy@sanctcast.app
If you are unhappy with our response, you may contact the Information Commissioner's Office (ICO) in the UK.