Privacy Policy
What personal data MAWCast handles, why, for how long, who receives it, and the rights you have over it.
This is the drafted text, published here for review. It describes what MAWCast does with personal data today, but it is not yet the notice the law asks for: 7 details are still blank — among them who the controller is and where they can be reached — and the document has not been reviewed by privacy counsel, which its own manifest requires before publication.
Version: 1.1-draft Last updated: [DATE] Effective: [DATE]
1. Who we are
MAWCast is operated by [OPERATOR NAME], [SERVICE ADDRESS] ("MAWCast", "we"). For the personal data described in sections 3, 5 and 6 we are the controller.
For anything about your data, write to contact@mawcast.com. It is the only address, for privacy as for everything else, and a person reads it.
This policy goes with the Terms of Service. The Terms say what the service is and who is responsible for what; this document says what happens to personal data.
2. Two roles, kept apart
MAWCast holds personal data in two different capacities, and they work differently.
- About you, our customer. Your account, sign-in, subscription, security, support and use of MAW Assistant. We decide why and how, so we answer for it. That is sections 3 and 5 to 11.
- About the people around your station. Your listeners and the guest DJs you invite. You decide to run and publish the station and whom to let broadcast on it, so you are the controller and we are your processor, as section 11 of the Terms sets out. That is section 4.
3. What we collect about you, and why
3.1 Your account and your stations
Your email address, your name, a profile picture if you upload one or sign in with a provider that has one, a password hash if you set a password (never the password itself), your language, your account ID, and the dates your account was created and last used.
What you put into MAWCast: your stations and their settings, time zone, descriptions and images, schedule, playlists, the audio and artwork you upload, and the history of your broadcasts.
Why: to give you an account and run the service.
Legal basis: contract, Art. 6(1)(b) GDPR. An email address is required to hold an account; without it we cannot provide one. Everything else in this section is yours to give or leave out.
3.2 Signing in with Google or Discord
If you choose to, the identifier, email address, name and picture address that Google or Discord send us, and the sign-in tokens they issue, stored encrypted. If you connect Discord to add MAW Assistant to a server, Discord also shows us the list of your servers, so that you can choose one.
Why: to let you sign in with that account and use the Discord features.
Legal basis: contract, Art. 6(1)(b). Google and Discord are independent controllers of your account with them; their own policies apply.
3.3 Security
Your sessions: when each started and was last used, how you signed in, and the browser identification string your browser sent (for MAWCast Studio, the app version and the name you gave the device). We do not store an IP address with a session. Sessions end after 30 days without use.
Your multi-factor authentication (MFA) set-up: the secret is encrypted and the recovery codes are stored only as hashes. The one-time codes and links we send you are stored only as hashes and expire within 30 minutes.
To stop password guessing and abuse, the server counts requests per IP address in its memory for a few minutes. Those counters are never written to disk.
Why: to keep your account yours and to show you where you are signed in.
Legal basis: contract, Art. 6(1)(b), and legitimate interests in security, Art. 6(1)(f).
3.4 Subscription and billing
Your plan, its status and dates, and the trial.
MAWCast takes no card payments today and holds no card data, billing address or tax number. No payment provider is connected yet. When one is, it will hold the card, we will keep a reference and the record of each payment, and this policy will name the provider before the first charge.
Why: to provide the plan you chose and, once payments exist, to take payment and meet our accounting duties.
Legal basis: contract, Art. 6(1)(b); legal obligation for invoices, Art. 6(1)(c).
3.5 One free trial per card
Not collected today. When trials that ask for a card open, we will keep a SHA-256 hash of a fingerprint of that card, supplied by the payment provider, with the ID of the account that used it. It cannot be turned back into the card. How long it is kept will be stated here before that happens.
Why: so the free trial is used once, not once per new account.
Legal basis: legitimate interests, Art. 6(1)(f).
3.6 Emails we send you
Emails about your account, security and billing only: a welcome message, verification codes, password resets, changes of email address or password, security alerts, confirmation that your account was deleted, receipts and billing notices. We keep a delivery log (recipient, type, delivery status and date; never the content) so we can tell you whether a message reached you and stop writing to an address that bounces or complains.
Why: to run the account and prove what we sent.
Legal basis: contract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f). We send no marketing email. Station alerts go to Discord, never to email.
3.7 MAW Assistant on Discord
MAW Assistant is a Discord bot. It reads the direct messages you send it and the commands and buttons you use; it does not read the conversations of a Discord server.
- Your Discord account. Your Discord user ID, with the language, time zone, station and notification choices you make in the Assistant, and a log of which notices it sent you.
- Your Discord server, if you add the Assistant to one: the server's ID and name, the channels and roles you choose for notices, and the Discord ID of the person who added it.
- Your messages. No transcript of your conversations is kept. The last three messages stay in the Assistant's memory for five minutes so it can follow the conversation. When a message about MAWCast is kept so the Assistant can learn how people phrase things, it is first stripped of passwords, keys, tokens, email addresses, web addresses, IP addresses, phone numbers and long numbers, and it is stored under a keyed code instead of your Discord or account ID. That text is deleted after 30 days. A second form of it, in which the names of your stations, shows, playlists and guests are also replaced by placeholders, is kept with the record for up to 365 days, and for longer only where it is an example behind a phrasing rule the Assistant has learned. Names you type that the Assistant does not recognise as yours are not removed.
- Answers that need AI. Most questions are answered by the Assistant itself. When it cannot, and your plan includes AI answers, it sends the stripped message to an AI provider (section 7) together with the date, your workspace's time zone and the number of stations you have. It does not send your Discord ID, your username, your email address, the names of your stations or the earlier conversation, and it never sends images or attachments.
- Security. Requests that look like attempts to extract secrets or misuse the Assistant are logged: the time, the keyed code, the kind of request and a risk score. The text is not stored. Section 10 explains the automatic pause this can cause.
We do not use your conversations to train AI models.
Legal basis: contract, Art. 6(1)(b); legitimate interests in security and in improving the Assistant's answers, Art. 6(1)(f).
3.8 Counting visits to our public website
For the public pages of mawcast.com (the home page and the documentation), one counter per day, per page and per kind of site the visit came from: search engine, AI assistant, social network, another site, a campaign link, or none.
What is not collected: no IP address, no identifier, no browser or device details, no cookie, nothing stored in your browser. The counter cannot tell one visitor from another. If your browser sends Do Not Track or Global Privacy Control, the visit is not counted at all. Pages inside your account are never counted.
Why: to know which pages are useful and which kinds of sites bring visitors.
Legal basis: legitimate interests, Art. 6(1)(f). The counts are aggregate and identify no one.
3.9 Where a new account came from
When you create an account, we note the visit that led to it: the name of the site that linked to us (for example google.com, never the full address), the kind of site, the first page you opened, and campaign tags (utm_*) if the link carried them. We also note how you signed up (password, Google or Discord) and the date you reached a few steps: created the account, created a station, first went on air, started a trial, first paid. No IP address or device data is kept with these.
While you browse before signing up, this is held in the page's memory only, never in a cookie or in browser storage.
Why: to know which channels bring people who actually use and pay for MAWCast.
Legal basis: legitimate interests, Art. 6(1)(f). You can object at any time (section 10); it is deleted with your account.
3.10 Broadcast credentials
The source passwords of your stations and the credentials of the guest DJs you invite, stored encrypted and apart from the rest of your data.
Why: to let you, and only the people you choose, broadcast to your station.
Legal basis: contract, Art. 6(1)(b).
3.11 Writing to us
If you write to contact@mawcast.com, we keep your message and our answer for as long as the matter needs.
Legal basis: contract or steps before a contract, Art. 6(1)(b), and legitimate interests in answering, Art. 6(1)(f).
4. Your listeners and your guest DJs: we are your processor
A public station involves people who are not our customers. We handle their data on your instructions and for your station only.
Listeners. To deliver the stream, the streaming server has to receive each listener's connection. MAWCast's audience figures are counts, not people: how many listeners are connected at a time, the highest number each day, how many connections there were and how long they lasted in total, and the same figures for each broadcast. We keep no list of listeners.
Where listeners connect from. So that a station can see which countries and cities its audience is in, the IP address of a listener's connection is looked up in a geolocation database while the listener is connected. The lookup happens in the server's memory: the address is turned into a country and, where the database knows them, a region, a city and that city's approximate position, and is then discarded. The address is not written to our databases, and neither is anything derived from it that could identify a listener: no hash, no identifier. What is kept is a count per country and per city, for each broadcast and for each day.
The player's identification string (its User-Agent) is treated the same way: it is reduced to a family of browser, device and operating system, counted, and not kept.
Because nothing kept identifies a listener, MAWCast cannot tell whether two connections came from the same person, and it does not report "unique" or "returning" listeners.
The geolocation database is DB-IP's "IP to City Lite" (IP Geolocation by DB-IP). It is a file on our own server: no listener data is sent to DB-IP, or to anyone else, to work out a location.
The streaming server itself keeps a technical access log, as web servers do: for each connection, the IP address, the time and length of the connection, the player's identification string and the page it came from. We use it only to operate and secure the streaming service, not to build audience figures, and it is kept for [STREAM LOG RETENTION].
Station pages and the web player set no cookies. Station pages have no chat today. If a station offers one, the nickname and message a listener sends are kept with the station, the most recent 500 only, and no IP address is stored with them.
Guest DJs. When you invite a DJ who has no MAWCast account, we keep the name they give (it is shown to you and in your station's notices), the times they connect, a record of what was done with their access and by whom, and their broadcast credentials, encrypted. We ask a guest for no email address and store no IP address for them.
For all of this:
- You are the controller. You need a lawful basis for it, you tell your listeners and your guests, and you answer their requests.
- We help you as Article 28 GDPR requires, on the terms of section 11 of the Terms of Service.
- Listeners and guests: a request about your data on a station goes to that station. If you write to us, we pass it on to the station and help it answer.
5. Cookies and browser storage
We use only what the service needs to work. No advertising cookies, no analytics cookies, no tracking scripts. That is why there is no consent banner.
| Name | Kind | What it does | How long |
|---|---|---|---|
maw_session | Cookie | Keeps you signed in | 30 days after you last used MAWCast, or until you sign out |
maw_pending | Cookie | Holds a sign-in half done while you enter an MFA code | 10 minutes |
mawcast_admin | Cookie | Keeps MAWCast staff signed in to the administration console. Never set for customers | 8 hours |
mc-language | Browser storage | Remembers the language you chose | Until you clear it |
mawcast-docs-lang | Browser storage | Remembers the language you read the documentation in | Until you clear it |
mawcast-docs-theme | Browser storage | Remembers light or dark mode in the documentation | Until you clear it |
mc-rail | Browser storage | Remembers whether Control's side menu is collapsed | Until you clear it |
mc-after-sign-in | Browser storage, this tab only | Takes you back to where you were after signing in, for example to connect MAWCast Studio | Until you close the tab |
mc-guest-onboarding | Browser storage, this tab only | Keeps a guest DJ's invitation open while they set up | 30 minutes, or until the tab is closed |
The administration console also remembers two layout choices of MAWCast staff in their own browser.
Two things your browser fetches from someone else. The typefaces of mawcast.com are loaded from Google Fonts, so your browser contacts Google's servers and Google receives your IP address as it would for any web request; no cookie is set by it. And if your profile picture, or the icon of a Discord server, comes from Google or Discord, your browser loads that image from them.
6. What our own servers log
The web server in front of MAWCast keeps no log of the pages you request, and the application does not write IP addresses or email addresses to its logs. The exception is the streaming server's access log described in section 4.
Authorised MAWCast staff can see your account's email address, name, dates and plan, and your stations, when they operate the service or answer you. What staff do in the administration console is recorded in an audit log.
7. Who else receives your data
We do not sell your data and do not share it for advertising. It reaches others only where the service needs it:
| Who | What for | Role |
|---|---|---|
| Contabo | The server MAWCast runs on, and the object storage that holds a copy of uploaded files and of backups | Our processor |
| Resend | Sending account, security and billing email: your address and the message | Our processor |
| Google (Gemini API) | Answering the questions MAW Assistant cannot answer itself: the stripped message described in section 3.7 | Our processor |
| Discord | The platform MAW Assistant works on: your messages to it, its answers, and the notices it posts where you asked for them. Also sign-in, if you use it | Independent controller |
| Sign-in, if you use it; and the typefaces of the site (section 5) | Independent controller | |
| Authorities | Only where the law obliges us, and only what it obliges | — |
Notices that MAW Assistant posts in your Discord server are visible to that server's members, and can include the station's name, listener numbers and the name of whoever is on air.
No payment provider receives anything today (section 3.4).
8. Transfers outside the European Economic Area
MAWCast's server and object storage are in the European Union. Resend, Discord and Google may process data outside the EEA, in particular in the United States. Where they do, the transfer is protected by [TRANSFER SAFEGUARD]. Write to us for a copy of the safeguard that applies.
9. How long we keep it
| Data | Kept |
|---|---|
| Your account, sign-in methods, sessions and MFA set-up (3.1 to 3.3), the signup source (3.9) and broadcast credentials (3.10) | While your account exists. Deleted when you delete it. A session is deleted 30 days after it was last used |
| Uploaded audio after a paid subscription ends | 14 days after the renewal date (or the day it ended, if it ended early), then deleted |
| Uploaded audio after a trial ends | 5 days after the trial ends, then deleted |
| Stations, schedule, broadcast history and audience counts | While your account exists |
| Guest DJs: name, connection times and access record | While your account exists |
| Invoices and payment records, once payments exist | [INVOICE RETENTION], as tax law requires, even after the account is deleted |
| Email delivery log (3.6) | 12 months, then the address is removed, also when the account was deleted earlier. A complaint ("this is spam") is kept, so that address is never mailed again |
| Discord server links (3.7) | While your account exists |
| Assistant settings kept under your Discord ID (3.7) | Until you ask us to delete them; the log of notices sent, 30 days |
| Assistant learning records (3.7) | Stripped text 30 days; the form with names replaced and its record up to 365 days; examples behind a learned phrasing rule, while the rule is in use |
| Assistant security events (3.7) and the staff audit log (6) | [SECURITY LOG RETENTION] |
| Streaming server access log (4) | [STREAM LOG RETENTION] |
| Error messages of the server | 14 days |
| Visit counts (3.8) | Aggregate, identify no one |
| Backups | 14 days. Data you delete can remain in backups until they expire |
10. Your rights
You can, at any time:
- Get a copy of your data. Account → Your data → Export your data gives your stations, schedule, playlists, broadcast history and settings as a file. Your audio is downloaded as the original files from Media → Download. For anything else we hold about you, write to us.
- Correct it. Most of it you can edit yourself in Account.
- Delete your account. Account → Your data → Delete account. It deletes your account, sign-in methods and sessions, your stations and their credentials, broadcast history, uploaded audio and images, guest DJs, Discord server links and the information in section 3.9, at once. What outlives it is what section 9 lists: the email delivery log for up to 12 months, payment records where the law requires them, the staff audit log, the Assistant's settings under your Discord ID, which we delete when you ask, its learning and security records, which carry a code instead of your identity, and backups until they expire. An account with a subscription that would renew has to cancel it first.
- Object to what we do on legitimate interests (sections 3.3, 3.5 to 3.9).
- Restrict processing, or take your data to another service.
- Withdraw consent, where we rely on it. Today nothing in this policy does.
Write to contact@mawcast.com for any of these. We answer within one month. We may ask you to prove the account is yours, and we will not charge you.
If you think we have got it wrong, you can complain to a data protection authority, in Spain the Agencia Española de Protección de Datos (aepd.es), or the one where you live. We would rather you told us first.
Automated decisions. MAWCast makes no automated decisions with legal or similarly significant effects on you. One thing does happen without a person: if many requests in a short time look like attempts to misuse MAW Assistant, it stops giving AI answers and making changes for that Discord user for 60 minutes. Your account, your subscription and Control are not affected, and a person at MAWCast can lift it; write to us if it happens to you by mistake.
11. How we protect it
Passwords are stored as hashes, never in readable form. Broadcast credentials, sign-in tokens and MFA secrets are encrypted. Multi-factor authentication is available for every account and applies to Google and Discord sign-in as well. Connections to mawcast.com are encrypted. MAWCast runs on its own server under an account without administrator rights. Uploaded files are deleted on the schedule in section 9 by an automated job.
12. Age
MAWCast accounts are for people aged 16 or older. If you believe a younger person has given us their data, write to us and we will delete it.
13. Changes
When this policy changes in a way that matters, we tell account holders by email before the change takes effect. The date at the top shows the current version.
14. Contact
| Purpose | Contact |
|---|---|
| Privacy, and everything else | contact@mawcast.com |
Controller: [OPERATOR NAME], [SERVICE ADDRESS].
Still need help? Write to contact@mawcast.com.
