Effective Date: June 13, 2026 · Last Updated: June 13, 2026
AuraCast ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use AuraCast services, including the website, desktop application, Android application, Discord bot, and API.
By using AuraCast, you consent to the data practices described in this policy. If you do not agree, please discontinue use of AuraCast.
| Data | Source | Purpose |
|---|---|---|
| Discord user ID | Discord OAuth | Account identification |
| Discord username | Discord OAuth | Display name |
| Discord avatar | Discord OAuth | Profile display |
| Playlist data | You | Playlist feature |
| Soundboard content | You | Soundboard feature |
| Favorite stations | You | Personalization |
| Station ratings/reports | You | Station quality |
| Radio station submissions | You | Database expansion |
| Data | Purpose | Retention |
|---|---|---|
| IP address | Security, fraud prevention, session management | 90 days in logs |
| User agent (browser/app version) | Device identification, security alerts | Stored per session |
| Session tokens (hashed) | Authentication | 30 days or until revoked |
| Radio listening history | Feature functionality | 90 days |
| API request logs | Security, debugging | 30 days |
| Audit logs | Security, compliance | 1 year (append-only) |
We use collected information to:
We do not use your data for targeted advertising. We do not sell your personal data to third parties.
When you authenticate with Discord:
Discord's own Privacy Policy governs how Discord handles your data. AuraCast is not responsible for Discord's data practices.
All payment processing is handled by Stripe, Inc. AuraCast does not store payment card numbers, CVV codes, or bank account details.
We store:
For questions about payment data, refer to Stripe's Privacy Policy.
When you use radio features, we collect:
Radio stream URLs are delivered directly to your device. AuraCast does not record or store your audio listening sessions.
Content you create on AuraCast (playlists, soundboards, community messages) is stored on our servers. This content:
| Data Type | Retention Period |
|---|---|
| Account data (user profile) | Until account deletion + 30 days |
| Session tokens | 30 days or until revoked |
| Listening history | 90 days rolling |
| Favorites, playlists, soundboards | Until deleted or account deletion |
| Audit logs | 1 year (legally required for security) |
| Access logs (IP addresses) | 30–90 days |
| Billing records | 7 years (tax and legal compliance) |
| DMCA records | 3 years minimum |
| Database backups | 14 days (encrypted, then deleted) |
| Community chat messages | Until deleted or account deletion |
After account deletion, personal data is purged within 30 days except where retention is required by law (billing records, audit logs). Anonymized aggregate data may be retained indefinitely.
We implement industry-standard security measures to protect your data:
No security system is infallible. If you discover a security vulnerability, please contact security@jsglow.name before public disclosure.
In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law within legally mandated timeframes.
You can access your account information through the AuraCast app at any time.
To correct inaccurate data, update your Discord profile (which syncs to AuraCast on next login) or contact support.
You can delete your account through AuraCast settings. We will delete your personal data within 30 days, subject to legal retention requirements. To request deletion, you may also email support@jsglow.name.
You may request a copy of your data by contacting support@jsglow.name. We will respond within 30 days.
Security-related Discord DM notifications for the account owner cannot be disabled as they are essential for account security. Other communications may be managed in account settings.
You can view and revoke active sessions through the AuraCast security settings in the desktop app.
AuraCast is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected information from a child under 13, we will promptly delete it.
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact support@jsglow.name.
Users between 13 and 18 must have parental consent to use AuraCast.
AuraCast is operated from servers in the United States. If you access AuraCast from outside the United States, your information may be transferred to and processed in the United States, which may have different data protection laws than your country.
By using AuraCast, you consent to this transfer. We take steps to ensure that transferred data is protected under appropriate safeguards.
California residents have specific rights under the California Consumer Privacy Act (CCPA):
To exercise these rights, contact support@jsglow.name with the subject "California Privacy Request." We will verify your identity before processing requests.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) or equivalent laws:
Legal Basis for Processing:
To exercise GDPR rights, contact support@jsglow.name. You also have the right to lodge a complaint with your local data protection authority.
When the AuraCast Discord bot is added to a server:
For users interacting with the bot, your Discord user ID is used to check your AuraCast account and premium status. No additional personal data is collected through bot interactions beyond what you provide through account creation.
We may update this Privacy Policy periodically. We will notify you of material changes by posting a notice on the AuraCast website or through the application. The "Last Updated" date at the top of this policy indicates when it was last revised.
Continued use of AuraCast after updates constitutes acceptance of the revised policy.
For privacy-related questions, requests, or concerns:
Email: support@jsglow.name
General Support: support@jsglow.name
Security: security@jsglow.name
We will respond to privacy requests within 30 days. For GDPR requests, we aim to respond within the legally required 30-day window, with the possibility of a 60-day extension for complex requests.