The short version
Star in Your Car ("we", "us", "the app") is a self-tape audition platform for actors. We collect the information needed to run the service — your account, your tapes, and the ratings on them — and nothing more. We don't sell your data. You can delete your account from inside the app at any time.
What we collect
When you create an account, we collect:
- Email address — used to log you in and contact you about your account.
- Password — stored only as a one-way bcrypt hash. We never see your plaintext password.
- Display name (optional) — shown to other users alongside your submissions and ratings.
- Account role — actor, public rater, or casting professional.
When you use the app, we also collect:
- Self-tape videos — uploaded directly from your device to our cloud storage. Videos are tied to your account and visible to other users on the platform.
- Submission metadata — title, notes, the casting call (if any), and a timestamp.
- Ratings and comments — the star rating and optional text feedback you give on others' submissions, and what others give on yours.
- Casting calls you create as a casting professional.
We do not collect your contacts, location, advertising identifier, browsing history, or device sensor data.
How we use it
- To authenticate you and keep your session secure.
- To show your tapes to other users so they can rate them, and to show you tapes from others so you can rate them.
- To display ratings and comments on submissions.
- To respond to support requests you send us.
- To detect and prevent abuse of the platform.
Where your data lives
- Account data and metadata live in a managed PostgreSQL database hosted by Xata in the EU (eu-central-1).
- Video files live in DigitalOcean Spaces (region sfo3, US). Object names are random UUIDs so they cannot be guessed from the outside.
- Authentication tokens on your device are stored in the iOS Keychain.
Who can see your tapes
Tapes you submit are visible to other authenticated users of Star in Your Car for rating purposes. Casting professionals you tape for can also view tapes submitted to their calls. Tapes are not made public on the open internet — playback URLs are short-lived signed links generated only for authenticated requests.
Rights to submitted content
By submitting a tape, you grant Star in Your Car a non-exclusive, worldwide license to host, display, transmit, and use that tape for the purpose of operating the platform — including showing it to raters and casting professionals. You retain ownership of your performance. Full terms are in our Terms of Service.
Sharing with third parties
We share data only with the infrastructure providers we need to run the service:
- Xata — managed PostgreSQL hosting.
- DigitalOcean — video file storage.
- Cloudflare — DNS and CDN for our website and API endpoints.
- Apple — for App Store distribution and push notifications, if you opt in.
We do not sell, rent, or trade your personal data. We do not share data with advertisers or analytics brokers.
Deleting your account
You can permanently delete your account from inside the app: Me → Delete account. This removes your profile, submissions, ratings, and any casting calls you posted. Deletions are immediate and irreversible. If you'd prefer to delete by email, write to [email protected] from the address on your account.
Data retention
We retain your data for as long as your account is active. When you delete your account, all associated data is removed from the database and from object storage. Routine backups may briefly retain copies for up to 30 days before being aged out.
Security
Passwords are hashed with bcrypt before storage. All traffic between the app and our servers uses HTTPS. Video uploads go directly from your device to cloud storage over signed URLs — our servers never proxy the bytes. Authentication uses short-lived JWT access tokens with refresh tokens stored in your device's Keychain.
Children
Star in Your Car is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has registered, contact us and we will delete the account.
Your rights (EU / UK / California)
You have the right to access, correct, export, or delete your personal data. The fastest way to exercise any of these rights is to use the in-app delete button or email [email protected]. We will respond within 30 days.
Changes to this policy
If we change this policy materially, we will notify you in the app or by email before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
Contact
Questions about this policy? Email [email protected].