Handcast Privacy Policy
Handcast records first-person video of everyday manual tasks so that it can be used as training data for robotics and machine learning. This policy explains exactly what the app collects, where it goes, and how to get it deleted.
What we collect
- Your account: email address and, if you give one, a display name. Signing in with Apple or Google gives us the identifier that provider issues, plus the email they share. Passwords are stored only as a salted scrypt hash, never in readable form.
- Your recordings: the video you record, the motion-sensor readings captured alongside it, and a metadata file describing the camera (resolution, lens geometry, orientation) and the phone (brand, model, OS version).
- Recording context you provide: the task you chose, your height, and the kind of place you are recording in, because the footage is only useful with that context.
- Location: when you allow it, the approximate coordinates where a recording was made are written into that recording's metadata. Decline, and recordings are stored without it.
- Account activity: sign-ins, sign-in failures, uploads and administrative actions, with the IP address and browser or device the request came from. This is a security log.
Where it is stored
Video, motion and metadata files are stored in Cloudflare R2 object storage. Accounts and recording records are stored in a MongoDB database hosted on Railway. Files are uploaded straight from your device to storage over an encrypted connection using short-lived signed links, so they are never handled by a third-party intermediary.
Who can see it
- You. Your recordings are private to your account.
- Administrators of this deployment, who can see accounts, recordings and the activity log in order to run the service.
- Shift (micro-agi), but only for a recording you explicitly choose to send there. That upload happens on request, never automatically, and only if you have linked your own Shift account. Once a recording reaches Shift it is governed by Shift's own terms.
- Your team, if you have one. A team is the recruiter or agency that brought you to Handcast: you join it with its team code, or we add you to the team that recruited you. The people running your team see your name and email, when you joined, and for each recording its date, length, task and phone model, along with Shift's decision on it and the reason Shift gives. They never see your video, motion data, location or metadata files, and they only ever see their own team. To leave a team, write to us at the address below.
How long it is kept
Recordings are kept until you delete them or delete your account. Security log entries are kept while the account exists.
Deleting your data
You can delete your account from inside the app: Settings → Delete account. That removes your account, your recordings' video, motion and metadata files from storage, any Shift account link, and your activity log. It cannot be undone, and we cannot recover it afterwards.
A recording already sent to Shift lives in Shift's systems too; deleting here does not remove it from there. Ask Shift directly for that.
To ask for deletion without using the app, email the address below from your account's email.
Permissions the app asks for
- Camera — to record the video. Used only while a recording screen is open.
- Motion — to capture the motion-sensor stream that accompanies the video.
- Location, while using the app — optional, to tag a recording with where it happened.
Children
Handcast is not intended for children, and accounts are not knowingly created for anyone under 16.
Changes
If this policy changes, the date at the top changes with it. Material changes will be announced in the app.
Contact
Questions, or a data request: alxashraf0@gmail.com.