PilotCast
AI Host Engine & Personal AI
Privacy Policy
Last updated: March 16, 2026
1. Who We Are
PilotCast.ai is operated by A Prompt PC ("we," "us," "our"). We provide AI-powered host agents for businesses and personal AI companions for individuals.
Contact: Kyle@PilotCast.ai
2. What Data We Collect
Account Information
- Email address — provided during signup or checkout
- Name or agent name — what you name your AI
- Personality preferences — tone, interests, and traits you select during setup
- Billing information — processed and stored by Stripe (we never see or store your card number)
Conversation Data
- Chat messages — text you send to your AI and the AI's responses
- Session metadata — session ID, timestamp, source (app, web, YouTube chat)
- Sentiment analysis — mood classification derived from conversations (positive, neutral, negative, concerned, excited). This is extracted by the AI during normal response generation at zero additional cost — no separate analysis service is used
Voice Data
- Speech-to-text input — if you use voice input, your speech is processed by your device's built-in speech recognition (Apple/Google). PilotCast receives only the transcribed text, not the raw audio
- Text-to-speech output — we generate audio of your AI's responses using edge-tts (Microsoft) or ElevenLabs. No voice data from you is stored
Device & Usage Data
- Visit logs — timestamp, page mode (embed, standalone, showcase), referrer domain, and coarse device type (mobile/desktop). No device fingerprinting, no cross-site tracking
- Server & security logs — like virtually all web services, our servers record the IP address and browser type of each request in operational logs, used only for security, abuse prevention, and debugging. These logs are never used for advertising or profiling and are purged on a rolling 90-day basis (see Data Retention)
- Push notification tokens — Expo push token for delivering notifications to your device (stored per-agent, max 5 devices)
- Feature usage metrics — LLM call counts, TTS character counts, costs — used for billing and analytics dashboards
Uploaded Content
- Avatar images — photos you upload during setup
- Voice samples — audio files uploaded for voice cloning (Enterprise tier only, processed manually)
Shared Tracking Pages (logistics clients)
Drivers on logistics fleets can share time-limited, read-only tracking links with freight brokers. These pages show only the fields the fleet's configuration allows (location, status) — never conversations or personal data. Links expire automatically (14 days by default), can be revoked at any time, and every access is logged (IP address, browser, time) so the fleet owner can audit who viewed their data.
3. How We Use Your Data
- Provide the service — power your AI's conversations, memory, personality, and voice
- Conversation memory — your AI remembers past conversations to provide continuity and personal insights (topics, goals, mood patterns)
- Billing — meter AI usage (LLM + TTS) and report to Stripe for subscription billing
- Analytics & insights — generate your personal dashboard (topics, goals, mood journal, weekly digest)
- Service improvement — diagnose errors, monitor performance, improve the platform
- Communications — send confirmation emails, welcome emails, weekly digests, billing notifications, and milestone celebrations
We do not use your conversations to train AI models. We do not sell your data. We do not serve ads.
4. Third-Party Services
We share data only with services required to operate PilotCast:
- Stripe — payment processing. Stripe receives your email and payment method. Stripe's privacy policy
- OpenRouter — AI model provider. Your chat messages are sent to language models (Meta Llama, Anthropic Claude, and similar) for response generation. Messages are not used for model training per OpenRouter's data policy. OpenRouter's privacy policy
- Microsoft — email delivery (welcome, digest, and billing emails are sent through Microsoft's mail service) and free-tier text-to-speech (Edge TTS)
- ElevenLabs — premium text-to-speech generation. Your AI's script text is sent for audio generation. No user messages are sent — only the AI's response text
- Discord — internal operational alerts to our own team channels (service health, billing events). Your conversation content is not sent to Discord
- Expo — push notification delivery for the mobile app. Expo receives your device push token. Expo's privacy policy
- Hetzner — server infrastructure (Germany). All data is stored on our Hetzner servers
We do not share data with advertisers, data brokers, or any other third parties.
5. Personal Information Protection
PilotCast automatically detects personal information in chat messages using pattern matching:
- Detected types: email addresses, phone numbers, credit card numbers, Social Security numbers, physical addresses
- What happens: messages containing personal information are automatically marked private — they are never displayed in public chat feeds, regardless of the user's visibility setting
- Both directions: we scan both your messages AND the AI's responses for personal information
- No false-negative risk: a second scan occurs when building the chat feed as a safety net
Business-tier lead capture: when you voluntarily share your email with a business agent, the account holder may see your email for follow-up purposes. This is clearly indicated in the chat experience.
6. Data Storage & Security
- Location: all data is stored on our servers hosted by Hetzner in Germany
- Encryption: all connections use HTTPS/TLS. Streaming credentials and API keys are stored in access-restricted environment files on our servers, never in code, configuration files, or repositories
- Access: only the platform operator (Kyle Burns) has server access. No employees, no contractors, no automated data mining
- Atomic writes: all data file updates use atomic write patterns (write to temp file, then replace) to prevent data corruption
- Backups: daily backups with 7-day rolling retention
- Incident response: if we confirm a data breach affecting your personal information, we will notify affected account holders by email without undue delay, and within 72 hours where required by law
7. Data Retention
- Active subscription: data is retained for the life of your subscription
- After cancellation: your data is retained (not automatically deleted) so your account can be reactivated without losing your configuration, history, or leads. If you want your data permanently removed, request deletion (see Your Rights below) — that is honored within 30 days regardless of subscription status
- TTS audio cache: generated speech audio is cached for performance (up to 30 days for paid voices, 6 hours for free voices), then automatically purged
- Visit logs: anonymized, retained indefinitely for aggregate statistics
- Server & security logs: purged on a rolling 90-day basis (includes tracking-link access logs)
8. Your Rights
You have the right to:
- Access — request a copy of all data we hold about you
- Correction — update or correct your account information
- Deletion — request deletion of your account and all associated data. Honored within 30 days
- Export — export your conversation history (Pro+ business tiers and Personal Pro, or on request)
- Opt out of communications — unsubscribe from weekly digest emails via your dashboard or settings
- Withdraw consent — stop using the service at any time by cancelling your subscription
To exercise any of these rights, email Kyle@PilotCast.ai.
9. Children's Privacy
PilotCast is not intended for users under 18 years of age. We do not knowingly collect data from minors. If we learn that a user is under 18, we will terminate the account and delete all associated data promptly.
10. Cookies & Tracking
- PilotCast uses no third-party tracking cookies, no Google Analytics, no Facebook Pixel
- We use sessionStorage and localStorage in your browser for session management, audio preferences, and UI state — these never leave your device
- We use Plausible Analytics (privacy-first, cookie-free, GDPR compliant) for anonymous page view statistics on our marketing and agent pages
- The mobile app uses SecureStore (encrypted device storage) for authentication tokens
11. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available at pilotcast.ai/privacy.
- Material changes will be communicated with at least 30 days notice via email
- Continued use of the service after changes constitutes acceptance
12. Contact
Questions about this privacy policy or your data?
Email: Kyle@PilotCast.ai
Web: pilotcast.ai
Operated by: A Prompt PC
Location: Georgia, United States