This Privacy Policy explains how Mincast processes personal data when you use the website mincast.ai, the application mincast.app, Mincast mobile applications and related services.
The Czech version of these legal texts is legally authoritative. This English translation keeps the same article numbers, defined terms, and structure.
1. Data controller
The controller of personal data is:
Tomáš Pukowiec
Dětmarovice 368
735 71 Dětmarovice
Czech Republic
Company ID (IČO): 75241587
VAT ID (DIČ): CZ8502085603
E-mail for questions and requests concerning personal data:
support@mincast.ai
Telephone: +420 608 251 214
(the “Mincast”, “we” or the “Controller”).
Mincast has not appointed a data protection officer.
2. Who these policies apply to
These policies apply in particular to:
- registered Mincast users,
- visitors to Mincast websites,
- persons contacting support,
- customers of a paid subscription,
- persons using the mobile applications.
The Service with a user account is intended for persons aged 16 and over.
3. What personal data we process
Account and sign-in
We may process in particular:
- e-mail address,
- optional name,
- password hash,
- information about e-mail address verification,
- Google account identifier when Google sign-in is used,
- internal user identifier,
- date of account creation and change,
- temporary tokens for e-mail verification and password reset.
Mincast does not know your original password. It stores only its cryptographic hash.
Session and security
When you use an account we may process:
- session token,
- IP address,
- User-Agent,
- date of last activity,
- technical data related to sign-in,
- data needed for rate limiting and prevention of abuse.
Settings and preferences
Mincast stores settings needed to personalise the Service, for example:
- selected RSS sources and their order,
- custom RSS URLs,
- categories,
- languages,
- digest length and time window,
- priority and blocked phrases,
- TTS settings,
- appearance settings,
- optional greeting,
- notification settings,
- time zone,
- weather settings and the stored city name.
Digests and stored content
We process in particular:
- created AI digests,
- the date and parameters of their creation,
- links to the articles used,
- information about public sharing and the public slug,
- saved articles, which consist in particular of a link, title and related metadata,
- named source lists.
Payments and subscription
We may process:
- the selected plan,
- subscription status,
- Stripe Customer ID,
- Stripe Subscription ID,
- price or plan identifier,
- end of the billing period,
- information about planned cancellation,
- data needed for invoicing and tax obligations.
The billing address, any VAT ID and payment data are processed at purchase in particular by Stripe.
Mincast does not store your payment card number or its security code.
Push notifications
If you enable notifications, we process in particular:
- device platform,
- push token or Web Push subscription,
- token status,
- date of last activity,
- scheduled notification times,
- time zone.
Location and weather
If you use the “Use my location” feature, the device may provide Mincast once with approximate or precise coordinates according to the device permission.
The coordinates are used to convert the location into a place name.
Mincast then stores only a text value for the chosen city or place. We do not store precise GPS location on a long-term basis.
Technical logs and diagnostics
We may process:
- server technical logs,
- IP addresses,
- requested URLs,
- error information,
- stack traces,
- information about the device, application and operating system,
- a technical internal user identifier if necessary for diagnostics.
Mincast uses Sentry for error monitoring. Session Replay is not enabled in Mincast.
Mincast seeks to remove authentication headers, cookies and query parameters from diagnostic data unless they are necessary to resolve a specific problem.
AI usage data
For cost control, limits and prevention of abuse we may store:
- internal user identifier,
- the AI feature used,
- model,
- number of tokens,
- calculated cost,
- technical metadata, for example the number of articles processed.
Analytics
On the marketing website mincast.ai we use Google Analytics 4 after obtaining the relevant consent.
Processing may in particular include:
- Analytics identifiers,
- visit information,
- approximate country or region,
- browser and device information,
- pages visited and interactions.
Google Analytics is not used for analytics of users inside mincast.app, unless later expressly stated otherwise in this policy.
Advertising
The FREE plan may display advertising through:
- Google AdSense in the web application,
- Google AdMob in the mobile applications.
Depending on the region, the consent given and device settings, these systems may process in particular advertising identifiers, device information, IP address, a consent string and data needed to measure and select advertising.
In the EEA and other areas where consent is required, we use the relevant consent-management mechanisms, for example a CMP or Google UMP.
4. Data from news sources
Mincast automatically processes publicly available news and other RSS sources.
The text of an article or a limited part of it may contain personal data of persons about whom the source reports.
Such information is processed only for automated analysis and creation of a news summary. Source text obtained for AI processing is not intended to create a permanent archive of articles. It is retained temporarily for the period necessary to create an AI digest or a more detailed summary requested by the user; content stored during ordinary processing of new articles is used for new summaries for at most 24 hours and is automatically deleted typically within 30 hours of retrieval; for later on-demand processing, newly obtained source text is retained only for the processing time necessary.
The user’s history may retain the created AI summary, the article title, the source designation and a link to the original source.
5. What we send to the AI provider
When creating a digest, Mincast may send the AI provider in particular:
- article titles,
- relevant parts of their text or excerpts,
- source names,
- categories,
- output language,
- parameters of the requested digest,
- selected preferences, priorities or a blocklist needed to create the result.
We do not as a standard send the user’s password, payment card number or other login or payment data in the AI prompt.
We use the API of OpenAI for generation.
6. Purposes and legal bases
| Purpose | Typical legal basis |
|---|
| Creation and operation of the account | performance of a contract |
| Sign-in, sessions and account verification | performance of a contract; security also legitimate interest |
| Source selection, preferences, AI digests and history | performance of a contract |
| TTS | performance of a contract |
| Push notifications | performance of a contract / feature activated by the user |
| Optional location and weather | performance of a user-requested feature; access to location is controlled by the device permission |
| Subscription and plan management | performance of a contract |
| Invoicing, accounting and taxes | legal obligation |
| Prevention of fraud, abuse and attacks | legitimate interest in the secure operation of the Service |
| Server logs and Sentry | legitimate interest in security, diagnostics and reliability |
| AI usage and cost control | legitimate interest in managing operations, costs and prevention of abuse |
| Internal operational notice of a new registration | legitimate interest in administering and controlling operations |
| Processing of public sources to create a digest | legitimate interest in providing a news-aggregation and AI service |
| Public sharing of a digest | performance of a contract and the user’s instruction |
Google Analytics on mincast.ai | consent |
| Advertising technologies requiring consent | consent |
| Handling support, complaints and legal claims | performance of a contract, legal obligation or legitimate interest depending on the situation |
Where processing is based on legitimate interest, we weigh Mincast’s interest against the rights and freedoms of the persons concerned and use only the scope of data we consider proportionate to the purpose.
7. Providers and recipients of data
To operate Mincast we use in particular the following providers:
| Provider | Purpose |
|---|
| Railway | backend, database, Redis, worker, infrastructure and logs |
| Vercel | hosting and delivery of websites and the web application |
| OpenAI | generation of AI digests and summaries |
| Google Cloud | text-to-speech and related cloud functions |
| Google OAuth | optional sign-in with a Google account |
| Google Analytics 4 | analytics of the marketing website after consent |
| Google AdSense | advertising in the web FREE plan |
| Google AdMob / UMP | advertising and consent management in mobile applications |
| Firebase Cloud Messaging | Android push notifications |
| Apple APNs | iOS push notifications |
| Stripe | payments, subscriptions, invoicing, taxes and Customer Portal |
| Resend | transactional e-mail communication |
| Seznam.cz SMTP | transactional e-mail communication |
| Sentry | diagnostics and error monitoring |
| Open-Meteo | weather information |
| Nominatim / OpenStreetMap infrastructure | conversion of coordinates into a place name |
| Operators of Web Push infrastructure | delivery of web push notifications |
When an article’s publisher is fetched in the ordinary way as RSS or an article from the Mincast server, the publisher does not receive the identity of the particular end user merely because that user selected the source in Mincast.
8. International transfers of data
Some of our providers are established in or use infrastructure outside the European Economic Area, in particular in the United States of America.
The Mincast backend operated on Railway is in the current configuration located in the region US West, California, USA.
When transferring personal data outside the EEA we use the mechanisms required by applicable law, in particular:
- a European Commission adequacy decision, if it applies to the particular recipient,
- or the European Commission’s standard contractual clauses and other appropriate contractual or technical measures.
You may request information about the specific mechanism used for a particular provider, or a copy of the relevant safeguards, at support@mincast.ai.
9. OpenAI
Mincast uses the standard OpenAI API.
Data sent through the OpenAI API is not by default used to train OpenAI models, unless the API customer expressly opts to share data for that purpose.
Under the standard API terms, OpenAI may for eligible API operations retain inputs, outputs and related security logs for a limited time for abuse prevention and service security.
10. Retention period
We do not retain personal data longer than is reasonable for the purpose of processing or required by law.
| Category | Intended retention period |
|---|
| Account and basic profile | for the life of the account; after a deletion request, deletion without undue delay, generally no later than 30 days |
| Active session | 14 days from the last relevant activity; the period may be extended while the Service is used |
| E-mail verification token | validity 24 hours; deleted immediately after use, after expiry removed in regular cleanup |
| Reset-password token | validity 1 hour; deleted immediately after use, after expiry removed in regular cleanup |
| History of AI digests | until deleted by the user or until the account is deleted |
| Saved article links | until removed by the user or until the account is deleted |
| Article source text for AI | temporarily for the period necessary to create an AI digest or a more detailed summary requested by the user; content stored during ordinary processing of new articles is used for new summaries for at most 24 hours and is automatically deleted typically within 30 hours of retrieval; for later on-demand processing, newly obtained source text is retained only for the processing time necessary |
| TTS audio cache | maximum 7 days |
| Active push token | for the life of the active device / feature |
| Revoked or invalid push token | maximum 90 days from revocation or marking as inactive |
| AI usage data linked to a user account | for the life of the account, while they are needed to monitor use of the Service, costs and prevention of abuse; when the account is deleted, the link to the user is removed |
| Anonymised or aggregated AI usage and cost statistics | may be retained long-term if they no longer enable identification of a particular user |
| Railway application logs | maximum 30 days on the production plan in use |
| Sentry error/trace data | 30 days |
| Google Analytics user/event data | 2 months according to the GA4 setting |
| Record of cookie / consent choice | typically up to 12 months; a refusal at least 6 months before a new request, unless there is a material change |
| Database backups | if active, maximum 1 month in ordinary rotation |
| Accounting and tax records | for the period required by the applicable accounting and tax laws |
After account deletion, some data may remain for a limited time in rotating backups and are then overwritten.
Data that we must retain for accounting, tax or other legal obligations may be retained even after account deletion.
11. Account deletion
The user may request deletion of the account through the Delete account function in the application or via support@mincast.ai.
Upon account deletion we delete or anonymise personal data that we no longer need for another legal reason.
Account deletion does not apply to data that we must continue to retain, for example for accounting or tax obligations, defence of legal claims or security obligations.
Anonymised statistics that can no longer be attributed to a particular person are not personal data and may be retained thereafter.
12. Public sharing of a digest
If the user enables public sharing, a selected AI digest is made available via a unique link.
The public page may contain:
- the AI summary,
- topics and digest parameters,
- article titles,
- source names,
- links to the original articles.
The public page does not as a standard display the user’s e-mail, account data, precise location or saved bookmarks.
Sharing can be turned off.
The user acknowledges, however, that information already obtained by a third party, a search engine or another external system may not be removable from systems outside Mincast’s control.
13. Cookies and similar technologies
Details of cookies, localStorage, Google Analytics, advertising identifiers, AdSense, AdMob and other similar technologies are set out in the separate Cookie and Similar Technologies Policy.
Consent may be withdrawn at any time through the relevant settings on the website, CMP, Google UMP or device settings, depending on the type of technology.
Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
14. Your rights
Under the conditions laid down by the GDPR and other applicable laws you have in particular the right to:
- obtain confirmation of whether we process your personal data and obtain access to it,
- request rectification of inaccurate or incomplete data,
- request erasure of personal data,
- request restriction of processing,
- receive the data in a structured, commonly used and machine-readable format where the right to data portability applies,
- object to processing based on legitimate interest,
- withdraw consent at any time where processing is based on consent,
- lodge a complaint with a supervisory authority.
You may send a request to:
support@mincast.ai
We will respond to the request without undue delay and within the statutory time limits.
15. Supervisory authority
In the Czech Republic the competent supervisory authority is:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
16. Automated decision-making
AI in Mincast automatically selects and summarises content according to the user’s settings.
This processing is not intended to take decisions that produce legal effects concerning the user or similarly significantly affect their rights within the meaning of automated individual decision-making under the GDPR.
Mincast does not carry out credit scoring, insurance decisions or similar high-risk profiling of users.
17. Sale of personal data
Mincast does not sell users’ personal data.
The use of advertising providers for the FREE plan does not of itself mean that Mincast sells its user database to advertising companies.
18. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or misuse.
Depending on the type of data, the measures used include for example:
- encrypted transmission,
- password hashing,
- separate authentication tokens,
- restricted access to production systems,
- technical logging and monitoring,
- removal of authentication data from diagnostic reports unless necessary,
- time-limited sessions.
No system can, however, guarantee absolute security.
19. Children
The Service with a user account is not intended for persons under 16 years of age.
If we find that an account was created by a person under 16 contrary to these rules, we may block the account and delete the related personal data, unless there is another legal reason for their retention.
20. Changes to this policy
We may update this policy in particular when the Service, the providers used, the law or the methods of processing change.
The current version is marked with the date of the last update.
If a change is material for registered users, we may also inform them by e-mail or a notice in the Service.
21. Contact
Questions and requests concerning personal data protection:
support@mincast.ai
Tomáš Pukowiec
Dětmarovice 368
735 71 Dětmarovice
Czech Republic