JB CAST · LEGAL & TRUSTJB CAST Privacy Policy
This Privacy Policy explains how JB CAST accesses, processes, uses, stores, protects, and deletes information when users use the JB CAST desktop application and supported platform integrations.
JB CAST is a product of Jalsha Bangla and is operated by Jalsha Bangla, referred to in this policy as “Jalsha Bangla,” “JB CAST,” “we,” “us,” or “our.”
This Privacy Policy applies specifically to JB CAST.
It does not replace the privacy policies or terms of third-party platforms such as Google, YouTube, Meta, Facebook, or TikTok.
1. Our Privacy Principles
JB CAST is designed around the following principles:
Data minimization We request only information and permissions needed for user-facing JB CAST functionality.
User control Users decide which platform account to connect and which publishing actions to approve.
Local-first operation Most operational JB CAST data is stored on the user’s own computer.
No password collection JB CAST does not request or store a user’s YouTube, Google, Facebook, Meta, or TikTok password.
No hidden secondary use Provider-authorized data is not used for unrelated hidden purposes.
No sale of provider user data JB CAST does not sell provider user data or use provider-authorized data for targeted advertising.
2. Information JB CAST May Process
Depending on the features a user chooses to use, JB CAST may process the following categories of information.
Local Application Data
This may include:
- workspace name and settings;
- content titles;
- captions or descriptions;
- publishing-package information;
- scheduling information;
- Queue information;
- selected publishing platform;
- publishing metadata;
- local media verification information;
- publishing status;
- Publishing Ledger information;
- application settings.
Platform Connection Information
When a user connects a supported platform, JB CAST may process:
- platform name;
- authorized channel, Page, profile, or creator identifier;
- provider display name;
- connection state;
- granted permissions/scopes;
- credential-expiry information;
- connection health information.
This information is used to ensure that publishing and analytics are associated with the correct authorized destination.
OAuth Tokens and Credentials
Supported providers may issue access tokens, refresh tokens, or equivalent credential material.
JB CAST uses this credential material only to perform actions authorized by the user.
Secret credential material is designed to be kept outside ordinary application UI state and outside normal diagnostic reports.
Where a provider requires confidential server-side token handling, limited credential lifecycle operations may be processed through an approved secure backend service operated by or on behalf of Jalsha Bangla.
Publishing Information
JB CAST may process information necessary to perform and verify a publishing request, including:
- destination;
- publishing metadata;
- platform-specific options;
- provider publication identifier;
- provider publication URL;
- publication time;
- provider result or status information.
Provider-Derived Analytics
Where authorized and supported, JB CAST may process provider-native analytics such as:
- views;
- likes;
- comments;
- shares;
- watch-time-related information;
- provider availability states;
- other provider-native metrics explicitly supported by the applicable API.
JB CAST does not represent unsupported metrics as provider data.
3. YouTube and Google Data
JB CAST uses YouTube API Services when the user enables and authorizes YouTube functionality.
Depending on the enabled feature, JB CAST may access or process information necessary to:
- identify the authorized YouTube channel;
- upload user-selected videos;
- manage supported upload metadata;
- perform supported playlist or caption operations;
- retrieve authorized YouTube statistics or analytics.
JB CAST does not request or store the user’s Google or YouTube password.
Use of YouTube-connected functionality is also subject to the YouTube Terms of Service and the Google Privacy Policy.
JB CAST is designed to provide users with a mechanism to revoke or disconnect YouTube access in the production version.
Users may also revoke Google account access through Google’s security/account permission controls.
When YouTube authorization is revoked or a qualifying deletion request is made, JB CAST will delete covered YouTube Authorized Data held by JB CAST as soon as possible and, where required by YouTube policy, no later than 7 calendar days after the applicable revocation or deletion request.
Deleting data held by JB CAST does not automatically delete content stored by YouTube.
To delete content hosted by YouTube, users must use YouTube’s own controls or an authorized function specifically designed to delete that content.
JB CAST’s use of information received from Google APIs is limited to providing or improving user-facing JB CAST functionality and is intended to comply with the Google API Services User Data Policy and Limited Use requirements.
4. Facebook / Meta Data
Where Meta platform access is approved and enabled, JB CAST may process authorized information necessary to:
- identify Pages or destinations available to the user;
- identify the Page selected by the user;
- perform supported publishing operations;
- retrieve supported engagement or insights information.
JB CAST requests only provider permissions needed for enabled functionality.
Unsupported or unapproved Meta functionality remains unavailable.
Meta access tokens, user identifiers, Page identifiers, publishing information, and other Meta Platform Data are handled only for the disclosed JB CAST functionality.
Where a user requests deletion of covered Meta Platform Data, JB CAST will delete or irreversibly de-identify that data without undue delay, subject to applicable law and provider requirements.
JB CAST provides a deletion request path that is available to users regardless of region.
JB CAST maintains a public privacy policy and clearly marked deletion path in accordance with applicable Meta data-use requirements.
5. TikTok Data
Where TikTok platform access is approved and enabled, JB CAST may process information necessary to:
- identify the authorized TikTok creator;
- retrieve supported Creator Info;
- display available privacy options;
- display supported interaction controls;
- perform user-approved content posting;
- retrieve supported post information or analytics.
JB CAST does not request a TikTok password.
Availability of TikTok features depends on the TikTok app’s review state, granted products/scopes, Content Posting requirements, provider limits, and account eligibility.
In the production version, TikTok access is designed to be disconnectable through JB CAST where supported, and users may also use applicable TikTok account controls.
Covered TikTok-derived data associated with a deletion request will be deleted or irreversibly de-identified according to the applicable provider requirement and JB CAST’s deletion policy.
6. How We Use Information
JB CAST uses information only for purposes connected to the product, including:
- authenticating provider connections;
- identifying the authorized destination;
- preparing content;
- scheduling content;
- publishing user-authorized content;
- verifying publication results;
- displaying supported analytics;
- maintaining Queue and Schedule state;
- maintaining local publishing history;
- securing connections;
- diagnosing technical problems;
- responding to support, privacy, or deletion requests;
- complying with provider, legal, and security requirements.
7. What We Do Not Do
JB CAST does not intentionally:
- collect provider account passwords;
- sell provider user data;
- use provider-authorized data for targeted advertising;
- secretly publish without user-authorized intent;
- use unofficial login scraping;
- scrape private platform accounts;
- create hidden databases of provider data for unrelated purposes;
- use provider data to bypass provider restrictions;
- use provider credentials after the connection has been disconnected.
8. Local-First Storage
JB CAST is primarily a local desktop application.
Application records may be stored locally on the user’s computer, including:
- workspaces;
- local content metadata;
- Queue state;
- Schedule state;
- Publishing Ledger records;
- settings;
- supported provider-derived analytics.
Users are responsible for securing their computer and operating-system account.
9. Source Media
JB CAST does not maintain a general Jalsha Bangla cloud archive of source media merely because a user adds content to JB CAST.
When a user approves a provider publishing action, the selected media may be transmitted to the selected provider as necessary to complete that publishing request.
Provider-hosted copies are governed by the provider’s own systems and policies.
10. Secure Server-Side Processing
Certain provider integrations may require confidential server-side handling.
Where used, such services may process only information necessary for approved functions such as:
- OAuth authorization-code exchange;
- token refresh;
- token revocation;
- provider-required secure credential handling;
- approved publishing-support operations.
Such services are not intended to become an independent content archive.
11. Sharing of Information
JB CAST may share information only where necessary:
- with the platform selected by the user;
- with approved infrastructure/service providers necessary to operate secure technical functionality;
- where required by law;
- where reasonably necessary to investigate security incidents, fraud, or abuse.
We do not sell provider user data.
12. Diagnostics
Users may choose to export diagnostic information.
JB CAST diagnostics are designed to exclude sensitive information such as:
- access tokens;
- refresh tokens;
- account passwords;
- OAuth authorization codes;
- app secrets;
- raw provider response bodies;
- source media;
- database files;
- unsafe absolute media paths.
Diagnostic exports are not automatically uploaded by the desktop application.
13. Data Retention
JB CAST retains information only for as long as reasonably necessary for the disclosed purpose, subject to provider requirements and applicable law.
Different categories may have different retention periods.
Provider-derived data subject to a provider deletion obligation will not be retained merely for convenience.
Where covered provider data must be deleted following revocation or user request, JB CAST will delete or irreversibly de-identify that data within the applicable deadline.
For covered YouTube Authorized Data, this will occur as soon as possible and no later than 7 calendar days where required by the applicable YouTube API Services policy.
14. Disconnecting a Platform
In the production version, users are designed to be able to disconnect a supported provider through JB CAST where supported.
A provider Disconnect is designed to:
- stop JB CAST from using the disconnected connection;
- remove the usable local credential reference;
- attempt provider-side revocation where supported;
- prevent new publishing operations using that credential;
- initiate the applicable provider-data deletion/de-identification process.
A provider-side network or service failure does not restore locally removed access.
15. Data Deletion Requests
Users may request deletion of provider-derived data held by JB CAST.
Full instructions are available at:
https://jalshabangla.com.bd/products/jb-cast/data-deletion/
Requests may also be sent to:
privacy@jalshabangla.com.bd
Users should never send:
- passwords;
- OTPs;
- access tokens;
- refresh tokens;
- app secrets.
16. Provider-Hosted Content
Deleting data from JB CAST does not automatically delete content stored by YouTube, Facebook, TikTok, or another third-party platform.
Provider-hosted content must be managed using the applicable provider controls or a separate explicitly supported deletion operation.
17. Security
JB CAST is designed to use technical safeguards to protect information, including:
- local secure credential storage;
- renderer isolation;
- restricted internal APIs;
- exact destination binding;
- user-controlled publishing;
- diagnostics filtering;
- provider capability gating;
- controlled revocation and deletion paths in the production version where supported.
No system can guarantee absolute security.
18. Children
JB CAST is a professional publishing and media operations tool.
It is not designed for children.
Users must have the legal authority to operate the connected accounts and accept the applicable terms.
19. International Processing
Provider APIs may process information in countries where the provider operates infrastructure.
If Jalsha Bangla-operated backend infrastructure is used, data may be processed through infrastructure necessary to provide that functionality, subject to applicable security and privacy obligations.
20. Changes to This Policy
If JB CAST materially changes how it accesses, uses, stores, or shares provider user data, this Privacy Policy will be updated.
Where renewed consent is required, users will be asked to accept the updated terms or privacy disclosure before the changed processing is used.
21. Contact
JB CAST / Jalsha Bangla
Operator: Jalsha Bangla Address: House 5/A, Road 1/C, Block B, Nobodoy Housing, Adabor, Dhaka 1207, Bangladesh Country: Bangladesh
Privacy enquiries: privacy@jalshabangla.com.bd Support: contact@jalshabangla.com.bd
CONTACT
JB CAST / Jalsha Bangla
House 5/A, Road 1/C, Block B, Nobodoy Housing, Adabor, Dhaka 1207, Bangladesh