This Privacy Policy explains how CASSO SOFTWARE ("CASSO SOFTWARE," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the Cassoproduct - including usecasso.app, our macOS desktop app, and related services (together, the "Service").
CASSO SOFTWAREis a registered business name in Australia and is the organisation responsible for personal information collected through the Service (the "APP entity" for Australian Privacy Principles purposes, where that framework applies). Casso is the product brand; it is not a separate legal entity.
In short: Screen annotations stay on your Mac. We process account, license, and payment-related data so you can sign in and buy a personal license. We use website analytics and session recordings (PostHog) and lightweight product telemetry to understand product usage - not advertising profiles. Form inputs in recordings are masked in the browser. We do not sell your personal information, do not use advertising cookies, and do not use your screenshots to train AI models.
1. Who we are and how to contact us
Controller / APP entity: CASSO SOFTWARE (Australia).
Privacy requests: [email protected]. Website: usecasso.app. We aim to respond within 30 days (or sooner where local law requires).
2. What Casso does and what this policy covers
Casso is a macOS desktop product for numbered screen annotations you can paste into coding agents and terminals you choose. The website (usecasso.app) provides marketing, account sign-up/sign-in, license and personal license purchase, downloads, and support. Annotations and screenshots are designed to stay on your machine; the core product does not run cloud AI on your screenshots.
This policy covers personal information we handle as a business when you create an account, use the website, authenticate the desktop app, purchase a license, receive transactional email, contact support, or when website analytics / product telemetry run as described below.
It does not cover how third-party apps (for example coding agents or terminals) handle content you paste into them after using Casso. Those tools have their own policies.
3. What we do not collect (by default)
As part of the normal annotate → paste flow, we do not:
- Upload your screenshots, crops, notes, or session image files to our servers
- Read the contents of your screen for advertising or profiling
- Store full payment card numbers on our servers (Stripe processes cards)
- Use third-party advertising cookies, ad retargeting pixels, or sell personal information
- Use your local annotation contents to train our own or third-party AI models
You still control what you paste into other tools. Once content leaves your device into a third-party agent, that agent's privacy practices apply.
4. Information we collect
Account information you provide. When you create an account we collect your email address, name (if provided), and password (stored hashed by our authentication stack, Better Auth). We store session records so you stay signed in on the web and desktop. If you email us, we process the content of that correspondence.
Trial and license status. We store when desktop access started, whether your account is licensed, related timestamps, and identifiers needed to enforce annotate access server-side.
Payment information. Payments are processed by Stripe. We receive payment metadata (for example status, amount, currency, and a Stripe customer or session identifier linked to your account). We do not store full card numbers on our servers.
Desktop authentication handoff. When you sign in from the desktop app via the browser, we use a short-lived one-time code and then a session token stored in your Mac's Keychain so the app can verify license status.
Technical and log data. Our hosting and security infrastructure may automatically process standard request logs (IP address, user agent, timestamps, URLs, and similar diagnostics). We use this for security, reliability, and debugging.
Website analytics and session recordings (PostHog). On usecasso.app we use PostHog (when configured) for product analytics and session recordings (session replay). Events and replay snapshots are sent through a same-origin path (for example /ingest) or a dedicated reverse proxy host we control (for example p.usecasso.app), then processed by PostHog as our analytics provider. Typical analytics data includes page views and page leave events, basic interaction events (autocapture such as clicks and link usage - password fields are excluded by library defaults), URLs and referrers, browser and device metadata, a random distinct identifier, and analytics session state. Session recordings capture a reconstructed view of how the page was used (DOM structure, mouse movement, scrolls, and similar interaction cues) so we can debug UX and conversion issues. Form field values are masked in the browser before upload (including passwords and other inputs); we also redact email-like text that appears on the page where practical. Console logs are not included in recordings. When you are signed in, we may link analytics events and recordings to your account identifier and, where available, email and name so we can understand authenticated product journeys. We use this to improve the website and product - not for advertising networks or selling profiles. PostHog stores a small amount of state in a first-party cookie and browser localStorage (see Cookie Policy).
Product / desktop telemetry. The macOS app may send lightweight product events to our API (for example /api/telemetry), which forwards them to PostHog for product analytics (same provider as website analytics). Expected event categories include app launch, annotation started / completed / cancelled, and auth success / failure. Properties are limited and scrubbed (for example optional box counts, platform, app version, a process session id, and coarse failure reasons). We do not upload screenshots, crops, notes, prompts, or the contents of your screen as part of this telemetry. Secrets, tokens, and passwords are stripped. When a valid session is present we may attach your account user id; anonymous events (for example before sign-in) are also accepted. Desktop telemetry is enabled by default and can be disabled via the app preference key casso.telemetry.enabled (UserDefaults; set to false to opt out).
Download counters (first-party). When you download the app we may record a coarse download event (platform, source, optional account id, timestamp) in our own database to understand distribution - not for advertising.
Update checks (desktop). The macOS app may contact our download / appcast host (for example via Sparkle) to check for software updates. That request can include technical details such as app version and basic device/network metadata handled by the update infrastructure.
Local desktop data (not uploaded by default). Screenshots, crops, notes, prompts, and session files created by the desktop app are stored on your device (for example under temporary session folders). We do not upload those annotation images to our servers as part of the normal annotate → paste flow, and they are not included in product telemetry. Those files remain under your control and may be cleared when temporary storage is cleaned (for example on reboot).
Operating system permissions. Screen Recording and Accessibility permissions are granted in macOS System Settings and controlled by Apple. We do not receive a copy of your permission dialogs; the app uses those permissions only on your device to capture and paste as you direct.
5. How we use information
We use personal information to:
- Provide, operate, maintain, and secure the Service
- Create and manage accounts, sessions, and licenses
- Process purchases and send related receipts
- Send transactional email (account verification, security, and license notices)
- Deliver software updates for the desktop app
- Respond to support and privacy requests
- Detect abuse, fraud, and security issues
- Measure website and product usage (PostHog analytics, session recordings, and first-party desktop telemetry) so we can fix issues and improve the Service without needing your screen annotation contents
- Comply with law and enforce our Terms of Service
We do not sell your personal information. We do not share personal information for cross-context behavioural advertising. We do not use the contents of your screen annotations for advertising or for training third-party AI models.
6. Legal bases (where GDPR / UK GDPR applies)
If you are in the EEA, UK, or another region that requires a lawful basis, we typically rely on:
- Contract - creating your account, running the license, authenticating the desktop app, processing payment, and providing the Service you request
- Legitimate interests - securing the Service, preventing abuse, debugging, improving reliability, product analytics and telemetry that do not require your annotation images, and related product improvement (balanced against your rights)
- Legal obligation - tax, accounting, and other mandatory record-keeping
- Consent - where we ask for it (for example optional marketing email, if we ever offer it). You can withdraw consent at any time without affecting prior lawful processing
7. How we share information
We share personal information only as needed to run the Service, with parties who process it on our behalf, or as required by law:
| Provider | Purpose | Privacy policy |
|---|---|---|
| Stripe | Payments, checkout, receipts, billing metadata | stripe.com/privacy |
| Resend | Transactional email (verification, license) | resend.com/legal/privacy-policy |
| PostHog | Website product analytics and session recordings (page views, interaction events, DOM replay snapshots with input masking; optional account link when signed in) | posthog.com/privacy |
| Railway | Application hosting and database infrastructure | railway.com/legal/privacy |
| Cloudflare | CDN / object storage for app downloads and updates | cloudflare.com/privacypolicy |
| Linear | Internal support ticket triage (when you contact support we may open an issue for our team) | linear.app/privacy |
- Professional advisors (legal, accounting) when reasonably necessary
- Authorities when we believe disclosure is required by law or to protect rights, safety, or security
- Business transfers - if we sell, merge, or reorganise the business, personal information may transfer as part of that transaction, subject to ongoing privacy commitments where required
Service providers are expected to use personal information only to perform services for us and to apply appropriate safeguards. Provider names and regions may change as our infrastructure evolves; material changes will be reflected in this policy.
8. Cookies and local storage
The website uses cookies and similar technologies for authentication and for product analytics (PostHog). The desktop app stores a session token in the system Keychain and may store preferences (including a telemetry opt-out flag) on your device. For the full inventory, categories, and control options, see our Cookie Policy.
| Name / storage | Type | Purpose | Duration | How to control |
|---|---|---|---|---|
| better-auth.session_token / __Secure-better-auth.session_token | Strictly necessary | Keep you signed in on the website | Session / up to ~30 days (refreshed while active) | Sign out, or clear site cookies in your browser (sign-in will stop working if blocked) |
| ph_*_posthog (cookie) + related localStorage keys | Analytics | PostHog product analytics and session recordings - distinct ID, session continuity, replay buffers, and related analytics state on the website | Typically up to ~365 days (library defaults; refreshed with use) | Clear cookies and site data for usecasso.app, or block storage for this site in your browser |
| Desktop Keychain session token | Strictly necessary (local) | Authenticate the macOS app for license checks | Until you sign out or revoke the session | Sign out in the app, or remove Keychain items for Casso |
| casso.telemetry.enabled (UserDefaults) | Preference (local, desktop) | Desktop preference controlling whether product telemetry events are sent to our API | Until you change it or reset app preferences | Set to false in UserDefaults to disable desktop telemetry |
We do not use advertising or retargeting cookies. Analytics cookies and localStorage used by PostHog help us understand how the website is used. You can control browser cookies and site data through your browser settings; blocking all cookies may prevent sign-in, while clearing analytics storage mainly resets analytics identifiers. We do not currently respond to Do Not Track browser signals in a specialised way beyond the practices described here.
9. International transfers
CASSO SOFTWARE operates from Australia. Personal information may be stored or processed in Australia and in other countries where our service providers operate (for example the United States). Those countries may have different privacy laws than your home country.
When we disclose personal information overseas, we take steps we consider reasonable in the circumstances so that the recipient does not breach the Australian Privacy Principles in relation to the information, where the Privacy Act 1988 (Cth) applies - for example by using reputable providers and contractual or policy controls appropriate to our size and the sensitivity of the data.
Where GDPR / UK GDPR transfer rules apply, we rely on appropriate safeguards offered by providers (such as Standard Contractual Clauses or equivalent mechanisms) where required, together with technical measures such as HTTPS in transit.
10. Security
We use measures appropriate to the Service and our size, including:
- HTTPS / TLS for data in transit to our website and APIs
- Hashed passwords via our authentication stack (Better Auth)
- Access controls on production systems and separation of admin tools
- Preferring not to upload screen annotation images to our servers in the normal product flow (reduces impact of a server-side incident on your captures)
No method of transmission or storage is completely secure. You are responsible for keeping your password and device access under control.
If we become aware of a personal data breach that is likely to result in a risk to individuals, we will take steps required under applicable law, which may include notifying the relevant regulator and affected users without undue delay (for example, within 72 hours of becoming aware where GDPR notification duties apply).
11. Retention
We use the following retention approach (approximate):
- Account profile - while your account is active, then deleted or de-identified within a reasonable period after a verified deletion request (unless longer retention is required)
- Sessions / auth tokens - until expiry, sign-out, or revocation (web sessions typically up to ~30 days with refresh while used)
- Trial / license / purchase records - for the life of the account and as needed for tax, accounting, fraud prevention, and legal claims
- Support email - while needed to resolve your request and for a limited period afterward for quality and dispute purposes
- Server logs - typically short-lived operational retention (on the order of days to weeks) unless needed longer for security investigation
- Website analytics and session recordings (PostHog) - retained according to our PostHog project settings and operational needs (order of months is typical for product analytics and replays unless we delete earlier). Browser cookie / localStorage identifiers typically last up to about a year unless cleared sooner
- Product telemetry events - retained in PostHog according to our project settings (order of months is typical) unless we delete earlier
- Download counters - coarse first-party download events retained for product metrics
- Local annotation files - controlled by you and your operating system; we cannot delete files that never left your device
When information is no longer required, we delete or de-identify it where practicable.
12. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to certain processing of personal information we hold about you, or to make a complaint about our handling of that information.
- Update account details while signed in
- Sign out of the web app and desktop app
- Request access, correction, deletion, or other rights by emailing [email protected]
- Opt out of marketing email if we send it (transactional messages about your account, security, or purchases may still be sent)
- Limit website analytics and session recordings by choosing "Necessary only" on the cookie banner, or by clearing cookies and site data for usecasso.app / blocking storage in your browser settings
- Disable desktop product telemetry by setting UserDefaults key
casso.telemetry.enabledto false (default is enabled) - Request deletion or correction of analytics-linked account data by emailing [email protected]
We may need to verify your identity before fulfilling a request. We may decline or limit a request where permitted by law (for example if retention is required for legal claims or fraud prevention). We aim to respond within 30 days (or sooner where local law requires).
If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC): oaic.gov.au.
13. EEA / UK regional supplement
If you are in the European Economic Area or the United Kingdom, this section applies in addition to the rest of this policy.
Controller. CASSO SOFTWARE is the controller of personal data processed through the Service. Contact: [email protected]. We have not appointed an EU or UK Article 27 representative at this time; contact us at the email above for privacy matters.
Legal bases. See section 6 (contract, legitimate interests, legal obligation, and consent where used). Product analytics and telemetry are typically processed under legitimate interests in product improvement and reliability, balanced against your rights; where local ePrivacy rules require consent for non-essential cookies, we will treat consent as the relevant basis for those storage items and update our Cookie Policy and consent UI accordingly.
Your rights. Subject to conditions in GDPR / UK GDPR, you may have rights of access, rectification, erasure, restriction, portability, and objection (including objection to processing based on legitimate interests), and the right not to be subject to solely automated decisions that produce legal or similarly significant effects (we do not use the Service for such decisions). You may lodge a complaint with your local supervisory authority.
International transfers. See section 9. Where we transfer personal data outside the EEA/UK, we use appropriate safeguards such as Standard Contractual Clauses (or equivalent) offered by our processors where required.
14. California and similar US state notices
If you are a California resident (or resident of another US state with similar privacy laws), we provide this additional notice.
Categories of personal information we may collect (examples; not all categories apply to every user):
| Category | Examples |
|---|---|
| Identifiers | Email, account IDs, analytics distinct IDs, IP address in logs |
| Customer records | Name (if provided), account profile fields |
| Commercial information | Trial status, license status, purchase metadata from Stripe |
| Internet / electronic activity | Server logs, PostHog website analytics, product telemetry events, download counters, auth/checkout flow usage |
| Geolocation | Coarse location derived from IP for security/logs only - not precise GPS |
| Inferences | Only as needed for abuse prevention and product reliability - not advertising profiles |
We do not sell or share personal information as those terms are commonly defined under the CCPA/CPRA for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond providing the Service.
You may request to know, delete, or correct personal information, and you will not be discriminated against for exercising privacy rights. Submit requests to [email protected]. Authorised agents may contact us with proof of authority.
15. Children
The Service is not directed to children under 16 (or the minimum age of digital consent where you live, if higher). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
16. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. For material changes, we may also notify you by email or in the product when practical. Continued use of the Service after the updated policy takes effect means you accept the changes, except where applicable law requires a different approach.
17. Contact
Privacy requests and questions:
CASSO SOFTWARE
Product: Casso
Email: [email protected]
Website: usecasso.app
See also our Terms of Service and Cookie Policy.
This policy is a product-specific disclosure for Casso. It is not legal advice. Have a qualified attorney review before relying on it for regulated markets or enterprise procurement.