ReviewCast

Privacy Policy

What Reviewcast, operated by ABRuntime, collects about you, why, and how to switch off the parts that are optional.

Last updated 22 September 2026

The short version

We collect your email address, the code you send us to make a video, and a record of what happened on the site. Analytics and advertising tags load by default and you can turn them off on the Privacy choices page — nothing else changes when you do.

There is no cookie banner because we would rather give you one switch that works.

Your email address

Your email address is your identity here — there is no username and no password. We use it to send your sign-in code and to answer you when you write to us.

We normalise it before storing it (lowercasing, and for Gmail-style addresses removing dots and anything after a +), so that the same mailbox always resolves to the same account and the same one-time free tier.

Sign-in codes are stored only as a hash, expire after a few minutes, and can be used once.

The code you send

To make a video we send your diff to a large language model provider to write the narration, and the narration text to a speech provider to voice it. The finished video is stored with our hosting provider so you can watch and download it.

We keep the video, and the repository name and commit range you sent with it, so it appears in your list of renders. We do not use your code to train anything, and we do not sell it or share it with anyone beyond the providers needed to produce your video.

We also instruct our model provider to route your diff only to services that do not retain prompts for training. That is a setting we send on every request, not a preference we hope is honoured by default.

Your IP address

Two things need to recognise a repeat visitor without knowing who they are: the limit on free trial keys, and the limit on how many sign-in codes can be requested.

Both work on a one-way fingerprint — for trial keys, derived from your IP address and browser user-agent string; for sign-in codes, from your IP address. We store the fingerprint, never the address or the user-agent, and it cannot be turned back into either. Only an equality check is ever needed, and a hash answers that just as well as the original would.

How we know the site is working

We keep our own record of events — page views, taking a key, signing up, a video finishing, a purchase — with a timestamp and, where you are signed in, your account. This is what tells us whether something is broken and whether advertising is worth the money. It stays on our servers.

This record is used for billing, for spotting abuse, and for counting. It is never used to build an advertising profile of someone who has opted out.

Analytics and advertising

By default we load Google Analytics and the X (Twitter) advertising pixel. They tell us which advertisement brought someone to the site and whether they went on to make a video. Both send data to those companies under their own privacy policies.

When you arrive from an advertisement, the campaign details in the link and X's click identifier are stored in a cookie for 90 days and copied onto your account when you first create one.

Turning the switch off on the Privacy choices page stops all of it: neither tag loads again, the campaign cookie is deleted, and no new one is set. Signing in, making videos and buying all keep working exactly as before.

Payments

Whop processes payments as Merchant of Record. Your card details go to them and never reach us. We receive confirmation that a payment succeeded, its identifier and its amount, so we can add videos to your balance and handle refunds.

Cookies we set

A sign-in cookie that keeps you signed in. A trial-key cookie that remembers which trial belongs to this browser. A cookie recording your choice on the Privacy choices page. A cookie holding your theme preference. And, unless you have opted out, the campaign cookie described above.

The first four are necessary for the site to work and are not affected by the opt-out.

How long we keep things

Sign-in codes, and the fingerprint stored beside them, are deleted within a day of being issued. The campaign cookie expires after 90 days. Our own event record is kept so we can compare periods over time.

Your account and your videos stay while you are using the service. If a free account goes untouched for 12 months we may delete its videos to reclaim the storage, and we will email you first. Paid balances are not affected.

Deleting your data

Email support@axonbuild.com and we will delete your account, your videos and the email address attached to them. We will keep the minimum needed for records of payments already made.

Deleting an account does not restore the free tier — the one-time free videos stay used.

Changes and contact

If this policy changes, the date at the top changes with it. Anything you want to ask about it goes to support@axonbuild.com.