Callback
Try it Pricing Terms Get early access

Privacy Policy

Last updated 13 August 2026 · Applies to the Callback Chrome extension, dashboard and website

The short version. Submissions are read and parsed on your own computer. Nothing about an actor reaches our servers unless you press “Save to Dashboard”. We never sell data, never use it to train models, and never use Google user data for advertising.

On this page

  1. Who we are
  2. Your role and ours
  3. What we collect
  4. Google API disclosure
  5. What stays on your machine
  6. Why we process it
  7. Who we share it with
  8. How long we keep it
  9. Security
  10. Your rights (DPDP)
  11. If you're an actor
  12. Children
  13. Changes
  14. Contact

1. Who we are

Callback is an independent product built and operated in India by Sanyam Jain. In this policy “Callback”, “we” and “us” mean that operator. “You” means the casting professional or organisation using the product.

We are currently in a private pilot. This policy describes the product as it actually works today, not as we hope it will work later.

2. Your role and ours

This distinction matters, because it decides who is responsible for what:

  • For your own account data (your email address, password, billing details) we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”).
  • For candidate data — the actors who submitted to your casting call — you are the Data Fiduciary and we act as a Data Processor on your instructions. You decide which submissions to import, what to do with them and when to delete them. We only store what you choose to sync, and only process it to provide the service to you.

That means the responsibility for collecting candidate consent lawfully sits with you. The product is built to help you meet it — see section 11.

3. What we collect

DataWhenWhy
Your name and email addressWhen you create an account or join the waitlistTo create your login and contact you
Your passwordAt signupStored only as a salted PBKDF2 hash — we cannot read or recover it
Your studio / production house and roleIf you enter it on the waitlist formTo understand who the product is for and set you up appropriately
Candidate records — name, email, phone, city, headshot URL, notes, stageOnly when you press “Save to Dashboard”To show your board, and to send messages you initiate
Message records — recipient, subject, body, delivery statusWhen you send a message through CallbackTo show sending history and prove consent and delivery
Consent log — opt-ins, opt-outs, timestamps, sourceWhen consent changesLegal requirement, and your audit trail
Basic technical logs — IP address, timestamps, error tracesOn API requestsSecurity, rate limiting and debugging

We do not collect: your Google password, your contacts, your calendar, your browsing history, or the contents of emails you did not point the product at.

We do not use cookies for advertising or third-party analytics. Your login session is held in your own browser's local storage, not in a tracking cookie.

4. Google API Services disclosure

The Callback Chrome extension requests these Google OAuth scopes, and only these:

ScopeWhat it allows
gmail.readonlyRead messages and attachments in the label you select. Read-only — the extension cannot send, delete or modify anything in your mailbox.
forms.body.readonlyRead the question structure of a Google Form you choose, so answers can be mapped to the right fields.
forms.responses.readonlyRead the responses to that Form.
spreadsheets.readonlyRead a Google Sheet you choose.

Limited Use commitment. Callback's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing features described on this site; we do not transfer it to third parties except as needed to provide those features, for security, or to comply with law; we do not use it for advertising; we do not allow humans to read it except with your explicit permission, for security purposes, to comply with law, or where the data has been aggregated and de-identified; and we do not use it to develop, improve or train generalised AI or machine-learning models.

You can revoke the extension's access at any time at myaccount.google.com/permissions. Revoking access stops all future reads immediately.

5. What stays on your machine

This is the part most people want to know, so we'll be precise about it.

  • Reading your Gmail label, Form or Sheet happens in your browser. The extension talks to Google directly — that traffic does not pass through our servers.
  • Extracting names, phone numbers, cities and photos happens in your browser.
  • Parsed candidates are held in your browser's local storage until you decide what to do with them.
  • If you only ever export to Excel, we never see a single candidate record.
  • Candidate data reaches our servers only when you press “Save to Dashboard”, and only the records in that sync.
  • Photos that arrive as email attachments are converted to images inside your browser and are deliberately excluded from sync. Only hosted image links (for example a public Drive link an actor shared) are uploaded.

6. Why we process it

Under the DPDP Act we rely on your consent, given when you create an account and when you choose to sync data, and on the legitimate need to perform the service you asked for. For candidate data we process solely on your documented instructions as your processor.

7. Who we share it with

We do not sell data. We do not share it for advertising. We use a small number of infrastructure providers who process data strictly to make the product work:

ProviderWhat they handleWhere
Cloudflare (Workers, D1, Pages)Application hosting and databaseGlobal edge network
Twilio SendGridSending the emails you choose to sendUnited States
TwilioWhatsApp messaging, once enabledUnited States
GoogleThe source data you point us at, and OAuth sign-inGlobal

This involves transferring data outside India. We will also disclose data where we are legally required to, and will tell you when we are permitted to do so.

Enterprise customers can request a signed Data Processing Agreement and a current sub-processor list — email us.

8. How long we keep it

  • Candidate and board data: until you delete it or close your account. Deleting a candidate removes the record from our database.
  • Account data: for as long as your account exists. On closure we delete it within 30 days.
  • Consent and unsubscribe logs: retained after deletion, because they are the evidence that an opt-out was honoured. These hold the minimum needed — an identifier, a channel, an action and a timestamp.
  • Waitlist emails: until you ask us to remove you, or we shut the pilot down.
  • Technical logs: short-lived, and not used to build any profile of you.

9. Security

  • All traffic is encrypted in transit over HTTPS/TLS.
  • Passwords are stored as salted PBKDF2-SHA256 hashes. Nobody at Callback can see your password.
  • Sessions use signed tokens that expire.
  • Every request is scoped to your own account — one customer's data is not reachable from another's session. This is enforced in the database queries themselves, not merely in the interface.
  • API keys and secrets are held in an encrypted secret store, never in our source code.
  • Rate limiting protects against automated abuse.

No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and affected users as required by the DPDP Act.

10. Your rights

Under the DPDP Act you have the right to access a summary of your personal data and how it is processed; to correct or complete inaccurate data; to erase data no longer needed; to nominate someone to exercise these rights if you die or become incapacitated; and to grievance redressal.

Most of this you can do yourself inside the product. For anything else, email us at sanyamjainbits@gmail.com and we will respond within 30 days. If you are unhappy with our response you may complain to the Data Protection Board of India.

11. If you're an actor who submitted to a casting call

Your details are in Callback because a casting professional imported the submission you sent them. They control that record, not us — so the fastest route is to contact the casting team you applied to.

You can also, at any time:

  • Click Unsubscribe in any email you receive through Callback. This is one click, needs no account, and takes effect immediately. Once you opt out, the system blocks further messages to you — it is not a preference someone can override.
  • Email us at sanyamjainbits@gmail.com and we will pass your request to the relevant customer and help enforce it.

Casting teams using Callback cannot message you at all unless you have been recorded as opted in, and every opt-in and opt-out is timestamped.

12. Children

Callback is for professional use and is not directed at children. We do not knowingly create accounts for anyone under 18. If a casting call involves child artists, the customer is responsible for obtaining verifiable parental consent as the DPDP Act requires; if you believe a child's data has been processed inappropriately, contact us and we will act promptly.

13. Changes to this policy

If we change this policy we will update the date at the top, and for material changes we will email account holders before the change takes effect.

14. Contact

Questions, requests or grievances: sanyamjainbits@gmail.com. We aim to reply within a few working days and are required to resolve grievances within 30 days.

Callback

The boring half of casting, done for you.

Product

Try it Pricing FAQ

Company

Join the pilot Contact us

Legal

Privacy policy Terms of service
© 2026 Callback. All rights reserved.
Made in India 🇮🇳