Last updated 13 August 2026 · Applies to the Callback Chrome extension, dashboard and website
The short version. Submissions are read and parsed on your own computer. Nothing about an actor reaches our servers unless you press “Save to Dashboard”. We never sell data, never use it to train models, and never use Google user data for advertising.
Callback is an independent product built and operated in India by Sanyam Jain. In this policy “Callback”, “we” and “us” mean that operator. “You” means the casting professional or organisation using the product.
We are currently in a private pilot. This policy describes the product as it actually works today, not as we hope it will work later.
This distinction matters, because it decides who is responsible for what:
That means the responsibility for collecting candidate consent lawfully sits with you. The product is built to help you meet it — see section 11.
| Data | When | Why |
|---|---|---|
| Your name and email address | When you create an account or join the waitlist | To create your login and contact you |
| Your password | At signup | Stored only as a salted PBKDF2 hash — we cannot read or recover it |
| Your studio / production house and role | If you enter it on the waitlist form | To understand who the product is for and set you up appropriately |
| Candidate records — name, email, phone, city, headshot URL, notes, stage | Only when you press “Save to Dashboard” | To show your board, and to send messages you initiate |
| Message records — recipient, subject, body, delivery status | When you send a message through Callback | To show sending history and prove consent and delivery |
| Consent log — opt-ins, opt-outs, timestamps, source | When consent changes | Legal requirement, and your audit trail |
| Basic technical logs — IP address, timestamps, error traces | On API requests | Security, rate limiting and debugging |
We do not collect: your Google password, your contacts, your calendar, your browsing history, or the contents of emails you did not point the product at.
We do not use cookies for advertising or third-party analytics. Your login session is held in your own browser's local storage, not in a tracking cookie.
The Callback Chrome extension requests these Google OAuth scopes, and only these:
| Scope | What it allows |
|---|---|
gmail.readonly | Read messages and attachments in the label you select. Read-only — the extension cannot send, delete or modify anything in your mailbox. |
forms.body.readonly | Read the question structure of a Google Form you choose, so answers can be mapped to the right fields. |
forms.responses.readonly | Read the responses to that Form. |
spreadsheets.readonly | Read a Google Sheet you choose. |
Limited Use commitment. Callback's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing features described on this site; we do not transfer it to third parties except as needed to provide those features, for security, or to comply with law; we do not use it for advertising; we do not allow humans to read it except with your explicit permission, for security purposes, to comply with law, or where the data has been aggregated and de-identified; and we do not use it to develop, improve or train generalised AI or machine-learning models.
You can revoke the extension's access at any time at myaccount.google.com/permissions. Revoking access stops all future reads immediately.
This is the part most people want to know, so we'll be precise about it.
Under the DPDP Act we rely on your consent, given when you create an account and when you choose to sync data, and on the legitimate need to perform the service you asked for. For candidate data we process solely on your documented instructions as your processor.
We do not sell data. We do not share it for advertising. We use a small number of infrastructure providers who process data strictly to make the product work:
| Provider | What they handle | Where |
|---|---|---|
| Cloudflare (Workers, D1, Pages) | Application hosting and database | Global edge network |
| Twilio SendGrid | Sending the emails you choose to send | United States |
| Twilio | WhatsApp messaging, once enabled | United States |
| The source data you point us at, and OAuth sign-in | Global |
This involves transferring data outside India. We will also disclose data where we are legally required to, and will tell you when we are permitted to do so.
Enterprise customers can request a signed Data Processing Agreement and a current sub-processor list — email us.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
Under the DPDP Act you have the right to access a summary of your personal data and how it is processed; to correct or complete inaccurate data; to erase data no longer needed; to nominate someone to exercise these rights if you die or become incapacitated; and to grievance redressal.
Most of this you can do yourself inside the product. For anything else, email us at sanyamjainbits@gmail.com and we will respond within 30 days. If you are unhappy with our response you may complain to the Data Protection Board of India.
Your details are in Callback because a casting professional imported the submission you sent them. They control that record, not us — so the fastest route is to contact the casting team you applied to.
You can also, at any time:
Casting teams using Callback cannot message you at all unless you have been recorded as opted in, and every opt-in and opt-out is timestamped.
Callback is for professional use and is not directed at children. We do not knowingly create accounts for anyone under 18. If a casting call involves child artists, the customer is responsible for obtaining verifiable parental consent as the DPDP Act requires; if you believe a child's data has been processed inappropriately, contact us and we will act promptly.
If we change this policy we will update the date at the top, and for material changes we will email account holders before the change takes effect.
Questions, requests or grievances: sanyamjainbits@gmail.com. We aim to reply within a few working days and are required to resolve grievances within 30 days.