Compliance and AI transparency
Controls you can verify, gaps we will not hide
This page reports current engineering controls and open assurance work. It is not a certification, legal opinion, or claim that every rule applies in the same way to every deployment.
Data protection
GDPR and ePrivacy
Local-first capture, explicit upload, authenticated exports, durable deletion requests, bounded retention, session revocation, and no non-essential tracking cookies in the current beta.
AI transparency
EU AI Act
AI endpoints require an authenticated same-origin request, identify local versus external generation, return provenance, and require human review before publishing.
Hosted content
Digital Services Act
Anyone can submit a structured illegal-content notice for a TechCast public share URL and receive a durable reference. Operational decision, appeal, and transparency reporting remain launch gates.
Accessibility
European Accessibility Act
Keyboard, labels, focus, responsive layouts, and semantic status output are product requirements. A qualified WCAG accessibility audit and accessibility statement remain required.
Software security
Cyber Resilience Act
Secure defaults, vulnerability intake, incident handling, dependency evidence, signed desktop distribution, and update/support commitments are tracked. CRA classification and conformity evidence require final product/legal review.
Subscriptions
EU consumer law
Paid self-service remains closed until trader identity, total pricing, renewal, withdrawal, cancellation, refund, tax, and support terms receive legal and production acceptance.
How AI is used
TechCast can send the title, transcript, or other content you select to a configured AI provider to draft transcripts, chapters, metadata, publishing copy, SEO feedback, or coaching. Generated material is a draft and is never a substitute for factual, legal, rights, or safety review.
External assurance still required
Before market launch, TechCast still needs verified controller/trader identity, legal bases and records, processor agreements and transfers, a DPIA decision, accessibility conformance, incident ownership, provider retention proof, security testing, and qualified legal review in the launch countries.