Privacy Policy
This Policy explains how HeyCatch, Inc. (1111B S Governors Ave STE 59736, Dover, DE 19904, USA) processes personal data when you use heycatch.ai and our services. For data you submit about your own customers or audience, you are the controller and we act as your processor (see our Data Processing Addendum).
1. Data we process
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, password hash, workspace name | you |
| Billing data | plan, transaction history; payment card handled by Stripe — we never store card numbers | you / billing partner |
| Product inputs | product descriptions, brand info, audience/ICP data, connected-account content you submit for analysis | you |
| Usage data | feature usage, logs, device/browser, IP, approximate location | automatic |
| Communications | support requests, emails | you |
| End-user analytics data (processor role) | site/app visits, sessions, interaction events (clicks/taps and form submissions — not the contents of inputs), signup and payment events, IP and device data of visitors to our customers’ websites and users of their mobile apps, collected by the HeyCatch SDK the customer installs | customer’s site visitors and app users (automatic, on the customer’s behalf) |
| Public social content | public posts, comments, usernames and profile context from platforms such as Reddit and X, retrieved via platform APIs and API partners to surface relevant conversations | public sources |
| Cookies | session, preferences, analytics (Amplitude — including session replay of marketing pages, with typed input masked — and Google Analytics on marketing pages; PostHog in the product app), support chat (Crisp), advertising pixels on marketing pages (Meta Pixel, where enabled — see §6 for your opt-out choices) | automatic |
We do not intentionally collect special-category (sensitive) data — please don’t submit it.
2. Why we process it (GDPR legal bases)
- Provide the Services — contract performance (Art. 6(1)(b)).
- Generate AI outputs from your inputs — contract performance; model providers process inputs as our processors/sub-processors.
- Billing, tax, accounting — legal obligation and contract (6(1)(c),(b)).
- Security, abuse prevention, service analytics — legitimate interests (6(1)(f)).
- Surface relevant public conversations (“catches”) — legitimate interests (6(1)(f)): we process only content its author made public, limited to the conversation context, retained for a limited period, and not used to build profiles of the authors.
- Product emails/updates — legitimate interest with opt-out; marketing where consent is required (6(1)(a)).
We do not sell personal data and do not use your private inputs to train our own or third-party foundation models. LLM access is API-only, via OpenRouter and the model providers available through it; we enforce routing policies that prohibit providers from training on your inputs. Providers may retain prompts for a limited period for abuse prevention and debugging under their own policies.
2a. When we act as your processor (HeyCatch SDK)
If you install the HeyCatch SDK on your website or mobile app, you are the controller of your visitors’ and users’ personal data and we process it only on your documented instructions under our Data Processing Addendum, which applies automatically to every customer using the SDK. You must disclose HeyCatch in your own privacy notice — and, for mobile apps, in your app-store privacy disclosures (Apple’s privacy details / Google Play’s Data safety section) — and obtain any legally required visitor consents (including cookie/tracking consent under ePrivacy laws) before enabling collection. If you are a visitor to a customer’s site or a user of a customer’s app, direct privacy requests to that site’s or app’s operator; we pass on any request we receive. If you are not a HeyCatch user and your public post appeared in our service: we obtained it from the public platform where you posted it (Art. 14(5)(b) notice); you may object or request erasure at support@heycatch.ai.
3. Who receives data (sub-processors / recipients)
| Recipient | Role | Location |
|---|---|---|
| Stripe | payment processing for purchases. Receives: card details entered directly in Stripe’s checkout, billing name/email, transaction amount; we see only masked card data and payment status | US |
| OpenRouter (OpenRouter, Inc.) | AI model routing for generation and analytics features. Receives: your product inputs, brand/audience info, the content of generation requests and, for AI analytics features, the end-user analytics data we process for customers, routed to third-party model providers under policies that prohibit training on inputs; providers may retain prompts for a limited period for abuse prevention | US (routing); model providers process in various locations |
| Vercel | frontend and application hosting (heycatch.ai, app.heycatch.ai). Processes request data incl. IP addresses and page requests | US |
| DigitalOcean | backend APIs, background workers, managed PostgreSQL. Stores account data, workspace content and encrypted connected-account tokens | US |
| Cloudflare | DNS for heycatch.ai. Our own DNS records are not proxied, so for our website and app Cloudflare sees lookups rather than page content. Our backend API and webhook hostnames resolve to DigitalOcean App Platform, whose ingress runs behind Cloudflare: for those requests Cloudflare terminates TLS and handles the request content | US/global |
| Clerk | authentication. Receives: name, email, password hash/OAuth identifiers, session and device data | US |
| bundle.social (Bundle sp. z o.o., Poland) | social publishing and post analytics for connected Instagram/TikTok/YouTube/Reddit accounts — stores connected-account OAuth tokens and content you publish | EU (Poland; some providers may process outside the EEA) |
| twitterapi.io (Prism Digital, LLC, Delaware) | retrieval of public X/Twitter data used to surface conversations. Receives: search queries derived from your product/audience settings (no account credentials, no personal data of yours) | US (AWS; vendor states max 48h retention) |
| FastLane (Possibility Studios Pty Ltd, Australia) | AI short-form video generation for the virality feature — receives your product/project info to generate content | Australia (may process outside AU via providers) |
| Apify (Apify Technologies s.r.o., Czech Republic) | scraping for the Reddit account audit (receives the Reddit username you connect/submit) | EU/US |
| Exa | web search used in product/competitor research (receives queries derived from your product info) | US |
| Customer.io | transactional and lifecycle email (stores contact attributes you provide at signup/waitlist) | US |
| Sentry | application error tracking. Receives request metadata, plus the pseudonymous identifiers we attach: internal user/project IDs in the app, and a pseudonymous browser/device ID on our landing pages. We do not attach email addresses, names or IP addresses | US |
| Axiom (Axiom, Inc., US) | log ingestion and querying. Receives application logs, which may include user/workspace identifiers and IPs | US/EU (AWS + Cloudflare) |
| Amplitude | marketing analytics on our landing pages (waitlist funnel), including session replay of marketing pages (typed input is masked). Receives page events, session recordings, device/browser and screen data. If you fill in the funnel, it also receives your answers as event data - including your email address (which we use as the Amplitude user ID), name, product link and chosen plan. Events also carry campaign attribution (UTM parameters), a pseudonymous visitor ID and the A/B test variants you were assigned. When you buy, our backend sends Amplitude a purchase-confirmation event with the same fields plus the payment method; card details and payment amounts are not sent | US |
| Google Analytics | website analytics on our marketing pages. Receives page events, device/browser data and IP on marketing pages | US |
| PostHog (PostHog, Inc.) | product analytics infrastructure (US Cloud). Receives usage events from our app and, where a customer enables the HeyCatch SDK, the end-user events we process on that customer’s behalf (page/screen events, sessions, IP, device/browser data, SDK identifiers) — no advertising use, session replay disabled | US |
| Crisp (Crisp IM SAS, France) | support chat on our website. Receives the messages you send in the chat, your email if you provide it, and device/usage metadata | EU (France) |
| Meta Platforms | advertising measurement on marketing pages, where enabled, as an independent controller. Receives: browser pixel page-event and device data, plus server-side conversion events carrying a hashed email address and first name; opt out per §6 (Global Privacy Control honored) | US |
| Upstash (Upstash, Inc., US) | queues and scheduled jobs. Receives job payloads referencing user/workspace identifiers | US/EU (AWS, region selectable) |
| Google Workspace | corporate email/support and our internal customer sheet. Receives the content of your emails to support@heycatch.ai, and one row per paid invoice (name, email, plan and transaction details) written to a Google Sheet we read | US/EU |
| Resend | transactional email delivery. Receives: the recipient address and the content of the message we send you | US |
| Slack (Slack Technologies, LLC) | internal engineering alerting. Receives the body of each alert, which can include stack traces and log lines carrying user, workspace and request identifiers | US |
| Trigger.dev | background job orchestration. Receives: task payloads and run logs, including user and workspace identifiers and the workspace content those jobs process | US |
| We may also disclose data | to comply with law, enforce terms, or in a merger/asset sale (with notice) | — |
Where you connect a YouTube account, publishing uses YouTube API Services (via bundle.social); Google’s Privacy Policy applies and you can revoke access at https://myaccount.google.com/permissions.
The current list is maintained at our sub-processors page. Business customers get 30-day notice of sub-processor changes via the DPA.
4. International transfers
We are US-based and process data in the US and other countries. Where the GDPR/UK GDPR applies: (a) for data transferred to us by customers (controller-to-processor or controller-to-controller), we rely on the EU Standard Contractual Clauses (2021/914) with the UK Addendum and Swiss amendments, incorporated into our DPA; (b) HeyCatch is not certified under the EU–US Data Privacy Framework; where an individual recipient is DPF-certified we may additionally rely on its certification, otherwise transfers rely on the safeguards above; (c) our sub-processor list identifies each vendor’s location.
5. Retention
Your account data and workspace content (inputs, generated outputs, connected-account content): retained for the life of the account — including after your subscription ends, so you can resume where you left off — and deleted within 30 days of your deletion request (account settings or support@heycatch.ai). End-user analytics data collected via the HeyCatch SDK (processor role): collected only while your subscription is active; retained for 2 months after subscription end so you can reactivate, then deleted or irreversibly anonymized, unless you reactivate or instruct earlier deletion. Public social content shown in catches: 30 days. Connected-account OAuth tokens: deleted promptly on disconnect and no later than 30 days after subscription end. Billing records: as required by tax law (typically 7 years). Logs: up to 13 months. Backups: managed database backups, daily, retained approximately 7 days (provider default).
6. Your rights
- EEA/UK: access, rectification, erasure, restriction, portability, objection; complaint to your supervisory authority; withdraw consent at any time.
- California (CCPA/CPRA): know/access, delete, correct, opt out of “sale”/“sharing”, limit sensitive-data use (we don’t collect it), non-discrimination. We do not sell personal information for money. If we deploy advertising pixels on our marketing sites (e.g., Meta Pixel), that disclosure may constitute “sharing” for cross-context behavioral advertising under the CPRA — you can opt out via the “Your Privacy Choices” link (available whenever such pixels are in use) or a browser with Global Privacy Control enabled, which we honor. Authorized agents may submit requests.
- Everyone: exercise rights via support@heycatch.ai or in-app. We verify requests and respond within the legally required period (30 days GDPR / 45 days CCPA, extendable).
7. Security
Encryption in transit and at rest; connected-account tokens stored encrypted with strictly limited access; access controls, least-privilege infrastructure, vendor due diligence. No system is 100% secure. If a breach affects your personal data we will notify you and regulators as required by law; where we process end-user data as your processor, we will notify you without undue delay so you can meet your own notification obligations.
8. Children
The Services are not for children under 18 and we don’t knowingly collect their data.
9. Do Not Track / GPC
We honor Global Privacy Control signals for opt-out where legally required.
10. Changes and contact
We’ll notify material changes by email or in-app; continued use after the effective date is acceptance. If we materially change our cookie or tracking practices (for example, adding new advertising pixels), we will update this Policy and, where consent is legally required, obtain it anew rather than rely on prior consent. Questions or requests: support@heycatch.ai · HeyCatch, Inc., 1111B S Governors Ave STE 59736, Dover, DE 19904, USA. If required, our EU/UK representative details will be published at this page.