Privacy Policy

Last updated: July 15, 2026

This Policy explains how HeyCatch, Inc. (1111B S Governors Ave STE 59736, Dover, DE 19904, USA) processes personal data when you use heycatch.ai and our services. For data you submit about your own customers or audience, you are the controller and we act as your processor (see our Data Processing Addendum).

1. Data we process

CategoryExamplesSource
Account dataname, email, password hash, workspace nameyou
Billing dataplan, transaction history; payment card handled by Paddle or Stripe — we never store card numbersyou / billing partner
Product inputsproduct descriptions, brand info, audience/ICP data, connected-account content you submit for analysisyou
Usage datafeature usage, logs, device/browser, IP, approximate locationautomatic
Communicationssupport requests, emailsyou
End-user analytics data (processor role)site visits, sessions, signup and payment events, IP and device data of visitors to our customers’ websites, collected by the HeyCatch SDK the customer installscustomer’s site visitors (automatic, on the customer’s behalf)
Public social contentpublic posts, comments, usernames and profile context from platforms such as Reddit and X, retrieved via platform APIs and API partners to surface relevant conversationspublic sources
Cookiessession, preferences, analytics (Amplitude and Google Analytics on marketing pages), advertising pixels on marketing pages (none currently active; any future pixels will be introduced behind a consent banner where required)automatic

We do not intentionally collect special-category (sensitive) data — please don’t submit it.

2. Why we process it (GDPR legal bases)

We do not sell personal data and do not use your private inputs to train our own or third-party foundation models. LLM access is API-only (Anthropic, directly and via Google Vertex AI), with no training opt-ins enabled.

2a. When we act as your processor (HeyCatch SDK)

If you install the HeyCatch SDK on your website, you are the controllerof your visitors’ personal data and we process it only on your documented instructions under our Data Processing Addendum, which applies automatically to every customer using the SDK. You must disclose HeyCatch in your own privacy notice and obtain any legally required visitor consents (including cookie/tracking consent under ePrivacy laws) before enabling collection. If you are a visitor to a customer’s site, direct privacy requests to that site’s operator; we pass on any request we receive. If you are not a HeyCatch user and your public post appeared in our service: we obtained it from the public platform where you posted it (Art. 14(5)(b) notice); you may object or request erasure at support@heycatch.ai.

3. Who receives data (sub-processors / recipients)

RecipientRoleLocation
Paddle (Paddle.com Inc. / Paddle.com Market Ltd.)merchant of record for purchases — independent controller of transaction data. Receives: name, email, billing country, plan and transaction details; your card details are entered directly with Paddle and never reach usUS/UK
Stripepayment processing for direct purchases. Receives: card details entered directly in Stripe’s checkout, billing name/email, transaction amount; we see only masked card data and payment statusUS
AnthropicLLM API provider. Receives: your product inputs, brand/audience info and the content of generation requests, to generate outputs; not used to train models. Served directly and via Google Vertex AIUS
Google CloudAI/compute infrastructure (Vertex AI). Receives the same generation inputs where Claude is served via VertexUS
Vercelfrontend and application hosting (heycatch.ai, app.heycatch.ai). Processes request data incl. IP addresses and page requestsUS
DigitalOceanbackend APIs, background workers, managed PostgreSQL. Stores account data, workspace content and encrypted connected-account tokensUS
CloudflareDNS for heycatch.ai (DNS-only; traffic is not proxied). Sees DNS lookups only, no page contentUS/global
Clerkauthentication. Receives: name, email, password hash/OAuth identifiers, session and device dataUS
bundle.social (Bundle sp. z o.o., Poland)social publishing and post analytics for connected Instagram/TikTok/YouTube/Reddit accounts — stores connected-account OAuth tokens and content you publishEU (Poland; some providers may process outside the EEA)
twitterapi.io (Prism Digital, LLC, Delaware)retrieval of public X/Twitter data used to surface conversations. Receives: search queries derived from your product/audience settings (no account credentials, no personal data of yours)US (AWS; vendor states max 48h retention)
FastLane (Possibility Studios Pty Ltd, Australia)AI short-form video generation for the virality feature — receives your product/project info to generate contentAustralia (may process outside AU via providers)
Apify (Apify Technologies s.r.o., Czech Republic)scraping for the Reddit account audit (receives the Reddit username you connect/submit)EU/US
Exaweb search used in product/competitor research (receives queries derived from your product info)US
Customer.iotransactional and lifecycle email (stores contact attributes you provide at signup/waitlist)US
Sentryapplication error tracking (may capture request metadata)US
Axiom (Axiom, Inc., US)log ingestion and querying. Receives application logs, which may include user/workspace identifiers and IPsUS/EU (AWS + Cloudflare)
Amplitudemarketing analytics on our landing pages (waitlist funnel). Receives page events, device/browser data and identifiers on marketing pages onlyUS
Google Analyticswebsite analytics on our marketing pages. Receives page events, device/browser data and IP on marketing pagesUS
Upstash (Upstash, Inc., US)queues and scheduled jobs. Receives job payloads referencing user/workspace identifiersUS/EU (AWS, region selectable)
Google Workspacecorporate email/support. Receives the content of your emails to support@heycatch.aiUS/EU
We may also disclose datato comply with law, enforce terms, or in a merger/asset sale (with notice)

Where you connect a YouTube account, publishing uses YouTube API Services(via bundle.social); Google’s Privacy Policy applies and you can revoke access at https://myaccount.google.com/permissions.

The current list is maintained at our sub-processors page. Business customers get 30-day notice of sub-processor changes via the DPA.

4. International transfers

We are US-based and process data in the US and other countries. Where the GDPR/UK GDPR applies: (a) for data transferred to us by customers (controller-to-processor or controller-to-controller), we rely on the EU Standard Contractual Clauses (2021/914) with the UK Addendum and Swiss amendments, incorporated into our DPA; (b) HeyCatch is not certified under the EU–US Data Privacy Framework; where an individual recipient is DPF-certified we may additionally rely on its certification, otherwise transfers rely on the safeguards above; (c) our sub-processor list identifies each vendor’s location.

5. Retention

Your account data and workspace content (inputs, generated outputs, connected-account content): retained for the life of the account — including after your subscription ends, so you can resume where you left off — and deleted within 30 days of your deletion request (account settings or support@heycatch.ai). End-user analytics data collected via the HeyCatch SDK (processor role): collected only while your subscription is active; retained for 2 months after subscription end so you can reactivate, then deleted or irreversibly anonymized, unless you reactivate or instruct earlier deletion. Public social content shown in catches: 30 days. Connected-account OAuth tokens: deleted promptly on disconnect and no later than 30 days after subscription end. Billing records: as required by tax law (typically 7 years). Logs: up to 13 months. Backups: managed database backups, daily, retained approximately 7 days (provider default).

6. Your rights

7. Security

Encryption in transit and at rest; connected-account tokens stored encrypted with strictly limited access; access controls, least-privilege infrastructure, vendor due diligence. No system is 100% secure. If a breach affects your personal data we will notify you and regulators as required by law; where we process end-user data as your processor, we will notify you without undue delay so you can meet your own notification obligations.

8. Children

The Services are not for children under 18 and we don’t knowingly collect their data.

9. Do Not Track / GPC

We honor Global Privacy Control signals for opt-out where legally required.

10. Changes and contact

We’ll notify material changes by email or in-app; continued use after the effective date is acceptance. If we materially change our cookie or tracking practices (for example, adding new advertising pixels), we will update this Policy and, where consent is legally required, obtain it anew rather than rely on prior consent. Questions or requests: support@heycatch.ai · HeyCatch, Inc., 1111B S Governors Ave STE 59736, Dover, DE 19904, USA. If required, our EU/UK representative details will be published at this page.


© HeyCatch, Inc. All rights reserved.