Privacy Policy

Last updated: August 31, 2026

This Policy explains how HeyCatch, Inc. (1111B S Governors Ave STE 59736, Dover, DE 19904, USA) processes personal data when you use heycatch.ai and our services. For data you submit about your own customers or audience, you are the controller and we act as your processor (see our Data Processing Addendum).

1. Data we process

CategoryExamplesSource
Account dataname, email, password hash, workspace nameyou
Billing dataplan, transaction history; payment card handled by Stripe — we never store card numbersyou / billing partner
Product inputsproduct descriptions, brand info, audience/ICP data, connected-account content you submit for analysisyou
Usage datafeature usage, logs, device/browser, IP, approximate locationautomatic
Communicationssupport requests, emailsyou
End-user analytics data (processor role)site/app visits, sessions, interaction events (clicks/taps and form submissions — not the contents of inputs), signup and payment events, IP and device data of visitors to our customers’ websites and users of their mobile apps, collected by the HeyCatch SDK the customer installscustomer’s site visitors and app users (automatic, on the customer’s behalf)
Public social contentpublic posts, comments, usernames and profile context from platforms such as Reddit and X, retrieved via platform APIs and API partners to surface relevant conversationspublic sources
Cookiessession, preferences, analytics (Amplitude — including session replay of marketing pages, with typed input masked — and Google Analytics on marketing pages; PostHog in the product app), support chat (Crisp), advertising pixels on marketing pages (Meta Pixel, where enabled — see §6 for your opt-out choices)automatic

We do not intentionally collect special-category (sensitive) data — please don’t submit it.

2. Why we process it (GDPR legal bases)

We do not sell personal data and do not use your private inputs to train our own or third-party foundation models. LLM access is API-only, via OpenRouter and the model providers available through it; we enforce routing policies that prohibit providers from training on your inputs. Providers may retain prompts for a limited period for abuse prevention and debugging under their own policies.

2a. When we act as your processor (HeyCatch SDK)

If you install the HeyCatch SDK on your website or mobile app, you are the controller of your visitors’ and users’ personal data and we process it only on your documented instructions under our Data Processing Addendum, which applies automatically to every customer using the SDK. You must disclose HeyCatch in your own privacy notice — and, for mobile apps, in your app-store privacy disclosures (Apple’s privacy details / Google Play’s Data safety section) — and obtain any legally required visitor consents (including cookie/tracking consent under ePrivacy laws) before enabling collection. If you are a visitor to a customer’s site or a user of a customer’s app, direct privacy requests to that site’s or app’s operator; we pass on any request we receive. If you are not a HeyCatch user and your public post appeared in our service: we obtained it from the public platform where you posted it (Art. 14(5)(b) notice); you may object or request erasure at support@heycatch.ai.

3. Who receives data (sub-processors / recipients)

RecipientRoleLocation
Stripepayment processing for purchases. Receives: card details entered directly in Stripe’s checkout, billing name/email, transaction amount; we see only masked card data and payment statusUS
OpenRouter (OpenRouter, Inc.)AI model routing for generation and analytics features. Receives: your product inputs, brand/audience info, the content of generation requests and, for AI analytics features, the end-user analytics data we process for customers, routed to third-party model providers under policies that prohibit training on inputs; providers may retain prompts for a limited period for abuse preventionUS (routing); model providers process in various locations
Vercelfrontend and application hosting (heycatch.ai, app.heycatch.ai). Processes request data incl. IP addresses and page requestsUS
DigitalOceanbackend APIs, background workers, managed PostgreSQL. Stores account data, workspace content and encrypted connected-account tokensUS
CloudflareDNS for heycatch.ai. Our own DNS records are not proxied, so for our website and app Cloudflare sees lookups rather than page content. Our backend API and webhook hostnames resolve to DigitalOcean App Platform, whose ingress runs behind Cloudflare: for those requests Cloudflare terminates TLS and handles the request contentUS/global
Clerkauthentication. Receives: name, email, password hash/OAuth identifiers, session and device dataUS
bundle.social (Bundle sp. z o.o., Poland)social publishing and post analytics for connected Instagram/TikTok/YouTube/Reddit accounts — stores connected-account OAuth tokens and content you publishEU (Poland; some providers may process outside the EEA)
twitterapi.io (Prism Digital, LLC, Delaware)retrieval of public X/Twitter data used to surface conversations. Receives: search queries derived from your product/audience settings (no account credentials, no personal data of yours)US (AWS; vendor states max 48h retention)
FastLane (Possibility Studios Pty Ltd, Australia)AI short-form video generation for the virality feature — receives your product/project info to generate contentAustralia (may process outside AU via providers)
Apify (Apify Technologies s.r.o., Czech Republic)scraping for the Reddit account audit (receives the Reddit username you connect/submit)EU/US
Exaweb search used in product/competitor research (receives queries derived from your product info)US
Customer.iotransactional and lifecycle email (stores contact attributes you provide at signup/waitlist)US
Sentryapplication error tracking. Receives request metadata, plus the pseudonymous identifiers we attach: internal user/project IDs in the app, and a pseudonymous browser/device ID on our landing pages. We do not attach email addresses, names or IP addressesUS
Axiom (Axiom, Inc., US)log ingestion and querying. Receives application logs, which may include user/workspace identifiers and IPsUS/EU (AWS + Cloudflare)
Amplitudemarketing analytics on our landing pages (waitlist funnel), including session replay of marketing pages (typed input is masked). Receives page events, session recordings, device/browser and screen data. If you fill in the funnel, it also receives your answers as event data - including your email address (which we use as the Amplitude user ID), name, product link and chosen plan. Events also carry campaign attribution (UTM parameters), a pseudonymous visitor ID and the A/B test variants you were assigned. When you buy, our backend sends Amplitude a purchase-confirmation event with the same fields plus the payment method; card details and payment amounts are not sentUS
Google Analyticswebsite analytics on our marketing pages. Receives page events, device/browser data and IP on marketing pagesUS
PostHog (PostHog, Inc.)product analytics infrastructure (US Cloud). Receives usage events from our app and, where a customer enables the HeyCatch SDK, the end-user events we process on that customer’s behalf (page/screen events, sessions, IP, device/browser data, SDK identifiers) — no advertising use, session replay disabledUS
Crisp (Crisp IM SAS, France)support chat on our website. Receives the messages you send in the chat, your email if you provide it, and device/usage metadataEU (France)
Meta Platformsadvertising measurement on marketing pages, where enabled, as an independent controller. Receives: browser pixel page-event and device data, plus server-side conversion events carrying a hashed email address and first name; opt out per §6 (Global Privacy Control honored)US
Upstash (Upstash, Inc., US)queues and scheduled jobs. Receives job payloads referencing user/workspace identifiersUS/EU (AWS, region selectable)
Google Workspacecorporate email/support and our internal customer sheet. Receives the content of your emails to support@heycatch.ai, and one row per paid invoice (name, email, plan and transaction details) written to a Google Sheet we readUS/EU
Resendtransactional email delivery. Receives: the recipient address and the content of the message we send youUS
Slack (Slack Technologies, LLC)internal engineering alerting. Receives the body of each alert, which can include stack traces and log lines carrying user, workspace and request identifiersUS
Trigger.devbackground job orchestration. Receives: task payloads and run logs, including user and workspace identifiers and the workspace content those jobs processUS
We may also disclose datato comply with law, enforce terms, or in a merger/asset sale (with notice)

Where you connect a YouTube account, publishing uses YouTube API Services (via bundle.social); Google’s Privacy Policy applies and you can revoke access at https://myaccount.google.com/permissions.

The current list is maintained at our sub-processors page. Business customers get 30-day notice of sub-processor changes via the DPA.

4. International transfers

We are US-based and process data in the US and other countries. Where the GDPR/UK GDPR applies: (a) for data transferred to us by customers (controller-to-processor or controller-to-controller), we rely on the EU Standard Contractual Clauses (2021/914) with the UK Addendum and Swiss amendments, incorporated into our DPA; (b) HeyCatch is not certified under the EU–US Data Privacy Framework; where an individual recipient is DPF-certified we may additionally rely on its certification, otherwise transfers rely on the safeguards above; (c) our sub-processor list identifies each vendor’s location.

5. Retention

Your account data and workspace content (inputs, generated outputs, connected-account content): retained for the life of the account — including after your subscription ends, so you can resume where you left off — and deleted within 30 days of your deletion request (account settings or support@heycatch.ai). End-user analytics data collected via the HeyCatch SDK (processor role): collected only while your subscription is active; retained for 2 months after subscription end so you can reactivate, then deleted or irreversibly anonymized, unless you reactivate or instruct earlier deletion. Public social content shown in catches: 30 days. Connected-account OAuth tokens: deleted promptly on disconnect and no later than 30 days after subscription end. Billing records: as required by tax law (typically 7 years). Logs: up to 13 months. Backups: managed database backups, daily, retained approximately 7 days (provider default).

6. Your rights

7. Security

Encryption in transit and at rest; connected-account tokens stored encrypted with strictly limited access; access controls, least-privilege infrastructure, vendor due diligence. No system is 100% secure. If a breach affects your personal data we will notify you and regulators as required by law; where we process end-user data as your processor, we will notify you without undue delay so you can meet your own notification obligations.

8. Children

The Services are not for children under 18 and we don’t knowingly collect their data.

9. Do Not Track / GPC

We honor Global Privacy Control signals for opt-out where legally required.

10. Changes and contact

We’ll notify material changes by email or in-app; continued use after the effective date is acceptance. If we materially change our cookie or tracking practices (for example, adding new advertising pixels), we will update this Policy and, where consent is legally required, obtain it anew rather than rely on prior consent. Questions or requests: support@heycatch.ai · HeyCatch, Inc., 1111B S Governors Ave STE 59736, Dover, DE 19904, USA. If required, our EU/UK representative details will be published at this page.


© HeyCatch, Inc. All rights reserved.