Privacy Policy
This Policy explains how HeyCatch, Inc. (1111B S Governors Ave STE 59736, Dover, DE 19904, USA) processes personal data when you use heycatch.ai and our services. For data you submit about your own customers or audience, you are the controller and we act as your processor (see our Data Processing Addendum).
1. Data we process
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, password hash, workspace name | you |
| Billing data | plan, transaction history; payment card handled by Paddle or Stripe — we never store card numbers | you / billing partner |
| Product inputs | product descriptions, brand info, audience/ICP data, connected-account content you submit for analysis | you |
| Usage data | feature usage, logs, device/browser, IP, approximate location | automatic |
| Communications | support requests, emails | you |
| End-user analytics data (processor role) | site visits, sessions, signup and payment events, IP and device data of visitors to our customers’ websites, collected by the HeyCatch SDK the customer installs | customer’s site visitors (automatic, on the customer’s behalf) |
| Public social content | public posts, comments, usernames and profile context from platforms such as Reddit and X, retrieved via platform APIs and API partners to surface relevant conversations | public sources |
| Cookies | session, preferences, analytics (Amplitude and Google Analytics on marketing pages), advertising pixels on marketing pages (none currently active; any future pixels will be introduced behind a consent banner where required) | automatic |
We do not intentionally collect special-category (sensitive) data — please don’t submit it.
2. Why we process it (GDPR legal bases)
- Provide the Services — contract performance (Art. 6(1)(b)).
- Generate AI outputs from your inputs — contract performance; model providers process inputs as our processors/sub-processors.
- Billing, tax, accounting — legal obligation and contract (6(1)(c),(b)).
- Security, abuse prevention, service analytics — legitimate interests (6(1)(f)).
- Surface relevant public conversations (“catches”) — legitimate interests (6(1)(f)): we process only content its author made public, limited to the conversation context, retained for a limited period, and not used to build profiles of the authors.
- Product emails/updates — legitimate interest with opt-out; marketing where consent is required (6(1)(a)).
We do not sell personal data and do not use your private inputs to train our own or third-party foundation models. LLM access is API-only (Anthropic, directly and via Google Vertex AI), with no training opt-ins enabled.
2a. When we act as your processor (HeyCatch SDK)
If you install the HeyCatch SDK on your website, you are the controllerof your visitors’ personal data and we process it only on your documented instructions under our Data Processing Addendum, which applies automatically to every customer using the SDK. You must disclose HeyCatch in your own privacy notice and obtain any legally required visitor consents (including cookie/tracking consent under ePrivacy laws) before enabling collection. If you are a visitor to a customer’s site, direct privacy requests to that site’s operator; we pass on any request we receive. If you are not a HeyCatch user and your public post appeared in our service: we obtained it from the public platform where you posted it (Art. 14(5)(b) notice); you may object or request erasure at support@heycatch.ai.
3. Who receives data (sub-processors / recipients)
| Recipient | Role | Location |
|---|---|---|
| Paddle (Paddle.com Inc. / Paddle.com Market Ltd.) | merchant of record for purchases — independent controller of transaction data. Receives: name, email, billing country, plan and transaction details; your card details are entered directly with Paddle and never reach us | US/UK |
| Stripe | payment processing for direct purchases. Receives: card details entered directly in Stripe’s checkout, billing name/email, transaction amount; we see only masked card data and payment status | US |
| Anthropic | LLM API provider. Receives: your product inputs, brand/audience info and the content of generation requests, to generate outputs; not used to train models. Served directly and via Google Vertex AI | US |
| Google Cloud | AI/compute infrastructure (Vertex AI). Receives the same generation inputs where Claude is served via Vertex | US |
| Vercel | frontend and application hosting (heycatch.ai, app.heycatch.ai). Processes request data incl. IP addresses and page requests | US |
| DigitalOcean | backend APIs, background workers, managed PostgreSQL. Stores account data, workspace content and encrypted connected-account tokens | US |
| Cloudflare | DNS for heycatch.ai (DNS-only; traffic is not proxied). Sees DNS lookups only, no page content | US/global |
| Clerk | authentication. Receives: name, email, password hash/OAuth identifiers, session and device data | US |
| bundle.social (Bundle sp. z o.o., Poland) | social publishing and post analytics for connected Instagram/TikTok/YouTube/Reddit accounts — stores connected-account OAuth tokens and content you publish | EU (Poland; some providers may process outside the EEA) |
| twitterapi.io (Prism Digital, LLC, Delaware) | retrieval of public X/Twitter data used to surface conversations. Receives: search queries derived from your product/audience settings (no account credentials, no personal data of yours) | US (AWS; vendor states max 48h retention) |
| FastLane (Possibility Studios Pty Ltd, Australia) | AI short-form video generation for the virality feature — receives your product/project info to generate content | Australia (may process outside AU via providers) |
| Apify (Apify Technologies s.r.o., Czech Republic) | scraping for the Reddit account audit (receives the Reddit username you connect/submit) | EU/US |
| Exa | web search used in product/competitor research (receives queries derived from your product info) | US |
| Customer.io | transactional and lifecycle email (stores contact attributes you provide at signup/waitlist) | US |
| Sentry | application error tracking (may capture request metadata) | US |
| Axiom (Axiom, Inc., US) | log ingestion and querying. Receives application logs, which may include user/workspace identifiers and IPs | US/EU (AWS + Cloudflare) |
| Amplitude | marketing analytics on our landing pages (waitlist funnel). Receives page events, device/browser data and identifiers on marketing pages only | US |
| Google Analytics | website analytics on our marketing pages. Receives page events, device/browser data and IP on marketing pages | US |
| Upstash (Upstash, Inc., US) | queues and scheduled jobs. Receives job payloads referencing user/workspace identifiers | US/EU (AWS, region selectable) |
| Google Workspace | corporate email/support. Receives the content of your emails to support@heycatch.ai | US/EU |
| We may also disclose data | to comply with law, enforce terms, or in a merger/asset sale (with notice) | — |
Where you connect a YouTube account, publishing uses YouTube API Services(via bundle.social); Google’s Privacy Policy applies and you can revoke access at https://myaccount.google.com/permissions.
The current list is maintained at our sub-processors page. Business customers get 30-day notice of sub-processor changes via the DPA.
4. International transfers
We are US-based and process data in the US and other countries. Where the GDPR/UK GDPR applies: (a) for data transferred to us by customers (controller-to-processor or controller-to-controller), we rely on the EU Standard Contractual Clauses (2021/914) with the UK Addendum and Swiss amendments, incorporated into our DPA; (b) HeyCatch is not certified under the EU–US Data Privacy Framework; where an individual recipient is DPF-certified we may additionally rely on its certification, otherwise transfers rely on the safeguards above; (c) our sub-processor list identifies each vendor’s location.
5. Retention
Your account data and workspace content (inputs, generated outputs, connected-account content): retained for the life of the account — including after your subscription ends, so you can resume where you left off — and deleted within 30 days of your deletion request (account settings or support@heycatch.ai). End-user analytics data collected via the HeyCatch SDK (processor role): collected only while your subscription is active; retained for 2 months after subscription end so you can reactivate, then deleted or irreversibly anonymized, unless you reactivate or instruct earlier deletion. Public social content shown in catches: 30 days. Connected-account OAuth tokens: deleted promptly on disconnect and no later than 30 days after subscription end. Billing records: as required by tax law (typically 7 years). Logs: up to 13 months. Backups: managed database backups, daily, retained approximately 7 days (provider default).
6. Your rights
- EEA/UK: access, rectification, erasure, restriction, portability, objection; complaint to your supervisory authority; withdraw consent at any time.
- California (CCPA/CPRA):know/access, delete, correct, opt out of “sale”/“sharing”, limit sensitive-data use (we don’t collect it), non-discrimination. We do not sell personal information for money.If we deploy advertising pixels on our marketing sites (e.g., Meta Pixel), that disclosure may constitute “sharing” for cross-context behavioral advertising under the CPRA — you can opt out via the “Your Privacy Choices” link (available whenever such pixels are in use) or a browser with Global Privacy Control enabled, which we honor. Authorized agents may submit requests.
- Everyone: exercise rights via support@heycatch.ai or in-app. We verify requests and respond within the legally required period (30 days GDPR / 45 days CCPA, extendable).
7. Security
Encryption in transit and at rest; connected-account tokens stored encrypted with strictly limited access; access controls, least-privilege infrastructure, vendor due diligence. No system is 100% secure. If a breach affects your personal data we will notify you and regulators as required by law; where we process end-user data as your processor, we will notify you without undue delay so you can meet your own notification obligations.
8. Children
The Services are not for children under 18 and we don’t knowingly collect their data.
9. Do Not Track / GPC
We honor Global Privacy Control signals for opt-out where legally required.
10. Changes and contact
We’ll notify material changes by email or in-app; continued use after the effective date is acceptance. If we materially change our cookie or tracking practices (for example, adding new advertising pixels), we will update this Policy and, where consent is legally required, obtain it anew rather than rely on prior consent. Questions or requests: support@heycatch.ai · HeyCatch, Inc., 1111B S Governors Ave STE 59736, Dover, DE 19904, USA. If required, our EU/UK representative details will be published at this page.