Legal

Privacy Policy

This Privacy Policy explains how Nodebyte OÜ ("we", "us", "our") collects and uses personal data when you use Mediastilo (the "Service"), and the rights you have over that data. Nodebyte OÜ is a company registered in Estonia, with its seat in Tallinn, and is the controller of the personal data described here.

For the personal data contained in the content you process through the Service on behalf of your own contacts and audiences, you are the controller and we act as your processor. That relationship is governed by our Data Processing Agreement. This Policy covers the data we handle as controller: your account, your use of the Service, and our communication with you.

Last reviewed: 20 July 2026

1. Who to contact

You can reach us about privacy at contact@heap-software.com, or by post to Nodebyte OÜ, Tallinn, Estonia. We have not appointed a statutory Data Protection Officer, because we are not required to, but the address above reaches the people responsible for data protection.

2. The data we collect

Data you give us.

  • Account data: your name, email address, password (stored only as a salted hash), and the name of your organisation or brand.
  • Billing data: your billing name and address, VAT identification number where you provide one, and a record of your plan, invoices, and credit balance. Card details are entered directly with Stripe and never reach our systems. We receive a token and the last four digits, not the full card number.
  • Content data: everything you submit or generate in the Service, including prompts, brand voice profiles, drafts, uploaded documents, and the source material you ingest. This may contain personal data if you choose to put it there.
  • Support data: the messages you send us and their contents.

Data we collect automatically.

  • Usage and device data: how you interact with the Service, along with your IP address, browser type, and similar technical information, collected to keep the Service running, secure, and measured.
  • Cookies and local storage: a small set of strictly functional and preference cookies, described in our Cookie Policy. We do not use advertising or third-party analytics cookies.

We do not intentionally collect special categories of personal data (such as health or political opinions) about you as our customer. Please do not put such data about identifiable people into the Service unless you have a lawful basis to process it and are prepared to be its controller.

3. Why we use it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and running your account, providing the Service, and processing your content at your instructionPerformance of a contract
Billing, collecting payment, and keeping the required financial recordsPerformance of a contract; compliance with a legal obligation
Securing the Service, preventing abuse and fraud, and debuggingOur legitimate interest in a safe and reliable service
Measuring and improving the Service using aggregated and technical dataOur legitimate interest in understanding and improving what we offer
Sending you service and transactional messages (for example, about your account, security, or a payment)Performance of a contract; our legitimate interest in operating the Service
Sending you product or marketing email, where we do thisYour consent, or our legitimate interest where the law allows, in each case with an easy opt-out
Responding to your requests and meeting legal and regulatory obligationsOur legitimate interest; compliance with a legal obligation

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to that processing as described in section 8.

4. How AI processing works

AI features are core to the Service. When you generate or analyse content, the content you submit or produce is sent to our AI provider, Google, through the Google Gemini API, so that a model can act on it. Where you enable web grounding, search queries derived from your content are sent to Google Search. Our provider processes this data only to return a result to us and under contractual terms that prohibit using your content to train its general models. AI output can be inaccurate, as explained in our Terms of Service; this Policy concerns the personal data involved, not the reliability of the output.

5. Who we share data with

We do not sell your personal data. We share it only in these situations:

  • Subprocessors. We use a small number of vetted providers to host and run the Service, process payments, send email, and monitor performance. Each is listed, with its purpose, the data it processes, and its location, on our Subprocessors page. Each is bound by a written contract with data-protection obligations.
  • At your instruction. When you publish a draft or connect an integration, we send your content to the destination you chose, using your credentials. You control those transfers.
  • Legal reasons. We may disclose data where we are legally required to, or to establish, exercise, or defend legal claims, or to protect the rights, safety, and security of our users, the public, or us.
  • Business transfer. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will require the recipient to honour this Policy, and we will tell you before your data becomes subject to a different privacy policy.

6. International transfers

Our primary database and core application processing are in the European Union. Some of our subprocessors, including Google, Stripe, and Axiom, process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision of the European Commission where one applies, including the EU-US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses together with supplementary measures. The Subprocessors page records where each provider processes data.

7. How long we keep it

  • While your account is active, we keep your account, billing, and content data so we can provide the Service.
  • When you close your account, we begin a 30-day retention window during which the account is deactivated and recoverable if you contact us. After the window, the account and its personal data are permanently deleted.
  • An anonymised financial record, the credit and billing ledger stripped of any link to you as an individual, is kept beyond that window to meet our accounting and audit obligations. It can no longer be traced back to you.
  • Backups age out on our normal backup cycle after deletion.
  • Where the law requires us to keep certain records (for example, invoices for tax purposes), we keep those for the period the law requires.

8. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • ask us to correct data that is inaccurate or incomplete;
  • ask us to erase your data ("right to be forgotten"), subject to records we must keep;
  • restrict or object to our processing, including processing based on legitimate interests, and object to direct marketing at any time;
  • receive the data you gave us in a portable, machine-readable format (portability);
  • withdraw consent at any time where we rely on consent, without affecting processing already carried out.

To exercise any of these, email contact@heap-software.com. Much of your data is also directly available or deletable inside the app under Settings. We will respond within the time the law allows, normally one month. You will not have to pay a fee unless your request is clearly unfounded or excessive.

You also have the right to complain to a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). If you are in another EU country, you may complain to your local authority instead; in Croatia this is the Personal Data Protection Agency (AZOP, azop.hr).

9. How we protect data

We use technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access controls that limit who can reach personal data, encrypted database backups, and continuous monitoring for errors and abuse. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents. If a breach affects your rights, we will notify you and the relevant authority as the law requires.

10. Children

The Service is not directed at children and is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy. If we make a material change, we will give reasonable notice, for example by email or a notice in the app, before it takes effect. The "last reviewed" date above always shows the current version.

12. Contact

Privacy questions or requests: contact@heap-software.com

Nodebyte OÜ, Tallinn, Estonia.