Privacy Policy
Introduction
HEKLA LTD (“Nikita”, “we”, “us”) is committed to protecting your personal data. This policy describes how we collect, use, and protect your data when you use heynikita.ai.
Data Controller
HEKLA LTD
Identification number: BG207563892
Registered office: bul./ul. Tsar Asen n° 11, Triaditsa district, 1000 Sofia, Stolichna, Bulgaria
Contact: [email protected]
Data we collect
- Account information: email address, name when you sign up or join the waitlist
- Meta Business Manager data: ad performance data, creative assets, campaign structure (read-only access, never modified)
- Usage data: pages visited, features used, anonymized analytics
- Brand Hub data: brand information you voluntarily provide (voice, positioning, personas, products)
How we use your data
- To provide and improve Nikita's services
- To analyze your ad account and generate creative intelligence (this is the core service)
- To communicate with you about your account and product updates
- To ensure security and prevent fraud
Meta Ads Data
Nikita accesses your Meta Business Manager with read-only permissions. We never modify your campaigns, ads, or settings. Your ad data is processed solely to provide you with creative intelligence. We do not sell, share, or transfer your ad data to any third party.
Data retention
- Account data: retained as long as your account is active
- Meta Ads data: processed in real-time, not permanently stored in raw form
- Brand Hub data: retained as long as your account is active, deleted upon account deletion
- Waitlist data: retained until you unsubscribe or the product launches
Your rights (GDPR)
Under EU/EEA regulations, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Delete your data (“right to be forgotten”)
- Restrict processing
- Data portability
- Object to processing
To exercise any of these rights, contact us at [email protected].
Cookies
Our site uses strictly necessary cookies and anonymized analytics cookies. You can configure your browser to refuse cookies.
Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, modification, disclosure, or destruction.
Third-party services
- Supabase (database and authentication): hosted in EU
- Railway (hosting): San Francisco, CA, USA
- Meta Marketing API: data accessed via official API with your authorization
Changes
We reserve the right to update this policy at any time. The last update date is indicated below.
Last updated: April 2026