Privacy Policy

Effective June 15, 2026·Updated June 15, 2026

This Privacy Policy explains how Aminta collects, uses, stores, and protects your information when you use the Aminta Chrome extension and web application. We are committed to transparency and to protecting your privacy under applicable law, including the EU General Data Protection Regulation (GDPR).

Data Controller

Aminta is operated by an independent developer based in North Macedonia. For the purposes of EU data protection law, the data controller is:

Aminta, North Macedonia

Email: hello@amintaapp.com

If you have any questions about this Privacy Policy or about how we handle your data, please contact us at the address above.

Information We Collect

We collect the minimum information necessary to provide and improve the Aminta service. The categories below describe what we collect, why we collect it, and how.

2.1 Account Information

When you create an Aminta account, we collect your email address and, if you choose to provide it, your display name. We use this to authenticate you, send service-related communications, and associate your data with your account.

2.2 User-Generated Content

Aminta processes text you provide as input, such as topics, draft posts, reply targets, and instructions, to generate AI-assisted content. This input is transmitted to the AI provider handling the request (see §8) to fulfil it. We do not permanently store the raw text of your prompts or generated outputs unless you explicitly save them within the application.

2.3 Voice Profile Data

If you configure a Voice Profile, you may provide sample posts and descriptions of your tone and writing style. This profile is stored in your account so that the AI can write in your voice. You can delete or modify your Voice Profile at any time from your account settings.

2.4 Browser Extension Data

The Aminta Chrome extension operates locally in your browser. It reads the active tab to detect the X (Twitter) composer so it can inject generated content on request. We do not collect or transmit your browsing history. See §6 for a full list of extension permissions.

2.5 Usage Analytics

We collect usage data to understand how Aminta is used and to improve the product. This may include feature usage frequency, error rates, and session duration. When you are signed in, this data may be linked to your account (see §8.3). We do not collect the content of your prompts or generated output through analytics.

2.6 API Keys

If you choose to use your own API keys (Bring Your Own Key, BYOK), those keys are stored exclusively in your browser's local storage. They are never transmitted to Aminta's servers. API requests made using your keys go directly from your browser to the respective AI provider. You are solely responsible for managing and protecting your API keys.

We do not sell your personal data. Your information is used only to provide and improve the Aminta service.

How We Use Your Information

We use the information we collect for the following purposes:

  • Providing, maintaining, and improving the Aminta extension and web application.
  • Authenticating your identity and managing your account.
  • Transmitting your prompts to AI providers to generate content on your behalf.
  • Storing your Voice Profile so Aminta can write in your style.
  • Sending transactional emails (account confirmation, password reset, billing receipts).
  • Analysing usage patterns to improve features and performance.
  • Preventing fraud, abuse, and violations of our Terms of Service.
  • Complying with our legal obligations under Belgian and EU law.

We do not use your content to train AI models. We do not use your data for advertising purposes. We do not share your personal data with third parties except as described in §8 and as required by law.

AI Processing Disclosure

Aminta uses third-party AI models to generate content on your behalf. When you use a generation feature, your prompt (including any Voice Profile context you have enabled) is transmitted to the AI provider you have selected or that we have configured as the default.

Each AI provider has its own privacy policy and terms of service. You are encouraged to review these before using Aminta, in particular regarding how providers handle submitted data and whether they use it for model training.

Generated content belongs to you. Aminta does not claim ownership over content produced using your prompts or Voice Profile. You are responsible for reviewing AI-generated content before publishing it. AI outputs may be inaccurate, incomplete, or unsuitable. Always review before use.

Chrome Extension Permissions

The Aminta Chrome extension requests the following browser permissions. We request only the permissions necessary for the extension to function.

  • activeTab:Allows Aminta to read the current tab's URL and inject content into the X composer when you activate the extension. We do not read page content unless you explicitly use a feature that requires it (e.g., Reply Generator reading a tweet you are replying to).
  • storage: Used to store your settings, Voice Profile, XP progress, and BYOK API keys locally in your browser. This data does not leave your device unless you are logged in and sync is enabled.
  • Host permissions (x.com, twitter.com):Required to detect the active composer and inject generated content into the text field when you click "Insert into X".

We do not access your browsing history. We do not read page content on sites you visit other than the supported platforms listed above, and only when you have activated the Aminta panel.

Data Storage and Security

Your account data and Voice Profile are stored on servers located within the European Economic Area. We use industry-standard security measures including:

  • Encryption in transit (TLS/HTTPS) for all data transmitted to our servers.
  • Encryption at rest for stored personal data.
  • Access controls limiting who within the operation can access user data.
  • Regular security reviews of our infrastructure and dependencies.

BYOK API keys are stored exclusively in your browser's local storage and are never transmitted to our servers. You are responsible for the security of your own device and browser environment.

No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

Third-Party Services

Aminta integrates with the following third-party services. When you use features that rely on these services, your data is subject to their respective privacy policies in addition to ours.

8.1 AI Providers

When you generate content, your prompt and relevant Voice Profile context are transmitted to the AI provider you have selected. Currently supported providers include:

  • OpenRouter: routes requests to various underlying AI models. Privacy policy: openrouter.ai/privacy
  • Groq: fast inference provider. Privacy policy: groq.com/privacy
  • Google Gemini: AI models by Google. Privacy policy: policies.google.com/privacy
  • OpenAI: AI models including GPT series. Privacy policy: openai.com/privacy

If you provide your own API key (BYOK), requests go directly from your browser to the provider and are governed entirely by that provider's terms.

If your plan includes AI generations (Included AI), the request is instead sent to Aminta's backend, which forwards it to Google Gemini using our own provider credentials. Your prompt is processed to fulfil the request and is not stored by us. See section 10 for what we retain afterwards.

8.2 Billing

Paid plans are sold through Creem, our payment provider. Checkout happens on Creem's own hosted pages, so your card details are entered with them and are never sent to or stored by Aminta. Privacy policy: creem.io/privacy

From a completed purchase we receive the billing email address and the resulting plan and subscription status, which we store on your account so your plan works across devices. The free plan requires no payment details at all.

8.3 Analytics

We use PostHog (EU-hosted) for product and website analytics and for diagnostic error reports. When you are signed in, analytics events may be associated with your Aminta account rather than being anonymous — typically your user identifier, and for subscription events your email address and plan. Privacy policy: posthog.com/privacy

We do not send the content of your AI prompts or generated outputs to PostHog. The extension, where generation happens, contains no analytics code at all.

8.4 Chrome Web Store

Distribution of the Aminta extension through the Chrome Web Store is subject to Google's privacy policy. We comply with all Chrome Web Store Developer Program Policies, including those relating to data use and disclosure.

Cookies and Local Storage

Aminta uses cookies and browser local storage to operate the service.

  • Authentication cookies: Used to keep you logged in to your Aminta account. These are strictly necessary for the service to function and do not require consent under ePrivacy Directive Article 5(3).
  • Local storage (extension): Used to store your preferences, XP progress, Voice Profile, and API keys locally on your device. This data is not transmitted to external servers except as explicitly described in this policy.
  • Analytics cookies: If we use analytics, we will only set analytics cookies with your consent, where required by law.

You can clear local storage and cookies via your browser settings at any time. Doing so will log you out and reset locally stored preferences.

Data Retention

We retain your personal data only for as long as necessary:

  • Account data: Retained for the duration of your account. Deleted within 30 days of account deletion, except where retention is required by law.
  • Billing records: Retained for 7 years as required by Belgian accounting and tax law.
  • Analytics data: Retained by PostHog under its own retention settings. Aggregated data that no longer identifies you may be kept indefinitely.
  • Prompt data: Not retained on our servers beyond the time needed to fulfil the AI request. We do not log or store the content of your prompts.
  • Generated output (Included AI): Kept briefly so that a repeated or retried request returns the same result instead of being generated and charged twice, then automatically scrubbed. Only the text is removed; the surrounding usage record remains. This does not apply to BYOK, where the output never reaches our servers.
  • AI usage records: Non-content details of each Included AI request — generation type, prompt length, image count, token counts, cost, timing, outcome, device identifier and a hashed IP address — are kept for up to 90 days for quota enforcement, abuse prevention and cost accounting. These records contain no prompt or output text.

Your Rights Under GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:

  • Right of access (Art. 15): You can request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): You can ask us to correct inaccurate data or complete incomplete data.
  • Right to erasure (Art. 17): You can request deletion of your personal data, subject to legal retention requirements.
  • Right to data portability (Art. 20): You can request your data in a structured, machine-readable format.
  • Right to restriction (Art. 18): You can ask us to restrict processing of your data in certain circumstances.
  • Right to object (Art. 21): You can object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at hello@amintaapp.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority. In North Macedonia, this is the Agency for Personal Data Protection (Агенција за заштита на личните податоци), reachable at privacy.mk.

International Data Transfers

Some of our third-party service providers, in particular AI model providers such as OpenRouter, Groq, and OpenAI, are based in the United States. When you use these services, your prompt data is transferred to the United States.

We rely on the following safeguards for such transfers:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission, where applicable and required.
  • The EU-US Data Privacy Framework, where the provider is certified.

If you use your own BYOK API keys, data is transmitted directly from your browser to the provider, and you take on the responsibility for that transfer.

Children's Privacy

Aminta is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@amintaapp.com.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify you by email (if you have an account) or via an in-app notice, where the changes are material.

Your continued use of Aminta after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you should stop using Aminta and may request deletion of your account.

Contact Information

If you have questions, concerns, or requests relating to this Privacy Policy or to how we handle your personal data, please contact us:

Aminta, North Macedonia

Email: hello@amintaapp.com

We aim to respond to all enquiries within 5 business days, and to data subject requests within 30 calendar days.