Privacy Policy
Effective June 15, 2026·Updated June 15, 2026
This Privacy Policy explains how Aminta collects, uses, stores, and protects your information when you use the Aminta Chrome extension and web application. We are committed to transparency and to protecting your privacy under applicable law, including the EU General Data Protection Regulation (GDPR).
- 1. Data Controller
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Legal Basis for Processing (GDPR)
- 5. AI Processing Disclosure
- 6. Chrome Extension Permissions
- 7. Data Storage and Security
- 8. Third-Party Services
- 9. Cookies and Local Storage
- 10. Data Retention
- 11. Your Rights Under GDPR
- 12. International Data Transfers
- 13. Children's Privacy
- 14. Changes to This Policy
- 15. Contact Information
Data Controller
Aminta is operated by an independent developer based in North Macedonia. For the purposes of EU data protection law, the data controller is:
Aminta, North Macedonia
Email: hello@amintaapp.com
If you have any questions about this Privacy Policy or about how we handle your data, please contact us at the address above.
Information We Collect
We collect the minimum information necessary to provide and improve the Aminta service. The categories below describe what we collect, why we collect it, and how.
2.1 Account Information
When you create an Aminta account, we collect your email address and, if you choose to provide it, your display name. We use this to authenticate you, send service-related communications, and associate your data with your account.
2.2 User-Generated Content
Aminta processes text you provide as input, such as topics, draft posts, reply targets, and instructions, to generate AI-assisted content. This input is transmitted to the AI provider handling the request (see §8) to fulfil it. We do not permanently store the raw text of your prompts or generated outputs unless you explicitly save them within the application.
2.3 Voice Profile Data
If you configure a Voice Profile, you may provide sample posts and descriptions of your tone and writing style. This profile is stored in your account so that the AI can write in your voice. You can delete or modify your Voice Profile at any time from your account settings.
2.4 Browser Extension Data
The Aminta Chrome extension operates locally in your browser. It reads the active tab to detect the X (Twitter) composer so it can inject generated content on request. We do not collect or transmit your browsing history. See §6 for a full list of extension permissions.
2.5 Usage Analytics
We collect usage data to understand how Aminta is used and to improve the product. This may include feature usage frequency, error rates, and session duration. When you are signed in, this data may be linked to your account (see §8.3). We do not collect the content of your prompts or generated output through analytics.
2.6 API Keys
If you choose to use your own API keys (Bring Your Own Key, BYOK), those keys are stored exclusively in your browser's local storage. They are never transmitted to Aminta's servers. API requests made using your keys go directly from your browser to the respective AI provider. You are solely responsible for managing and protecting your API keys.
How We Use Your Information
We use the information we collect for the following purposes:
- –Providing, maintaining, and improving the Aminta extension and web application.
- –Authenticating your identity and managing your account.
- –Transmitting your prompts to AI providers to generate content on your behalf.
- –Storing your Voice Profile so Aminta can write in your style.
- –Sending transactional emails (account confirmation, password reset, billing receipts).
- –Analysing usage patterns to improve features and performance.
- –Preventing fraud, abuse, and violations of our Terms of Service.
- –Complying with our legal obligations under Belgian and EU law.
We do not use your content to train AI models. We do not use your data for advertising purposes. We do not share your personal data with third parties except as described in §8 and as required by law.
Legal Basis for Processing (GDPR)
For users in the European Economic Area and the United Kingdom, we rely on the following legal bases under Article 6 GDPR:
- –Contract (Art. 6(1)(b)): Processing your account information and content to provide the service you signed up for.
- –Legitimate Interests (Art. 6(1)(f)): Processing analytics data to improve our product, and processing data to detect and prevent abuse.
- –Legal Obligation (Art. 6(1)(c)): Retaining billing records as required by Belgian and EU tax law.
- –Consent (Art. 6(1)(a)): For any optional communications or data uses beyond what is strictly necessary to provide the service, where we will ask for your explicit consent.
AI Processing Disclosure
Aminta uses third-party AI models to generate content on your behalf. When you use a generation feature, your prompt (including any Voice Profile context you have enabled) is transmitted to the AI provider you have selected or that we have configured as the default.
Each AI provider has its own privacy policy and terms of service. You are encouraged to review these before using Aminta, in particular regarding how providers handle submitted data and whether they use it for model training.
Chrome Extension Permissions
The Aminta Chrome extension requests the following browser permissions. We request only the permissions necessary for the extension to function.
- –activeTab:Allows Aminta to read the current tab's URL and inject content into the X composer when you activate the extension. We do not read page content unless you explicitly use a feature that requires it (e.g., Reply Generator reading a tweet you are replying to).
- –storage: Used to store your settings, Voice Profile, XP progress, and BYOK API keys locally in your browser. This data does not leave your device unless you are logged in and sync is enabled.
- –Host permissions (x.com, twitter.com):Required to detect the active composer and inject generated content into the text field when you click "Insert into X".
We do not access your browsing history. We do not read page content on sites you visit other than the supported platforms listed above, and only when you have activated the Aminta panel.
Data Storage and Security
Your account data and Voice Profile are stored on servers located within the European Economic Area. We use industry-standard security measures including:
- –Encryption in transit (TLS/HTTPS) for all data transmitted to our servers.
- –Encryption at rest for stored personal data.
- –Access controls limiting who within the operation can access user data.
- –Regular security reviews of our infrastructure and dependencies.
BYOK API keys are stored exclusively in your browser's local storage and are never transmitted to our servers. You are responsible for the security of your own device and browser environment.
No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
Third-Party Services
Aminta integrates with the following third-party services. When you use features that rely on these services, your data is subject to their respective privacy policies in addition to ours.
8.1 AI Providers
When you generate content, your prompt and relevant Voice Profile context are transmitted to the AI provider you have selected. Currently supported providers include:
- –OpenRouter: routes requests to various underlying AI models. Privacy policy: openrouter.ai/privacy
- –Groq: fast inference provider. Privacy policy: groq.com/privacy
- –Google Gemini: AI models by Google. Privacy policy: policies.google.com/privacy
- –OpenAI: AI models including GPT series. Privacy policy: openai.com/privacy
If you provide your own API key (BYOK), requests go directly from your browser to the provider and are governed entirely by that provider's terms.
If your plan includes AI generations (Included AI), the request is instead sent to Aminta's backend, which forwards it to Google Gemini using our own provider credentials. Your prompt is processed to fulfil the request and is not stored by us. See section 10 for what we retain afterwards.
8.2 Billing
Paid plans are sold through Creem, our payment provider. Checkout happens on Creem's own hosted pages, so your card details are entered with them and are never sent to or stored by Aminta. Privacy policy: creem.io/privacy
From a completed purchase we receive the billing email address and the resulting plan and subscription status, which we store on your account so your plan works across devices. The free plan requires no payment details at all.
8.3 Analytics
We use PostHog (EU-hosted) for product and website analytics and for diagnostic error reports. When you are signed in, analytics events may be associated with your Aminta account rather than being anonymous — typically your user identifier, and for subscription events your email address and plan. Privacy policy: posthog.com/privacy
We do not send the content of your AI prompts or generated outputs to PostHog. The extension, where generation happens, contains no analytics code at all.
8.4 Chrome Web Store
Distribution of the Aminta extension through the Chrome Web Store is subject to Google's privacy policy. We comply with all Chrome Web Store Developer Program Policies, including those relating to data use and disclosure.
Data Retention
We retain your personal data only for as long as necessary:
- –Account data: Retained for the duration of your account. Deleted within 30 days of account deletion, except where retention is required by law.
- –Billing records: Retained for 7 years as required by Belgian accounting and tax law.
- –Analytics data: Retained by PostHog under its own retention settings. Aggregated data that no longer identifies you may be kept indefinitely.
- –Prompt data: Not retained on our servers beyond the time needed to fulfil the AI request. We do not log or store the content of your prompts.
- –Generated output (Included AI): Kept briefly so that a repeated or retried request returns the same result instead of being generated and charged twice, then automatically scrubbed. Only the text is removed; the surrounding usage record remains. This does not apply to BYOK, where the output never reaches our servers.
- –AI usage records: Non-content details of each Included AI request — generation type, prompt length, image count, token counts, cost, timing, outcome, device identifier and a hashed IP address — are kept for up to 90 days for quota enforcement, abuse prevention and cost accounting. These records contain no prompt or output text.
Your Rights Under GDPR
If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
- –Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- –Right to rectification (Art. 16): You can ask us to correct inaccurate data or complete incomplete data.
- –Right to erasure (Art. 17): You can request deletion of your personal data, subject to legal retention requirements.
- –Right to data portability (Art. 20): You can request your data in a structured, machine-readable format.
- –Right to restriction (Art. 18): You can ask us to restrict processing of your data in certain circumstances.
- –Right to object (Art. 21): You can object to processing based on legitimate interests.
- –Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at hello@amintaapp.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority. In North Macedonia, this is the Agency for Personal Data Protection (Агенција за заштита на личните податоци), reachable at privacy.mk.
International Data Transfers
Some of our third-party service providers, in particular AI model providers such as OpenRouter, Groq, and OpenAI, are based in the United States. When you use these services, your prompt data is transferred to the United States.
We rely on the following safeguards for such transfers:
- –Standard Contractual Clauses (SCCs) adopted by the European Commission, where applicable and required.
- –The EU-US Data Privacy Framework, where the provider is certified.
If you use your own BYOK API keys, data is transmitted directly from your browser to the provider, and you take on the responsibility for that transfer.
Children's Privacy
Aminta is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@amintaapp.com.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- –Update the "Last updated" date at the top of this page.
- –Notify you by email (if you have an account) or via an in-app notice, where the changes are material.
Your continued use of Aminta after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you should stop using Aminta and may request deletion of your account.
Contact Information
If you have questions, concerns, or requests relating to this Privacy Policy or to how we handle your personal data, please contact us:
Aminta, North Macedonia
Email: hello@amintaapp.com
We aim to respond to all enquiries within 5 business days, and to data subject requests within 30 calendar days.