Content Ninja logo
arrow_back Back to homepage

Privacy Policy

Published: 9 September 2026 · Last updated: 10 September 2026 · Effective: 9 October 2026 · Digitallwork.hu Kft. (company reg. no. 01-09-426906, VAT no. 32489819-2-43)

This policy is available in Hungarian and English. In case of any discrepancy, the Hungarian text prevails.

1. Data Controller

Content Ninja (the "Service") is an AI-powered content marketing tool for online stores. The Service creates social media content (text, images, video) and publishes it on the user's behalf to the user's own Facebook Pages and Instagram business accounts; composes and sends newsletters through the user's own newsletter provider account; publishes blog articles to the user's webshop; rewrites product descriptions and category page copy; creates advertising creatives; and performs keyword and topic research. The Service is available to businesses only. It is operated by:

Company name
Digitallwork.hu Kft.
Registered seat
1118 Budapest, Pálinkás Antal u. 3/A FSZ/8, Hungary
Company reg. number
01-09-426906
VAT number
32489819-2-43
Privacy contact
support@getcontentninja.com

This policy covers both this marketing website (getcontentninja.com) and the Content Ninja application (app.getcontentninja.com). It is drawn up in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"), the Hungarian Act CXII of 2011 on informational self-determination, and Act C of 2000 on accounting.

The contractual conditions of using the Service are set out in the Terms of Service; this Privacy Policy forms an integral part of them.

2. What data we process

2.1. Account and registration data

Dataname, e-mail address, password (stored in hashed/encrypted form), billing company name, VAT number
Purposecreating and managing your user account, providing the Service, invoicing
Legal basisperformance of a contract (Art. 6(1)(b) GDPR); invoicing: legal obligation (Art. 6(1)(c) GDPR)

2.2. Payment data

Datasubscription plan and status, payment transaction references
Purposecollecting subscription fees
Legal basisperformance of a contract (Art. 6(1)(b) GDPR)
Notecard details are processed exclusively by Stripe, our payment provider. We never see or store your card number; we only store the state of your subscription.

2.3. Content data

Databrands and brand-identity settings you create, prompts, generated content (text, images, video, narrated video), uploaded media files, knowledge-base entries, product data imported from your webshop (product names, descriptions, images, prices, categories), your newsletter, blog and advertising content, and the access keys of the external systems you connect, stored in encrypted form (webshop, newsletter and social platform keys)
PurposeAI-based content generation and scheduled publishing in your brand's style
Legal basisperformance of a contract (Art. 6(1)(b) GDPR)

2.4. Facebook / Instagram (Meta) data

When you connect your Facebook account via Facebook Login, we access and store the following data through the Meta Graph API:

  • your long-lived user access token (stored encrypted);
  • the list and identifiers of the Facebook Pages you manage and the Instagram business accounts linked to them;
  • Page access tokens (stored encrypted);
  • the identifiers and links of the posts published through the Service;
  • performance statistics (insights) of your Pages, Instagram account and published posts (e.g. reach, impressions, engagement);
  • comments on your published posts, so that you can view and manage them in the Service.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR). These tokens and identifiers are used exclusively to publish and manage the content you create in the Service and to show you the performance statistics and comments of that content — see Sections 3 and 4.

2.5. Newsletter integrations (MailerLite, SalesAutopilot)

Datathe access key of your newsletter provider (MailerLite API key, or SalesAutopilot username and password, stored encrypted), and the subscriber data stored in your own newsletter account (e-mail addresses, names, lists and segments)
Purposecomposing and sending newsletter campaigns on your behalf
Legal basisperformance of a contract (Art. 6(1)(b) GDPR)
Notewe act in your newsletter account solely on your instructions; access can be terminated at any time by revoking the key. In this respect you are the controller and we are the processor — the terms are set out in Annex 1 to the Terms of Service.

2.6. Usage logs

Datalogs of content-generation and publishing operations (timestamp, status, error message, model and cost data); row-level data audit log (which record changed when, from what to what — the values of sensitive fields are masked); technical error log
Purposetroubleshooting, reliability, abuse prevention, traceability of operations
Legal basislegitimate interest (Art. 6(1)(f) GDPR)

2.7. Content Ninja newsletter

Datae-mail address
Purposesending news and updates about the Content Ninja service
Legal basisconsent (Art. 6(1)(a) GDPR); withdrawable at any time by unsubscribing

2.8. Website visitors – Meta Pixel

Databehavioural data of website visitors (page views, clicks, conversions), cookie identifiers, IP address
Purposemarketing, remarketing, measuring ad effectiveness
Legal basisconsent (Art. 6(1)(a) GDPR) — the Pixel loads only after you accept it in the cookie banner (see Section 10)

2.9. Data of prospects (website forms, demo requests)

Dataname, company name, e-mail address, phone number, the answers you gave to the questions on the website form (e.g. whether you have a webshop, who creates your content today, when you would start), the source page of the submission and the campaign identifiers (UTM), the time of the demo and the video-call link, internal notes created during our contact with you, the discount coupon sent to you, and — for abuse protection — the technical data of the submission
Purposegetting in touch, organising the demo, making an offer, sales contact, tracking applications
Legal basissteps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR); legitimate interest for subsequent sales contact (Art. 6(1)(f)); consent for the newsletter (Art. 6(1)(a))
Retention24 months from the last meaningful contact, unless you become a customer in the meantime — in that case the rules applicable to your account apply. You can opt out of being contacted at any time at support@getcontentninja.com.
Recipientsan internal notification e-mail about each submission is sent to our team; prospects' e-mail addresses may be placed into the lifecycle groups of our own MailerLite account (prospect / customer / churned), and demo appointments are transmitted by the Fillout booking form.

2.10. Public surfaces (Ninja AI demo chat, sample post generator)

The demo-chat and sample-post pages can be used without logging in.

Datathe messages of the conversation, the data you provide during the conversation (e-mail address, webshop address, role, reason for your interest), the identifier token placed in your browser, a pseudonymous hash of the visitor's IP address (we do not store raw IP addresses), the product or store link given for creating the sample post, and the generated sample content
Purposeoperating the demo and allowing you to continue it, abuse and cost protection, sending the requested discount coupon, improving the service
Legal basisa service provided at your request and steps prior to entering into a contract (Art. 6(1)(b) GDPR); legitimate interest for abuse protection (Art. 6(1)(f))
Retentionfor as long as it is necessary to continue the demo, to verify coupon redemption and to prevent abuse; if the conversation results in a prospect, the rules in Section 2.9 apply.

2.11. Ninja AI assistant conversations and memories

Datathe conversations between the logged-in user and the AI assistant, the trace of the operations performed by the assistant, and the "memories" saved persistently to the workspace (facts needed for the work, provided by the user or noted by the assistant — for example brand characteristics or recurring requests)
Purposeoperating the assistant, allowing earlier conversations to be continued, personalised assistance
Legal basisperformance of a contract (Art. 6(1)(b) GDPR)
Notememories can be viewed, edited and deleted at any time in the interface.

2.12. Support access to your account

For troubleshooting and customer support, a member of our staff may view your account from your perspective for a maximum of 60 minutes, in read-only mode. During such access no data is modified, no credits are consumed and no content is published. Every such access is logged (who, whose account, when, for how long and on what grounds).

Legal basis: performance of a contract and legitimate interest in the quality of support (Art. 6(1)(b) and (f) GDPR).

3. How we use your data — purposes and legal bases

We use the data described above for the following purposes:

  • Providing the Service — generating content, publishing / scheduling it on your behalf to the social media accounts you connected, sending newsletters and publishing blog articles on your instruction, and displaying the performance statistics (insights) and comments of your published posts (performance of a contract);
  • Invoicing and accounting (legal obligation);
  • Product improvement and reliability — usage logs and aggregated statistics (legitimate interest);
  • Sales contact with prospects — replying to form submissions, organising demos, making offers (steps prior to a contract, legitimate interest);
  • Marketing on this website — Meta Pixel remarketing (consent).

Meta access tokens and Meta platform data are used exclusively to publish and manage the content you create in the Service. We do not sell them, do not share them with any third party beyond the processors listed in Section 5, and do not use them for advertising, profiling, or any purpose unrelated to the Service.

4. Meta permissions we request and why

When you connect your account with Facebook Login, we request the following permissions:

  • pages_show_list — to list the Facebook Pages you manage so you can choose which one to connect;
  • pages_manage_posts — to create, schedule and publish posts on your connected Page on your behalf;
  • pages_read_engagement — to read your Page's content and basic engagement data needed for publishing and for verifying that posts went live;
  • instagram_basic — to identify the Instagram business account linked to your Facebook Page;
  • instagram_content_publish — to publish content to your connected Instagram business account;
  • read_insights — to read the performance statistics (insights) of your Page and its posts and display them to you in the Service;
  • instagram_manage_insights — to read the performance statistics (insights) of your Instagram business account and its posts and display them to you in the Service;
  • pages_manage_engagement — to read and reply to comments on your Page's posts from within the Service;
  • instagram_manage_comments — to read and reply to comments on your Instagram posts from within the Service.

You can revoke these permissions at any time in your Facebook settings (Settings & privacy → Settings → Business integrations) or by disconnecting the account inside the Content Ninja application.

5. Who we share data with (processors and sub-processors)

We use the following processors to provide the Service. We never sell your personal data to third parties.

Processor Location Activity
Supabase, Inc. EU region Database, authentication, file storage
Vercel, Inc. EU (Frankfurt) Application hosting
Cloudflare, Inc. USA Domain and content delivery (CDN), protection
GitHub, Inc. USA Hosting of this marketing website
Stripe, Inc. USA Payment processing
KBOSS.hu Kft. (Szamlazz.hu) Hungary Invoicing
Meta Platforms, Inc. USA / Ireland Publishing to Facebook / Instagram; website marketing (Pixel)
OpenAI, Inc. USA AI text and image generation, analysis, research; converting voice dictation to text
Anthropic, PBC USA AI text generation, Ninja AI assistant
Google LLC USA AI text, image and video generation; retrieving search performance data from Google Search Console
Google Ireland Limited Ireland, EU Google Search Console API — retrieving the search data of the website you connect (read-only)
xAI Corp. USA AI video generation
Alibaba Cloud (Singapore) Private Limited EU (Frankfurt) AI video generation
Replicate, Inc. USA Image-to-animation generation
MiniMax (MiniMax AI) Singapore AI voice and music generation for narrated video
Shotstack Pty Ltd Australia Video composition and rendering
DataForSEO Third country Retrieving keyword and search data
MailerLite (UAB MailerLite) Lithuania, EU Newsletter delivery (in the customer's account), managing our own prospect list
SalesAutopilot Kft. Hungary Newsletter delivery in the customer's account
Mailjet (Sinch Email) France, EU Transactional e-mail delivery (account, billing and system notifications)
Fillout, Inc. USA Demo booking form
Sentry (Functional Software, Inc.) EU region Error logging

When generating content, only the inputs required for generation (e.g. product data, prompts, brand settings, uploaded images) are sent to the AI providers — never your access tokens or account credentials. Under their contractual terms, the AI providers do not use the data submitted to them to train their models.

Note on Sentry: when an error occurs in the application, the technical details of that error (error message, page address, browser type, timestamp) are sent to Sentry's European servers so that we can fix it. We do not send IP addresses, cookies, form contents, or the part of the web address after the question mark. Purpose: bug fixing and operational reliability; legal basis: our legitimate interest; retention: 90 days at most.

Note on Google Search Console: if you connect your website via Google Sign-in, we retrieve the search data of your own webshop through the Google Search Console API — search queries, impressions, clicks, average position and landing page URLs — and display it to you on the Analytics screen of the application. This access is read-only: we do not write, modify or delete anything in your Search Console account. The transfer stays within the European Union (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), under Google's data processing terms. Connecting requires the authorisation of your own Google account, which you can withdraw at any time — either by disconnecting the integration in the application, or in your Google account settings. We store the access token encrypted and delete it immediately when the connection is removed; access ceases at the same moment. We retain the search data collected for 16 months at most — the period Google itself returns — after which it is deleted automatically. Purpose: measuring and reporting the search performance of your webshop; legal basis: performance of a contract (you requested the connection).

Note on voice dictation: in the app you can give instructions by voice in text fields and to the Ninja AI assistant. The recording is sent to OpenAI solely to convert it to text. We do not store the recording: it is not saved to any database or file storage, and nothing of it is kept after processing. We only record its length (in seconds, totalled per day) for the daily limit. Dictation is optional, and the microphone turns on only when the user starts it and the browser grants permission. Legal basis: performance of contract.

Note on Meta Platforms: when the Service publishes content to your Facebook Page or Instagram account, or reads insights and comments on your behalf, Meta Platforms processes that data as an independent data controller under its own privacy policy — not as our processor. Meta acts as our processor only in respect of the Meta Pixel used on this marketing website (see Section 10).

Note on your webshop and newsletter provider: UNAS, Shoprenter and your newsletter provider are your own systems. The Service reads from and writes to them using your access key, on your instruction. Their operators act as independent controllers under their own privacy policies.

6. Where we store your data, and how we protect it

  • Storage in the EU: your data is stored within the European Union (Supabase EU region, Vercel Frankfurt).
  • Third-country transfers: some of our processors operate outside the European Union. Transfers to the United States (Stripe, Meta, OpenAI, Anthropic, Google LLC, xAI, Replicate, GitHub, Cloudflare, Fillout) rely on the adequacy decision under the EU–US Data Privacy Framework and/or on the European Commission's Standard Contractual Clauses (SCC). Transfers to Singapore (MiniMax), Australia (Shotstack) and other third countries (DataForSEO) are based on the European Commission's Standard Contractual Clauses (SCC) with the necessary supplementary measures. Only the inputs of generation (text, image, narration script) are sent to these providers — never account identifiers or access tokens.
  • Isolation: data is separated per user / workspace at the database level (row-level security, RLS).
  • Encryption: all platform access tokens (Meta user and Page tokens, webshop and newsletter API keys) are stored encrypted using AES-256-GCM; data in transit is protected by TLS.

7. Retention and deletion

  • Account and content data: retained while your account exists, then deleted within 30 days after account deletion.
  • Meta access tokens and connected-account data: deleted immediately when you disconnect the account in the app, revoke the app's access in your Facebook settings, or delete your account.
  • Connected webshop and newsletter keys: deleted immediately when the connection is removed.
  • Google Search Console search data: 16 months at most, deleted automatically thereafter; access ceases immediately when you disconnect the integration.
  • Invoicing data: retained for 8 years, as required by the Hungarian Accounting Act (Act C of 2000).
  • Usage logs: retained while your account exists and for as long as they are necessary for troubleshooting, accounting for credit usage and preventing abuse; they are deleted thereafter.
  • Data audit log: retained for up to 90 days (deleted automatically).
  • Error logs (Sentry): retained for up to 90 days.
  • Backups: retained for the duration of the backup cycle, for as long as it is necessary to be able to restore the most recent backups; deleted data disappears from the backups when that cycle expires.
  • Prospect (lead) data: 24 months from the last meaningful contact.
  • Public demo conversations: for as long as it is necessary to continue the demo, to verify coupon redemption and to prevent abuse.
  • Newsletter data: retained until you unsubscribe.

You can request deletion of your data at any time, in any of the following ways:

  • delete your account inside the Content Ninja application;
  • send a deletion request to support@getcontentninja.com;
  • remove the app's access in your Facebook settings (Settings & privacy → Settings → Business integrations) — this immediately invalidates the stored tokens.

Deletion requests are completed within 30 days at the latest, except for data we are legally required to retain (e.g. invoices). Step-by-step instructions are available on our Data Deletion Instructions page.

8. Your rights under the GDPR

Right of access — you may request information about the data we process about you.

Right to rectification — you may request the correction of inaccurate data.

Right to erasure — you may request deletion of your data where there is no longer a legal basis for processing.

Right to restriction of processing — you may request that processing be restricted in certain cases.

Right to data portability — you may request your data in a machine-readable format.

Right to object — you may object to processing based on legitimate interest.

Right to withdraw consent — for consent-based processing (newsletter, Meta Pixel), you may withdraw consent at any time without giving reasons; withdrawal does not affect the lawfulness of processing before the withdrawal.

You can exercise these rights by e-mailing support@getcontentninja.com. We respond to requests within 30 days at the latest.

8.1. Automated decision-making

We do not take decisions based solely on automated processing that produce legal effects concerning you. The AI features of the Service suggest and produce content; the decision to publish and use it is always yours.

8.2. Personal data breach

In the event of a personal data breach we notify the supervisory authority within the statutory deadline (72 hours from becoming aware of it) and — if the breach is likely to result in a high risk — the data subjects as well.

8.3. Data Protection Officer

Based on the nature of our activity, appointing a Data Protection Officer is not mandatory; for data protection matters you can reach us at support@getcontentninja.com.

8.4. Restriction by age and user group

The Service is available to businesses only; we do not knowingly process the data of persons under 18.

9. Complaints

If you believe we have infringed the rules on data processing, you may lodge a complaint with the Hungarian supervisory authority:

NameNemzeti Adatvédelmi és Információszabadság Hatóság (NAIH — Hungarian National Authority for Data Protection and Freedom of Information)
Address1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address1363 Budapest, Pf. 9., Hungary

You may also bring the matter before a court, or complain to the supervisory authority of your own EU member state.

10. Cookies

10.1. Strictly necessary cookies

Cookies essential for the operation of the website and the application: maintaining the login session (Supabase session cookie), the security (CSRF) cookie of the connection flow, and the browser identifier that allows a conversation on the public demo surfaces to be continued. These do not require consent.

10.2. Marketing cookies (Meta Pixel)

The Meta Pixel places cookies in the visitor's browser for remarketing and advertising purposes. These are activated only with your explicit consent given in the cookie banner.

10.3. Managing cookies

You may modify or withdraw your cookie consent at any time via the cookie banner, and cookies can also be deleted or blocked individually in your browser settings.

11. Facebook / Meta platform clause

The application accesses the user's Pages and accounts through the Meta Platform (Facebook Login, Facebook Graph API, Instagram Graph API) solely for the purpose of publishing and managing content created by the user and displaying the performance statistics (insights) and comments of that content to the user. This access can be revoked at any time in the user's Facebook settings and within the application. The use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and the applicable Meta Developer Policies.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by e-mail and publish the updated policy on this page. Changes are published at least 15 days before they take effect; where a new processor is engaged, we publish notice at least 30 days in advance, in line with Section 9 of Annex 1 to our Terms. This version is effective from 9 October 2026 (published on 9 September 2026, last updated on 10 September 2026). The policy is available in Hungarian and English; in case of any discrepancy, the Hungarian text prevails.

12.1. Change log

  • 9 October 2026 — New processor added to Section 5: Alibaba Cloud (Singapore) Private Limited (Alibaba Cloud Model Studio) — AI video generation. We use the service through an endpoint running in the European Union (Frankfurt region), so no third-country transfer takes place. Only the prompt text and the reference images are sent for generation — never account identifiers, access tokens or customer lists. Published: 9 September 2026.
  • 16 September 2026 — New processor added to Section 5: Google Ireland Limited (Google Search Console API). We retrieve the search data of the website you connect (search queries, impressions, clicks, average position, landing page URLs) with read-only access and display it on the Analytics screen of the application. A related retention entry was added to Section 7 (16 months at most). Published: 1 September 2026.
  • 10 September 2026 — The activity of OpenAI, Inc. in Section 5 was extended with converting voice dictation to text, and a note on voice dictation was added below the table (we do not store the recording; we only record its length for the daily limit). No new processor. Published and effective: 10 September 2026.
  • 20 August 2026 — First effective version of this policy (published on 3 August 2026).