Privacy Policy
Last updated: 24 July 2026
1. Controller
heej — a product of The NEED GmbH
The NEED GmbH
Zettachring 12A
70567 Stuttgart, Germany
Managing Director: Sinan Yurttadur
Email: info@theneed.works
Phone: +49 (0) 711 25 25 1916
The controller decides, alone or jointly with others, on the purposes and means of the processing of personal data. A data protection officer has not been appointed, as the statutory conditions requiring an appointment (Art. 37 GDPR, Section 38 German Federal Data Protection Act) are not met. Please direct privacy enquiries to the contact details above.
2. When You Visit Our Website
Each time you access our website, our hosting providers (Vercel for the frontend, Render for the API — see Section 13) automatically record data about the requesting device in server logs:
- IP address of the requesting device
- Date and time of access
- Name and URL of the requested file
- Referring website (referrer URL)
- Browser used and, where applicable, operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical provision, stability and security of the website). Server logs are deleted or anonymised after 30 days at the latest.
3. Cookies and Local Storage
We use strictly necessary cookies and comparable storage techniques only. We do not use any tracking, analytics or advertising cookies. In detail:
- Authentication cookies (sb-*-auth-token): session cookies of our auth provider Supabase that keep you signed in. During magic-link login, a short-lived PKCE code-verifier cookie is also set.
- Language preference (NEXT_LOCALE): stores your selected language (German/English). Lifetime: 1 year.
- Flow cookies (auth_redirect, pending_role, google_oauth_origin): short-lived cookies that ensure you return to the right page during login, sign-up and OAuth flows.
- Cookie notice (localStorage): the entry
heej_cookie_consentremembers that you acknowledged the cookie notice. - Cloudflare Turnstile: the bot protection on login and sign-up pages (Section 12) may set its own strictly necessary cookies as part of its security check.
Legal basis: Section 25(2) no. 2 of the German TDDDG (strictly necessary storage) in conjunction with Art. 6(1)(f) GDPR. Should we introduce analytics tools in the future, we will obtain your consent beforehand and update this policy.
4. Registration and Account
When you register for and use heej, we process:
- Email address (passwordless login via magic link or one-time code)
- When signing in with Google: your Google account email and profile name
- Name, profile picture, tagline, niche and bio (where provided — publicly visible on the avatar page for creators)
- Language preference (German/English)
- Usage statistics within the platform (e.g. number of conversations, subscriber counts in the creator dashboard)
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
5. AI Chat and Knowledge Base
The core of heej is an AI avatar that generates answers based on content provided by the creator. In doing so, we process:
- Content uploaded by the creator (PDFs, texts, website content, video/audio transcripts): split into text chunks, converted into vector embeddings (OpenAI) and stored as the knowledge base. Each creator's data is strictly isolated.
- Chat histories between followers (or guests) and the AI avatar: message contents are stored so conversations can be continued and the creator can review them in their dashboard. To generate a reply, the message and relevant knowledge excerpts are transmitted to the Anthropic API (Claude).
- Guest chats without an account (public avatar page and embed widget on the creator's own websites): messages you enter are processed to generate replies and are associated with the respective conversation even without registration. Please do not enter sensitive data in the chat.
Legal basis: Art. 6(1)(b) GDPR (provision of the service) and Art. 6(1)(f) GDPR (legitimate interest in abuse prevention and service integrity for guest chats). Neither Anthropic nor OpenAI use content submitted via their APIs to train their models.
6. Voice Cloning (Creators Only)
Creators may optionally have a synthetic model of their own voice created. To do so, the creator records a voice sample, which is transmitted to our service provider ElevenLabs and processed there into an individual voice model. Voice recordings may constitute biometric or otherwise specially protected data within the meaning of Art. 9 GDPR. Processing therefore takes place exclusively on the basis of the creator's explicit consent (Art. 9(2)(a), Art. 6(1)(a) GDPR), which the creator gives by actively recording and submitting their voice sample for the purpose of voice cloning. Creating a voice model is voluntary and not required to use the platform.
Consent may be withdrawn at any time with effect for the future (by email to info@theneed.works or by deleting the account). Upon withdrawal or account deletion, the voice model is deleted at ElevenLabs without undue delay. It is used exclusively for the respective creator's avatar and is not shared with third parties.
7. Voice Calls with the AI Avatar
Subscribers can talk to the AI avatar. During a call, the user's microphone audio is streamed in real time to our service provider Deepgram, where it is converted into text (speech-to-text). The audio is used solely to transcribe the ongoing conversation; no voice model of the user is created from it. The transcribed text is processed like a chat message (Section 5). The avatar's reply is synthesised as speech via ElevenLabs. To prevent abuse, we record the speaking time used per day (usage metering).
Legal basis: Art. 6(1)(b) GDPR (provision of the voice feature). Microphone access only occurs after you actively grant it in your browser and can be ended at any time.
8. Content Import (Creators Only)
- File upload: PDFs and texts are stored in our storage (Supabase, EU) and processed for the knowledge base.
- Website import:at the creator's request, our servers fetch a publicly accessible URL specified by the creator and extract its text as a knowledge source.
- YouTube and Google Drive:import via Google OAuth consent — see the section "Google API Services User Data Policy" (Section 14) for details.
- Dropbox: import of files selected by the creator via OAuth consent (see Section 13).
- Audio/video transcription: media files (Pro Plan only) are transcribed via the OpenAI Whisper API.
Legal basis: Art. 6(1)(b) GDPR. For OAuth connections additionally Art. 6(1)(a) GDPR (consent, revocable at any time by disconnecting the account).
9. Payment Processing (Stripe)
Payments (follower subscriptions, Pro Plan) and payouts to creators (Stripe Connect) are processed via Stripe. Name, email address and payment information are transmitted to Stripe; for creator payouts, Stripe additionally collects identification and account data (statutory KYC/anti-money-laundering obligations). We do not store complete payment data (e.g. credit card numbers) ourselves. For payment processing, Stripe acts in part as an independent controller.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligations).
10. Email Delivery (Resend)
We send transactional emails (login links, welcome emails, subscription confirmations, notifications) via Resend. The recipient's email address and, where applicable, name are transmitted. Legal basis: Art. 6(1)(b) GDPR. Marketing emails are only sent with consent.
11. Error Monitoring (Sentry)
To detect and fix technical errors, we use Sentry with EU data residency. When an error occurs, technical information is captured (error message, browser/device data, truncated IP address, affected page). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable, secure service).
12. Bot Protection (Cloudflare Turnstile)
On login and sign-up pages we use Cloudflare Turnstile to fend off automated abuse. Turnstile evaluates technical browser signals (including IP address and device characteristics), usually without any user interaction. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing bots and abuse) and Section 25(2) no. 2 TDDDG.
13. Processors and Third-Country Transfers
We use the following service providers to deliver our services. Data processing agreements pursuant to Art. 28 GDPR are in place with our processors:
Supabase
Purpose: database (PostgreSQL), authentication and file storage. All user data, chat histories and uploaded content are stored on Supabase infrastructure.
Provider: Supabase Inc., San Francisco, USA
Third-country transfer: servers located in the EU (Ireland, eu-west-1) — no third-country transfer for stored data.
Privacy policy: https://supabase.com/privacy
Vercel
Purpose: hosting and delivery of the web application (frontend, CDN). Server-side functions run in the EU region (Dublin).
Provider: Vercel Inc., San Francisco, USA
Third-country transfer: certified under the EU-US Data Privacy Framework (DPF); additionally Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
Privacy policy: https://vercel.com/legal/privacy-policy
Render
Purpose: hosting of the backend API server. API requests (chat, import, voice features) are processed on Render infrastructure in the EU region (Frankfurt).
Provider: Render Services, Inc., San Francisco, USA
Third-country transfer: processing in the EU (Frankfurt); otherwise Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
Privacy policy: https://render.com/privacy
Anthropic (Claude)
Purpose: AI-based text generation for the chat avatar (large language model). Chat requests and relevant knowledge excerpts are transmitted to the Anthropic API to generate replies.
Provider: Anthropic, PBC, San Francisco, USA
Third-country transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
Privacy policy: https://www.anthropic.com/privacy
Note: API inputs are not used to train Anthropic models.
OpenAI
Purpose: generation of text embeddings for semantic search in the knowledge base and Whisper transcription of audio/video content (Pro Plan).
Provider: OpenAI, L.L.C., San Francisco, USA
Third-country transfer: certified under the EU-US Data Privacy Framework (DPF); additionally Standard Contractual Clauses (SCC).
Privacy policy: https://openai.com/privacy
Note: API inputs are not used to train OpenAI models.
ElevenLabs
Purpose:voice cloning (only with the creator's explicit consent, Section 6) and text-to-speech generation for the avatar's spoken replies.
Provider: ElevenLabs Inc., New York, USA
Third-country transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
Privacy policy: https://elevenlabs.io/privacy
Cartesia
Purpose:alternative provider for voice cloning (only with the creator's explicit consent, Section 6) and text-to-speech generation for the avatar's spoken replies. May be used in place of ElevenLabs.
Provider: Cartesia AI, Inc., San Francisco, USA
Third-country transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR or the EU-US Data Privacy Framework, where certified.
Privacy policy: https://cartesia.ai/privacy
Deepgram
Purpose: real-time speech recognition (speech-to-text) during voice calls with the AI avatar. Microphone audio is streamed to Deepgram for transcription (Section 7).
Provider: Deepgram, Inc., San Francisco, USA
Third-country transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR or the EU-US Data Privacy Framework, where certified.
Privacy policy: https://deepgram.com/privacy
Stripe
Purpose: payment processing and payouts (follower subscriptions, Pro Plan, Stripe Connect for creators). As a payment service provider, Stripe acts in part as an independent controller.
Provider: Stripe Payments Europe, Ltd., Dublin, Ireland (for EU customers) / Stripe, Inc., South San Francisco, USA
Third-country transfer: certified under the EU-US Data Privacy Framework (DPF); EU payment data is primarily processed by Stripe Payments Europe, Ltd. (Ireland).
Privacy policy: https://stripe.com/privacy
Resend
Purpose: delivery of transactional emails (login links, welcome emails, subscription confirmations, notifications).
Provider: Resend, Inc., San Francisco, USA
Third-country transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
Privacy policy: https://resend.com/legal/privacy-policy
Sentry
Purpose:error monitoring (Section 11). Error data is stored in Sentry's EU region.
Provider: Functional Software, Inc. (Sentry), San Francisco, USA
Third-country transfer: EU data residency; otherwise Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework, where certified.
Privacy policy: https://sentry.io/privacy/
Cloudflare (Turnstile)
Purpose: bot protection on login and sign-up pages (Section 12).
Provider: Cloudflare, Inc., San Francisco, USA
Third-country transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR or the EU-US Data Privacy Framework, where certified.
Privacy policy: https://www.cloudflare.com/privacypolicy/
Google (OAuth, YouTube Data API v3, Drive API)
Purpose: sign-in with Google and content import (YouTube captions, Drive documents) as knowledge sources for the AI avatar. The user explicitly authorises access via OAuth consent. For details on access, use, storage and sharing of Google user data, see the dedicated section "Google API Services User Data Policy" (Section 14).
OAuth scopes: youtube.force-ssl(only to retrieve captions of the user's own YouTube videos), drive.file (per-file access: the user explicitly selects files in the Google Picker; only those files are shared with the app — no Drive-wide read access), userinfo.profile (profile name for displaying connected accounts).
Data: OAuth tokens (access and refresh tokens), YouTube video metadata (title, ID, duration), caption texts (transcripts), Drive file contents (text from PDFs, Google Docs, spreadsheets), Drive file metadata (name, MIME type, ID), Google profile name.
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Third-country transfer: USA — Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR and the EU-US Data Privacy Framework (DPF, Google LLC is certified).
Privacy policy: https://policies.google.com/privacy
Dropbox
Purpose: content import (PDFs, documents, media files) as knowledge sources for the AI avatar. The user explicitly authorises access via OAuth consent.
Data: OAuth tokens, file names, file contents of the files selected by the user.
Provider: Dropbox Inc., 1800 Owens St, San Francisco, CA 94158, USA
Third-country transfer: USA — Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
Privacy policy: https://www.dropbox.com/privacy
Note on third-country transfers: the specific transfer mechanism (EU server location, DPF or SCC) is stated individually for each provider above. Where a provider is certified under the EU-US Data Privacy Framework (DPF), an adequacy decision of the EU Commission pursuant to Art. 45 GDPR applies. Otherwise, we base transfers on Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR.
14. Google API Services User Data Policy
Access, Use, Storage and Sharing of Google User Data
heej's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Below we document in detail how heej accesses, uses, stores and shares Google user data.
1. How does heej access Google user data?
Access takes place exclusively via the Google OAuth 2.0 consent flow. The user is redirected to the official Google consent page, where they actively authorise the requested scopes. No data is accessed without the user's explicit consent. The connection can be revoked at any time in the account settings (Dashboard → Sources → Connected accounts → Disconnect) or directly at myaccount.google.com/permissions.
Requested scopes and their purpose:
https://www.googleapis.com/auth/youtube.force-ssl— retrieval of video titles and captions of the user's own YouTube videos via the YouTube Data API v3. Only videos owned by the authorising Google account are read. No uploads, no changes, no deletions.https://www.googleapis.com/auth/drive.file— per-file access via the Google Picker: heej does NOT show its own Drive browsing UI and has no Drive-wide read access. When the user wants to import files, the native Google Picker opens (in a Google-owned iframe) where the user explicitly selects one or more files. Only through this selection does the user grant the app read access to exactly those file IDs; all other Drive files remain invisible and inaccessible to heej. Only what the user selects in the Picker is downloaded, extracted and stored. No write access, no editing, no deletion in Drive.https://www.googleapis.com/auth/userinfo.profile— retrieval of the Google profile name to display the connected account in the dashboard.
2. How does heej use Google user data?
Google user data is used exclusively for the core function requested by the user: building the knowledge base of their AI avatar.
- YouTube captionsare downloaded, split into text chunks, converted into vector embeddings and stored as a knowledge source for the retrieval-augmented generation (RAG) of the user's AI avatar.
- Drive file contents (PDFs, Google Docs, text files) are downloaded, extracted, chunked, converted into embeddings and likewise stored as a RAG knowledge source. Audio and video files are additionally transcribed via OpenAI Whisper (Pro Plan only).
- The Google profile nameis used only for display in the dashboard ("Connected as: Jane Doe").
Google user data is not used for: advertising, retargeting, profiling or transfer to ad networks; sale to third parties; creditworthiness checks or other unrelated analyses; training, development or fine-tuning of generalised AI/ML models (neither by heej nor by our processors such as OpenAI or Anthropic — both providers have contractually committed not to use API inputs for training).
3. How does heej store Google user data?
- Storage location: Supabase PostgreSQL (eu-west-1, Ireland, EU) with row-level security. Each influencer has an isolated pgvector namespace — other users cannot access the data.
- Encryption: all data is encrypted at rest (AES-256, Supabase standard) and in transit (TLS 1.2+).
- OAuth tokens: access and refresh tokens are stored in the database to enable access without repeated consent. They are never exposed in the frontend, in logs or to third parties.
- Retention: content remains stored for as long as the user uses it as a knowledge source. When the Google connection is disconnected, OAuth tokens are deleted immediately. Individual knowledge sources can be deleted in the dashboard at any time (with cascade deletion of all associated embeddings). Upon account deletion (Art. 17 GDPR), the account is deactivated immediately; all Google user data is completely and irrevocably deleted after a 90-day safety period (see Section 17).
4. Does heej share Google user data?
Google user data is not sold and not shared with ad networks or other third parties for commercial purposes. It is shared only with the following processors (Art. 28 GDPR), which act exclusively on behalf of and under the instructions of heej:
- OpenAI, L.L.C. — text embeddings (text-embedding-3-small) and optional audio/video transcription (Whisper). Per the OpenAI enterprise privacy policy, API inputs are not used for training.
- Anthropic PBC — chat replies via the Claude API. Relevant text excerpts from Google user data are passed to the API as context at runtime. API inputs are not used for training.
- Supabase Inc. — database and storage provider. EU region (Ireland).
- Render Services Inc. — hosting of the backend (EU region Frankfurt) that runs OAuth flows and content processing.
Data processing agreements pursuant to Art. 28 GDPR are in place with all processors. In addition, excerpts from Google user data become visible as chat replies to the followers of the respective influencer — this is the core purpose of the platform explicitly intended by the user (the influencer publishes knowledge to their community via the AI avatar).
5. Limited Use and Prohibition of AI Training Use
heej affirms compliance with the Google API Services User Data Policy — Limited Use requirements. In particular:
- Data obtained from restricted scopes (e.g. YouTube and Drive) is used exclusively to provide the user-facing feature requested by the user (AI avatar knowledge base).
- The data is not used for advertising and is not transferred to third parties for advertising purposes.
- The data is not sold.
- The data is not used to develop, train or improve generalised/non-personalised AI or ML models. This applies both to heej and — contractually assured — to all processors used (OpenAI, Anthropic). The models generate replies exclusively at runtime for the respective AI avatar and do not learn from user data.
- Human access to Google user data occurs only (a) with the user's explicit consent, (b) for security purposes (e.g. abuse investigation), (c) to comply with applicable law, or (d) in aggregated, anonymised form for internal operational purposes.
6. User Controls and Rights
- Disconnect:Dashboard → Sources → "Disconnect Google account". Revokes OAuth access and deletes access/refresh tokens.
- Delete individual sources: every imported YouTube or Drive source can be removed individually in the dashboard. All associated embeddings are cascade-deleted.
- Delete account and all data: Settings → "Delete account" (Art. 17 GDPR). Immediate deactivation; final cascade deletion of all Google user data after the 90-day safety period (Section 17).
- Revocation on Google's side: myaccount.google.com/permissions — access can be revoked there independently of heej.
- Access, rectification, portability: requests by email to team@heej.chat (Art. 15, 16, 20 GDPR).
15. Use of Artificial Intelligence (EU AI Act)
heej deploys AI avatars that automatically generate replies based on content uploaded by the creator. Users are always clearly informed within the application that they are communicating with an AI avatar and not with a real person, in accordance with the transparency requirements of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, Art. 50). Generated replies are machine-produced and may be inaccurate or incomplete. Synthetically generated speech output of the AI avatar is labelled as artificially generated in accordance with Art. 50(4) EU AI Act.
16. Your Rights as a Data Subject
Under the GDPR you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): information about the personal data we process about you.
- Right to rectification (Art. 16 GDPR): immediate correction of inaccurate data or completion of your stored data.
- Right to erasure (Art. 17 GDPR): deletion of your stored data, unless statutory retention obligations or the establishment, exercise or defence of legal claims prevent this. You can delete your account yourself at any time in the account settings.
- Right to restriction (Art. 18 GDPR): restriction of the processing of your personal data.
- Right to data portability (Art. 20 GDPR): receipt of the data you provided in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR): objection to processing based on Art. 6(1)(f) GDPR.
- Right to withdraw consent (Art. 7(3) GDPR): withdrawal of any consent given, at any time with effect for the future.
- Right to lodge a complaint (Art. 77 GDPR): with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
17. Retention Periods and Account Deletion
Personal data is deleted as soon as the purpose for its storage no longer applies. Statutory retention periods (e.g. tax and commercial law obligations of 6 or 10 years) remain unaffected.
Account deletion: you can delete your account at any time in the account settings. All active subscriptions are cancelled immediately, the voice model at ElevenLabs is deleted, and the account is deactivated (avatar page offline, no further follower access). After a 90-day safety period — which serves, among other things, to settle outstanding payouts and prevent abuse — all personal data, uploaded content and chat histories are finally and irrevocably deleted, unless statutory retention obligations require otherwise.
Specific Retention Periods
- Server logs (IP addresses, access data): up to 30 days
- Chat messages: duration of the contractual relationship; final deletion 90 days after account deletion
- Uploaded content and embeddings: until the creator deletes the source; final deletion 90 days after account deletion
- Voice model (voice clone): until consent is withdrawn; deleted at ElevenLabs immediately upon account deletion
- Payment and billing data: 10 years (Section 147 German Fiscal Code, Section 257 German Commercial Code)
18. Automated Decision-Making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. AI-generated chat replies serve informational purposes only and produce no legal or similarly significant effects.
19. Data Security
All connections to our website and API are encrypted using TLS. Data is stored encrypted at rest. Our database is protected by row-level security (RLS), so users can only access their own data; each creator's knowledge base is strictly isolated from others. Access to internal systems is restricted to the necessary minimum.
20. Changes to this Privacy Policy
We update this privacy policy when our processing activities or the legal situation change. The current version published on this page applies; the date of the last update is shown above.
21. Contact for Privacy Enquiries
For questions about the collection, processing or use of your personal data, or to exercise your rights, please contact:
The NEED GmbH — Sinan Yurttadur
Zettachring 12A, 70567 Stuttgart, Germany
Email: info@theneed.works
Phone: +49 (0) 711 25 25 1916