Privacy Policy
Last updated: 27 April 2026
Your privacy matters to us. This policy explains what personal data Monstric collects, how we use it, who we share it with, and what rights you have under the EU General Data Protection Regulation (GDPR) and the Slovak Personal Data Protection Act.
1. Who we are
Monstric is operated by Stanislav Vojtko, a sole trader (živnostník) registered in the Slovak Republic. We act as the data controller for personal data processed through monstric.com and related services. You can reach us at hello@monstric.com.
2. Data we collect
- Account data: email address, name (optional), and authentication identifiers when you sign up or log in.
- Brand inputs: prompts, business descriptions, niches, and any text you submit to generate names, brand kits, or websites.
- Generated outputs: brand names, logos, color palettes, copy, and other assets produced for your account.
- Billing data: when you make a purchase, Stripe collects your payment details and shares with us a customer ID, the amount, and a receipt URL. We do not store full card numbers.
- Technical data: IP address (hashed for rate limiting and abuse prevention), browser type, device, and basic usage events.
- Cookies: a session cookie for authentication, a theme preference, and a basic analytics cookie. We do not use cross-site tracking cookies.
3. Why we use your data
- To provide the service: generate names and brand assets you request.
- To create and secure your account and process payments.
- To send transactional emails (login links, receipts, account notices).
- To prevent abuse, fraud, and rate-limit free generations.
- To improve the product through aggregated, non-identifying analytics.
Lawful bases under GDPR: performance of a contract (Art. 6(1)(b)), our legitimate interest in operating and improving the service (Art. 6(1)(f)), and your consent where applicable (Art. 6(1)(a)).
4. Third parties we work with
We share the minimum data needed with these processors:
- Google (Gemini API): prompts and brand inputs are sent to Google to generate AI outputs. Google does not use this data to train models when accessed via the paid API.
- Stripe: payment processing and billing.
- Resend: transactional email delivery.
- Neon: managed Postgres database hosting.
- Vercel: application hosting and serverless infrastructure.
- Umami: privacy-friendly analytics (no personal identifiers).
- PostHog (EU region): product analytics, funnel and session tracking. Inputs are masked by default and IPs are anonymised at the project level.
- fal.ai, ElevenLabs: optional AI features (image vectorization, voice agent) used only when you trigger them.
Some processors are based outside the EU. Where that is the case, transfers rely on Standard Contractual Clauses or equivalent safeguards.
5. How long we keep your data
- Account data: while your account is active, plus up to 30 days after deletion.
- Brand inputs and generated outputs: while your account is active, or until you delete them.
- Billing records: 10 years, as required by Slovak accounting law.
- Anonymous usage logs: up to 12 months.
6. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion (right to be forgotten).
- Restrict or object to processing.
- Receive a copy of your data in a portable format.
- Withdraw consent at any time, where consent is the basis.
- Lodge a complaint with the Slovak Data Protection Authority (dataprotection.gov.sk).
To exercise any of these rights, email hello@monstric.com. We respond within 30 days.
7. Security
We protect your data using industry-standard encryption in transit (HTTPS) and at rest. Access to production systems is limited and logged. No method is 100% secure, but we apply commercially reasonable safeguards.
8. Children
Monstric is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced on this page. Continued use of Monstric after changes means you accept the updated policy.
10. Contact
Questions about privacy or your data? hello@monstric.com.
