Privacy Policy
Mythika is a one-person business. This policy says exactly what data is handled, who else sees it, how long it is kept, and how to have it deleted — in plain language, with every third party named rather than hidden behind “trusted partners”.
Who we are
Mythika is a marketing services business operated by Ramy Sentawos, based in Egypt, serving clients internationally. For any privacy question, or to exercise any right described here, contact ramy@mythika.agency.
What we collect
If you email us or request a Growth Brief
- Your name and email address
- Your business website, city, and anything else you choose to tell us
- The content of your messages, and our replies
We ask for a website URL and a city. We do not ask for, and do not want, patient information, medical records, or any personal data about your customers.
If you become a client
- Business contact and billing details
- Brand materials you send us — logos, images, existing marketing
- Publicly available information about your business and competitors, gathered by research
- Social media account access you explicitly grant, and performance metrics for your own posts
If you visit this website
This site is a static page. It sets no Mythika advertising cookies. Cloudflare Web Analytics is active and produces aggregate, cookieless measurements; it does not create visitor profiles for Mythika. Our host, Cloudflare, processes standard server logs including IP addresses for security and delivery. Google Fonts receives the network information needed to return font files requested by your browser.
How we use it
- To research your market and produce the work you asked for
- To communicate with you about that work
- To invoice and keep required financial records
- To improve our own service quality — internally, using our own records of what worked
We do not sell your data. We do not share it for advertising. We do not use your business information to train any public AI model.
Artificial intelligence, stated plainly
We use AI tools to research and draft work. That means text about your business — your website content, your market, your brief — may be sent to Anthropic or OpenAI to generate drafts.
A human reviews and approves every piece of work before it reaches you or the public. Nothing is published automatically. We do not send your customers' personal data to AI providers, because we do not collect it.
Who else processes your data
Running this service requires third parties. Each one below is named because it genuinely handles data, and this list is checked against our actual systems rather than copied from a template. It is updated whenever a provider is added.
| Provider | What it handles |
|---|---|
| Supabase | Our database and file storage — business records and finished work |
| Anthropic | AI drafting and analysis of the text described above |
| OpenAI | AI drafting, structured analysis, and internal quality checks |
| Google (Workspace and Fonts) | Email messages and replies; font-file requests made by your browser |
| n8n | The automation platform that runs our internal processes |
| Cloudflare | Website hosting, security logs, and aggregate Cloudflare Web Analytics measurements |
| Telegram | Internal approval notifications to the owner's own device |
| HTML/CSS to Image | Turning designs into image files |
| Tavily, Jina | Public-web research queries; Jina also receives a normalized public URL entered into the free page reader |
| Meta (Facebook, Instagram) | Only where you have explicitly connected an account — see below |
Facebook and Instagram data
If, after a separate connection test and written approval, you connect a Facebook Page or Instagram Business account so we can publish on your behalf, we access only what that permission covers:
- What we access: your account and page identifiers, the ability to publish posts you have approved, and performance metrics for those posts (reach, engagement, saves)
- What we do with it: publish approved content and report results back to you
- What we never do: read your private messages for any purpose other than responding to enquiries you asked us to handle; access data about your followers as individuals; or use any of it for advertising or resale
- How long we keep it: the written engagement scope states the period; no account connection is accepted until that period and deletion method are confirmed
You can disconnect our access at any time from your own Facebook or Instagram settings, without contacting us. To have the data deleted as well, see Data Deletion.
How long we keep things
Interim pilot position: automatic retention schedules and verified backup expiry are not yet implemented end to end. We therefore do not promise automatic 12-month or 90-day deletion. Enquiry and pilot data is kept to the minimum needed, deletion requests are handled manually, and any record that must be retained for tax or legal reasons is identified.
No ongoing client engagement or social-account connection will start until its written scope states the applicable retention period, responsible system, backup treatment, and deletion owner.
Your rights
Whatever country you are in, you may ask us to:
- Tell you what data we hold about you
- Give you a copy of it
- Correct anything wrong
- Delete it — see Data Deletion
- Stop using it for a particular purpose
Email ramy@mythika.agency. We acknowledge the request, verify the records and legal exceptions involved, and confirm the completion timetable in writing. There is no charge.
Security
Privileged database access is credential-controlled. Public forms are deliberately limited to validated submissions and cannot read stored records. Some deliverables may use unlisted public links, so sensitive or personal material must not be placed there. Access and storage controls are being reviewed before paid client onboarding.
No system is perfectly secure, and claiming otherwise would be dishonest. If a breach affects your data, we will tell you what happened and what we are doing about it — promptly, and without being asked.
Children
This is a business-to-business service and is not directed at anyone under 18. We do not knowingly collect data about children.
Changes
If this policy changes materially, the date at the top changes and existing clients are told directly. We will not make a material change quietly.