Privacy

Privacy Policy

Last updated 14 August 2026

Mythika is a one-person business. This policy says exactly what data is handled, who else sees it, how long it is kept, and how to have it deleted — in plain language, with every third party named rather than hidden behind “trusted partners”.

Who we are

Mythika is a marketing services business operated by Ramy Sentawos, based in Egypt, serving clients internationally. For any privacy question, or to exercise any right described here, contact ramy@mythika.agency.

What we collect

If you email us or request a Growth Brief

  • Your name and email address
  • Your business website, city, and anything else you choose to tell us
  • The content of your messages, and our replies

We ask for a website URL and a city. We do not ask for, and do not want, patient information, medical records, or any personal data about your customers.

If you become a client

  • Business contact and billing details
  • Brand materials you send us — logos, images, existing marketing
  • Publicly available information about your business and competitors, gathered by research
  • Social media account access you explicitly grant, and performance metrics for your own posts

If you visit this website

This site is a static page. It sets no Mythika advertising cookies. Cloudflare Web Analytics is active and produces aggregate, cookieless measurements; it does not create visitor profiles for Mythika. Our host, Cloudflare, processes standard server logs including IP addresses for security and delivery. Google Fonts receives the network information needed to return font files requested by your browser.

How we use it

  • To research your market and produce the work you asked for
  • To communicate with you about that work
  • To invoice and keep required financial records
  • To improve our own service quality — internally, using our own records of what worked

We do not sell your data. We do not share it for advertising. We do not use your business information to train any public AI model.

Artificial intelligence, stated plainly

We use AI tools to research and draft work. That means text about your business — your website content, your market, your brief — may be sent to Anthropic or OpenAI to generate drafts.

A human reviews and approves every piece of work before it reaches you or the public. Nothing is published automatically. We do not send your customers' personal data to AI providers, because we do not collect it.

Who else processes your data

Running this service requires third parties. Each one below is named because it genuinely handles data, and this list is checked against our actual systems rather than copied from a template. It is updated whenever a provider is added.

ProviderWhat it handles
SupabaseOur database and file storage — business records and finished work
AnthropicAI drafting and analysis of the text described above
OpenAIAI drafting, structured analysis, and internal quality checks
Google (Workspace and Fonts)Email messages and replies; font-file requests made by your browser
n8nThe automation platform that runs our internal processes
CloudflareWebsite hosting, security logs, and aggregate Cloudflare Web Analytics measurements
TelegramInternal approval notifications to the owner's own device
HTML/CSS to ImageTurning designs into image files
Tavily, JinaPublic-web research queries; Jina also receives a normalized public URL entered into the free page reader
Meta (Facebook, Instagram)Only where you have explicitly connected an account — see below

Facebook and Instagram data

If, after a separate connection test and written approval, you connect a Facebook Page or Instagram Business account so we can publish on your behalf, we access only what that permission covers:

  • What we access: your account and page identifiers, the ability to publish posts you have approved, and performance metrics for those posts (reach, engagement, saves)
  • What we do with it: publish approved content and report results back to you
  • What we never do: read your private messages for any purpose other than responding to enquiries you asked us to handle; access data about your followers as individuals; or use any of it for advertising or resale
  • How long we keep it: the written engagement scope states the period; no account connection is accepted until that period and deletion method are confirmed

You can disconnect our access at any time from your own Facebook or Instagram settings, without contacting us. To have the data deleted as well, see Data Deletion.

How long we keep things

Interim pilot position: automatic retention schedules and verified backup expiry are not yet implemented end to end. We therefore do not promise automatic 12-month or 90-day deletion. Enquiry and pilot data is kept to the minimum needed, deletion requests are handled manually, and any record that must be retained for tax or legal reasons is identified.

No ongoing client engagement or social-account connection will start until its written scope states the applicable retention period, responsible system, backup treatment, and deletion owner.

Your rights

Whatever country you are in, you may ask us to:

  • Tell you what data we hold about you
  • Give you a copy of it
  • Correct anything wrong
  • Delete it — see Data Deletion
  • Stop using it for a particular purpose

Email ramy@mythika.agency. We acknowledge the request, verify the records and legal exceptions involved, and confirm the completion timetable in writing. There is no charge.

Security

Privileged database access is credential-controlled. Public forms are deliberately limited to validated submissions and cannot read stored records. Some deliverables may use unlisted public links, so sensitive or personal material must not be placed there. Access and storage controls are being reviewed before paid client onboarding.

No system is perfectly secure, and claiming otherwise would be dishonest. If a breach affects your data, we will tell you what happened and what we are doing about it — promptly, and without being asked.

Children

This is a business-to-business service and is not directed at anyone under 18. We do not knowingly collect data about children.

Changes

If this policy changes materially, the date at the top changes and existing clients are told directly. We will not make a material change quietly.