Privacy

Last updated 27 September 2026.

This policy describes what Bitnook GmbH, publishing on Google Play as Mutator Apps, stores when you use Mutator, why, and what you can do about it. Mutator is for people 18 and older. It is written to be checkable: the retention periods and the list of companies below match how the product actually behaves.

What we store

The waitlist. If you left your email address while signups were closed, we store that address, the page you left it on, and the date. We also record how you reached us: the campaign tags on the link you followed, if it carried any, and the domain of the site you came from — never the address of the page itself, which is not ours to keep. It is used to tell you when there is a place for you. If you also ask for occasional product updates — by ticking the box on the form, or with the button that email links to — we send you those as well, and keep a record of when you asked, where, the words you agreed to, and which updates went to you. Nobody gets updates without asking for them. Every message we send carries a link to stop it, without needing an account or a reply. Under an update it stops the updates and keeps your place on the list; you can leave the list altogether from there, or from any other message we send. Your entry stays until you ask us to delete it, or until you delete a Mutator account with the same address. We do not use your address for anything else, and we do not share it.

Your account. Your name, email address, and a hash of your password — never the password itself. If you sign up with Google instead, we keep the id Google gives your Google account in place of a password. Sessions are stored so you stay signed in. Each one records when it started and when it was last used (to within a day), the IP address it was signed in from, and the browser or app it came from, so Settings can show you where you are signed in. From there you can sign out any other device, or every other device at once. Signing a device out deletes that session’s record, and deleting your account deletes all of them.

What you create. Brands, automations, the images, videos and other files you upload, generated videos, images and captions, what you chose to post and when, the email addresses of people you invite, and the record of what was published where. Some of this contains whatever you typed into it, so it is worth knowing that brand profiles and prompts are stored as you wrote them.

Somebody else in what you upload. A photograph or a recording of another person is processed on your instruction, and our terms ask you to have that person’s agreement before you upload it. We handle it the way we handle the rest of your media: stored with your workspace, and deleted when you delete it or close your account.

Connections to other services. When you connect a provider account, the credential is encrypted (AES-256-GCM) before it is stored and is only ever decrypted to make a call you asked for. Credentials are never shown back to the browser, never written to logs, and are deliberately excluded from data exports.

Results. Views, watch time, clicks and similar figures for posts you published, retrieved from the account that published them.

Billing. Your workspace’s plan and its status, its trial, renewal and cancellation dates, whether and when a card was added, the country Stripe reported for its most recent purchase, the credits it has been given or has bought and how they were spent, and Stripe’s references for all of these. If you buy a plan or credits in the Mutator app, Apple or Google takes the payment. They tell us what was bought, when, whether it renews or was cancelled or refunded, and which workspace it is for. We never receive your card details.

Operational records. An activity log of who did what in a workspace (runs started, content reviewed, captions edited, files uploaded, members invited with the address each invitation went to, and changes to connections, schedules and billing), which the workspace’s owners and admins can read; a record of the emails we send; error reports from our servers and from web pages, including the signed-in pages the apps open, which can include a stack trace and the path of the page; and first-party product events, named actions like “created an automation”, stored in our own database.

Advertising. Our public pages and the first screen after you sign up load X’s advertising pixel and Google’s ads tag, so we can tell whether our ads on X and Google lead to people making an account. Each sees which of those pages you opened, that an account was made (as an internal number), and what any website request carries, such as your IP address and browser. Google’s tag also keeps cookies on this site that remember whether you arrived from one of its ads, except in the EEA, the UK and Switzerland, where it stores nothing on your device. We tell Google not to use these visits to personalise ads. When you sign up or pay, we send Google Ads a scrambled (hashed) version of your email address so it can tell which of its ads led to your account. Google never receives the address itself. Neither runs inside the app, where your work is. There is no session replay and no other third-party analytics script.

Reports you make. If you report a generated image or video, we keep the reason you chose, anything you wrote, and a copy of what produced it — the prompt, the model and the provider’s reference for that request — so our team can review it and stop the same thing being made again. Reports come to us, not to anyone else in your workspace. If you report it as sexual or violent, we take it out of use while we review it: it can’t be previewed, scheduled or posted, and scheduled posts of it are cancelled. Your workspace can see that it is under review, but not who reported it. Copies already downloaded or posted can’t be recalled. If we uphold the report we delete the file; otherwise it goes back into use. If the media is deleted later, or you delete your account, the report stays without the link to the media and without your name; deleting the workspace deletes its reports.

Content checks. Every check of a prompt, caption, title, uploaded file or generated picture or video leaves a record: what kind of thing it was, where in Mutator it came from, what the check decided and why, which model decided it, and when. Text that passes is kept there only as a fingerprint that cannot be turned back into the words. Text that fails is kept, up to 2,000 characters of it, so our team can see what was refused. No picture or video is ever kept in these records, and one that fails a check is not stored by Mutator at all. The records are kept for 90 days, except the one showing that a file still in your workspace passed, which is kept as long as the file. If the same person has several different things refused in a day, or anything is refused as sexual content involving a minor, our team is told so that a person can look; nothing is suspended automatically. If you delete your account, the records stay without your name; deleting the workspace deletes them.

Visitor counts. So we know how many people reach the site, each page view is counted against a short-lived code worked out from your IP address and browser using a secret that changes every day. It is not reversible, nothing is stored on your device, and because the secret changes at midnight the code cannot be used to recognise you tomorrow or to follow you between visits. We also record which country you are in, and we work it out from the time zone your browser reports rather than from your IP address, and for these counts your address is never looked up, never sent to anyone, and never stored. We keep only the country, not the time zone itself. Only the website’s public pages are counted, including when one of the apps opens one; the apps themselves send no page views. On those pages we also count, the same way, whether a visit stayed about ten seconds, scrolled, or clicked or typed in the website field, and on the start page which step it reached, but never what was typed. That tells us whether a page gets read, not who read it. We keep the counts for 90 days. If a page was reached from somewhere else we record only that site’s domain, never the address of the page you came from, which is not ours to keep. Where a link we posted carries a campaign tag, such as ?utm_source=pinterest, we record that tag against the visit: it says which of our own links you came through and nothing about you.

If we wrote to you about your website. We sometimes email people who publish lists or reviews of marketing tools, to suggest Mutator for their readers. We use the address your site publishes for this, keep your name, that address, where we found it and our emails with you, and delete them six months after our conversation ends. Reply “no thanks” to any of our emails, or write to us, and we will not contact you again; we keep a one-way hash of your address so that we never do. When you reply, Claude, an AI model made by Anthropic, reads it to sort it, so a person sees it and a request to stop is honoured at once. Our emails with you are kept in our mailbox at Zoho.

Who else sees it

Mutator passes data to a small number of companies, only where the feature requires it:

  • The providers you connect yourself — your publishing accounts, and any generation account you connect. You hold those directly, and their own terms and privacy policies govern what they do with what you send.
  • The providers Mutator holds accounts with — where you generate on our accounts rather than your own, what you write is sent to them by us, under our contract with them. They are named in the list further down this page.
  • Content checks — prompts, captions, titles, uploaded files, and the pictures and video frames Mutator generates are sent to Anthropic, which checks them against the content rules in our terms: nudity, sexual content, graphic violence and symbols of hate. Files are sent as their contents, never as a link to where we keep them. This happens on Mutator’s account whichever way you generate. Anthropic may keep anything its own safety systems flag for up to two years, under its own retention policy.
  • Payment processing — handled by Stripe. Card details go to Stripe and never reach Mutator’s servers.
  • The spam check on the contact form is Cloudflare Turnstile, which decides whether a submission came from a person. It sets no cookie and does not track you across sites. What you write in the form is not sent to it. Your message is mailed to us and nowhere else: we answer from the inbox and keep no database of messages.
  • The infrastructure behind Mutator — the companies that store the database and your media, send the emails Mutator sends, hold the inbox where our team reads the reports you send, and generate the images, videos and captions you ask for. They process what Mutator sends them only to do those things, and for nothing else:
    • Railway Corporation — hosting, the database and the background worker, in the United States
    • Cloudflare, Inc. — storage for the files you upload and the media Mutator makes, in the United States
    • Higgsfield, Inc. — generating images and video from your prompts and reference photos, in the United States
    • fal - Features & Labels, Inc. — generating video from your prompts and reference photos, in the United States
    • Resend, Inc. — delivering the approval and notification emails you turn on, account, invitation and billing emails, waitlist emails, the product updates you ask for, and the reports you send to our team, in the United States
    • Anthropic PBC — drafting captions from the briefs you write, describing the product photos you upload, and checking prompts, captions, uploads and generated media against the content rules in the terms, in the United States
    • Proton AG — holding the inbox where our team reads the reports you send, in Switzerland

Nothing is sold, and apart from the X pixel and the Google tag above, nothing is shared for advertising.

Where it is processed. Taken together, that means your data is stored and processed in the United States and Switzerland. Bitnook GmbH is established in Switzerland, so where that list names somewhere else, your data leaves the country to be held and served there.

Google user data

When you connect a YouTube channel, Google gives us the channel’s id, its name and its picture, along with the access token that lets Mutator upload on your behalf. We use them for one purpose: to show you which channel you connected, and to publish the videos you choose to post to it.

Who we share it with. Only Railway Corporation — the company that runs the database this is stored in. Nobody else on the list above receives it: it is never written to object storage, never included in the briefs sent to the AI writer, and never put in an email. It is not shared with any other third party, sold, used for advertising, or used to train anyone’s AI models.

The access token is encrypted before it is stored and decrypted only to make a call to Google. Disconnecting the channel deletes the stored tokens immediately; the channel’s id, its name and the address of its picture stay on the disconnected connection until the workspace is deleted. Deleting the workspace deletes everything with it, and so does deleting your account, for every workspace you are the only owner of.

When you sign up or sign in with Google, Google tells us your name, your email address, whether Google has confirmed that address, and an id for your Google account. We use them only to create your Mutator account and sign you in. We do not keep your Google profile picture, or any token that would let us act for you on Google.

Mutator’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Pinterest data

When you connect a Pinterest account, Pinterest gives us the account’s id, its username and the address of its picture, along with the access token that lets Mutator create pins on your behalf. We use them for one purpose: to show you which account you connected, to list the boards you can post to, and to create the pins you choose to post.

Who we share it with. Only Railway Corporation — the company that runs the database this is stored in. Nobody else on the list above receives it: it is never written to object storage, never included in the briefs sent to the AI writer, and never put in an email. It is not shared with any other third party, sold, used for advertising, or used to train anyone’s AI models.

The access token is encrypted before it is stored and decrypted only to make a call to Pinterest. Disconnecting the account deletes the stored tokens immediately; the account’s id, its username and the address of its picture stay on the disconnected connection until the workspace is deleted. Your boards are never stored: they are read from Pinterest each time a screen asks you to choose one, and only the board you pick is kept, on the post it is for.

If you are a business customer

Where you use Mutator to process personal data belonging to other people — your own team, or anyone identifiable in the content you upload — you are the controller of that data and Bitnook GmbH is your processor. We have a data processing agreement covering that relationship, including the sub-processors above, the security measures behind them and how international transfers are handled.

Ask for it at hello@mutator.app and we will send it to you. You do not need to be on a particular plan to have one.

How long it is kept

Generated media is deleted after 90 days. The record of what was published survives that, so your history and reporting stay readable after the files themselves are gone. Product events are kept for 400 days, and deleting your account unlinks them from you at once. Error reports and visitor counts are kept for 90 days, and so are the records of password-reset, verification, invitation, notification, waitlist, newsletter and report emails; the records of billing and welcome emails are kept until your account is deleted. Our hosting provider keeps server logs for 30 days. They include the addresses and subject lines of the emails we send, waitlist addresses, the prompts sent to our image and video generator, and error text sent from web pages. Database backups are kept for up to 89 days. Everything else is kept until you delete it, with two exceptions: in a workspace that has another owner, what you made there, its activity log and your reports stay with that workspace after your account is deleted; and when deleting your account deletes a workspace, we keep a record that a workspace was deleted, without its name. A picture or video that fails a content check is not stored by Mutator.

What you can do

From Settings you can delete your account and sign out every other device. A workspace’s owner can also export its records as a readable file and delete it permanently, and its owners and admins can read its recent activity. These are built into the product, so you do not need to email anyone to use them. If you cannot sign in, the data deletion page explains how to ask us by email instead.

If you are in the UK or EU, you also have rights of access, correction, portability, erasure and objection under the GDPR, and the right to complain to your local data protection authority.

Contact

Privacy questions go to hello@mutator.app.

Bitnook GmbH Spitalgasse 28 3011 Bern Switzerland