Data Deletion
Last Updated: April 30, 2026
Operated by: Mighty Lucky Ventures Pty Ltd (trading as Heista), ABN 51 653 328 628
Contact: support@heista.co
We respect your right to control your data. This page explains how to request deletion of your personal data from Heista, including data received from third-party platforms such as Meta (Facebook/Instagram).
1. Delete Your Heista Account
To delete your entire Heista account and all associated data:
- Log in to your Heista account at app.heista.co.
- Navigate to Settings.
- Select Delete Account.
- Confirm the deletion.
Upon account deletion, we will permanently delete the following within 30 days:
- Your account profile and credentials.
- All Power Sources (brand intelligence data).
- All Vault assets and project data.
- All saved scripts, briefs, and generated outputs.
- All connected third-party platform data (Meta ads data, OAuth tokens).
- Operator conversation history.
- Usage and behavioural data.
What we retain: Operator Protocol acceptance logs are retained for 7 years for legal compliance purposes. Anonymised, aggregated analytics data that cannot identify you is retained indefinitely. Decoded structural intelligence that has been incorporated into the Heista Decoded Library is not deleted, as it constitutes independently derived analysis of publicly available content and does not contain your personal data (see Section 4 for details).
2. Delete Meta (Facebook/Instagram) Data Only
If you connected your Meta advertising account to Heista and want to remove that data specifically:
Option A: Disconnect from Heista
- Log in to your Heista account.
- Navigate to Settings > Connected Accounts.
- Click Disconnect next to your Meta account.
This revokes our access and triggers deletion of all stored Meta platform data within 30 days, including:
- Meta user ID and ad account IDs.
- OAuth access tokens and refresh tokens.
- Cached ad creatives, campaign data, and performance metrics.
Option B: Remove from Facebook Settings
- Go to your Facebook Settings.
- Navigate to Security and Login > Apps and Websites (or Business Integrations).
- Find Heista and click Remove.
When you remove Heista from your Facebook settings, Meta sends us a data deletion callback. We automatically process this callback and delete all stored Meta platform data associated with your account within 30 days. You will receive a confirmation code that you can use to check the status of your deletion request.
What is NOT deleted
Decoded frameworks, strategic briefs, and competitive intelligence that were generated from your ads are retained in your Heista account. These are Heista-generated analytical outputs and do not contain raw Meta platform data. If you want these deleted as well, please delete your Heista account (Section 1) or contact us at support@heista.co.
3. Delete API Data
If you use the Heista API and want to delete your API data:
Revoke API Keys
- Log in to your Heista account.
- Navigate to API Console > API Keys.
- Click Revoke next to each key you want to delete.
Revoked keys are immediately deactivated. Key metadata (creation date, prefix, last used) is retained for 90 days for audit purposes, then permanently deleted.
API Job Results
API decode job results are automatically deleted 90 days after completion. You do not need to request deletion of job results.
API Usage Logs and Balance
API usage logs (request history, costs, endpoints) are deleted within 30 days of account deletion. Your API credit balance is forfeited upon account deletion, subject to the Service Discontinuation provisions in our Terms of Service.
Decoded Library Intelligence
Structural intelligence derived from content you submitted for decoding through the API (PatternMap analysis, beat structures, psychological classifications, ad formulas) that has been incorporated into the Heista Decoded Library is not deleted upon account closure. This intelligence is independently derived analysis of publicly available content. It does not contain your personal data, account information, API key, or proprietary brand data.
4. Request Deletion via Email
If you are unable to delete your data through the methods above, or if you want to make a specific data deletion request, contact us:
Email: support@heista.co
Subject line: "Data Deletion Request"
Include: Your account email address and a description of which data you want deleted.
We will:
- Acknowledge your request within 5 business days.
- Verify your identity to prevent unauthorised deletion.
- Complete the deletion within 30 days of verification.
- Send you written confirmation once deletion is complete.
5. Deletion Timelines
| Data Category | Deletion Timeline |
|---|---|
| Account profile and credentials | Within 30 days of request |
| Power Sources and brand data | Within 30 days of request |
| Vault assets and projects | Within 30 days of request |
| Meta platform data (ads, tokens, metrics) | Within 30 days of disconnection or callback |
| Operator conversation history | Within 30 days of request |
| Usage and behavioural data | Within 30 days of request (then anonymised) |
| Technical and server logs | Automatically purged after 90 days |
| Operator Protocol acceptance logs | Retained 7 years (legal compliance) |
| API keys (revoked) | Immediately deactivated; metadata deleted after 90 days |
| API job results | Automatically deleted 90 days after completion |
| API usage logs | Within 30 days of account deletion |
| API credit balance | Forfeited on account deletion |
| Decoded Library intelligence | Not deleted (structural analysis of public content, no personal data) |
6. Your Rights
In addition to data deletion, you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Portability: Request an export of your data in a commonly used format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
For full details on your privacy rights, please refer to our Privacy Policy.
If you are located in Australia, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If you are located in the EEA or UK, you may lodge a complaint with your local data protection supervisory authority.
2026 Mighty Lucky Ventures Pty Ltd (trading as Heista). All rights reserved.