Legal
Privacy Policy
Last updated: April 2026
1. Introduction
Epic Splitter (“we”, “us”, “our”) operates epicsplitter.com and is committed to protecting the personal information of everyone who uses our platform.
This Privacy Policy explains what data we collect when you use Epic Splitter, how we use that data, who we share it with, how we store and protect it, and what rights you have over your information. By creating an account or using any part of the Epic Splitter service, you agree to the practices described in this policy.
If you have questions or concerns about this policy or how we handle your data, please contact us at privacy@epicsplitter.com.
2. Information We Collect
2.1 Information you provide directly
When you register for or use Epic Splitter, you provide us with information directly. This includes:
- Account registration data: Your full name, email address, and password. Passwords are stored in encrypted form using bcrypt and are never stored in plain text.
- Product idea descriptions: The content you submit for blueprint generation, including any product descriptions, feature lists, or business context you provide.
- Payment information: We do not store your card details. All payments are processed by Paystack, a PCI-DSS compliant payment processor. We receive a confirmation and reference number after a successful transaction, not your card data.
- Profile information: Any optional profile details you choose to add, such as your profile photo, bio, timezone, or notification preferences.
- Support communications: Any messages, emails, or other communications you send to us when seeking help or reporting a problem.
2.2 Information collected automatically
When you access Epic Splitter, certain technical information is automatically collected to help us operate and improve the service:
- IP address and approximate geographic location
- Browser type, version, and language settings
- Device type and operating system
- Pages visited within the application and time spent on each
- Referring URLs (the page you visited before arriving at Epic Splitter)
- Usage patterns and feature interactions within the application
2.3 Information from integrations
When you connect third-party services to Epic Splitter:
- Jira: When you connect your Jira workspace, we access your workspace name, project list, and the permission to create issues on your behalf. We do not store your Jira password. OAuth tokens used to authenticate with Jira are encrypted before being stored in our database.
- Other integrations: Any OAuth tokens or access credentials for third-party integrations are encrypted at rest using AES-256 encryption.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the service: To operate, maintain, and deliver the core Epic Splitter platform, including generating AI-powered product blueprints from the descriptions you submit.
- Processing payments: To facilitate credit purchases via Paystack and maintain accurate records of your account balance and transaction history.
- Sending transactional emails: To send account confirmation emails, payment receipts, blueprint share notifications, and other service-related communications that are necessary for the operation of your account.
- Product updates and announcements: To inform you about new features, improvements, and relevant updates to the Epic Splitter platform. You can unsubscribe from marketing communications at any time.
- Improving our service: To analyse how users interact with the platform and improve our AI models, product quality, and overall user experience. We use aggregated and anonymised data for this purpose where possible.
- Fraud detection and security: To detect, investigate, and prevent fraudulent activity, abuse, and violations of our Terms of Use.
- Legal compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.
- Support: To respond to your support requests, questions, and feedback.
5. Data Storage and Security
We take the security of your data seriously and implement the following technical and organisational measures to protect it:
- All data is stored on secure cloud servers with restricted physical and network access.
- Passwords are hashed using industry-standard bcrypt encryption and are never stored in plain text under any circumstances.
- All data transmission between your browser and our servers uses HTTPS/TLS encryption.
- Integration tokens (such as Jira OAuth tokens) are encrypted at rest using AES-256 encryption.
- We implement role-based access controls internally. Only authorised team members can access user data, and only when strictly necessary for operational or support purposes.
Data retention: We retain your personal data for as long as your account is active. If you delete your account, your personal data is permanently deleted within 30 days. Payment records and financial transaction history may be retained for up to 7 years to comply with legal and accounting obligations.
Security incident notification: While we implement robust security measures, no system can guarantee absolute security. In the event of a data breach that affects your personal information, we commit to notifying affected users promptly in accordance with applicable data protection law.
6. Nigerian Data Protection (NDPR Compliance)
Epic Splitter operates in compliance with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act 2023 (NDPA).
Our lawful basis for processing your data:
- Contract performance: Processing that is necessary to deliver the service you signed up for, including generating blueprints, managing your account, and processing your payments.
- Legitimate interests: Processing that is in our legitimate business interests, including improving the quality of our service and preventing fraudulent activity, where those interests are not overridden by your rights.
- Consent: For marketing communications and any processing not covered by the above bases, we will ask for your consent and respect your right to withdraw it at any time.
Your rights under NDPR and NDPA include:
- Right of access: The right to request a copy of the personal data we hold about you.
- Right to rectification: The right to request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure: The right to request deletion of your personal data in certain circumstances. You can also delete your account directly from your account settings page.
- Right to withdraw consent: The right to withdraw your consent for marketing communications at any time, without affecting the lawfulness of any processing carried out prior to withdrawal.
- Right to lodge a complaint: The right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe we have not handled your data in accordance with applicable law.
To exercise any of these rights, please contact us at privacy@epicsplitter.com. We will respond to all valid requests within 30 days.
8. Third-Party Links
The Epic Splitter platform may contain links to third-party websites, tools, and services such as Lovable, Claude Code documentation, Jira, Paystack, and others. These links are provided for your convenience and to enhance the value of the service.
Epic Splitter has no control over and assumes no responsibility for the content, privacy policies, or practices of any third-party services. We strongly encourage you to review the privacy policy of any third-party service before sharing personal information with them. Our Privacy Policy does not apply to information you provide to or that is collected by third-party services.
9. Children's Privacy
Epic Splitter is designed for use by adults and is not directed at children under the age of 16. We do not knowingly collect, process, or store personal information from any person under 16 years of age.
If you are a parent or guardian and believe that a child under 16 has provided us with personal information without your consent, please contact us immediately at privacy@epicsplitter.com. We will investigate and take appropriate steps to delete that information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes to this policy, we will notify registered users by email and/or by displaying a prominent notice within the application before the changes take effect.
The “Last updated” date at the top of this page indicates when the policy was most recently revised. We encourage you to review this page periodically. Your continued use of Epic Splitter after any changes to this policy constitutes your acceptance of those changes.
11. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
Privacy enquiries: privacy@epicsplitter.com
Website: epicsplitter.com
Account deletion: You can also delete your account and request data removal directly from the account settings page inside the application.