homeHEISTA

Terms of Service

Last Updated: September 16, 2026 (plans, credits and product names brought into line with what is actually sold)

Operated by: Mighty Lucky Ventures Pty Ltd (trading as Heista), ABN 51 653 328 628

Website: https://www.heista.co

Please read these Terms of Service carefully before using the Heista platform. By creating an account, subscribing to a paid plan, buying credits, using the Heista API with an API key, or installing or using a Heista Skill in a third-party AI surface, you agree to be bound by these Terms in full.

1. Acceptance of Terms

By accessing and using Heista (the "Service"), you accept and agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the Service.

These Terms govern your use of the Heista platform located at heista.co and all associated services, modules, features, APIs, and integrations operated by Mighty Lucky Ventures Pty Ltd (trading as Heista) ("Heista," "we," "our," or "us"). This includes, without limitation, the Heista web app, the Heista API, and any Heista Skills or integrations available through third-party AI platforms.

2. Description of Service

Heista is the creative development workspace for agencies and creative teams. It is where you explore ideas, creative directions and executions in the space between a brief and production. The workspace is made up of purpose-built apps (each a "Specialist AI"), each of which does one creative job — decoding advertising, writing scripts and hooks, building briefs, extracting brand intelligence, making images and film, and related work.

Heista delivers that workspace across three surfaces: the web app, the API, and Skills. All three share the same underlying intelligence layer, including the Decoded Library, PatternMap, and Power Source technology.

2.1 The Heista Web App and Specialist AIs

The web app is the customer-facing surface of Heista. Every Specialist AI is included with every plan, including the Free plan — there is nothing to buy app by app. The Service includes, but is not limited to:

  • Specialist AIs: Individual AI-powered creative apps covering jobs such as ad decoding, script generation, image creation, creator briefs, brand intelligence, competitive analysis, and visual production.
  • Decoded Library: A continuously expanding catalogue of decoded ads with structural analysis, browseable by all users.
  • Creative Strategy (Power Sources): Brand intelligence layer that extracts positioning, voice, audience, and competitive context from your website and loads it into the output of every Specialist AI.
  • PatternMap: Proprietary decoding engine that analyses winning ads into structural intelligence including hooks, beats, psychology, and visual grammar.
  • Meta ads integration: A Meta (Facebook/Instagram) advertising account integration that decodes your running ads, compares them against category benchmarks, and generates strategic briefs.
  • Creative Director: AI-powered strategic assistant with access to your decoded library, brand intelligence, and creative apps.

2.2 The Heista API

Heista provides a public API for programmatic access to creative intelligence capabilities. The API exposes atomic endpoints (such as Decode, Brand Find, and others as they become available) that developers can compose into custom workflows and integrate into their own products and services.

  • API access requires an API key issued through the Heista API Console.
  • API usage is paid for in AI Credits on the same terms as the rest of the Service, including the ninety (90) day expiry in §10.2(b).
  • The API is subject to rate limits, usage caps, and availability constraints as described in the API documentation and these Terms.
  • API documentation, endpoint specifications, and pricing are available through the API Console at heista.co/api-console.

2.3 Heista Skills

Heista capabilities may be made available as skills, plugins, or integrations within third-party AI platforms (such as Claude, ChatGPT, or other AI surfaces). Skills are free to install from their respective marketplaces. Usage of Skills consumes credits from your Heista account.

  • Using a Skill requires authentication with your Heista account. First-time use will prompt you to create an account or sign in via your browser.
  • Skills are subject to both these Terms and the terms of the third-party platform through which the Skill is accessed.
  • Skill functionality may differ from the web app experience depending on the capabilities of the host platform.

2.4 Nature of the Service

Heista is a competitive intelligence and strategic analysis platform. It provides research-derived structural frameworks based on independent analysis of publicly available communication patterns. What we license to you is functional logic and structural templates derived from our own analysis; we do not sell or license third-party creative assets. Advertising we analyse is retained and displayed as described in section 6.8.

2.5 No Professional Advice

The Service provides strategic intelligence tools and AI-generated content frameworks across all surfaces (web app, API, and Skills). It does not constitute and should not be relied upon as legal advice, financial advice, marketing compliance advice, medical or health claims guidance, or any other form of professional service. Outputs may be used in regulated contexts (including health, finance, and advertising), and you are solely responsible for ensuring that any content you publish complies with applicable laws, regulations, industry codes, and advertising standards in your jurisdiction. Where professional advice is required, you should consult an appropriately qualified professional.

3. Defined Terms

For all legal purposes and notwithstanding the thematic nomenclature used throughout the platform, the following terms are defined:

  • "Specialist AI" (noun): One of the purpose-built apps in the Heista workspace, each built on a proprietary structural framework or logic model derived from the independent, reverse-engineered analysis of public communication patterns. A Specialist AI is a research product, not a transfer of ownership or unauthorised access to private data. Heista's own code, databases and internal documentation use the legacy word "Heist" for the same thing; the two mean the same and nothing turns on which is used.
  • "Run" (verb/action): The execution of a generative algorithmic process that combines the functional logic of a Specialist AI with the user's specific brand inputs ("Inputs") to produce a unique output ("Output").
  • "Power Source" (noun): A stored brand identity profile containing extracted or user-provided data including brand voice, strategic posture, target audience, and product details.
  • "PatternMap" (noun): A proprietary timeline visualisation that segments content into psychological and structural beats.
  • "Decoded Library" (noun): The shared catalogue of structural intelligence derived from decoded ads and content. The Decoded Library contains PatternMap analyses, beat structures, psychological classifications, format data, and ad formulas. It does not contain user account information, API keys, or proprietary brand data.
  • "Credits" (noun): The prepaid, usage-based currency that governs platform consumption. Every generative action costs Credits, at the same consumption rates whether the action is taken in the web app, through the API, or through a Skill. Credits belong to the workspace and expire under §10.2(b).
  • "API Key" (noun): A unique authentication credential issued to your account for programmatic access to the Heista API.
  • "Endpoint" (noun): A specific API capability (such as Decode, Brand Find, or others) accessible via the Heista API.
  • "Decode" (verb/action): The process of analysing an ad URL, video, or piece of creative content through PatternMap and returning structural intelligence.
  • "Skill" (noun): A Heista capability packaged for use within a third-party AI platform (such as Claude or ChatGPT).
  • "Operator" (noun): The AI assistant available inside the Heista workspace. It does not mean "a user": earlier versions of these Terms used the word both ways, and only the assistant sense is a real thing in the product.
  • "Workspace" (noun): The contracting entity described in section 4.3, to which plans, Seats, Credits, brand data and stored files belong.

4. User Accounts

4.1 Registration

To access certain features of the Service, you must register for an account. You agree to:

  • Provide accurate, current, and complete information during registration.
  • Maintain and promptly update your account information.
  • Maintain the security and confidentiality of your password and account credentials.
  • Accept responsibility for all activities that occur under your account.
  • Notify us immediately of any unauthorised use of your account.

4.2 Account Types

Heista supports individual accounts and, where applicable, agency or team accounts. Agency accounts may manage multiple Power Sources and client workspaces under a single billing relationship. Your account may be used to access the Service through the web app, the API, and/or third-party Skills. The account holder is responsible for all activity conducted under their account, including by any team members or sub-users granted access, and including all activity conducted using API keys issued to the account.

4.3 Workspaces and Seats

(a) Workspace. When you register, a workspace is created and you become its owner. The workspace is the contracting entity for the purposes of these Terms: subscriptions, Seats, add-ons, AI Credits, Brand data, saved library items and stored files all belong to the workspace rather than to any individual user. An owner may transfer ownership of a workspace to another member, and a workspace may have more than one owner.

(b) Seats. A Seat entitles one named individual to access the workspace. Subscription fees are charged per Seat per month. You may add Seats at any time; an added Seat takes effect immediately and is charged on a pro-rata basis for the remainder of the current billing period, then at the full Seat price from the next renewal. You may reduce your Seat count at any time; a reduction takes effect at the end of the current billing period and no refund is given for the unused portion of that period. You cannot reduce your Seat count below the number of Seats then in use (members plus outstanding invitations). Only a workspace owner may change the Seat count or other billing settings.

(c) Seats are not personal to a user. A Seat is a capacity within your workspace, not a licence granted to a particular person. If a member leaves, you may remove them and invite a replacement into the same Seat at no additional charge.

(d) Allowances are workspace-level. Brand, saved library item and storage allowances are granted to the workspace as a whole and are shared by all of its members. They are not multiplied by the number of Seats. Add-ons purchased to increase those allowances likewise apply to the workspace.

(e) Removing a member. Removing a member ends that person's access to the workspace. Work they created remains in the workspace, because it belongs to the workspace and not to the individual. Removing a member does not by itself reduce your Seat count or your fees; to stop being charged for a Seat you must also reduce the Seat count under clause (b).

4.4 Eligibility

You must be at least 18 years of age to use the Service. By creating an account, you represent and warrant that you meet this age requirement and have the legal capacity to enter into these Terms.

4.5 API Key Security

If you use the Heista API, you are responsible for maintaining the security of your API keys. You agree to:

  • Keep your API keys confidential and not share them with unauthorised third parties.
  • Not embed API keys in client-side code, public repositories, or any publicly accessible location.
  • Revoke any API key immediately if you believe it has been compromised, through the API Console.
  • Accept responsibility for all activity conducted using your API keys, whether or not authorised by you.

Heista stores API keys as one-way cryptographic hashes. The full key is displayed once at creation and cannot be recovered. You are responsible for storing your key securely.

5. Research and Analysis Acknowledgements

By agreeing to these Terms you acknowledge the following about how Heista's frameworks are produced and what they are:

5.1 The Extraction Principle

You acknowledge that the frameworks behind each Specialist AI are the result of independent signal-mapping and the reverse-engineering of publicly available data. Heista conducts proprietary research and algorithmic analysis; it does not distribute or authorise access to third-party copyrighted works.

5.2 Non-Affiliation Disclosure

Heista is not affiliated with, endorsed by, or sponsored by any creators, brands, or entities referenced in the Decoded Library or in any decode or scan output. Their public success is our research subject; their observable patterns are our data inputs. References to specific individuals or brands are made in good faith solely for the purpose of identifying the source of the analysed patterns. No suggestion of endorsement or commercial association is intended.

5.3 The Transformation Mandate

You agree to use these frameworks to generate original, transformative content that belongs to your brand. You provide the brand variables; we provide the extracted structural framework. You are solely responsible for ensuring your final published output does not infringe on any third-party rights in your specific jurisdiction.

6. Intellectual Property

6.1 Your Content and Inputs

"Inputs" means material you supply to the Service — files you upload, brand and ethos documents, briefs, product information, and anything else you provide from your own systems. You retain full ownership of your Inputs.

Pointing Heista at a publicly-published ad is not an Input. When you give us the URL of an ad the platform already publishes, that ad is analysed and handled under section 6.8, not under this section, and the warranties below do not apply to it. We do not ask you to own a competitor's advertising in order to study it.

By uploading or submitting Inputs, you represent and warrant that:

  • You own all necessary rights, or have obtained explicit permission from the relevant rights holder, to perform structural analysis and generate derivative works from your Inputs.
  • Your Inputs do not include third-party confidential, proprietary, or non-public materials for which you lack authorisation.
  • Where you provide URLs from third-party platforms (including TikTok, Instagram, YouTube, Facebook, and others), you have complied with the applicable terms of service of those platforms in obtaining or referencing such content.

You grant Heista a limited, non-exclusive licence to process your Inputs solely for the purpose of delivering the Service (generating outputs, building Power Sources, and running Specialist AI apps). Your Inputs will not be used to train any AI model, whether ours or any third-party model provider's. We do not share your Inputs with other users. Your Inputs may be processed transiently by third-party AI sub-processors as described in our Privacy Policy and our Subprocessors page; those providers process inputs and outputs for inference only and are contractually prohibited from training on or retaining your data beyond the limited abuse-monitoring windows described in our Privacy Policy.

6.2 Our Content and Platform

The Service, including its original code, design, features, Specialist AI frameworks, PatternMap visualisations, API endpoint designs, response schemas, documentation, and all associated materials, is owned by Mighty Lucky Ventures Pty Ltd and protected by applicable intellectual property laws. You may not reproduce, distribute, modify, or create derivative works of our platform, proprietary frameworks, or API infrastructure without express written permission.

6.3 AI-Generated Outputs

Content generated by the Service ("Outputs"), whether through the web app, API, or Skills, is provided to you for your use. You are responsible for reviewing, editing, and ensuring the accuracy, originality, and legal compliance of all Outputs before publication or commercial use. Heista does not guarantee that Outputs will be free of similarities to existing market content.

6.4 Independent Strategic Analysis

Heista provides a platform for the analysis and reverse-engineering of public communication patterns, marketing frameworks, and strategic structures. Our decoded frameworks and structural analyses are the result of independent research and algorithmic analysis of publicly available data.

We do not sell or license third-party creative assets, and we do not present anyone else's advertising as our own or as material you may reuse verbatim. We do retain and display a copy of the advertising we analyse, so that the analysis can be read alongside the ad it describes — see section 6.8. What we provide is functional logic and structural templates derived from that analysis. To the extent permitted by applicable law, we believe these functional elements represent unprotectable ideas, methods, and processes rather than copyrightable expression. However, the legal treatment of such analysis may vary across jurisdictions, and we do not make any absolute legal determination regarding copyright status.

6.5 The Idea/Expression Distinction

Heista is designed to extract underlying logic, psychological frameworks, and structural patterns from publicly available content, rather than copying or reproducing the protected expression (video, audio, or specific text) of any creator. All scripts and content generated by running a Specialist AI are intended to be original works created by the combination of our analysed logic models and specific user-provided brand inputs. Notwithstanding, you acknowledge that copyright law varies by jurisdiction, and you bear responsibility for ensuring your use of any Output complies with applicable laws.

6.6 Third-Party Trademark References

Any product names, logos, brands, or other trademarks featured or referred to within the Heista platform are the property of their respective trademark holders. These trademark holders are not affiliated with Heista, our products, or our website. They do not sponsor or endorse Heista or any of our services.

We reference these names in good faith solely for the purpose of identifying the source of the strategic patterns we have analysed. We use only so much of the name as is reasonably necessary for identification and do not use third-party logos or branding where avoidable. We aim to operate within applicable trademark law defences, including good faith descriptive use under the Trade Marks Act 1995 (Cth) (Australia) and equivalent provisions in other jurisdictions.

6.7 Data Processing for Research

In order to perform our strategic analysis, Heista may conduct intermediate processing of publicly available content, including transcriptions and structural scans. This processing is conducted for the purpose of extracting functional elements and strategic logic. We may retain limited copies of processed content for as long as reasonably necessary to provide the Service, prevent abuse, comply with legal obligations, or resolve disputes. Specific retention periods are described in our Privacy Policy. Copies of analysed advertising are retained and published as part of the Decoded Library described in section 6.8, and may be removed on request under section 6.8.

6.8 The Decoded Library

When you decode an ad through Heista, the decode enters the Heista Decoded Library. The Library is public. Each decode is given a page on heista.co that is open to anyone, whether or not they have a Heista account, and that page is submitted to search engines for indexing. We retain and display a copy of the source ad on that page so the analysis can be read alongside the advertising it describes.

We only decode advertising that the platform already publishes. The Meta Ad Library and TikTok's public ad archive exist because those platforms require advertisers to make their creative publicly viewable. A decode records structural intelligence — PatternMap analysis, beat structures, psychological classifications, format classifications and ad formula data — and that intelligence is a shared resource. You do not acquire exclusive rights over the decoded intelligence for an ad you were the first to submit, and it may be surfaced to other users through the Library, Intelligence features, or the API.

Files you upload yourself are treated differently. A video, image or document you supply from your own device is your material, not published advertising. It stays private to your workspace, is not given a public page, is not indexed, and does not enter the Decoded Library.

Your brand data is never shared and never published. That includes Power Sources, brand documents, ethos documents, briefs, generated scripts, custom frameworks, saved assets and account data. These remain exclusively associated with your workspace.

Removal requests. If you are a rights holder and you want advertising of yours removed from the Decoded Library, write to support@heista.co with the page URL and the basis of your request. We will review it and, where the request is properly made, remove the page and the retained copy. You do not need a Heista account to make a request, and we will not require you to bring a legal claim before we act on a reasonable one.

6.9 API Output Usage Rights

You may use outputs generated through the Heista API in products, services, and applications you build. You may incorporate API outputs into your own offerings that add value beyond the raw output. We encourage developers to build on the Heista API.

  • Attribution to Heista is not required but is appreciated.
  • You may not use Heista's name, logo, or branding to imply that your product is Heista, is part of Heista, or is officially endorsed by Heista without our prior written permission.
  • Products, services, and applications you build using the Heista API are your property. The Heista API itself, including its infrastructure, intelligence layer, and documentation, remains ours.

6.10 Use of AI Functions

The Service is built on artificial intelligence (the "AI Functions"). The AI Functions assist with decoding ads, extracting brand intelligence, generating scripts, hooks, copy, briefs, images, and other creative outputs based on your Inputs. By using the Service, you acknowledge and agree that:

  • AI carries inherent risks. The AI Functions may produce outputs that are factually incorrect, biased, inconsistent, incomplete, or that resemble third-party works. AI-generated content can "hallucinate" (state things confidently that are untrue). You must review every Output before commercial use.
  • Third-party AI providers. The AI Functions are powered in part by third-party AI model providers (collectively, the "AI Providers") accessed through model routing infrastructure. We select AI Providers based on capability, cost, jurisdiction, and our internal evaluation. We are not responsible for the acts, omissions, downtime, or model behaviour of any AI Provider. A current list of AI Providers is maintained at heista.co/subprocessors.
  • Ongoing legal evolution. The legal landscape around AI — including the right to train on third-party data, the copyrightability of AI outputs, and the allocation of liability for AI-assisted content — is unsettled and evolving. We make no representation about how courts will treat any specific Output in any jurisdiction.
  • IP and publicity risk. Outputs may inadvertently resemble protected expression, trademarks, or the likeness of identifiable individuals. You are responsible for clearing rights, verifying originality, and ensuring lawful publication of any Output you use.
  • Privacy risk. Do not include personally identifiable information, regulated data (per §7.2), or third-party confidential information in your prompts or Inputs. Anything you send to the AI Functions may be transiently processed by an AI Provider.
  • No warranty on AI Functions. To the maximum extent permitted by law, Heista provides the AI Functions on an "AS IS" basis and disclaims all warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement, in relation to any Output or any AI Function behaviour.

For clarity: nothing in this clause limits your statutory rights under the Australian Consumer Law or equivalent consumer protection law in your jurisdiction.

7. Acceptable Use Policy

You agree not to use the Service (including the web app, API, and Skills) to:

  • Generate content that is illegal, harmful, threatening, abusive, harassing, defamatory, or discriminatory.
  • Violate any applicable laws, regulations, or industry codes in your jurisdiction.
  • Infringe upon the intellectual property rights, rights of publicity, or other proprietary rights of any third party.
  • Generate spam, misleading, or deceptive content.
  • Conduct surveillance of individuals without lawful basis.
  • Create or distribute political manipulation content or disinformation campaigns.
  • Attempt to gain unauthorised access to our systems, networks, or other users' accounts.
  • Interfere with, disrupt, or place an undue burden on the Service or its infrastructure.
  • Reverse-engineer, decompile, or disassemble any aspect of the Heista platform itself (as distinct from the content analysis the platform performs).
  • Use Outputs in a manner that violates the Transformation Mandate (i.e., direct copying or reproduction of third-party expression without transformation).
  • Publish Outputs that you know or reasonably should know infringe on a third party's copyright, trademark, or right of publicity.

7.1 Additional API and Skills Restrictions

When using the API or Skills, you additionally agree not to:

  • Use Heista's name, logo, or branding in any way that implies your product is Heista, is part of Heista, or is officially endorsed by Heista, without our prior written permission.
  • Share API keys with third parties or embed them in publicly accessible code, repositories, or client-side applications.
  • Circumvent or attempt to circumvent rate limits, authentication mechanisms, or billing systems.
  • Use automated means to systematically download, scrape, or cache API responses beyond what is reasonably necessary for your application's normal operation.

For clarity: we encourage developers to build products and services on the Heista API, including products that may overlap with Heista's own features. You pay for credits, and you may use them in whatever way serves your business, subject to the restrictions above.

7.2 Prohibited Content (Uploads)

Heista is built to handle marketing creative — brand assets, campaign briefs, ad references, product information, and similar commercial content. Some categories of data require specialised compliance controls that Heista has not implemented, and uploading them creates legal and security risk for both you and us.

You may NOT upload to Heista (including through brand document uploads, ethos document uploads, the API, or any Heista Skill):

  • Protected Health Information (PHI) regulated by HIPAA, including medical records, patient data, prescription information, insurance claims, or any health data linked to an identifiable individual.
  • Payment card data subject to PCI-DSS, including full credit card numbers, card verification codes (CVV/CVC), magnetic stripe data, or PIN blocks.
  • Government-issued identification numbers including Social Security Numbers, Tax File Numbers, passport numbers, driver's license numbers, or national ID numbers.
  • Special category personal data under GDPR Article 9, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, or data concerning a person's sex life or sexual orientation.
  • Personal information of children under 13 (or under 16 where applicable under local law), including any content that would trigger COPPA, GDPR-K, or analogous child privacy regulations.
  • Classified, export-controlled, or otherwise legally restricted material (ITAR, EAR, national security classifications, etc.).
  • Material that is unlawful in your jurisdiction or ours, including content that infringes third-party rights in ways the Acceptable Use Policy above already prohibits.

If you upload prohibited content: we will delete it as soon as we become aware of it, and we may suspend or terminate your account without refund. You remain responsible for any liability arising from the upload.

Your responsibility: you are responsible for reviewing content before upload and ensuring it complies with this section. If you are uncertain whether specific content is permitted, contact us at support@heista.co before uploading.

Enterprise exception: if your use case genuinely requires handling one of the above categories, contact us before uploading. We may offer a separately contracted enterprise arrangement with the necessary compliance controls in place, or we may decline. We will not unilaterally accept regulated data without a written agreement.

7A. Visual References and Generative Outputs

This section applies to features that accept reference images and generate visual content, including Visual Presets, visual styles, and related image generation features (together, the "Visual Features"). It supplements, and is to be read together with, the Acceptable Use Policy (Section 7), your content licence and our training carve-out (Section 6.1), the AI Functions clause (Section 6.10), your responsibility and indemnification obligations (Section 8), our IP complaints process (Section 9), the Disclaimers (Section 13), and the Limitation of Liability (Section 14).

7A.1 Intended Purpose

The Visual Features are creative tools provided for concept development, visual exploration, art direction, prototyping, internal review, and the creation of original visual content. Outputs may be used commercially subject to these Terms, applicable law, and any third-party rights.

7A.2 How References Are Used

Reference images you upload are used to assist the Service in identifying and applying broader visual characteristics to new content. These characteristics may include lighting, colour palette, texture, technique, medium, lens treatment, framing tendencies, and finish. The Visual Features are designed to apply such characteristics to new subjects and compositions rather than to reproduce an existing work.

Heista does not promise that any output will be legally distinct from all existing works. Whether a generated output is sufficiently different from existing material is contextual, and you must assess outputs before any external or commercial use.

7A.3 Prohibited Uses of References

In addition to Section 7, you must not use the Visual Features to:

  • Reproduce or create a near-identical version of a copyrighted work without permission, where permission is required.
  • Recreate protected characters, artwork, logos, packaging, or other proprietary material in an infringing manner.
  • Impersonate, replicate, or commercially exploit an identifiable person without any consent required by law.
  • Create content that falsely suggests sponsorship, endorsement, authorship, or affiliation.
  • Remove or imitate watermarks, signatures, copyright notices, or creator attribution.
  • Upload confidential client material without authority to do so.
  • Evade safeguards designed to prevent prohibited reproduction.

7A.4 No Legal Clearance

Heista does not conduct copyright, trade mark, privacy, publicity, model-release, passing-off, or advertising-clearance reviews on behalf of users. Generation of an output, availability of a preset, or successful completion of a request does not constitute confirmation that the material is lawful, non-infringing, or cleared for publication.

7A.5 Review Before Use

Before publishing, distributing, advertising, selling, or otherwise commercially using an output from a Visual Feature, you must review it for potential infringement, misleading representations, identifiable persons, confidential information, logos, protected characters, and other third-party rights.

7A.6 Similar Outputs and No Exclusive Style Rights

Generative systems can produce comparable results from similar inputs. Other users may receive outputs that are similar or identical to yours. No exclusive right is granted in a general style, technique, aesthetic, prompt structure, or visual treatment.

7A.7 Identifiable People

You must not use the Visual Features to create or publish content depicting an identifiable real person in a misleading, defamatory, intimate, exploitative, or commercial context without any consent required by law.

7A.8 First-Use Acknowledgement

Before your first reference upload, the Service presents an in-product acknowledgement of this section's core obligations. Your acceptance is recorded against your user account and workspace, together with the time of acceptance and the version of the acknowledgement accepted, and forms part of your agreement to these Terms. Uninstalling a Visual Feature and later reinstalling it may require a fresh acknowledgement.

For clarity: references you upload are processed under the limited licence in Section 6.1 and are not used to train any AI model, whether ours or any third-party model provider's.

8. User Responsibility and Indemnification

8.1 Your Responsibility

You acknowledge that Heista provides competitive intelligence tools across multiple surfaces. You are solely responsible for:

  • The legality and appropriateness of all Inputs you provide to the Service, whether through the web app, API, or Skills.
  • Reviewing and editing all Outputs before publication or commercial use.
  • Ensuring your final published content does not infringe on any third-party trademarks, copyrights, or rights of publicity in your specific jurisdiction.
  • Compliance with all applicable laws, regulations, advertising standards, and platform-specific terms of service where you publish content.
  • Ensuring that any claims made in published content (including health, financial, or performance claims) are substantiated and compliant with applicable consumer protection laws.
  • The legality and appropriateness of any products, services, or applications you build using the Heista API.

8.2 Indemnification

To the extent permitted by applicable law, you agree to indemnify, defend, and hold harmless Mighty Lucky Ventures Pty Ltd (trading as Heista), its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from or related to:

  • Your use of the Service or any Outputs generated through the Service, whether via the web app, API, or Skills.
  • Your breach of these Terms.
  • Your violation of any applicable law or third-party right.
  • Any claim that your published content infringes upon the intellectual property or other rights of a third party.
  • Any claim arising from products, services, or applications you build using the Heista API.

This indemnification obligation does not apply to the extent that a claim arises from our negligence, wilful misconduct, or breach of a non-excludable statutory guarantee.

9. Intellectual Property Complaints and Takedown

9.1 Reporting IP Concerns

We respect the intellectual property rights of others. If you believe that any content, framework, or output available through the Service infringes your intellectual property rights, please submit a written notice to support@heista.co containing:

  • Your full name and contact information (or the name and contact information of the rights holder you represent).
  • A description of the copyrighted work, trademark, or other intellectual property you claim has been infringed.
  • A description of the material on our platform that you believe is infringing, with sufficient detail for us to locate it.
  • A statement that you have a good faith belief that the use of the material is not authorised by the rights holder, its agent, or the law.
  • A statement, made under penalty of perjury (where applicable), that the information in your notice is accurate and that you are the rights holder or authorised to act on behalf of the rights holder.
  • Your physical or electronic signature (or that of the authorised agent).

9.2 Our Response

Upon receipt of a valid IP complaint, we will:

  • Acknowledge receipt within 5 business days.
  • Investigate the claim in good faith.
  • Where appropriate, disable access to or remove the allegedly infringing material.
  • Notify the affected user of the complaint and any action taken.

9.3 Counter-Notice

If you believe that material was removed or disabled as a result of a mistake or misidentification, you may submit a counter-notice to support@heista.co explaining why you believe the material is not infringing and requesting restoration. We will evaluate counter-notices in good faith and, where appropriate, restore access.

9.4 Repeat Infringer Policy

We maintain a policy of terminating the accounts of users who are repeat infringers of third-party intellectual property rights. Users who receive multiple valid IP complaints may have their accounts suspended or permanently terminated at our discretion.

10. Plans, Payment, and Credits

10.1 Plans

Heista is offered on two plans. Every Specialist AI in the workspace is included on both — nothing is sold app by app, and installing an app costs nothing on any plan.

  • Free. $0 per month, one Seat. The workspace, your brand data and every Specialist AI are available to you. No Credits are included, so no generation is possible until you buy Credits (see §10.2). We may apply usage limits to free workspaces; where limits apply they are shown in the app.
  • Workspace. Charged per Seat per month at the price published on our pricing page at the time you subscribe. Seats work as set out in §4.3. No Credits are included with the plan fee.

Current plans and prices are published at heista.co/pricing and may be updated from time to time in accordance with §10.6. Neither plan includes, or has ever included, a free trial.

10.2 AI Credits

The Service operates on a prepaid, usage-based currency called AI Credits. Every generative action consumes AI Credits, wherever it is taken — the web app, the API, or a Skill. Credits belong to the workspace, not to an individual Seat.

(a) No credit allowance is included with any plan. Neither the Free plan nor the Workspace plan grants a monthly, annual or one-off allocation of AI Credits. The plan fee buys access to the workspace and its Seats; AI Credits are bought separately under (b), and generation is only possible while you hold a Credit balance.

(b) Buying Credits. You may purchase AI Credits ("Additional Credits") at any time. Additional Credits will expire ninety (90) days from the time of purchase. Additional Credits may only be spent while your account is open and in good standing. An account on the Free plan is open for this purpose, so Credits bought on the Free plan can be spent on the Free plan. If your account is suspended or otherwise not in good standing, any unspent Additional Credits are not forfeited: they remain in your workspace but cannot be spent until it is restored. The ninety (90) day expiry period continues to run during any such period, and Additional Credits that reach the end of that period while unavailable will expire. The price of Additional Credits will be as specified on our website at the time of purchase.

(c) AI Credits Management Fee. A management fee of 4.9% is added at checkout to purchases of Additional Credits. The fee covers payment processing, credit provisioning and account administration. It is shown to you before you confirm a purchase and appears as a separate line item on your receipt. The fee applies only to purchases of Additional Credits: it is not charged on plan fees.

(d) Generation is billed at cost. Separately from (c), the compute consumed when you spend Credits is billed at the price our model providers charge us, with no margin added by Heista. These are two distinct facts and neither qualifies the other: the 4.9% is charged once, when you buy Credits; spending them adds nothing.

(e) General. For the avoidance of doubt, AI Credits and Additional Credits:

  • are non-transferable;
  • have no monetary value;
  • are non-refundable, except as required by applicable law (including the Australian Consumer Law); and
  • may only be used in accordance with these Terms.

Different actions consume different amounts of AI Credits (for example, a video decode or a film render consumes more than a short text generation). AI Credits consumed through the API or through a Skill are drawn from the same balance as web app usage, at the same consumption rates regardless of surface. Upon account deletion or termination for cause, all unused AI Credits are forfeited, except as required by applicable law.

10.3 Paid API and Skills Usage

Usage of the Heista API and of Heista Skills is paid for in AI Credits, on the same terms as §10.2 — including the ninety (90) day expiry in §10.2(b). There is no credit of any kind that does not expire. Where the API presents a balance separately from the web app, it is a view of the same entitlement and is governed by the same rules. In addition:

  • Credits must be bought before use. No plan grants them, and no free credits are issued.
  • Pricing for each API endpoint is displayed in the API Console and API documentation. We reserve the right to adjust API pricing; changes apply to future usage only.
  • If you enable auto-recharge, we may charge your saved payment method when your Credit balance falls below a threshold you specify. The AI Credits Management Fee in §10.2(c) applies to an auto-recharge purchase in the same way as to any other purchase of Credits.
  • Upon account deletion or termination for cause, unused Credits are forfeited, subject to the Service Discontinuation provisions in Section 12A.

10.4 Billing

Plan fees are charged per Seat per month and are billed in advance on a recurring monthly basis. Changes to your Seat count are handled as set out in §4.3(b). Credits are billed as one-time purchases at the time of purchase, together with the AI Credits Management Fee in §10.2(c). You agree to pay all fees associated with your plan, your Seats, and your Credit purchases. No part of a plan fee is an allocation of Credits.

10.5 Refund Policy

Plan and Seat fees are generally non-refundable except as required by applicable law, including the Australian Consumer Law. Credit purchases are non-refundable once consumed; refunds of unconsumed Credits are provided at our sole discretion on a case-by-case basis, and Credits that have expired under §10.2(b) are not refundable. If you are unsatisfied with the Service, you may cancel at any time; cancellation takes effect at the end of the current billing period.

10.6 Price Changes

We reserve the right to change our pricing with at least 30 days' written notice. Price changes will take effect at the start of your next billing cycle following the notice period. API pricing changes apply to future usage only and do not affect your existing credit balance. Continued use of the Service after a price change constitutes acceptance of the new pricing.

10.7 Taxes

The fees are exclusive of all taxes, including GST, levies, duties, withholding taxes, or similar governmental assessments of any nature (collectively, "Taxes"). You agree to pay any Taxes levied by any authority on, or in connection with, these Terms (other than income taxes payable by us on our net income). Where we are required by law to collect Taxes from you, we will add the applicable Taxes to your invoice. You are responsible for providing accurate tax information (including any required tax IDs) and for ensuring that you comply with the tax laws of your jurisdiction in respect of your use of the Service.

11. Privacy and Data

Your privacy is important to us. Our Privacy Policy, available at heista.co/privacy, governs the collection, use, and disclosure of your personal information and forms part of these Terms. For information about how we handle data deletion requests, including data received from third-party platforms, please visit our Data Deletion page.

Key data handling principles are summarised below for convenience. In the event of any inconsistency between this summary and the Privacy Policy, the Privacy Policy prevails:

  • Power Source data (brand identities, product details, audience profiles) is stored securely and used to deliver the Service to you.
  • URLs and video content submitted for decoding or scanning are processed for structural analysis. Retention periods for processed content are detailed in the Privacy Policy.
  • We use third-party AI sub-processors to deliver AI-powered features, routed through model gateway infrastructure that lets us select the most appropriate AI Provider for each task. AI Providers include US-based companies (such as OpenAI, Anthropic, Google, xAI), EU-based companies (such as Mistral), and non-Western companies where we have evaluated them and determined they meet our security bar (and only for tasks that do not include user-uploaded customer content). A current list of AI Providers is maintained at heista.co/subprocessors. Your Inputs and Outputs may be transmitted transiently to these providers for inference. Customer-uploaded documents (brand documents, ethos documents, files uploaded via the API or any Heista Skill) are technically restricted to US-jurisdiction AI Providers only — this restriction is enforced in our routing layer, not just policy. Full details of our sub-processors, their data handling practices, and the protections in place are set out in the Privacy Policy.
  • Decoded structural intelligence from content submitted through any surface (web app, API, or Skills) is stored in the Decoded Library and may be accessible to other users. This intelligence is derived from publicly available content and does not contain your proprietary brand data or account information.
  • API usage data (requests, endpoints, IP addresses, costs) is logged for billing, security, and analytics purposes.
  • We do not sell your personal information or brand data to third parties.
  • Consent records for features that require a first-use acknowledgement (see §7A.8) are maintained for legal compliance purposes.

For full details on how we handle your data, including cookies, analytics, AI sub-processor disclosures, and your rights under applicable privacy legislation (including the Australian Privacy Act 1988), please refer to our Privacy Policy.

11A. Third-Party Platform Integrations

11A.1 Meta (Facebook/Instagram) Ads Integration

The Meta ads integration allows you to connect your Meta advertising account(s) to Heista. By connecting your Meta account, you:

  • Authorise Heista to access your ad account data, including campaigns, ad sets, ads, creatives, and performance insights, via the Meta Marketing API.
  • Acknowledge that your use of the Meta integration is subject to both these Terms and the Meta Platform Terms.
  • Agree that you have the authority to grant access to the ad accounts you connect (you are an admin or advertiser on those accounts).
  • Understand that Heista uses this data to decode your ad creatives, compare performance against category benchmarks in the Decoded Library, and generate strategic recommendations.

11A.2 Disconnection and Data Deletion

You may disconnect your Meta account at any time by:

  • Removing the connection from your Heista account settings.
  • Removing the Heista app from your Facebook Settings > Business Integrations.

Upon disconnection, we will delete your stored Meta platform data within 30 days, including access tokens, ad account data, and cached creatives. Any decoded frameworks or briefs generated from your ads will be retained in your account as Heista-generated intelligence (they do not contain raw Meta platform data).

11A.3 Compliance with Platform Terms

We comply with all applicable Meta Platform Terms and Developer Policies, including:

  • We do not sell, license, or transfer Meta platform data to any third party.
  • We do not use Meta platform data for purposes unrelated to the Service you have authorised.
  • We do not use Meta platform data to build or augment user profiles for advertising or data brokerage.
  • We honour all data deletion callbacks from Meta when users remove our app from their Facebook settings.

11A.4 Third-Party Platform Compliance (General)

When you submit URLs for decoding through the web app or API, you are solely responsible for ensuring your access to that content complies with the relevant platform's terms of service. When using Skills within third-party AI platforms, you must also comply with that platform's terms of service.

Heista is not responsible for your violations of third-party platform terms. The availability of decoded content depends on the continued public availability of the source material, which we do not control.

11A.5 AI Marketplace Integrations

Heista Skills available through third-party AI marketplaces (such as Claude or ChatGPT) are subject to both these Terms and the terms of the respective marketplace. The authentication flow for Skills involves a browser redirect to Heista for account creation or sign-in. Third-party platforms may have their own data practices separate from ours, which are governed by their own privacy policies.

11A.6 Upstream Dependencies

The Service depends on third-party data providers, AI model providers, and infrastructure services to deliver its capabilities. The availability of specific features depends on continued access to these upstream services. We are not liable for disruptions, changes, or restrictions imposed by upstream providers that affect the Service's availability or functionality.

12. Service Availability

12.1 No Uptime Guarantee

The Service, including the web app, API, and Skills, is provided without uptime guarantees unless separately agreed in writing. We strive to maintain high availability but do not guarantee uninterrupted access to any part of the Service.

12.2 Changes to the Service

API endpoints may be modified, deprecated, or removed. We will provide reasonable notice where practicable but are not obligated to maintain backward compatibility. Features and capabilities available through the web app may change as Specialist AIs are added, modified, or retired. Skills availability depends on third-party marketplace policies, which we do not control.

12.3 External Dependencies

External data sources (including ad libraries and social media platforms) may change or restrict access at any time, affecting the availability and accuracy of decoded intelligence. We are not responsible for lost business, revenue, or data arising from service interruptions, API changes, or third-party platform restrictions.

12A. Service Discontinuation

We may discontinue the Service, or any part of it (including specific Specialist AIs, API endpoints, or Skills), at any time. Where we discontinue a paid feature:

  • We will provide at least 30 days' notice where practicable.
  • Where a discontinuation materially reduces what your plan provides, plan fees will not be charged beyond the current billing period.
  • Unused Credits at the time of full Service discontinuation will be refunded on a pro-rata basis for Credits purchased within the preceding 90 days. Credits that have already expired under §10.2(b), and any Credits granted for free, are not refundable.
  • We are not liable for lost business, revenue, or data resulting from Service discontinuation.

This section does not limit any rights you may have under the Australian Consumer Law.

13. Disclaimers

13.1 Service Provided "As Is"

The Service, including the web app, API, and Skills, is provided on an "AS IS" and "AS AVAILABLE" basis. To the maximum extent permitted by applicable law, we disclaim all warranties, whether express, implied, or statutory, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement.

13.2 No Guarantee of Results

Heista provides structural frameworks and strategic intelligence tools. We do not guarantee that use of the Service will result in viral content, increased sales, audience growth, or any other specific commercial outcome. Past performance of analysed content is not a guarantee of future results. This applies equally to outputs generated through the web app, API, and Skills.

13.3 Output Accuracy

AI-generated Outputs, whether delivered through the web app, API, or Skills, are provided for your consideration and editing. We do not guarantee the accuracy, completeness, originality, or legal compliance of any Output. You retain full editorial responsibility for all content you publish. API response schemas and data structures may change over time.

13.4 Third-Party Content

Heista analyses publicly available content created by third parties. We make no representations or warranties regarding the accuracy of our analysis, the continued public availability of analysed content, or the legal status of any third-party material.

13.5 API and Skills Disclaimers

Decoded intelligence is based on analysis of publicly available content at a point in time. We do not guarantee the accuracy, completeness, or continued relevance of decoded data. API rate limits, pricing, and endpoint specifications may change. Skills depend on third-party AI platforms we do not control, and their functionality may differ from the web app experience. We do not guarantee compatibility with all AI platforms or continuous availability of Skills.

13.6 Australian Consumer Law

Nothing in these Terms is intended to exclude, restrict, or modify any consumer guarantees, rights, or remedies that cannot be excluded under the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)) or any other applicable law that cannot be excluded by agreement. To the extent that our liability cannot be excluded, our liability is limited to, at our election: re-supply of the services, or payment of the cost of having the services re-supplied.

14. Limitation of Liability

This section is subject to, and does not limit or exclude, any rights or remedies available to you under the Australian Consumer Law or any other applicable law where such rights or remedies cannot be excluded or limited.

To the maximum extent permitted by applicable law:

  • In no event shall Heista, its directors, employees, partners, agents, suppliers, or affiliates be liable for any indirect, incidental, special, consequential, or punitive damages, including without limitation loss of profits, loss of data, loss of goodwill, business interruption, or other intangible losses, resulting from your access to or use of (or inability to access or use) the Service, including the web app, API, and Skills.
  • Our total aggregate liability for any claims arising out of or relating to these Terms or the Service shall not exceed the total amount you have paid to Heista in the twelve (12) months immediately preceding the event giving rise to the claim. This includes claims arising from products or services you build using the Heista API.
  • The limitations in this section apply regardless of the legal theory on which the claim is based, whether in contract, tort (including negligence), strict liability, or otherwise, and even if Heista has been advised of the possibility of such damages.

Nothing in this section limits our liability for fraud, wilful misconduct, death or personal injury caused by our negligence, or any other liability that cannot be excluded by law.

15. Termination

15.1 Termination by You

You may cancel your subscription and terminate your account at any time through your account settings or by contacting us at support@heista.co. Cancellation takes effect at the end of your current billing period. You will retain access to the Service until the end of the paid period.

15.2 Suspension and Termination by Us

We may suspend or restrict your access to the Service where we reasonably believe you have breached these Terms, or where your conduct is harmful to other users, to us, or to third parties. Where practicable, we will:

  • Provide you with written notice of the alleged breach.
  • Give you a reasonable opportunity (not less than 7 days) to remedy the breach, where the breach is capable of remedy.

If the breach is not remedied within the cure period, or if the breach is not capable of remedy, we may terminate your account.

Immediate suspension or termination without notice: We reserve the right to immediately suspend or terminate your account without prior notice in cases of suspected fraud, illegal activity, serious abuse of the Service, or activity that poses an imminent risk to the security or integrity of the platform or its users. In such cases, we will provide written reasons for the termination as soon as reasonably practicable.

15.3 API-Specific Suspension and Termination

API keys may be individually revoked by us if we detect misuse, without necessarily affecting your web app access. API access may be suspended separately from web app access if API-specific terms are violated (such as rate limit circumvention or key sharing). Upon any account termination, all API keys are immediately and automatically revoked.

15.4 Effect of Termination

Upon termination:

  • Your right to access and use the Service ceases immediately (or at the end of your billing period, for voluntary cancellation).
  • All API keys are immediately revoked.
  • Your Vault data and Power Sources will be retained for 90 days following termination, after which they may be permanently deleted. You may request an export of your data during this period.
  • All unused Credits are forfeited upon account deletion, subject to the Service Discontinuation provisions in Section 12A and except as required by applicable law.
  • Decoded intelligence that has been incorporated into the Decoded Library is not deleted, as it constitutes independently derived analysis of publicly available content.
  • Provisions of these Terms that by their nature should survive termination (including Sections 6, 8, 9, 13, 14, and 17) shall survive.

15.5 Skills Termination

Removal of Skills from third-party marketplaces does not entitle you to a refund of credits. Skills access depends on both your Heista account status and the policies of the third-party platform. If your Heista account is terminated, all Skills will cease to function.

16. Modifications to Terms

We reserve the right to modify these Terms at any time. We will notify you of material changes by posting updated Terms on the platform and updating the "Last Updated" date. For material changes affecting your rights or obligations, we will provide at least 14 days' notice via email or in-platform notification.

Your continued use of the Service after the effective date of any modifications constitutes acceptance of the updated Terms. If you do not agree to the modified Terms, you must discontinue use of the Service and cancel your account.

17. Governing Law and Dispute Resolution

17.1 Governing Law

These Terms shall be governed by and construed in accordance with the laws of the State of South Australia and the Commonwealth of Australia, without regard to conflict of law principles.

17.2 Dispute Resolution

In the event of any dispute arising out of or in connection with these Terms, the parties agree to first attempt to resolve the dispute through good faith negotiation. If the dispute cannot be resolved through negotiation within 30 days, either party may submit the dispute to mediation administered by the Resolution Institute (Australia). If mediation is unsuccessful, either party may pursue resolution through the courts of South Australia.

17.3 Jurisdiction

You submit to the non-exclusive jurisdiction of the courts of South Australia for any dispute arising under these Terms. Nothing in this clause limits the right of any party to seek interim or injunctive relief in any court of competent jurisdiction, or limits any non-excludable rights available to consumers under applicable law, including the right to bring proceedings in any jurisdiction permitted by law.

18. General Provisions

18.1 Entire Agreement

These Terms, together with our Privacy Policy, any first-use acknowledgement you give under §7A.8, and any applicable API documentation or Skills documentation referenced herein, constitute the entire agreement between you and Heista regarding your use of the Service and supersede all prior agreements, negotiations, and communications.

18.2 Severability

If any provision of these Terms is found to be unenforceable or invalid by a court of competent jurisdiction, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.

18.3 Waiver

Our failure to exercise or enforce any right or provision of these Terms shall not constitute a waiver of that right or provision. Any waiver must be in writing and signed by an authorised representative of Heista.

18.4 Assignment

You may not assign or transfer these Terms or your rights under them without our prior written consent. We may assign our rights and obligations under these Terms without restriction, including in connection with a merger, acquisition, or sale of assets, provided the assignee agrees to be bound by these Terms.

18.5 Force Majeure

Heista shall not be liable for any failure or delay in performance due to circumstances beyond our reasonable control, including but not limited to natural disasters, war, terrorism, pandemic, government actions, power failures, internet disruptions, or third-party service outages.

18.6 Notices

All notices to Heista must be sent to support@heista.co or to our registered business address. We may provide notices to you via the email address associated with your account or through in-platform notifications.

19. Contact Information

If you have any questions, concerns, or complaints about these Terms, the Service, or our practices, please contact us:

Email: support@heista.co

API Support: support@heista.co (subject line: "API")

Website: https://www.heista.co

Back to home

2026 Mighty Lucky Ventures Pty Ltd (trading as Heista). All rights reserved.