Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how Hooksie ("Hooksie", "we", "us") collects, uses, stores, shares, and protects personal information when you use our website, application, and services (the "Service"). This page is maintained by the Hooksie team to answer common privacy questions about the Service. It is app-owned editable content, not an independent certification.

1. Data controller

Hooksie is the data controller for personal information processed through the Service. For privacy questions or requests, contact us at privacy@hooksie.com.

2. Information we collect

We collect only what we need to operate the Service:

  • Account data — email, hashed password (via Supabase Auth), and profile fields you provide (niche, app URL, preferences).
  • TikTok data (only if you connect your account) — your TikTok open_id, union_id, display name, avatar, scopes granted, and OAuth access/refresh tokens obtained through the TikTok Login Kit. We use this data solely to (a) display which account is linked to your project and (b) publish or schedule posts you explicitly create using the TikTok Content Posting API. We do not sell or share TikTok data with third parties, and we do not use TikTok data for advertising or profiling.
  • Content you create — carousels, slides, hooks, image selections, and generation prompts.
  • Billing data — handled by our payment processor (Paddle.com Market Limited). Paddle is the Merchant of Record and collects billing name, address, tax identifiers, and payment details directly. We receive only a customer ID, subscription status, and transaction metadata.
  • Technical data — IP address, browser/device information, and log data for security, abuse prevention, and debugging.

3. How we use information

  • Provide, maintain, and improve the Service.
  • Authenticate you and secure your account.
  • Publish TikTok posts and schedules you initiate.
  • Process payments, subscriptions, refunds, and taxes via Paddle.
  • Communicate service updates, security notices, and support replies.
  • Detect, prevent, and respond to fraud, abuse, or policy violations.

We do not use your content or your connected TikTok data to train foundation AI models.

4. TikTok data — specific commitments

  • We request only the scopes required for the features you use:user.info.basic,video.upload,video.publish.
  • Access and refresh tokens are stored encrypted at rest and are used only server-side.
  • You can disconnect your TikTok account at any time from Settings → TikTok accounts. Disconnection deletes the stored tokens.
  • We do not share TikTok user data with any third party except infrastructure sub-processors listed below strictly to operate the Service.
  • We honour deletion requests within 30 days.

5. Legal bases (GDPR/UK GDPR)

  • Contract — to provide the Service you signed up for.
  • Legitimate interests — security, abuse prevention, service improvement.
  • Consent — for optional integrations (e.g. connecting TikTok).
  • Legal obligation — tax, accounting, and lawful requests.

6. Sub-processors

  • Supabase — authentication, database, storage.
  • Cloudflare — hosting, CDN, edge compute.
  • Paddle — Merchant of Record for billing, tax, and payments.
  • OpenAI, Anthropic, Google (AI Gateway) — AI generation of text and images from your prompts.
  • TikTok — publishing carousels/videos you initiate.

7. Data retention

We retain account data while your account is active and for up to 90 days after deletion for backup rotation, security investigations, and legal obligations. Billing records are retained as required by tax law (typically 7 years). TikTok tokens are deleted immediately upon disconnection or account deletion.

8. International transfers

Data may be processed in the United States, the European Union, and other regions where our sub-processors operate. We rely on Standard Contractual Clauses and equivalent safeguards where required.

9. Your rights

Depending on your jurisdiction you may have the right to access, correct, port, restrict, or delete your personal data, and to object to certain processing. Email privacy@hooksie.com to exercise any of these rights. You may also lodge a complaint with your local data protection authority.

10. Security

We use HTTPS in transit, encryption at rest for tokens and secrets, Row-Level Security on all user tables, least-privilege service roles, and audit logging. No system is perfectly secure; report suspected vulnerabilities to security@hooksie.com.

11. Children

The Service is not directed to children under 13 (or 16 in the EEA/UK). We do not knowingly collect data from children.

12. Changes to this policy

We will post material changes to this page and update the "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance.

13. Contact

Hooksie — privacy@hooksie.com