Privacy Policy
How Hookly AI handles and protects your data
At Hookly AI, we take your privacy seriously. This Privacy Policy describes how we collect, use, disclose, store, and protect your personal information when you visit our website hooklyai.com, use our AI-powered LinkedIn content creation platform (including Hook Generator, Full Post Generator, Post Analyzer, First Comment Generator, Hashtag Generator, LinkedIn Feed & Insights, and Direct Publishing features), subscribe to our services, or otherwise interact with us. This policy applies to all users, including visitors, registered users, and paying subscribers across our Free, Pro, and Elite plans.
By accessing or using Hookly AI, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our platform. We comply with applicable data protection laws including the General Data Protection Regulation (GDPR) for European users and the California Consumer Privacy Act (CCPA) for California residents.
1. Information We Collect
We collect several categories of information to provide and improve our services.
Personal Information
When you create an account or interact with our platform, we may collect the following personal information:
- Full name and display name
- Email address and contact information
- LinkedIn profile information (when connected via OAuth 2.0): name, profile photo, headline, and post activity — only with your explicit authorization
- LinkedIn engagement data (likes, comments, shares, impressions) for posts you publish through our platform — used to provide analytics and insights
- Billing and payment information (processed securely through third-party payment processors)
- Account credentials (passwords are encrypted and never stored in plain text)
Usage Data
We automatically collect certain information when you use our platform, including:
- Log data such as IP address, browser type, operating system, and referring URLs
- Pages visited, features used, and time spent on the platform
- AI generation requests, prompts, topics, and selected tone/style/industry settings you submit
- Number of hooks, posts, comments, and hashtags generated, saved, and exported
- Hook Scoring results and post analysis scores
- LinkedIn posts viewed, engagement metrics accessed, and content published through our platform
- Interaction patterns including clicks, scrolls, and navigation paths
- Device identifiers and screen resolution
- Session duration and frequency of visits
Cookies & Tracking Data
We use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your browsing activities. For detailed information on how we use cookies, please refer to .
AI-Generated Content
When you use our AI-powered tools, the prompts, inputs, and AI-generated outputs (including hooks, posts, comments, hashtags, and analyses) are processed to provide the service. This content is used solely to deliver your requested results and is not retained for model training purposes. You retain full ownership of all AI-generated content created through your account. Hook Scoring (1-100) results and post analysis scores are stored to track your content performance over time.
2. How We Use Your Information
We use the information we collect to operate, maintain, and improve our platform.
Service Delivery
Create, maintain, and deliver our AI-powered content generation tools (hooks, posts, comments, hashtags, analyses), process your requests, manage LinkedIn integration (OAuth, feed, publishing), and provide customer support.
Account Management
Create and manage your account, authenticate your identity, send transactional emails, and communicate updates about our services.
Personalization
Customize your experience by remembering your preferences, settings, saved hooks, generation history, Hook Scoring results, and LinkedIn engagement analytics to provide more relevant results.
Analytics & Improvement
Analyze usage patterns to improve our AI models, develop new features, fix bugs, and enhance the overall quality of our platform.
Security & Fraud Prevention
Detect, prevent, and address fraud, abuse, security breaches, and other illegal activities, and enforce our Terms of Service.
Marketing & Communications
Send promotional emails, newsletters, and product updates (with your consent), and measure the effectiveness of our marketing campaigns.
Legal Compliance
Comply with applicable laws, regulations, legal processes, or governmental requests, and establish, exercise, or defend legal claims.
Payment Processing
Process subscription payments and refunds, and communicate with you about billing matters through our secure payment processors.
4. Data Storage & Security
We implement industry-standard measures to protect your data.
Data Storage
Your data is stored on secure servers hosted by industry-leading cloud infrastructure providers. Our infrastructure is primarily hosted in the United States with data encryption at rest (AES-256) and in transit (TLS 1.3). Backups are encrypted and stored in geographically distributed locations to ensure data redundancy and disaster recovery. We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, or as required by law. We comply with GDPR for European users and CCPA for California residents regardless of where our servers are located.
Data Retention
We apply the following retention periods:
- Account data: Retained for the duration of your account and for 30 days after deletion to allow recovery.
- Usage and analytics data: Anonymized after 24 months; raw data deleted after 36 months.
- AI generation history: Retained for 12 months after your last interaction, then permanently deleted.
- Payment records: Retained for 7 years as required by financial regulations.
- Support tickets: Retained for 24 months after resolution.
Security Measures
We implement a comprehensive security program that includes AES-256 encryption for data at rest, TLS 1.3 encryption for data in transit, regular security audits and penetration testing, role-based access controls (RBAC) for internal team members, two-factor authentication (2FA) support for user accounts, automated intrusion detection and prevention systems, and a comprehensive incident response plan. While we strive to protect your personal information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
5. Your Rights
You have significant control over your personal data. We respect and facilitate the exercise of your privacy rights.
Depending on your location, you may have certain rights under applicable data protection laws, including GDPR (for EU/EEA residents) and CCPA (for California residents). We are committed to honoring these rights:
Right of Access
You have the right to request a copy of the personal data we hold about you. You can also access most of your data directly through your account settings dashboard.
Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal data we hold about you. You can update most information directly in your account settings.
Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data, subject to certain exceptions such as legal obligations, ongoing disputes, or fraud prevention requirements.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV), and to transmit that data to another service provider.
Right to Object
You have the right to object to the processing of your personal data for direct marketing purposes, profiling, or processing based on our legitimate interests.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Withdraw Consent
Where we rely on your consent to process your data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
CCPA-Specific Rights
California residents have additional rights including the right to know what personal information is collected, the right to delete personal information, and the right to opt-out of the sale of personal information. Note: Hookly AI does not sell personal information.
How to exercise your rights: You can exercise any of the above rights by contacting us at privacy@hooklyai.com or through your account settings. We will respond to your request within 30 days (or such shorter period as required by applicable law). We may ask for verification of your identity before processing your request. If you are dissatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
7. Third-Party Services
We integrate with carefully vetted third-party services to operate and improve our platform.
Hookly AI integrates with the following third-party services. Each of these providers has their own privacy policies that govern their use of your information:
LinkedIn (Microsoft)
privacy.microsoft.comOptional account connection via OAuth 2.0 for viewing your posts and feed, accessing engagement metrics (likes, comments, shares), and publishing content directly to LinkedIn (Pro and Elite plans). We only access data you explicitly authorize, and you can disconnect at any time.
Stripe
stripe.com/privacySecure payment processing for subscription billing, refunds, and invoice management. Hookly AI does not store your full credit card number.
AI Inference Provider
Privacy policy available upon requestProcesses AI generation requests for hooks, posts, comments, hashtags, and content analyses. Prompts and generated content are processed through their API with no data retention for model training.
Web Analytics
Privacy policy available upon requestWeb performance monitoring and real-time analytics to understand how visitors use our website.
Resend
resend.com/privacyTransactional and marketing email delivery for account notifications, newsletters, and product updates.
Cloudflare
cloudflare.com/privacypolicyContent delivery, DDoS protection, and web application firewall services to ensure platform security and performance.
Important: These third-party services may collect information about you when you interact with our platform. We encourage you to review their privacy policies. We are not responsible for the privacy practices of these third-party services, and the links provided are for your convenience only.
8. Children's Privacy
Hookly AI is not intended for children under the age of 16.
Hookly AI is a professional tool designed for adults and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16 years of age. If you are a parent or guardian and you become aware that your child has provided us with personal information without your consent, please contact us immediately at privacy@hooklyai.com.
If we discover that we have collected personal information from a child under 16 without verification of parental consent, we will take steps to delete that information from our servers as quickly as possible. If you believe that a child under 16 has provided us with personal information, please contact us so that we can take appropriate action.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence.
Hookly AI is a global service, and our operations involve the transfer of your personal information across international borders. Your data may be transferred to, stored, and processed in countries other than your own, including the United States and member states of the European Economic Area (EEA). These countries may have data protection laws that differ from those in your country of residence.
When we transfer personal data internationally, we take appropriate safeguards to ensure that your data receives an adequate level of protection, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to countries without an adequacy decision.
- Reliance on applicable legal frameworks such as the EU-U.S. Data Privacy Framework (DPF) for transfers of personal data from the EU to the United States.
- Ensuring that our third-party service providers provide an equivalent level of data protection through contractual commitments.
- Conducting transfer impact assessments where required by law.
If you have questions about the specific safeguards we use for international data transfers, please contact us at privacy@hooklyai.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws.
We reserve the right to modify or update this Privacy Policy at any time. When we make material changes, we will notify you by updating the “Last updated” date at the top of this page, posting a notice on our website, or sending you an email notification (for registered users). We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of our platform after any changes to this Privacy Policy constitutes your acceptance of such changes. If you do not agree with the revised policy, please discontinue your use of our platform and contact us to request deletion of your account and personal information.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, we're here to help.
We value your privacy and are committed to addressing any questions, concerns, or requests you may have about this Privacy Policy or our data handling practices. You may contact us through any of the following channels:
Data Protection Officer
Hookly AI, Inc.
privacy@hooklyai.com
Website
hooklyai.com
GDPR Representative
EU Representative details available upon request
We will endeavor to respond to all privacy-related inquiries within 30 days of receipt. For urgent privacy concerns or data breach notifications, please contact us at security@hooklyai.com for an expedited response. If you are an EU resident, you also have the right to lodge a complaint with your local supervisory authority if you believe that our processing of your personal data violates applicable data protection laws.
Thank you for trusting Hookly AI with your data. We are committed to protecting your privacy and being transparent about our practices.