Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your data.
Last updated: June 6, 2026
Introduction
HookTide ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, which helps content creators manage and analyze their social media accounts across multiple platforms.
By using HookTide, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.
Information We Collect
Account Information
When you create an account, we collect:
- Email address (required for account creation)
- Name (optional)
- Profile image (optional)
- Password (hashed and securely stored)
- Last login timestamp
Social Media Platform Data
When you connect your social media accounts, we collect data from the following platforms:
X (Twitter) (X API v2)
- Tweet text content
- Like counts, retweet counts, reply counts
- Impression counts and bookmark counts
- Tweet timestamps and URLs
- OAuth access tokens (encrypted at rest)
LinkedIn (LinkedIn API)
- Post content and engagement data
- Professional profile information
- OAuth access tokens (encrypted at rest)
Usage and Analytics Data
We collect information about how you use our service:
- Page views and navigation patterns
- Feature usage and interactions
- API request logs
- Error logs and performance metrics
Billing Information
When you subscribe to a paid plan, we collect:
- Subscription plan details
- Payment status and billing periods
- LemonSqueezy subscription IDs (payment processing handled by LemonSqueezy)
- Note: We do not store credit card information. All payments are processed securely through LemonSqueezy.
How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide, maintain, and improve our analytics and insights services
- Data Analysis: To analyze your social media performance and generate insights, recommendations, and content ideas
- Account Management: To manage your account, authenticate users, and process your requests
- Communication: To send you service-related emails, weekly briefings, and important updates
- Billing: To process payments and manage subscriptions
- Security: To detect, prevent, and address technical issues, fraud, and security threats
- Legal Compliance: To comply with legal obligations and enforce our terms of service
Third-Party Services and Data Sharing
We use the following third-party services to operate our platform:
Google Analytics
We use Google Analytics to track website usage and analyze user behavior. Google Analytics collects:
- Page views and navigation paths
- Time spent on pages
- Device and browser information
- Geographic location (general, not precise)
- Referral sources
Google Analytics uses cookies and similar technologies. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on. Google's use of data is governed by their Privacy Policy.
AI Service Providers
We use third-party large language model (LLM) providers to power our AI features, including content insights, idea generation, and topic extraction. When processing your content, we may send post captions and metadata to these AI service providers. We select providers that offer enterprise-grade privacy protections and do not use your data to train their models. The specific providers we use may change over time as we optimize our service.
LemonSqueezy
We use LemonSqueezy for payment processing and subscription management. When you subscribe, LemonSqueezy collects payment information. LemonSqueezy's use of data is governed by their Privacy Policy.
Resend
We use Resend to send transactional emails and weekly briefings. Resend's use of data is governed by their Privacy Policy.
Upstash Redis
We use Upstash Redis for rate limiting and caching. Upstash's use of data is governed by their Privacy Policy.
We do not sell your personal information. We only share your data with third-party services that are necessary to provide our service, and only to the extent required for those services to function.
Data Security
We implement industry-standard security measures to protect your data:
- Encryption: OAuth tokens are encrypted at rest using AES-256-GCM encryption
- Secure Connections: All data transmission uses HTTPS/TLS encryption
- Password Security: Passwords are hashed using secure hashing algorithms
- Access Controls: Access to your data is restricted to authorized personnel only
- Rate Limiting: We implement rate limiting to prevent abuse and protect your accounts
- Regular Audits: We conduct regular security audits and updates
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or United Kingdom, you have certain rights under the General Data Protection Regulation (GDPR):
- Right to Access: You can request a copy of all personal data we hold about you
- Right to Rectification: You can request correction of inaccurate or incomplete data
- Right to Erasure: You can request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: You can request that we limit how we use your data
- Right to Data Portability: You can request your data in a structured, machine-readable format
- Right to Object: You can object to processing of your data for certain purposes
- Right to Withdraw Consent: You can withdraw consent for data processing at any time
To exercise these rights, please contact us through our contact page. We will respond to your request within 30 days.
Legal Basis for Processing: We process your data based on:
- Your consent (when you connect social media accounts)
- Performance of a contract (providing our service)
- Legitimate interests (security, fraud prevention, service improvement)
- Legal obligations (compliance with applicable laws)
Data Retention
We retain your data for as long as necessary to provide our services and comply with legal obligations:
- Account Data: Retained while your account is active. You can delete your account at any time.
- Social Media Data: Retained while your account is connected. When you disconnect an account, we delete associated posts and metrics within 30 days.
- Billing Data: Retained for 7 years as required by tax and accounting laws.
- Usage Logs: Retained for up to 1 year for security and debugging purposes.
When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal purposes.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
- Maintain your session and authenticate you
- Remember your preferences
- Analyze website usage through Google Analytics
- Improve our service and user experience
You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our service.
Children's Privacy
Our service is not intended for users under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete that information.
International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the European Commission.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
Data Controller: HookTide (Webika Ltd)