Privacy Policy
Last updated: October 3, 2026
Hookhaus (hookhaus.studio) is a marketing workspace for iOS app developers: store copy, screenshots, social media posts and measurements in one place. Hookhaus is operated by Furkan. Questions: dev.furkanios@gmail.com.
Information we collect
- Account: your email address and name (the basic profile Google provides if you sign in with Google). We do not store passwords: sign-in is with Google or a code sent to your email.
- Workspace content: your app information, texts, images and videos you upload, carousels you create, your publishing calendar and campaigns.
- Platforms you connect (Instagram, Facebook, Threads, X, LinkedIn, YouTube, TikTok, Google Search Console, Google Analytics, App Store Connect): the account ID, username and access tokens granted through official OAuth; posts you publish through Hookhaus and the metrics the platform's API returns for them (such as views and likes).
- Technical records: server logs for security and debugging; an audit log of actions in your workspace.
- Cookies: a single session cookie. We do not use advertising or analytics trackers.
How we use information
- To do what you ask: publish the posts you approve at the times you choose, show your own metrics, generate AI suggestions.
- For security, abuse prevention and fixing errors.
- We do not sell your data, use it for advertising, or use it to train our own models.
- Hookhaus never posts to any platform without your approval.
Platform data
Data from your social media and Google accounts is used only for the publishing and measurement tasks you request and is not shared with anyone. Access tokens are stored encrypted. Hookhaus's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If you upload to YouTube, the YouTube Terms of Service and the Google Privacy Policy apply; you can revoke Hookhaus's access at Google account permissions.
Service providers
- Hosting: Google Cloud (European Union, Frankfurt).
- Sign-in code email: Resend.
- When you use AI features, your request and the related workspace content are sent to one of these providers: Anthropic, OpenAI, Google (Gemini), Perplexity, Replicate. Your access tokens are never sent to them.
- If you set up a notification channel: Telegram, Slack or WhatsApp.
Retention
- We keep your data while your account is active.
- When you disconnect a platform, its access and refresh tokens are deleted immediately and pending posts are canceled.
- Posts read from Reddit's official API are deleted after 48 hours.
- Database backups are deleted automatically after 14 days.
Your rights and data deletion
Depending on where you live (for example GDPR or Turkey's KVKK), you have the right to access, correct, export and delete your data. How to delete it is described on the Data deletion page. Requests: dev.furkanios@gmail.com.
Security
All traffic is encrypted with HTTPS; access tokens are stored encrypted; only people you invite can access your workspace, and important actions are recorded in an audit log.
Children
Hookhaus is not intended for anyone under 16.
Changes
If we change this policy, the date above is updated.