Legal

Privacy Policy

Last updated: June 17, 2026

HookMachineAI (“we”, “us”, or “our”) is committed to protecting your privacy. This policy explains what data we collect when you use our viral hook generator, how we use it, and what rights you have over it.

1. What We Collect

Account Information

When you create an account we collect your email address and a securely hashed password. We do not collect your real name unless you provide it.

Content You Upload

Videos and images you upload for hook preview generation are stored temporarily on our servers for up to 24 hours and then automatically deleted. We do not analyze the content of your videos beyond generating a preview.

Hook & Usage Data

We store the hooks you choose to save or bookmark, along with the role and concept used to generate them. Chat messages exist only for your current session and are not stored permanently. We track your monthly hook usage count to enforce plan limits.

Social Account Tokens

When you connect TikTok, Instagram, YouTube, or Facebook, we store an OAuth access token (and refresh token where applicable) to perform uploads on your behalf. We never store your social media passwords.

Usage & Technical Data

We may collect standard technical data such as browser type, device type, IP address, and pages visited to help us diagnose bugs and improve the product. This data is not sold or used for advertising.

2. How We Use Your Data

  • Providing the service: Generating viral hooks via the Gemini AI API based on your descriptions and selected role.
  • Preview generation: Temporarily processing your uploaded video to add hook text overlays using FFmpeg on our servers.
  • Social sharing: Using your stored OAuth tokens to upload content to the social platforms you authorize.
  • Plan enforcement: Tracking monthly hook usage to ensure your usage stays within your subscription tier.
  • Account management: Authenticating you, storing your preferences, and managing your subscription via Stripe.
  • Product improvement: Analyzing aggregated, anonymized usage patterns to identify bugs and improve features.

We do not sell your data, use it for advertising, or share it with third parties except as described in Section 3.

3. Third-Party Integrations

Database (user accounts, saved hooks, social tokens), file storage for uploaded videos and previews, and user authentication.

Google Gemini APIPrivacy Policy ↗

AI hook generation. Your video descriptions and role selections are sent to Google's Gemini API to generate hook suggestions.

Payment processing. We never see or store your credit card details — Stripe handles all payment data.

Only used when you explicitly connect your TikTok account. Video uploads are submitted directly to TikTok's servers.

Meta (Instagram / Facebook) APIPrivacy Policy ↗

Only used when you connect Instagram or Facebook. Uploads go directly to Meta's infrastructure.

YouTube Data APIPrivacy Policy ↗

Only used when you connect your YouTube account. Videos are uploaded directly to YouTube.

Hosting and deployment infrastructure for the HookMachineAI web application.

4. Data Retention

Data TypeRetention PeriodNotes
Uploaded videos & images24 hoursAutomatically deleted from storage after 24 hours
Generated preview videos24 hoursRendered previews deleted after 24 hours
Chat session messagesSession onlyNot stored permanently — cleared when session ends
Saved / bookmarked hooksUntil deletedRetained until you delete them or close your account
Hook usage counts13 monthsMonthly usage counters retained for billing purposes
Social OAuth tokensUntil disconnectedDeleted when you disconnect the platform or close your account
Account email & passwordUntil account deletedRetained while your account is active
Stripe payment dataPer Stripe policyHookMachineAI does not store card data

5. Your Rights (GDPR / CCPA)

Depending on where you live, you may have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you.

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of your account and all associated data (the "right to be forgotten").

Portability

Request your data in a structured, machine-readable format.

Restriction

Request that we restrict processing of your data in certain circumstances.

Objection

Object to processing of your data for specific purposes.

Opt-out of sale

We do not sell personal data. California residents can confirm this at any time.

Non-discrimination

Exercising your rights will not affect your access to our services.

To exercise any of these rights, email us at support@hookmachineai.com. We will respond within 30 days.

6. Security

We take reasonable technical and organizational measures to protect your data, including:

  • All data transmitted over HTTPS/TLS encryption
  • Passwords hashed using industry-standard algorithms (managed by Supabase Auth)
  • OAuth tokens encrypted at rest in our database
  • Row-level security (RLS) policies so users can only access their own data
  • Automatic deletion of uploaded media after 24 hours

No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please report it responsibly to support@hookmachineai.com.

7. Children's Privacy

HookMachineAI is not directed to children under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify you by email or in-app notification. Continued use of HookMachineAI after changes take effect constitutes acceptance of the updated policy.

9. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or your data, please reach out: