Privacy Policy
Last updated: October 6, 2026
This Privacy Policy explains how Hookpost ("Hookpost", "we", "us", or "our"), operated by JR Consulting Co., collects, uses, shares, and protects personal data in connection with the Hookpost social-media scheduling, publishing, analytics, and team-collaboration platform (the "Service"), the website at hookpost.hookstep.in and related sub-domains (the "Site"). It applies to visitors to the Site, account holders, members of customer workspaces, and anyone else who interacts with us. By using the Site or the Service, you acknowledge this Policy. For our contractual terms, see our Terms of Service.
1. Who We Are (Data Controllers)
Hookpost is owned and operated by JR Consulting Co. JR Consulting Co. is the contracting party for paid subscriptions, the recipient of subscription revenue, and the primary data controller for account, billing, customer-support, marketing, and Service-usage data.
JR Consulting Co. also holds the developer accounts, OAuth integrations, and platform-side approvals with third-party social media platforms whose APIs the Service uses (including X / Twitter, Meta / Facebook / Instagram / Threads, LinkedIn, YouTube, TikTok, Pinterest, Bluesky, Discord, Slack, Telegram, and GitHub).
For all privacy questions, requests, and data inquiries, you can reach us at [email protected].
2. The Service in Brief
Hookpost lets you connect multiple social-media and chat channels to centrally schedule, publish, analyze, and collaborate on content. The platform includes a visual content calendar, media storage engine, publishing queue, analytics dashboards, AI-assisted content optimization, team permissions, and third-party integrations.
3. The Data We Collect
3.1 Account & Identity Data
- Name, email address, password (stored solely as a cryptographically salted one-way hash), profile picture, workspace name, role, language, and timezone preferences.
- If you sign in via a social-login provider (e.g., Google or GitHub), the basic profile fields and email address returned by that provider.
- Workspace membership, invitations sent/accepted, and permissions granted within an organization.
3.2 Connected Platform Data
When you connect a third-party social or messaging account to Hookpost, we receive and store via authorized APIs:
- OAuth access & refresh tokens (kept in our access-controlled main database, which our database provider encrypts at rest with AES-256), the scopes granted, platform username, user IDs, page IDs, channel IDs, and profile avatars.
- Content and engagement data needed to provide the Service: scheduled posts, published posts, comments, post-level analytics (impressions, reach, clicks, engagement metrics), and aggregate audience data exposed by platform APIs.
- For YouTube specifically: The Service uses YouTube API Services. Your use of those features is subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke Hookpost's access to your Google data at any time via Google Security Settings.
- For Pinterest specifically: We access your Pinterest user boards and profile solely to create Pins on your behalf in compliance with Pinterest Developer Policies.
- For TikTok specifically: You connect TikTok by signing in with TikTok (TikTok Login Kit) and approving the permissions Hookpost requests. With your permission:
- We read your basic profile (avatar, display name, and open ID), your username, your profile stats (followers, following, likes, and video count), and your recent public videos (ID, cover image, and title) with their view, like, comment, and share counts. We use this to show your account and analytics inside Hookpost. If you use Hookpost's AI assistant, your request and the names and usernames of your connected channels (including TikTok) are sent to our AI provider (OpenAI) so it can carry out the request.
- We post to TikTok, or upload to your TikTok inbox as a draft, only content you create in Hookpost and choose to publish. Before you post, we read your TikTok posting settings (who can see your videos, which interactions are allowed, and your maximum video length) so the post screen matches what TikTok allows.
- Your TikTok access and refresh tokens are stored in our database and used only for the features above. We never sell them or your TikTok data.
- You can remove the TikTok channel in Hookpost at any time. We then stop using it (no more posts, data reads, or token refreshes) and delete its tokens from our database by overwriting them with a one-way hash. Copies held by our job scheduler and in our database backups expire on a rolling schedule, normally within 30 days, except where we must keep them longer to investigate a security incident or meet a legal obligation. Your TikTok username, display name, avatar, and open ID may stay with the removed connection until your Hookpost workspace is deleted; you can ask us to erase them sooner at [email protected]. You can also revoke Hookpost's access at any time in your TikTok app settings.
3.3 Content You Upload
Text, images, video, audio, captions, links, hashtags, schedules, prompts, notes, and calendar metadata you upload to or generate within the Service.
3.4 Billing Data
Plan tier, subscription status, invoice history, billing email, and transaction IDs. Card numbers and banking details are processed directly by our PCI-compliant payment gateways (including Razorpay); Hookpost never stores your raw card credentials.
3.5 Logs, Usage & Device Data
- IP address, browser user-agent, operating system, referrer URL, and approximate geographic location derived from IP.
- Application telemetry: pages visited, features used, post dispatch logs, error reports, and performance metrics.
4. How We Use the Data & Legal Bases
- Provide the Service: Authenticate users, manage workspaces, store media, publish content across connected social channels, and generate analytics dashboards. (Performance of contract)
- Billing & Subscriptions: Process subscriptions, issue invoices, prevent payment fraud, and fulfill tax requirements. (Performance of contract; legal obligation)
- Security & Abuse Prevention: Detect and mitigate unauthorized account access, DDoS attacks, spamming, and platform policy violations. (Legitimate interests)
- Improve the Service: Debug issues, monitor uptime, and optimize application performance. (Legitimate interests)
- Transactional Communications: Send critical notifications regarding failed posts, security alerts, and account changes. (Performance of contract)
We do not use your private posts or messages to serve third-party advertising, and we do not sell your personal data.
5. AI-Assisted Features
The Service offers optional AI tools to generate or refine captions, hashtags, and copywriting. Prompts and drafted text are transmitted securely to sub-processor model providers (such as OpenAI). We enforce contractual terms requiring that your data is not used to train public foundation models. AI outputs are probabilistic; you remain responsible for reviewing content before publishing.
6. Controller vs. Processor
For account, billing, site telemetry, and security data, Hookpost acts as a data controller. For the content you schedule and the audience metrics fetched on your behalf, Hookpost acts as a data processor operating under your instructions.
7. Who We Share Data With
We do not sell personal data. We share data only with:
- Connected Third-Party Platforms: Transmitting scheduled posts and media to the platforms you choose (Pinterest, YouTube, TikTok, Meta, X, LinkedIn, etc.).
- Infrastructure & Hosting Sub-processors: Contabo and Google Cloud (servers), Neon (PostgreSQL database), Upstash (Redis), Cloudflare (media storage and content delivery), and Resend (transactional email).
- Service Providers: OpenAI (AI writing and the AI assistant), Razorpay (payments), Google (Sign-In, Tag Manager and Google Ads conversion measurement), Meta (Pixel and Conversions API for ad measurement: IP address, browser data, click IDs, and hashed email), and Plausible (website analytics).
- Workspace Collaborators: Team members assigned to your Hookpost organization based on their designated roles.
- Legal Authorities: When required by valid legal process, court order, or regulatory mandate.
8. Data Retention
- Account & Workspace Data: Retained while your account is active. Upon account deletion, data is purged or anonymized within 30 days.
- OAuth Tokens: Retained while connected. Removing a channel immediately deletes its access tokens and other connection credentials from our database by overwriting them with a one-way hash. Copies held by our job scheduler and in our database backups expire on a rolling schedule, normally within 30 days, except where we must keep them longer to investigate a security incident or meet a legal obligation.
- Scheduled Content: Retained until published or manually deleted by the user.
- Billing Invoices: Retained as required under statutory financial and taxation regulations.
9. Security
We implement comprehensive technical and organizational measures: TLS 1.3 encryption in transit, AES-256 encryption at rest for our main database (applied by our database provider), cryptographic password hashing, isolated database networks, and automated intrusion monitoring.
10. Your Rights (GDPR / CCPA / India DPDP Act 2023)
Depending on your jurisdiction, you have statutory rights concerning your personal data:
- GDPR (Europe) & CCPA (California): Right to access, rectify, or erase personal data, object to or restrict processing, data portability, and non-discrimination.
- Digital Personal Data Protection Act, 2023 (India): As an Indian enterprise operated by JR Consulting Co., we recognize your rights as a Data Principal under the DPDP Act 2023, including the right to access summaries of personal data processed, the right to correction and erasure, the right of grievance redressal, and the right to nominate an individual in the event of death or incapacity.
To exercise any of these rights, email our Data Privacy team at [email protected]. Requests are addressed within statutory timelines (and no later than 30 days).
11. Contact Us
For questions or privacy requests, contact:
Ready to grow your social media presence?
Schedule, analyze, and manage all your accounts from one dashboard.
Start with Hookpost