Privacy policy. What we hold, and why.
What Hoook collects when you use the platform, how it is used, and the choices you have.
Updated 16 September 2026
Who this covers
This policy covers visitors to this site, account holders, the people who use a Hoook workspace, and the end users who connect accounts through a product built on Hoook.
Where you use Hoook for an organisation, that organisation controls the workspace data and its own privacy notice applies to it as well.
What we collect
Account details: your name, email address, sign-in identifier, organisation and role. Billing details are handled by our payment processor, and we never store full card numbers.
Workspace content: the workflows, code and settings you create. Usage data: tool calls, events, run logs and credit use. Connected accounts: the OAuth tokens and API keys you or your end users store to reach third-party apps, which are encrypted.
How we use it
To run the platform: authenticate to connected apps, run tools and workflows, deliver events, keep it secure, and recover from failures.
To bill you, support you, prevent abuse, improve the service, and meet our legal obligations. We send service and security messages, and marketing only where you have agreed.
AI and connected accounts
When your agent calls a tool through Hoook, the model sees the tool's inputs and results, never the credentials behind it. The model provider you choose is governed by its own terms.
Your content and connected account data are never used to train shared or foundation models. Every tool call runs with the permissions of the account it uses, and is written to the audit log.
Who we share it with
We do not sell personal data. We share it with the providers that help us run the service, such as cloud hosting, our database provider, payment processing and email, under confidentiality and data protection terms.
We share it with the integrations and AI providers you connect, at your direction. We disclose it where the law requires, or to protect people and the service. If the business is sold, this policy travels with the data.
Where it is held
We may process and store data in countries other than yours. Where we transfer personal data across borders we rely on appropriate safeguards, such as standard contractual clauses.
Business customers can agree data residency and retention terms in their order form.
How long we keep it
We keep your content while the account is open and you can delete workspaces and content at any time.
After an account closes we delete or anonymise what is left within a reasonable period, except where we must keep it for legal, tax or security reasons.
How we protect it
Encryption in transit and at rest, workspace and end-user isolation, encrypted credential storage, access on a need-to-know basis, and monitoring.
No system is completely secure, so we review our practices and act on what we find.
Your rights
Depending on where you are, including under the GDPR and the CCPA, you may ask to access, correct, port, restrict or delete your personal data, object to some processing, or withdraw consent.
Much of it you can do in your account settings. For anything else write to [email protected] and we may need to confirm who you are. Where we hold data for an organisation we pass the request to them. You may also complain to your data protection authority.
Cookies
We use cookies that are needed to sign you in and remember your preferences, and analytics cookies only where you have agreed.
You can change your choice at any time in your browser.
Children
Hoook is for business use and is not directed at children under 18, and we do not knowingly collect their data.
Changes
If this policy changes we post the new version here and update the date above, and for material changes we tell account holders.
Questions go to [email protected].