HOOKINTENT

Privacy Policy

Last updated: 2026-09-15

This Privacy Policy explains how the operator of HOOKINTENT (“we”, “us”) collects, uses, stores, and shares personal information when you use the website and the Chrome extension. It should be read with the Terms of Use. If you do not agree, please do not use the service.

1. Who this applies to

This policy covers visitors, registered users, and sub-accounts. It does not cover third-party platforms you open in Chrome (Xiaohongshu, Douyin, YouTube, Instagram, payment networks, email providers). Those sites have their own policies.

Depending on your location, the Personal Information Protection Law of the PRC and, where they apply, other privacy rules may govern our processing. We act as the controller of account data on our systems; the extension processes page content on your device to carry out tasks you start.

2. Information we collect

We collect only what we need to run the product:

  • Account data: email, password hash or third-party login identifiers, role, plan, expiry, sub-account links.
  • Configuration: persona and guidelines, follow-comment scripts, keyword dictionary, watch-account URLs, auto-DM scripts, feature flags your admin enables.
  • Operations data: comments and post cards the extension sends back, lead scores, reports, comment-contact logs so we do not message the same person twice, plugin heartbeat / last-seen time.
  • Billing data: SKU, amount, currency, FX rate used, payment method, network label, your note, and the payment voucher you upload. We do not store full card numbers; crypto and bank transfers are completed outside our site.
  • Technical data: IP address, user agent, approximate time, and security logs when you sign in or call our APIs.
  • Support content: messages you send via the in-site inbox or email.

3. Information we do not try to collect

We do not ask for your third-party platform passwords. Login to those sites stays in your browser. We do not sell personal information. We do not use your comment corpus to train a public foundation model of our own. We ask the extension to minimise other people’s identifiers where the product allows (for example truncated display in logs).

4. How we use information

We use personal information to:

  • Create and secure your account, enforce plan limits, and show the workbench.
  • Sync configuration to the extension and write back task results and reports.
  • Generate replies or lead analysis through a third-party AI provider using the prompts you saved.
  • Process orders, review vouchers, send payment-notice emails, and keep accounting records.
  • Detect abuse, debug failures, and send service notices (expiry, task finished, security).
  • Comply with law, lawful requests, and dispute handling.

5. Cookies, local storage, and the extension

The website uses cookies or similar storage for login sessions and preferences. You can block cookies in your browser; some features will stop working.

The extension stores task queues and settings in Chrome storage on your computer so work can resume if a tab reloads. Uninstalling the extension deletes that local copy. It does not mean we have erased the copies already uploaded to your account on the server.

6. Sharing

We share information only with processors who help us operate the service, under contractual confidentiality, or when the law requires it:

  • Infrastructure and database hosting (for example Supabase or equivalent).
  • Transactional email (for example Resend) for verification, password reset, task notices, and payment notices.
  • AI inference providers (for example DeepSeek) that receive prompts and comment snippets you asked us to analyse — not your password.
  • You and teammates you invite (sub-accounts see assigned DM lists and related snippets).
  • Authorities, courts, or counterparties when we reasonably believe disclosure is required to protect rights, safety, or the service.

7. Cross-border processing

Servers, email, or AI vendors may be located outside your province or country. Where required, we rely on your consent, contractual necessity, or other lawful mechanisms, and we require vendors to protect the data. If you do not want cross-border processing, do not use features that send content to those vendors (in particular AI reply and lead analysis).

8. Retention

Account and configuration data are kept while the account is active. Task reports and some export files are kept for a limited window (for example about 15 days for certain Excel reports). Inbox messages follow the TTL you or an admin set.

Payment records and vouchers may be kept longer for bookkeeping, anti-fraud, and dispute purposes. When you delete the account, we delete or anonymise personal data we no longer need, unless a legal duty requires storage.

9. Security

We use HTTPS, access control, and least-privilege service keys on the server. No method is 100% secure. You should use a unique password, keep Chrome updated, and not install unofficial copies of the extension.

10. Your rights

Subject to identity verification and legal exceptions, you may request to access, correct, copy, or delete personal information we hold, or to restrict or object to certain processing. You may also withdraw consent where processing is based on consent (withdrawal does not affect prior lawful use).

You can update persona and dictionaries in the workbench, change your password, and log out. To delete the whole account, contact us using the address on the site. We may refuse requests that are unfounded, excessive, or would break accounting or security duties.

11. Children

The service is not directed at children under 14 (or the higher age in your region). We do not knowingly collect their personal information. If you believe a child registered, contact us and we will delete the account.

12. Changes

We may update this policy when the product or the law changes. The “Last updated” date will change. Material changes may also be noticed in the product or by email. Continued use after the effective date means you accept the revised policy.

13. Contact

Privacy requests can be sent to the notice or support email published on HOOKINTENT. Please describe the account email and what you need (access, correction, or deletion) so we can respond.