Privacy
Privacy policy
What Hooky knows about you and your sites’ visitors, why, for how long, and how to stay in control of it. As jargon-free as we can make it.
Last updated: October 6, 2026
In short. Hooky doesn’t sell any data and doesn’t show any ads. We collect what’s needed to run the service: your profile, your sites, conversations with your visitors and the stats your sites send us. In the app, usage measurement and crash reports help us improve it: you can turn them off. You can delete your profile at any time, from the app or the web workspace.
Who is responsible
Hooky is published by theAppsfactory, a simplified joint-stock company (SAS) with share capital of €1,000, 24 rue Abel Gance, 84100 Orange, France, registered with the Trade and Companies Register (RCS) of Avignon under number 821 324 332 (“we”).
For any question about your data, write to us at support@heyhooky.com.
This policy applies to the heyhooky.com site, the web workspace, the Hooky apps (iPhone, iPad, Mac and Android), the chat bubble and the API.
Two different roles
- For your own data (your profile, your account, your subscription), we are the controller within the meaning of the GDPR.
- For the data of your sites’ visitors (their messages, their email if they leave it, your sites’ stats), you, or the business that publishes the site, are the one responsible for it. Hooky processes it on your behalf, as a processor, according to your instructions and the terms of use. So it’s up to you to inform your visitors, for example in your site’s privacy policy, by mentioning Hooky.
What we collect about you
When you create a profile, log in or use Hooky:
| Data | Why | Legal basis |
|---|---|---|
| Email address, first or last name, login identifier (Google, Apple or email link, via Firebase) | Log you in without a password, recognize you, send you the service’s emails (login link, invitations, reminders) | Performance of the contract |
| Language and time zone | Write to you in your language, date messages and stats in your local time | Performance of the contract |
| Your account: name, sites, allowed addresses, bubble color and message, team, roles, invitations, API keys | Run the service | Performance of the contract |
| Your replies to visitors | Deliver them to the visitor and keep them in the conversation | Performance of the contract |
| Sessions: IP address, browser or device, date last used | Security of your profile, knowing which devices are logged in | Legitimate interest (security) |
| Device notification token (Firebase Cloud Messaging) | Send you a notification when a visitor writes to you or a channel receives a message | Performance of the contract, after you’ve given permission on your device |
| Subscription: plan, billing cycle, status, end of period, identifiers at Stripe, Apple or Google | Manage your subscription and its renewal | Performance of the contract, accounting obligations |
| App usage measurement and crash reports (see below) | Fix bugs and improve the app | Legitimate interest, can be turned off in the app |
Hooky doesn’t keep any passwords: login goes through Google Firebase Authentication. We don’t store your profile picture. We don’t use your data to show you ads, and we don’t sell it.
Your sites’ visitors’ data
When a visitor writes in a site’s Hooky bubble, we process, on the site’s behalf:
- their messages, with their date and read status;
- the photos and files they send (photos, PDFs): photos are resized and stripped of their metadata (EXIF, GPS location), and the original isn’t kept;
- their name and email address, only if they choose to leave them, so they get replies by email;
- the address of the page they’re writing from, their language and their time zone (provided by the browser), to reply in their language and at their local time;
- a conversation token, kept in the browser’s local storage on the site, so they find their conversation on their next visit. The bubble sets no cookies.
Stats. The events the site sends (Hooky.track("inscription") or the API) are counted with no visitor identifier: an event name, an optional value, the date and the properties chosen by the site. Stats don’t follow anyone from one page or site to another. The site must not put any personal data in them (email, name, phone number).
Channels. Notifications a site posts to its channel are kept for 90 days, then erased. They must not contain any personal data.
Are you a visitor to a site that uses Hooky and want to access your messages or have them erased? Contact the site in question first. You can also write to us: we’ll pass your request on to the site.
Usage measurement and crashes in the app
The Hooky apps use two Google tools:
- Firebase Crashlytics: when the app crashes, a technical report is sent (device model, system and app version, error trace), so we can fix the bug.
- Google Analytics for Firebase: usage measurement of the app (screens viewed, and events such as logging in, creating a site, sending a message or making a purchase), linked to your Hooky identifier, without your email or the content of your messages. It helps us understand what works and what gets stuck in the app.
Neither uses an advertising identifier, and no data is used for advertising: ad data storage and sharing are denied (Google Consent Mode). You can turn both off at any time in the app, in the Me tab, with the “Anonymous usage statistics” setting. The web workspace and the heyhooky.com site have no audience measurement at all.
Cookies and local storage
No advertising cookies or third-party trackers on heyhooky.com. The site and the workspace only keep, in your browser:
- the
hooky_langcookie, your language when you choose it (1 year); - your session, your language and your theme (light or dark) in local storage, and Firebase’s login state;
- on your clients’ sites, the bubble only keeps the visitor’s conversation token (see above).
All of this is needed for the service or keeps a choice you made: no consent is requested.
Payments
We never see your card number.
- On the web, payment goes through Stripe, which collects your payment details and issues the invoices. We only keep your Stripe customer identifier and your subscription status.
- In the app, purchases go through the App Store (Apple) or Google Play. They process payment under their own privacy rules; we receive a signed proof of purchase (product, dates, transaction identifier) to activate your plan.
Who else sees this data
In your account, your team members see the conversations and stats of the sites they have access to. Otherwise, only our technical processors, each for its own task:
| Provider | Role | Where |
|---|---|---|
| Hostinger International Ltd | Hosting of the server and database | Server in the European Union |
| Google (Firebase Authentication, Cloud Messaging, Crashlytics, Analytics) | Login, push notifications, crash reports and app usage measurement | European Union and United States |
| Apple | Sign in with Apple, notifications on iPhone, iPad and Mac, App Store purchases | European Union and United States |
| Twilio SendGrid | Sending emails (reminders, invitations, activation) | United States |
| Stripe | Payment of subscriptions on the web, invoices | European Union and United States |
| Google Play | Purchases in the Android app | European Union and United States |
| Cloudflare | DNS servers for the heyhooky.com domain; storage of photos and files sent in conversations (Cloudflare R2) | Worldwide for DNS; European Union for files |
We may also disclose data if the law requires us to (at the request of an authority, for example).
Transfers outside the European Union
Some providers are based in the United States or process data there. These transfers are covered by the EU–U.S. Data Privacy Framework when the provider is certified under it, and by the European Commission’s standard contractual clauses.
How long
| Data | Retention |
|---|---|
| Profile (email, name, language, time zone) | As long as your profile exists; erased when you delete it |
| Sessions and notification tokens | Until the device logs out or the profile is deleted; a token Firebase no longer recognizes is discarded |
| Accounts, sites, conversations, messages and stats | As long as the account exists, or until you delete the site or the account |
| Photos and files in conversations | Like their message: deleted with the message, the conversation, the site or the account. They only open through signed links, valid for 1 hour (7 days in emails) |
| Channel messages | 90 days |
| Invitations | Valid for 7 days, erased with the account |
| Account created by an AI and never activated | Erased about 8 days after it was created, along with its sites and conversations |
| App crash reports and usage measurement | According to Firebase’s settings: 90 days for crash reports, 14 months at most for usage measurement |
| Invoices and accounting records | 10 years, as required by law |
| Server technical logs (IP address, date, requested address) | 12 months at most, for security |
When you delete your profile, your replies stay in the conversations of accounts where others work, but without your name.
Security
Everything goes over HTTPS. Session tokens are only kept as hashes, API keys are encrypted in the database, and server access is restricted. Each team member only sees the sites they’ve been given access to.
Your rights
You can at any time request access to your data, its rectification, erasure or portability, object to processing based on our legitimate interest or request its restriction, and give instructions on what happens to your data after your death.
- Delete your profile: in the app, Me tab › Delete my profile; in the web workspace, My profile › Delete my profile. Accounts where nobody else works are erased along with their sites and conversations, and their Stripe or Google Play subscriptions canceled. An App Store subscription is canceled in your Apple account settings.
- Delete an account (and all its sites): at the bottom of the Team page, for the owner.
- To also erase your login identity at Firebase, or for any other request, write to support@heyhooky.com. We reply within one month.
If you believe your rights aren’t being respected, you can lodge a complaint with the CNIL (cnil.fr), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or the data protection authority of your country.
Minors
Hooky is a tool for people who run websites. It isn’t intended for children under 15, and we don’t knowingly collect their data.
Changes
If this policy changes in a significant way, we’ll let you know by email or in the app before the change takes effect. The date of the last update is at the top of this page.