Legal
Privacy Policy
Version of 2026-08-22
This policy explains how Hooty.to handles personal data in connection with the Hooty website, console, widget, API and demo. It forms part of our Terms of Service.
We act in two different roles, and it matters which one applies. For your account and our own site we are the controller — we decide why and how the data is handled. For the content we crawl on your instruction and for the conversations your assistant has with your visitors, we are your processor: you decide, and we act on your instructions. Section 8 sets out the processing terms that apply in that second role.
This English text is the authentic version. Translations are for convenience; if they differ, this text prevails.
1. What we collect
As controller, for your account and our website:
- Account data — email address, the identifier issued by our authentication provider, the workspace you belong to, your plan, and whether your address is verified. We never receive your password.
- Billing data — plan, subscription status, invoices and balance history. Card details are handled by the payment provider and never reach us.
- Usage and diagnostic data — requests made, crawls run, quota consumed, error and audit logs, and the IP address and user agent of requests to our API.
- Support correspondence — tickets, messages and attachments you send us.
- Website analytics — which pages of our website and console get opened, measured with Google Analytics and PostHog. Without your consent this is done without cookies, so you are not recognised from one visit to the next.
As processor, on your instruction:
- Crawled content — the text of the pages of the website you nominate, and the vector representations we derive from it. Those pages may contain personal data if you have published it there.
- Conversations — questions your visitors type into your assistant, the answers given, and technical metadata such as a visitor identifier, timestamp and truncated IP used for rate limiting and abuse prevention.
For the public demo, we store the submitted address, the pages crawled from it, the questions asked and the requesting IP address, for abuse prevention and for the short life of the demo.
2. Why we use it, and on what legal basis
- To provide the Service and perform our contract with you — account, crawling, indexing, answering, billing and support. Legal basis: performance of a contract.
- To keep the Service secure and working — rate limiting, abuse and fraud prevention, debugging, capacity planning. Legal basis: our legitimate interest in a service that stays available and is not abused.
- To communicate with you about the Service — changes, incidents, billing. Legal basis: contract, and legitimate interest in keeping you informed.
- To send marketing about our own similar services, where permitted. Legal basis: consent where required, otherwise legitimate interest. You can opt out at any time using the link in the message or by writing to privacy@hooty.to.
- To meet legal obligations — accounting, tax, and responding to lawful requests. Legal basis: legal obligation.
We do not sell personal data. We do not use your content, your visitors’ questions or our answers to train machine-learning models, and our model providers are engaged on terms that do not permit them to do so either.
3. Who else is involved
We use the following categories of sub-processor. This list is kept current; write to privacy@hooty.to for the specific providers in use on a given date, or to be notified of changes.
- Cloud hosting and managed databases — running the Service and storing its data.
- Model and inference providers — generating embeddings and answers. They process the text sent to them for that purpose only.
- Authentication provider — sign-in, email verification and password handling.
- Payment provider acting as merchant of record — checkout, billing, invoicing and tax.
- Bot protection and content delivery — protecting the public demo and serving static assets.
- Email delivery — transactional messages such as verification and billing notices.
- Error monitoring and logging — diagnosing failures.
- Website analytics — counting visits and seeing how our website and console are used. Google Analytics and PostHog; without consent, without cookies.
We may also disclose data to professional advisers, to an acquirer in connection with a merger or sale of assets, and to authorities where we are legally required to. Where we receive a request for your data, we will tell you unless we are prohibited from doing so.
4. International transfers
Our providers operate internationally, so personal data may be processed outside your country, including outside the European Economic Area. Where that happens we rely on an adequacy decision where one exists, and otherwise on the European Commission’s Standard Contractual Clauses together with additional measures where they are needed. You may ask privacy@hooty.to for details of the safeguards applied.
5. How long we keep it
- Account and billing records — for as long as your account exists, and afterwards for as long as needed for tax and accounting, typically six years.
- Crawled content and index — until you delete the source, delete your account, or 30 days after termination.
- Conversations and analytics — for the retention period of your plan, as shown in the console. Shorter plans keep less.
- Demo data — deleted automatically a short time after the demo is created, as stated on the demo itself.
- Security and audit logs — normally up to 12 months.
- Backups — overwritten on their ordinary cycle, normally within 35 days.
6. Your rights
Depending on where you live, you may have the right to access a copy of your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing is based on consent. Withdrawing consent does not affect processing already carried out.
Write to privacy@hooty.to. We will respond within one month, and will tell you if we need longer. We may ask you to confirm your identity first.
If you are a visitor to a customer’s website and want your conversation data removed, the customer is the controller for that data — contact them. If you cannot reach them, write to us and we will forward the request.
You may complain to your data protection supervisory authority. We would appreciate the chance to address your concern first.
8. Processing terms (data processing agreement)
This section applies where we process personal data as your processor, and together with the Terms of Service constitutes a data processing agreement for the purposes of Article 28 of the GDPR and equivalent laws. A separately signed agreement is available on request to privacy@hooty.to.
- Subject matter and duration — provision of the Service, for as long as your subscription lasts.
- Nature and purpose — crawling, storing, indexing and retrieving content you nominate, and generating answers from it.
- Types of data and data subjects — as described in section 1; the data subjects are your website visitors and any individuals referred to in the content you publish.
- We process such data only on your documented instructions, including as to transfers, unless required otherwise by law, in which case we will inform you unless prohibited.
- Our personnel with access are bound by confidentiality.
- We implement appropriate technical and organisational measures, including encryption in transit, tenant isolation, access control and logging.
- We engage sub-processors of the categories in section 3, imposing equivalent obligations, and remain responsible for their performance. You may object to a new sub-processor on reasonable data protection grounds; if we cannot resolve it, you may terminate the affected part of the Service.
- We assist you, taking account of the nature of processing, with data subject requests, security, breach notification and impact assessments.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data.
- On termination we delete or return the data as described in section 5, unless retention is required by law.
- We make available the information necessary to demonstrate compliance and allow for audits, which may be satisfied by documentation and responses to reasonable questionnaires no more than once a year, except after a breach.
9. Security
We use encryption in transit, isolate each workspace’s data, restrict internal access to those who need it, keep audit logs, and review our own code and dependencies. No service can promise perfect security, and we do not.
10. Children
The Service is not directed at children and we do not knowingly collect their personal data. If you believe a child has provided us with data, write to privacy@hooty.to and we will delete it.
11. Changes
We may update this policy. The version date is shown at the top. Where a change is material we will notify you by email or in the console before it takes effect.
12. Contact
Hooty.to. Privacy enquiries and data subject requests: privacy@hooty.to.