Legal

Privacy Policy

Last updated September 24, 2026

The short version
  • We use the email you forward to Hooky only to handle that email for you.
  • We do not sell your data, show ads, or use your email to train AI models.
  • Messages, attachments, and logs are deleted after 90 days.
  • Everything runs on Amazon Web Services in the United States.

Who we are

Hooky is an email support service at hooky.email, operated by who.is (“we”, “us”). This policy explains what personal data Hooky collects, why, who processes it, how long we keep it, and your choices. It applies to the website, the console at app.hooky.email, the Hooky API, and the email Hooky receives and sends. Our Terms of Service include this policy.

Two kinds of data

Your account data. This is data about you and your team as Hooky customers. We decide how it is used, as described here.

Your customers’ email. This is the email you forward to Hooky, which contains personal data about the people who write to you. You decide what Hooky does with it, through the actions you set up. For this data, you are the controller and we are your processor. We handle it only to provide Hooky to you, on your instructions.

What we collect

Account data

  • Your email address and the email addresses of the members you invite.
  • Your workspace name and domain, your actions and their instructions, and your settings.
  • Webhook URLs and secrets. We store secrets encrypted and never show them again.
  • API keys. We store only a hash of each key.
  • A record of the approvals and overrides that members make.

Email you forward to Hooky

  • The full message: sender, recipients, subject, body, headers, and attachments.
  • What Hooky did with it: the action it chose, how sure it was, the reason, the inputs it filled, the reply it wrote, and the result of each step.
  • Email that Hooky sends for you, and delivery results such as bounces and complaints.

Technical data

  • Our servers log requests, including IP addresses and user agents, to run the service and stop abuse.
  • The console keeps your sign-in token in your browser’s local storage. Hooky does not use cookies, analytics, or ads on this website or in the console.

How we use it

  • To receive, sort, and act on your email as your actions tell Hooky to.
  • To send sign-in links, approval requests, daily digests, and service notices.
  • To keep Hooky secure, stop spam and abuse, and fix problems.
  • To meet legal duties.

We look at a specific message only when you ask us to, when we need it to fix a problem with your account, or when the law requires it.

AI processing

Hooky uses AI models to read each email, pick an action, fill in the inputs, and write replies. The models run on Amazon Bedrock, in our own AWS account. Under Amazon’s terms, Bedrock does not store your prompts or outputs and does not use them to train models, and the model makers do not receive them.

We do not use your email or your customers’ email to train or improve any AI model.

AI can make mistakes. You can make any action wait for your approval, and Hooky holds an email when it is not sure.

Who processes your data

We do not sell or rent personal data. We share it only with these parties:

WhoWhat for
Amazon Web Services (US)Hosting, storage, receiving and sending email, and AI models through Amazon Bedrock.
Your own webhooksWhen an action calls your webhook, Hooky sends it the message details and inputs that the action includes. You control these endpoints.
The people you emailReplies and forwards go to the addresses that your actions set.
Legal and safetyWhen the law requires it, or to protect the rights and safety of our users or others.
A buyer of our businessIf who.is sells all or part of its business, under this policy.

If we add a new processor, we will update this page first.

How long we keep it

DataKept for
Messages, attachments, decisions, runs, and logs90 days, then deleted automatically
Server logs30 days
Daily usage counts (numbers only)About 13 months, for limits and billing
Account dataUntil you delete your workspace or ask us to delete it

When you delete a workspace in the console, we delete its account data at once. Copies of messages that remain in storage are deleted within 90 days of when they arrived. Backups of account data are overwritten within 35 days.

Security

All stored data is encrypted. The website, the console, the API, and webhook calls use HTTPS only. Webhook secrets have their own encryption key, and API keys are stored only as hashes. Each workspace can see only its own data. Sign-in uses single-use email links, not passwords.

Hooky does not hold SOC 2 or HIPAA certification. Do not use it for health records, payment card numbers, or other data that needs those protections.

Where your data is

Hooky stores and processes all data in the United States (AWS us-east-1). If you use Hooky from outside the United States, your data goes to the United States.

Your rights

You can see, correct, export, or delete your account data. Most of this is in the console. We answer within 30 days.

Depending on where you live, you may have more rights under laws such as the GDPR or the CCPA. These include the right to object, to restrict use, and to complain to your data protection authority. We do not sell or share personal data for advertising.

If you wrote to a business that uses Hooky, that business controls your message. Contact them first. If you contact us, we will pass your request to them.

Children

Hooky is for businesses. It is not for anyone under 18, and we do not knowingly collect data from children.

Changes to this policy

If we change this policy, we will update the date at the top. If a change is important, we will email the members of each workspace before it takes effect.