Privacy Policy
Last updated: 2026-07-11
This policy explains what data AgentHook (the service) collects when you use it, why we collect it, who we share it with, and the choices you have. We keep this short and specific: it describes what the service actually does, not what a longer template might promise.
What we collect
- Account data. Your email and name, and a hashed password or hashed API keys. We never store your password or raw keys in a form we can read back.
- Generation data. Your prompts, reference image URLs, generated outputs, and run metadata (timestamps, credits, status). We keep these so you can list and re-fetch your past generations.
- Billing data. Your credit ledger, meaning the record of grants, debits, and refunds against your balance.
- Usage analytics. We use PostHog (hosted in the US cloud) to understand how the service is used: pageviews and console sessions in the browser, plus server-side events about your account activity such as signups, generation runs, and purchases. This data identifies you by your account, is used only to improve the product, and is never sold.
How we use it
We use your account and billing data to run your account, meter credits, and provide support. We use generation data to produce your media and to let you retrieve it later. When you submit a run, your prompts and reference images are sent to the upstream model providers that perform the generation. We use analytics to see how the product is used and to improve it.
We do not sell your data, and we do not use your prompts or outputs to train models.
Who we share it with
We share data with a small number of service providers, only as needed to run the service:
- Model providers. Your prompts and reference images go to the upstream providers that generate your media. Their handling of that data is governed by their own terms.
- Our payment provider. When you buy credits, your purchase is processed by a third-party payment provider that handles the transaction and its records. We do not store your full card details.
- PostHog. Our analytics provider receives the usage events described above.
We do not sell your data to anyone, and we do not share it for advertising.
Where it lives and how long we keep it
Account and run data live in our database. Generated media lives in our object storage under a per-user prefix. Output URLs are unlisted, but anyone who has the URL can fetch the file, so treat an output URL like a shareable link.
We keep your account, generation, and billing data for as long as your account is active. When you delete your account we remove your account data and stored media, though ledger records may be retained where bookkeeping requires it.
Your choices and deletion
You can view and manage your data from the console. To delete your account, email us at aviv@avivkaplan.com and we will remove your account data and stored media, keeping only the ledger records bookkeeping requires. If you want a copy of the data we hold about you, or want to correct it, email the same address and we will help.
International transfers
Our providers, including our analytics provider, may process data in the United States. By using the service you understand that your data may be processed there and in other countries where our providers operate.
Children
The service is SFW only and is not directed at children. It is meant for adults building with AI agents, and we do not knowingly collect data from anyone under the age required to consent in their country.
Changes to this policy
We may update this policy as the service changes. If a change is material, we will announce it to the email on your account. Your use of the service is also governed by our Terms of Service and Refund Policy.
Contact
Questions about privacy or your data go to aviv@avivkaplan.com.