1. Scope
This policy applies to the public Hook Relay website and the Hook Relay Clip Factory desktop workflow. Hook Relay is operated from Queensland, Australia. The website is informational: it does not provide user accounts, run advertising trackers, use analytics cookies or collect payment information.
2. Information the connected application may access
When an authorized operator connects a provider account, Clip Factory may receive the minimum information and permissions needed for the selected workflow:
- account or channel name, handle, profile image and provider account identifier;
- OAuth access and refresh tokens issued by the provider;
- permission to upload media, create or manage posts, and obtain publishing status;
- first-party metrics for content published to the connected account; and
- technical error details required to diagnose a failed connection or publication.
Hook Relay never asks for or receives the user's provider password through this website or Clip Factory.
3. How information is used
Connected account data is used only to authenticate the account chosen by its owner, publish content that has been approved for that account, display connection status, retrieve performance metrics for Hook Relay's own content, maintain security and troubleshoot errors. It is not sold, rented, used to build unrelated advertising profiles or shared for independent marketing.
4. Google and YouTube data
For a connected YouTube channel, Clip Factory may use Google OAuth data to identify the channel, upload approved videos, set permitted video metadata and read performance information for those uploads. Hook Relay's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Meta, TikTok and X data
For Facebook and Instagram, permissions are used to identify authorized Pages and professional accounts, publish approved media and retrieve associated first-party metrics. For TikTok and X, equivalent provider permissions are used only when approved and authorized for direct publishing, status checks and first-party performance reporting.
6. Storage and security
Clip Factory is designed as a local desktop workflow. Provider secrets and tokens are stored on the operator's Windows device using Windows Credential Manager when available. Operational records are stored in the local application database. The public website does not receive or store those credentials. Reasonable technical and organizational safeguards are used, but no system can guarantee absolute security.
7. Sharing and service providers
Information is sent to the relevant platform only to perform an authorized action. Limited technical providers may process data where required to host this website or deliver the connected platform service. Hook Relay does not authorize those providers to use connected-account data for their own marketing.
8. Retention
OAuth credentials are retained until the connection is removed, revoked, expires or is replaced. Local campaign, media, log and publication records remain until removed by the operator or through a deletion request. Provider-hosted posts and metrics remain subject to that provider's own retention rules.
9. Your choices and deletion
An authorized operator can disconnect a provider inside Clip Factory and can separately revoke access in the provider's own security settings. For a complete deletion request, follow the Data Deletion Instructions. We may need enough information to locate the correct record, but we will never ask for a password or access token.
10. Children
Hook Relay and Clip Factory are not directed to children and do not knowingly collect personal information from children through this website.
11. Changes
This policy may be updated when the workflow, provider requirements or applicable law changes. The effective date above will be revised when a material update is published.
12. Contact
Privacy questions or requests may be sent to peteschliff@gmail.com with the subject “Hook Relay Privacy Request”.