Privacy Policy
At HookLab ("we", "us") we respect your privacy. This document explains what data we collect, why, and what rights you have. Applies to our website, the HookLab app, and the /api/* endpoints.
1. What data we collect
When you paste your YouTube channel URL, we send the channel identifier to the public YouTube Data API v3 to retrieve public info (name, subscriber count, thumbnails, recent videos). This info is publicly shown by YouTube to any visitor.
We save the channel ID you analyzed in a cookie named "hooklab:channelId" for 30 days so the app remembers your context across sessions. This cookie contains no personally identifiable information.
We do not ask for email, name, or any other personal info unless you choose to create an account (feature not available yet). When accounts launch, we will update this policy.
2. AI services use
To generate video ideas, we send Anthropic (Claude) a public summary of your channel: title, description, subscriber count, country, and titles/metrics of the last 20 videos. All this information is already public on your YouTube channel.
Anthropic processes this data to generate the response and, per their policy, does not train models on API-submitted data. More info at https://www.anthropic.com/legal/privacy
3. Analytics and third parties
The site is hosted on Vercel (US), which receives basic traffic logs (IP, user agent, URLs visited) for up to 30 days. These logs are used only to debug errors. More info at https://vercel.com/legal/privacy-policy
We do not use Google Analytics, Facebook Pixel, or any advertising trackers.
4. YouTube Analytics (your channel's private data)
If you connect YouTube Analytics from Settings, we access YOUR channel's private statistics through the YouTube Analytics API, using the Google scope "https://www.googleapis.com/auth/yt-analytics.readonly". This is a READ-ONLY analytics scope: it does not let us post, edit or delete anything on your channel, read your revenue data, or access any other channel.
What we read, exactly: for each of your most recent videos, views, estimated minutes watched, average view duration and average percentage viewed; plus the audience retention curve (what share of viewers is still watching at each point of the video).
What we use it for: solely and exclusively to show you the performance of your own channel inside HookLab and to evaluate the quality of the ideas we suggest to you. We do not use it for advertising, we do not sell it, we do not share it with third parties, and we do not use it to train artificial intelligence models. This data is NOT sent to Anthropic or any other AI provider.
Where and for how long: stored in our Supabase database for as long as you keep the connection active. Access credentials (Google tokens) are unreachable from the browser and are DELETED the moment you disconnect. Historical measurements already collected are kept as part of your channel history; if you want those deleted too, email us at contact@hooklabco.com and we will do it.
How to revoke access, through two independent routes: (a) from Settings → YouTube Analytics → Disconnect, which revokes the grant with Google and deletes our credentials; (b) from your Google account permissions page, https://myaccount.google.com/permissions, removing HookLab's access. Either one cuts off access immediately.
HookLab's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically: we use this data only to provide the features you requested, we do not transfer it to third parties except where legally required, we do not use it for advertising purposes, and we do not allow humans to read it except with your explicit consent or where necessary for security or to comply with the law.
HookLab is also bound by the YouTube API Services Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy).
5. Your rights
Under GDPR (EU) and CCPA (California), you have the right to: access your data, rectify it, delete it, object to processing, and receive a portable copy.
Since we barely collect personal data, exercising these rights is simple: delete the "hooklab:channelId" cookie from your browser and we keep no trace of you. If you created an account (when available), email contact@hooklabco.com.
6. Changes to this policy
We may update this policy. Material changes will be announced via a site-wide banner at least 14 days in advance.
7. Contact
For any privacy questions: contact@hooklabco.com