This policy explains what BeHooked collects when you use the service, why, and what control you have over it. It applies to the website, the dashboard, the API and the CLI.
What we collect
Account data. Your email address, and a display name if you set one. If you sign in through a third-party provider we receive the identifier and email that provider releases to us, and nothing else.
Content you submit. Prompts, uploaded images, video and audio, and the outputs generated from them. This is the material the service exists to process.
Usage data. Which generations you ran, against which models, at what cost in credits, and whether they succeeded. This is what the usage page reports back to you, and it is also how we bill accurately.
Technical data. IP address, browser and device type, and error diagnostics when something fails. Collected because a service that cannot see its own failures cannot fix them.
We do not collect payment card numbers. Payments are handled by our payment processor, and we receive only the result of a transaction and the last four digits of the instrument.
Why we collect it
| Purpose | What it uses |
|---|---|
| Running generations you request | Content you submit |
| Billing and credit accounting | Usage data, account data |
| Preventing abuse and fraud | Technical data, usage data |
| Support, when you contact us | Account data, relevant usage data |
| Fixing defects | Technical data |
What we do not do
We do not train models on your content. Material you submit is processed to fulfil the generation you asked for and is not used to train, fine-tune or evaluate any model, ours or a third party’s.
We do not sell personal data, and we do not share it with advertisers.
We do not read your content for any purpose other than delivering the service, other than automated checks required to detect abuse of the kind described below.
Third parties who process data for us
Generation runs on model providers’ infrastructure. When you select a model, the prompt and any input media for that generation are transmitted to that provider in order to produce the output. Providers are bound by contract to process it only for that purpose.
We additionally use processors for hosting, error reporting, product analytics and payments.
Retention
Generated outputs and their inputs are retained in your library until you delete them. Deleting an asset removes it from your library immediately and from backups within 30 days.
Usage and billing records are retained for as long as required for tax and accounting purposes, because we are obliged to keep them.
Account data is deleted when you delete your account, subject to the billing records above.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, obtain a portable copy, or object to particular processing. You can exercise all of these by writing to [email protected], and we will respond within 30 days.
You do not need to give a reason, and exercising any of these rights will never degrade the service you receive.
Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it to do their jobs and is logged. If a breach affects your data we will tell you promptly and directly.
Children
The service is not directed at anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
If we change this policy materially we will say so on this page and update the effective date above. Where the change affects how we handle data we already hold, we will contact you directly rather than relying on you noticing.
Contact
Questions about this policy, or about anything we hold: [email protected].