hooky.

Legal

Privacy Policy

Last updated: September 5, 2026

This Privacy Policy explains what information Hooky (“Hooky”, “we”, “us”) collects when you use our mobile application, our Visual Studio Code extension, our relay and speech services, and this website at hooky-ai.com(together, the “Services”), how we use that information, who we share it with, and the choices you have. We have written this policy in plain language. Where defined terms are used, they are explained the first time they appear.

1. Summary

Hooky connects your phone to the workspace and coding agents on your computer. Some data is stored on your devices. Account data, saved chats and remote delivery history are also processed and stored by Hooky services. Remote connections, voice features, the Files workbench tunnel and your selected coding agent can send content through external services. The route depends on the features and connection mode you use.

2. Who is the controller of your data?

The controller for personal data processed through the Services is the operator of Hooky (the “Operator”). You can contact us about this policy or any privacy matter by writing to privacy@hooky-ai.com.

3. Information we collect

3.1 Information you provide directly

  • Account information. You can sign in with GitHub, Google or email and password. For GitHub and Google sign-in, we process the identity and profile fields returned by the provider, such as account ID, name, email address and avatar. Email accounts use an email address and a stored password hash. We also store account profile settings and linked sign-in methods. This data authenticates you and associates chats, sessions and messages with your account.
  • Early-access email. If you submit your email address on an access-request or signup form on hooky-ai.com, we store that email address solely to notify you when Hooky becomes available and to send occasional launch-related updates.
  • Content you send to the Services. Chat messages, file content you choose to upload, screenshots, prompts for the AI agent, and similar inputs that you submit through the app or extension. Voice features also process recordings, live audio, transcripts and text used to produce spoken replies.
  • Support and feedback. If you contact us, we keep the contents of your message and our reply.

3.2 Information collected automatically

  • Connection metadata. Pairing codes, session tokens, device identifiers generated by the app, IP address of the connecting device, timestamps, and basic diagnostic information (operating system version, app version). This information is used to establish and maintain the connection between your phone and your IDE. Transport differs between Direct and Remote modes.
  • Push notification tokens.If you allow the app to send notifications, your device’s push token (from Apple Push Notification service or Firebase Cloud Messaging) is sent to our relay backend so that we can deliver a notification when your AI agent needs your attention.
  • Access and usage records. We process account entitlement records and feature-usage counters, such as relay traffic and voice duration, to apply access and usage limits. Where store purchase validation is enabled, this can also include store transaction identifiers and subscription status. Current purchase availability is described in the app and on this site.
  • Server logs. Our servers automatically record standard request information (IP address, request path, response code, timestamp, user agent) for security, abuse prevention, and diagnostic purposes.

3.3 Information we do not collect

We do not use third-party analytics, advertising trackers, or behavioural profiling cookies on the website. We do not request access to your contacts or calendar. The app requests permissions for features such as microphone recording, camera pairing, photos, files and notifications. You can manage these permissions in your device settings. Host screen capture and computer actions also depend on permissions on the connected computer.

4. How your content is stored and transmitted

  • Direct mode (LAN). The phone can connect directly to the extension on a trusted local network using a WebSocket. That workspace connection does not pass through the Hooky relay, but it is not universally protected by TLS. Account services, speech processing, selected agent providers and workbench tunnels may still use internet services when you use those features.
  • Remote mode. Traffic passes through the Hooky relay over TLS/WSS. The relay processes application messages and stores supported message payloads and delivery history to support notifications and catch-up. This can include chat text, agent responses and file-change data. Operational logs can also contain message details. This is transport encryption, not end-to-end encryption between your phone and computer.
  • Account and delivery storage. Profile records, saved chats, sessions and messages are stored on our backend and associated with your account. Remote delivery history uses server-side message storage, including Firestore when configured. These records are separate from the copies on your devices.
  • Files workbench.The browser VS Code workbench runs on your connected computer. It can be reached over the local network or through a Cloudflare tunnel. Tunnel traffic, including workspace content you view or edit, passes through that provider. The workbench selects its connection separately from the chat session’s Direct or Remote mode.
  • Audio and agent processing.Voice recordings and live audio are sent through speech services for transcription. Text for spoken replies is sent for speech synthesis. Transcripts you send become chat content. Optional prompt polishing and your chosen coding agent send relevant prompts and context to their providers under those providers’ terms and policies.
  • On-device data.Chat history, drafts, pairing tokens and editor state are also stored on your phone and in your IDE’s storage. Removing the app or extension does not by itself delete backend records, and local removal depends on the operating system’s storage and backup behavior.

5. How we use information

We process personal data for the following purposes and on the following legal bases (in jurisdictions where this terminology applies, such as the EU/EEA and the United Kingdom):

  • To provide the Services. Authenticating you, pairing your devices, routing messages between them, persisting your chats, processing voice input and spoken replies, applying feature-access limits, and sending push notifications you have opted into. (Legal basis: performance of a contract.)
  • To keep the Services secure. Detecting and preventing abuse, brute-force attacks, and unauthorised access. (Legal basis: legitimate interests.)
  • To improve the Services. Aggregated, non-personal diagnostics about errors and reliability. (Legal basis: legitimate interests.)
  • To notify you of launch and updates. If you joined the waitlist or subscribed to launch updates. (Legal basis: consent. You can withdraw it at any time.)
  • To comply with law. Where we are required to retain or disclose information to comply with a legal obligation. (Legal basis: legal obligation.)

We do not sell your personal information, and we do not use your content to train artificial intelligence models.

6. Third-party processors

Hooky uses external providers to operate the Services and connect to the agents you choose. Their own terms and privacy policies also apply to their processing:

  • GitHub, Inc.— used for authentication (OAuth) and, if you enable it, GitHub Copilot integration in the IDE. See GitHub’s Privacy Statement.
  • Anthropic, PBC.— used to translate casual mobile messages into developer-friendly prompts when you enable AI translation, and to power Claude Code where you choose to use it. See Anthropic’s Privacy Policy. When this feature is enabled, the text of the affected messages is sent to Anthropic for processing.
  • OpenAI.— provides Codex when you select that agent. Prompts, workspace context and agent interactions are processed according to your agent setup and OpenAI account terms.
  • Deepgram.— processes recorded and live audio for speech-to-text and reply text for speech synthesis when you use enabled voice features.
  • Apple Inc.— delivers push notifications through Apple Push Notification service. App Store services may also process purchases where enabled.
  • Google LLC.— provides Google sign-in, Firebase Cloud Messaging for notifications and Firestore for server-side message history where configured. Google Play may also process purchases where enabled.
  • Cloudflare.— provides the tunnel used to reach your browser VS Code workbench remotely.
  • Hosting providers. Our relay server and waitlist backend run on third-party infrastructure providers in the regions we operate. They process data on our behalf under data processing agreements where required.

We do not share your personal data with third parties for their own marketing purposes.

7. International transfers

Our infrastructure providers may process data in regions outside of your country of residence, including the European Union and the United States. Where personal data is transferred outside of the European Economic Area or the United Kingdom, we rely on appropriate safeguards (such as Standard Contractual Clauses) recognised under applicable data protection law.

8. Retention

Account records, saved chats, remote delivery history, operational logs, usage records and push tokens have separate storage lifecycles. Removing a local chat, signing out or uninstalling the app does not necessarily remove every related server record. We do not promise a fixed automatic deletion time for all of these records.

Early-access email addresses are used for access and launch updates. To stop those updates, or to request deletion of account data, messages or other personal information, contact privacy@hooky-ai.com. We handle requests subject to applicable legal obligations. External providers apply their own retention policies to data they process.

9. Your rights

Depending on where you live, you may have the following rights with respect to your personal data:

  • access to a copy of the information we hold about you;
  • correction of inaccurate or incomplete information;
  • deletion of your data (sometimes called the “right to be forgotten”);
  • restriction or objection to certain types of processing, including processing based on our legitimate interests;
  • portability of the data you have given us;
  • withdrawal of consent at any time, where processing is based on consent;
  • the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, write to privacy@hooky-ai.com. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on certain requests.

10. Security

Remote relay connections use Transport Layer Security (TLS/WSS). Direct local connections are not universally encrypted; use Direct mode only on a trusted network. Pairing and authentication controls restrict workspace access. Relay services can process and store message content, so this is not an end-to-end encrypted service. Keep your devices and agent credentials secure. No system can be guaranteed to be perfectly secure, and we work to fix reported security issues.

11. Children

Hooky is intended for software developers and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where the changes are material, we will provide a more prominent notice (for example, an in-app message or an email to subscribers).

13. Contact

Questions or requests about this Privacy Policy can be sent to privacy@hooky-ai.com.