PRIVACY POLICY
Effective Date: October 6, 2026 | Forge Analytics & Systems Inc.
This Privacy Policy describes how Forge Analytics & Systems Inc. ("we", "us", or "our") collects, uses, and shares information when you use Hogmatix ("the Service"), available at hogmatix.com. By using the Service, you agree to the practices described in this policy.
1. Who We Are
Hogmatix is operated by Forge Analytics & Systems Inc., incorporated in Ontario, Canada. For privacy inquiries, contact us at [email protected].
2. Information We Collect
Account Information: When you sign up, we collect your email address and a hashed password to authenticate your account.
Connected Platform Accounts: When you connect a social media account (such as X/Twitter, TikTok, YouTube, or Instagram), we receive and store OAuth access tokens that authorize Hogmatix to post on your behalf. We do not store your social media passwords.
TikTok Data: When you connect your TikTok account via the TikTok API, we collect and store:
- Your TikTok Open ID (a platform-specific identifier)
- Your TikTok display name and username
- OAuth access tokens and refresh tokens required to publish content
- Content you submit through Hogmatix for publishing to TikTok (text, images, videos)
- Post status and publish results returned by the TikTok API
- Public TikTok video IDs returned for the videos you publish through Hogmatix
YouTube / Google Data: When you connect your YouTube channel via Google OAuth and the YouTube Data API, we collect and store:
- Your YouTube channel ID, channel title, and channel thumbnail
- OAuth access tokens and refresh tokens required to upload videos on your behalf
- Videos and their metadata (title, description, visibility, and "made for kids" status) that you submit through Hogmatix for upload to YouTube
- Upload status and the resulting video ID returned by the YouTube Data API
Instagram Data: When you connect an Instagram professional account through Instagram Login, we store the account details, access token and post data listed in Section 6.
Content You Create: We store posts, schedules, and content you create within the Service, including drafts, media you upload for publishing, and published post history. If you generate AI videos for TikTok, we also store their prompts, asset provenance, approval records, and public-video attribution.
AI Processing: When you use AI generation features, the prompts, source images, and generated media needed for the requested operation may be sent to Google Gemini and xAI. We use their responses to generate creative assets; deterministic application rules—not an AI model—enforce publishing approval.
AI Assistant Connections: If you connect an AI assistant such as ChatGPT to Hogmatix, we store a record of that connection: the assistant's name and sign-in return address, your account, the permissions you approved, and one-way hashes of its access and refresh tokens. We receive the requests the assistant makes for you, including post text, captions, titles, descriptions, scheduling times and posting settings. When you attach a file in the assistant and ask Hogmatix to schedule it, we download that file from the assistant provider's file storage and store it with your other uploaded media under the retention rules in Section 8. We delete the temporary copy made during the transfer when the transfer ends, or when Hogmatix next starts if the transfer was interrupted.
Billing: Hogmatix subscriptions are sold by Forge Analytics & Systems Inc. and processed by Stripe. Our billing system checks your subscription status using your email address. We do not receive or store your full card number.
Usage Data: We collect standard server logs including IP addresses, browser type, pages visited, and timestamps for security and debugging purposes.
3. How We Use Your Information
- To authenticate you and maintain your account session
- To connect to social media platforms and publish content on your behalf
- To schedule and automate posts according to your preferences
- To detect and prevent duplicate content
- To generate and quality-check creative media you request
- To let an AI assistant you connect read your schedule and schedule or cancel posts at your request
- To check your subscription and apply your plan's posting allowance
- To attribute videos you publish through Hogmatix to the public TikTok video IDs TikTok returns for them
- To improve the reliability and performance of the Service
- To respond to your support requests
- To comply with legal obligations
4. TikTok API Data — Specific Disclosures
- We do not sell TikTok user data to any third party.
- We do not use TikTok data for advertising targeting on any platform.
- We do not share TikTok data with any third party except infrastructure providers strictly necessary to operate the Service, and an AI assistant you connect and authorize on hogmatix.com, which receives it when it uses Hogmatix's tools for you (for example, listing your connected accounts returns your TikTok account's name and identifier; see Section 7).
- TikTok data is used solely to provide account connection, creator-approved posting and scheduling, and public-video attribution within Hogmatix, including through AI assistants you connect.
- We do not claim to collect TikTok watch time, completion rate, retention, or follower-conversion data when TikTok has not supplied those fields.
- How to disconnect: You can revoke Hogmatix's access to your TikTok account at any time using the Disconnect TikTok button on the TikTok tab inside Hogmatix. This calls TikTok's token revocation endpoint, deletes your access and refresh tokens from our store, and cancels any pending scheduled uploads. You may also revoke access from TikTok directly at tiktok.com → Settings → Manage app permissions.
- How to delete all your data: Email [email protected] from the address associated with your account and we will permanently delete your Hogmatix account, OAuth tokens, scheduled-upload records, and post history within 30 days. We will reply to confirm completion.
- We retain post-history metadata (titles, publish timestamps, content hashes) for duplicate detection for up to 12 months after account deletion, then permanently delete it.
5. YouTube API Data — Specific Disclosures
Hogmatix uses YouTube API Services to upload videos to your channel on your behalf. By connecting your YouTube channel you agree to the YouTube Terms of Service. Information Hogmatix obtains from the YouTube and Google APIs is also handled in accordance with the Google Privacy Policy.
Limited Use. Hogmatix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We request only the scopes needed to provide the Service:
youtube.upload (to upload the videos you submit) and youtube.readonly (to display your channel name and avatar in Hogmatix, and your channel name in AI assistants you connect).
- We do not sell Google or YouTube user data to any third party.
- We do not use Google or YouTube data for advertising or to serve targeted ads.
- We do not transfer or share Google or YouTube data with third parties except infrastructure providers strictly necessary to operate the Service, an AI assistant you connect and authorize on hogmatix.com, which receives it when it uses Hogmatix's tools for you (for example, listing your connected accounts returns your channel name and ID; see Section 7), or where required by law.
- We do not use Google or YouTube data for any purpose other than uploading and scheduling the videos you submit through Hogmatix and showing you their status.
- We do not allow humans to read this data unless you give explicit consent for specific data, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized.
- How to disconnect: Use the Disconnect YouTube button on the YouTube tab inside Hogmatix. This revokes the token with Google, deletes your access and refresh tokens from our store, and cancels any pending scheduled uploads. You may also revoke access directly from your Google Account security settings at https://security.google.com/settings/security/permissions.
- How to delete all your data: Email [email protected] from the address associated with your account and we will permanently delete your Hogmatix account, OAuth tokens, scheduled-upload records, and upload history within 30 days.
6. Instagram API Data — Specific Disclosures
Instagram is a product of Meta Platforms, Inc. Hogmatix uses the Instagram API with Instagram Login to publish the photos and reels you submit to your Instagram professional (Business or Creator) account. Our use of data obtained through the Instagram API is governed by the Meta Platform Terms, and your use of Instagram by the Instagram Terms of Use. We request instagram_business_basic and instagram_business_content_publish for account display and publishing.
What we store. When you connect an Instagram account, we collect and store:
- Your Instagram professional account ID and the app-scoped ID Instagram issues to Hogmatix
- Your Instagram username, name, profile picture URL, and account type (Business or Creator)
- The access token that authorizes Hogmatix to publish for you, and when it expires
- The photos and videos you submit through Hogmatix for Instagram, with their captions, alt text, and whether a reel is also shared to your feed
- The media IDs and permalinks Instagram returns for the posts Hogmatix publishes
- Instagram data is used only to show which account a post will go to, publish the posts you compose and submit in Hogmatix (now or at the time you choose), show their status with a link to the published post, and keep your access token current.
- To publish, Instagram fetches your photo or video from Hogmatix's private storage through a link that expires within one hour. Hogmatix never makes your media public.
- We do not read your Instagram media, followers, comments, messages, or insights.
- We do not sell Instagram user data to any third party.
- We do not use Instagram data for advertising or ad targeting on any platform.
- We do not share Instagram data with any third party except infrastructure providers strictly necessary to operate the Service (see Section 7), or where required by law. Instagram is not part of Hogmatix's AI assistant tools, so we do not send your Instagram account details or posts to an AI assistant you connect.
- How to disconnect: Use the Disconnect button on the Instagram tab inside Hogmatix. This deletes the account's access token and account details from our store and cancels any pending scheduled posts for that account. Instagram does not give apps a way to revoke their own access, so also remove Hogmatix in Instagram under Settings → Website permissions → Apps and websites.
Data deletion. You can have Hogmatix delete your Instagram data in any of these ways:
- In Hogmatix: choose the account on the Instagram tab and click Disconnect. We delete its access token and account details at once and cancel its pending scheduled posts.
- In Instagram: remove Hogmatix under Settings → Website permissions → Apps and websites. Meta then sends Hogmatix a deauthorization or data deletion request, and we delete that account's access token and account details and cancel its pending scheduled posts. For a data deletion request, Meta gives you a confirmation code and a link where you can check that the deletion is done.
- By email: email [email protected] from the address associated with your Hogmatix account, and we will delete your Instagram data, including uploaded media and post records, or your whole Hogmatix account, within 30 days. We will reply to confirm completion.
Media you uploaded and records of submitted posts are otherwise removed on the schedule in Section 8.
7. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Social media platforms: Content you schedule is transmitted to the respective platform APIs (X/Twitter, TikTok, YouTube, Instagram, etc.) to fulfil your posting requests.
- Application hosting: Hogmatix application workers and its PocketBase database run on a company-operated Mac mini located in Canada.
- Cloudflare: Cloudflare terminates public HTTPS traffic and carries requests to our private origin through Cloudflare Tunnel. Cloudflare therefore processes request content and standard connection metadata such as IP addresses. Private Cloudflare R2 buckets temporarily store media you upload and durable copies needed for immediate or scheduled publishing. Neither bucket has a public development URL or public custom domain.
- AI service providers: We send the inputs needed for AI features to Google Gemini and xAI to generate images, videos, structured ideas, or quality-review results you request.
- AI assistants you connect: If you connect an AI assistant such as ChatGPT (provided by OpenAI) to Hogmatix, we send it the results of the requests it makes for you. Depending on the request, that can include your connected X, TikTok and YouTube account names and identifiers (listing your connected accounts can return all of them, even when you ask about one platform); your scheduled and recent posts with their text, media details, times and status; your TikTok account's current posting options; media upload status; and your plan and posting usage. The assistant's provider handles this information under its own privacy policy. The assistant receives nothing unless you connect it and approve access on hogmatix.com, and only while that connection is active.
- Billing: Stripe processes subscriptions and payments. We share your email address with our billing system, which we operate, to check whether your subscription is active.
- Email delivery: Verification, password-reset and service emails are sent through our mail servers and email delivery providers, which process your email address and the message.
- Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of our users.
8. Data Retention
- Account data is retained for the duration of your account plus 30 days after deletion.
- OAuth tokens for connected platforms are deleted from our live token store immediately when you disconnect an account, or within 30 days of account deletion. Copies in server snapshots and backups remain until those snapshots and backups are deleted.
- Post history and content logs are retained for up to 12 months after account deletion for deduplication purposes, then permanently deleted.
- AI video prompts, asset provenance, approval records, and public-video attribution are retained while your account is active and for up to 12 months after account deletion, unless you request earlier deletion where applicable.
- Managed source images and preview videos are normally deleted after posting, cancellation, or terminal failure; a 30-day cleanup backstop removes stale managed media. Content hashes and non-media provenance may remain for the metadata-retention period above.
- Incomplete multipart uploads and completed temporary-upload objects in our private R2 staging bucket are configured to expire after seven days. Cloudflare applies lifecycle deletion asynchronously, so removal may occur later than the exact seven-day mark.
- Private durable media is not subject to an age-based bucket lifecycle. Media that is uploaded or imported but never scheduled or posted becomes eligible for deletion one day after its upload finishes; an unscheduled import may be deleted sooner to make room for a newer one. Claimed media is retained while queued, uploading to a platform, or scheduled. After a platform accepts the post, the media becomes eligible for deletion after one day; after a failed or cancelled submission, after seven days. Media with an ambiguous platform outcome is retained until an operator resolves that outcome so an uncertain post is not automatically retried or its evidence destroyed.
- Final submission and idempotency records are retained for at least 90 days after completion and until associated media has been safely removed. These small records prevent a delayed browser retry from creating a duplicate platform post.
- AI assistant connections: access tokens expire after one hour; refresh tokens expire 60 days after they are issued and are replaced each time they are used. We store access and refresh tokens only as one-way hashes. Remove Hogmatix in the assistant's settings to disconnect it, or contact us and we will end every assistant's access to your account.
- Server logs are retained for up to 90 days.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for data processing
- Lodge a complaint with a data protection authority
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. Cookies and Tracking
Hogmatix uses session cookies strictly necessary for authentication. We do not use third-party analytics cookies or advertising tracking cookies.
11. Security
OAuth tokens for the accounts you connect are stored on our server in files that only the account running the Hogmatix service can read, and are never sent to your browser or to an AI assistant you connect. Access and refresh tokens we issue to AI assistants, and personal API tokens, are stored only as one-way hashes. Access to production systems is restricted to authorized personnel only. We use HTTPS at the public edge, an encrypted Cloudflare Tunnel to a loopback-only origin, and private storage for uploaded media. Despite these measures, no system is completely secure — if you discover a security issue, please report it to [email protected].
12. Children's Privacy
Hogmatix is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
13. International Data Transfers
If you access Hogmatix from outside Canada, your data is transferred to and processed in Canada. Cloudflare and the social-media and AI providers described above may also process data in the United States or other countries where they operate. Our R2 buckets use Cloudflare's Automatic/default placement rather than a guaranteed regional data-residency jurisdiction.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
15. Contact
Forge Analytics & Systems Inc.
Ontario, Canada
Email: [email protected]
Website: hogmatix.com