Privacy Policy
HypeDuck Privacy Policy
Last updated: September 11, 2026
1. Overview
HypeDuck helps creators, marketers, and e-commerce sellers discover and analyze public short-form content, including Instagram Reels, through the HypeDuck web dashboard and Chrome extension.
This Privacy Policy explains what information we collect, how we use it, and the choices available to users of HypeDuck.
2. Information we collect
Account information: We may collect information such as your name, email address, and account identifiers when you create or use a HypeDuck account.
Website content: When you intentionally use the Chrome extension to scan supported pages, HypeDuck may collect public content signals such as Reel URLs, captions, thumbnails, public engagement metadata, and related page information needed for analysis.
User activity: We may process actions taken inside HypeDuck, such as scan requests, selected Reels, analysis jobs, dashboard interactions, and extension workflow state.
Technical information: We may collect logs, device/browser information, and diagnostic data needed to secure, debug, and improve the service.
3. How we use information
We use information to provide HypeDuck’s core functionality: scanning supported Instagram Reels pages at the user’s request, sending selected content signals to the HypeDuck dashboard, and generating analysis results for content research and marketing workflows.
We also use information to authenticate users, maintain extension and dashboard state, improve product reliability, prevent abuse, and provide support.
4. Chrome extension permissions
The HypeDuck Chrome extension requests permissions only to support its stated purpose. These permissions may include storage, activeTab, tabs, cookies, scripting, offscreen, alarms, debugger, unlimitedStorage, and host permissions for supported websites and HypeDuck services.
The extension does not use these permissions to monitor unrelated browsing activity, sell user data, or profile users for unrelated advertising purposes.
5. Sharing and third-party services
We do not sell user data. We do not use or transfer user data for purposes unrelated to HypeDuck’s single purpose, and we do not use user data for creditworthiness, lending, or similar eligibility decisions.
We may use service providers for hosting, databases, analytics, storage, authentication, and AI-assisted analysis. These providers process information only as needed to operate HypeDuck.
6. Data retention and security
We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and maintain business records.
We use reasonable administrative, technical, and organizational safeguards to protect information, but no online service can guarantee absolute security.
7. User choices
You can stop using the Chrome extension, remove it from your browser, or contact us to request assistance with account or data-related questions.
Where required by applicable law, you may request access, correction, deletion, or export of certain personal information.
8. Connected Instagram and Threads accounts
If you choose to connect your own Instagram professional account or Threads account, HypeDuck uses secure OAuth login (Instagram API with Instagram Login, and the Threads API) and receives an access token for that account.
Where enabled by HypeDuck’s access policy and the permissions you grant, the connected Instagram account supports the features below. Availability may be restricted to designated review accounts; implementation does not mean that every permission has Meta approval for general users.
instagram_business_basic lets HypeDuck read your connected account profile (including account ID, username, name, profile picture, account type and public counts) and media information to identify the account and display your media. Profile information and recent post captions also help build a content persona that personalizes generated scripts and captions.
instagram_business_content_publish lets HypeDuck publish the media and caption you select and confirm to your connected Instagram account. instagram_business_manage_comments lets HypeDuck read comments on media owned by that account and request replies, hiding or deletion of comments that you confirm. The server checks the media and comment ownership; comment deletion does not mean deletion of Instagram posts. instagram_business_manage_insights lets HypeDuck retrieve and display account and owned-media statistics.
If you explicitly enable a keyword resource rule for a selected post or Reel, instagram_business_manage_comments also lets HypeDuck check new comments and send one private reply containing your configured text and resource link when the keyword matches. The server verifies the connected account, media ownership and comment age. Private replies are limited to one per comment within seven days; the rule does not initiate further messages. Rules are saved disabled until you enable them.
Keyword rules store the selected media ID, keyword, reply text, resource URL and enabled state. Delivery records store comment and media identifiers, status, error code and timestamps. We keep a short-lived hashed account-and-comment reservation to prevent duplicate private replies even after reconnecting; it does not contain the reply text. Disconnecting removes connection-linked rules and delivery records; the duplicate-prevention reservation expires separately.
instagram_business_manage_messages lets HypeDuck process conversation, participant and message identifiers, message text and timestamps to display DM conversations and send replies you explicitly write and confirm. Before a reply, the server checks the current connected account and permissions and verifies evidence of an incoming message from the recipient within the last 24 hours. A reply request does not guarantee delivery or a read receipt.
The DM reply operation ledger stores request identity, a request hash, state and provider result identifiers without saving the reply body as its operation payload. Browser tab recovery stores only a request key. These statements describe those specific stores, not every place where message text may be processed. Webhook reply-window records hold connected-account, peer and message identifiers, recent incoming-message time and expiry; retention cleanup removes expired records in bounded batches, without promising immediate erasure when the reply window closes.
For the connected Threads account, threads_basic lets HypeDuck display the account you connected. If you also grant threads_content_publish and threads_manage_replies, HypeDuck can publish a root post and the ordered tail replies you wrote and confirmed for that publication. This can run immediately when you confirm it or at the time you scheduled the already-approved content. Each tail is linked to the actual preceding post ID returned by Threads. HypeDuck does not use this permission to manage unrelated conversations or other users' content. See our Security & Data Behavior page for the full capability list.
If you grant threads_delete, you can remove your own Threads post that HypeDuck previously published through the official API. HypeDuck resolves the account and post ID from your HypeDuck publication record, does not accept an arbitrary Threads post ID, and requires a separate irreversible-action confirmation before requesting deletion. The HypeDuck record is then marked deleted so the action remains auditable.
Access tokens are encrypted at rest. We also store connection identifiers, profile details, granted permissions, token expiry and operation records. Connected-account data is never sold or shared for purposes unrelated to HypeDuck.
Disconnecting in Settings removes the stored connection and tokens; it does not automatically erase all authored content, personas or analysis results. A verified Meta deletion request returns a receipt and processing status for the scoped connection-data request; older or copied data may require further review. An email can request broader account-data deletion, but submitting the request is not confirmation that deletion has completed.
See our Data Deletion page for request options and status details.
9. Contact
If you have questions about this Privacy Policy or HypeDuck’s privacy practices, contact us at support@hypeduck.ai.