
How HATS:OFF handles the information you and your team put into the Service.
Last updated August 14, 2026
HATS:OFF ("we", "us") provides an AI marketing service for home-service businesses: you set up an organization, add your team, and we help you draft, generate, schedule, and publish social media content. This policy explains what information we collect, why, who we share it with, and how to get it deleted.
It covers our website and application. It does not cover the social platforms you connect to us — Facebook, Instagram, LinkedIn, Slack, Google, and Dropbox each have their own privacy policies that govern what they do with your data on their side.
We collect what you give us and what your use of the Service generates.
We do not ask for or intentionally collect government identifiers, financial account numbers, health information, or precise location.
The Service generates marketing images that feature the people on your team. To do that it uses the photos you upload as reference images for AI image generation — for example, placing a team member's face into a branded flyer template.
We do not sell or rent your personal information, and we do not use your content to train our own AI models.
Generating a caption or an image means sending material to a third-party AI provider. Depending on what you are creating, that can include your prompt, your brand voice and guidelines, the text of your post, and the images you uploaded — including team member photos. The providers we use are OpenAI, Anthropic, Google, and Replicate.
We use these providers' standard business APIs. What each provider does with the data it receives is governed by that provider's own terms and privacy policy, not this one. If you do not want a particular piece of information processed by an AI provider, do not put it into a prompt, a brand guideline, or an uploaded image.
Content produced by these systems is drafted automatically and is published only after someone in your organization approves it. Review it before it goes out — see our Terms of Service for what that responsibility means.
When you connect a third-party account we store the access token that lets us act on your behalf, plus the identifiers and names needed to show you which account is connected. We request the narrowest permissions that let the feature work.
You can disconnect any of these at any time from the Integrations page in the app, which deletes the stored token. You can also revoke our access from the platform's own settings. Disconnecting stops future access; it does not by itself delete content already imported — see section 12.
If you connect a Google account we request only the scopes the feature needs: read-only access to the Drive files and folders you select, permission to send email on your behalf, and permission to upload videos and read their analytics on the channel you choose. Signing in with Google gives us your basic profile and email address only.
HATS:OFF's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google at any time from the Integrations page or from your Google account permissions, which revokes our tokens immediately.
Data is stored in the United States. Access is restricted, traffic is encrypted in transit over TLS, and records are scoped so that one organization cannot read another's. No system is perfectly secure, and we cannot guarantee absolute security.
Uploaded photos and generated images are stored in a public storage bucket and served from long, randomly generated URLs. Those URLs are not guessable, but they are not password-protected either: anyone you share one with — or anyone who obtains it — can view the file without signing in. Keep this in mind before sharing links to media that contains team member photos.
A small number of our administrators can sign into your organization to investigate a problem you have reported or to address a security or abuse issue. Every such session is recorded in an audit log.
We keep your information for as long as your account is active. When you delete something in the app it is removed from the live Service. When an account is deleted we remove its data from production systems within 30 days, and encrypted backups age out within 90 days. We may retain limited records longer where the law requires it, or in an aggregated form that no longer identifies anyone.
You can delete most information yourself, at any time, from inside the app:
To delete your account and everything in your organization, email jaxon@therecruitingschool.io from the email address on the account, with "Delete my account" in the subject line. We will confirm it is you, delete the account and its data from production systems within 30 days, and let you know when it is done. This is permanent and cannot be undone.
You can revoke our access at any time from the settings of your Facebook or Instagram account, which immediately stops us from reading or publishing anything further. To also delete the data we already retrieved, use the email process above and say which platform it concerns.
Depending on where you live you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Email jaxon@therecruitingschool.io and we will respond within the time the applicable law allows. We will not treat you differently for exercising these rights.
We do not sell personal information and we do not share it for cross-context behavioral advertising. California residents may request to know the categories and specific pieces of personal information we have collected, request deletion or correction, and appoint an authorized agent to make a request on their behalf. The categories we collect are described in section 2, the purposes in section 4, and the recipients in section 8.
Where GDPR applies, we process personal information to perform our contract with you (operating the Service), on the basis of our legitimate interests (securing and improving the Service), and with your consent where consent is required. You may lodge a complaint with your local supervisory authority.
For information you upload about other people — your team members and the people in your photos — your organization is the controller and we act as a processor on your instructions. If one of those people contacts us directly, we will refer them to you unless we are required to respond ourselves.
The Service is for businesses and is not directed to children. You must be at least 18 to use it. Do not upload photos of children. If we learn we have collected information from a child, we will delete it.
We may update this policy as the Service changes. When we do we will revise the "last updated" date above, and for material changes we will notify account owners by email or in the app before the change takes effect. Continuing to use the Service after that means you accept the updated policy.
Questions about this policy, or a request about your data: jaxon@therecruitingschool.io.