HATS:OFF

Privacy Policy

How HATS:OFF handles the information you and your team put into the Service.

Last updated August 14, 2026

1. Overview

HATS:OFF ("we", "us") provides an AI marketing service for home-service businesses: you set up an organization, add your team, and we help you draft, generate, schedule, and publish social media content. This policy explains what information we collect, why, who we share it with, and how to get it deleted.

It covers our website and application. It does not cover the social platforms you connect to us — Facebook, Instagram, LinkedIn, Slack, Google, and Dropbox each have their own privacy policies that govern what they do with your data on their side.

2. Information we collect

We collect what you give us and what your use of the Service generates.

  • Account information. Your email address, and any name or phone number you add. If you sign in with Google, we receive your email address and basic profile information from Google — not your Google password.
  • Organization information. Your business name, time zone, brand voice and brand guidelines, industry settings, and the manager name and phone number you provide.
  • Team member records. For each team member you add, the name, email, region, team, division, and manager you enter about them.
  • Photographs. Photos uploaded by you or by team members through the upload links you send them, including photos of people's faces. See section 3.
  • Content you create. Posts, captions, templates, schedules, approvals, comments, leaderboard entries you import from a spreadsheet, and the images generated for you.
  • Connected account data. Access and refresh tokens, account identifiers, page and profile names, and the performance metrics we retrieve for posts published through the Service.
  • Usage and technical data. Product analytics events, AI usage and cost records, background job results, and standard server logs including IP address, browser type, and pages viewed.

We do not ask for or intentionally collect government identifiers, financial account numbers, health information, or precise location.

3. Photos and likeness

The Service generates marketing images that feature the people on your team. To do that it uses the photos you upload as reference images for AI image generation — for example, placing a team member's face into a branded flyer template.

  • Photos can be uploaded by an admin, or by a team member through a private, expiring upload link that you send them.
  • We use photos only as reference material to generate images for your organization. We do not run facial recognition, we do not use photos to identify anyone, and we do not build or share a face database.
  • You are responsible for having each person's permission before uploading their photo. Our Terms of Service require it, and some states regulate biometric and likeness data specifically.
  • Photos can be removed at any time from the team member's record in the app. If someone wants their photo and the images generated from it removed and you cannot do it yourself, email us and we will handle it.

4. How we use information

  • To operate the Service — create your organization, generate content, run your posting schedule, and publish to the accounts you connect.
  • To send service communications: approval requests, invitations, password resets, and notices about your account.
  • To provide support and troubleshoot problems you report.
  • To keep the Service secure — detect abuse, prevent fraud, and enforce our Terms.
  • To understand how the product is used in aggregate so we can improve it.
  • To comply with law and respond to lawful requests.

We do not sell or rent your personal information, and we do not use your content to train our own AI models.

5. AI processing

Generating a caption or an image means sending material to a third-party AI provider. Depending on what you are creating, that can include your prompt, your brand voice and guidelines, the text of your post, and the images you uploaded — including team member photos. The providers we use are OpenAI, Anthropic, Google, and Replicate.

We use these providers' standard business APIs. What each provider does with the data it receives is governed by that provider's own terms and privacy policy, not this one. If you do not want a particular piece of information processed by an AI provider, do not put it into a prompt, a brand guideline, or an uploaded image.

Content produced by these systems is drafted automatically and is published only after someone in your organization approves it. Review it before it goes out — see our Terms of Service for what that responsibility means.

6. Connected accounts

When you connect a third-party account we store the access token that lets us act on your behalf, plus the identifiers and names needed to show you which account is connected. We request the narrowest permissions that let the feature work.

Facebook
Publish posts to the Pages you select and read back their performance metrics.
Instagram
Publish posts to your Instagram professional account, read back metrics, and read comments on posts published through the Service.
LinkedIn
Publish posts to the organization page you select.
Slack
Send approval requests and notifications to the channel you choose, and receive your approve or reject responses.
Google Drive
Read the files and folders you choose so they can be imported as brand assets and templates.
Gmail
Send invitations and notifications from your address, if you enable it.
Dropbox
Read the files you choose so they can be imported as media.

You can disconnect any of these at any time from the Integrations page in the app, which deletes the stored token. You can also revoke our access from the platform's own settings. Disconnecting stops future access; it does not by itself delete content already imported — see section 12.

7. Google user data and Limited Use

If you connect a Google account we request only the scopes the feature needs: read-only access to the Drive files and folders you select, permission to send email on your behalf, and permission to upload videos and read their analytics on the channel you choose. Signing in with Google gives us your basic profile and email address only.

HATS:OFF's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Google user data only to provide the features you connected it for.
  • We do not transfer it except as needed to provide those features, to comply with law, or as part of a merger with notice to you.
  • We do not use it for advertising.
  • We do not use it to train generalized AI models.
  • No human reads it except with your explicit permission, for security purposes, to comply with law, or on aggregated and de-identified data.

You can disconnect Google at any time from the Integrations page or from your Google account permissions, which revokes our tokens immediately.

8. Who we share information with

We share information with service providers who process it on our behalf, and with the platforms you explicitly ask us to publish to. We do not sell it, and we do not share it for cross-context behavioral advertising.

Supabase
Authentication, database, and file storage.
Railway
Application hosting.
PostHog
Product analytics.
AI providers
OpenAI, Anthropic, Google, and Replicate — text and image generation.
Apify
Retrieving publicly available social content used for template inspiration.
Social platforms
Facebook, Instagram, LinkedIn, Slack, Google, and Dropbox receive the content and requests you direct to them.

We may also disclose information if required by law, to protect our rights or someone's safety, or in connection with a merger, acquisition, or sale of assets — in which case this policy continues to apply to the transferred information until it is replaced, and we will give you notice.

9. Storage and security

Data is stored in the United States. Access is restricted, traffic is encrypted in transit over TLS, and records are scoped so that one organization cannot read another's. No system is perfectly secure, and we cannot guarantee absolute security.

Media files are served from public links

Uploaded photos and generated images are stored in a public storage bucket and served from long, randomly generated URLs. Those URLs are not guessable, but they are not password-protected either: anyone you share one with — or anyone who obtains it — can view the file without signing in. Keep this in mind before sharing links to media that contains team member photos.

Support access to your account

A small number of our administrators can sign into your organization to investigate a problem you have reported or to address a security or abuse issue. Every such session is recorded in an audit log.

10. Cookies and analytics

We use essential cookies to keep you signed in — without them the Service cannot work. We also use PostHog for product analytics, which sets its own identifiers to measure how features are used. We do not use advertising cookies or third-party ad trackers.

Most browsers let you block or delete cookies. Blocking essential cookies will sign you out and prevent the Service from functioning.

11. How long we keep information

We keep your information for as long as your account is active. When you delete something in the app it is removed from the live Service. When an account is deleted we remove its data from production systems within 30 days, and encrypted backups age out within 90 days. We may retain limited records longer where the law requires it, or in an aggregated form that no longer identifies anyone.

12. Deleting your data

You can delete most information yourself, at any time, from inside the app:

  • Photos and team member records — delete them from the team member's page.
  • Posts, drafts, templates, and generated images — delete them from the page where they appear.
  • Connected accounts — disconnect them from the Integrations page, which deletes the stored access token.

Deleting your whole account

To delete your account and everything in your organization, email jaxon@therecruitingschool.io from the email address on the account, with "Delete my account" in the subject line. We will confirm it is you, delete the account and its data from production systems within 30 days, and let you know when it is done. This is permanent and cannot be undone.

Facebook and Instagram users

You can revoke our access at any time from the settings of your Facebook or Instagram account, which immediately stops us from reading or publishing anything further. To also delete the data we already retrieved, use the email process above and say which platform it concerns.

13. Your rights

Depending on where you live you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Email jaxon@therecruitingschool.io and we will respond within the time the applicable law allows. We will not treat you differently for exercising these rights.

California (CCPA/CPRA)

We do not sell personal information and we do not share it for cross-context behavioral advertising. California residents may request to know the categories and specific pieces of personal information we have collected, request deletion or correction, and appoint an authorized agent to make a request on their behalf. The categories we collect are described in section 2, the purposes in section 4, and the recipients in section 8.

EEA and UK (GDPR)

Where GDPR applies, we process personal information to perform our contract with you (operating the Service), on the basis of our legitimate interests (securing and improving the Service), and with your consent where consent is required. You may lodge a complaint with your local supervisory authority.

For information you upload about other people — your team members and the people in your photos — your organization is the controller and we act as a processor on your instructions. If one of those people contacts us directly, we will refer them to you unless we are required to respond ourselves.

14. Children

The Service is for businesses and is not directed to children. You must be at least 18 to use it. Do not upload photos of children. If we learn we have collected information from a child, we will delete it.

15. Changes to this policy

We may update this policy as the Service changes. When we do we will revise the "last updated" date above, and for material changes we will notify account owners by email or in the app before the change takes effect. Continuing to use the Service after that means you accept the updated policy.

16. Contact us

Questions about this policy, or a request about your data: jaxon@therecruitingschool.io.