User Data Deletion
You can request deletion of your Hookology account and any personal data we hold about you at any time. This page explains how the process works and what to expect.
How to request deletion
Send an email to privacy@hookology.ai from the email address associated with your Hookology account. Include:
- The email address of the account to delete
- The workspace name (if you belong to more than one)
- Whether you want to delete just your user account, or the entire workspace and all its data
If you are a workspace owner, deleting the workspace also deletes all of its connected ad-platform data, creatives, performance metrics, AI-generated insights, and any uploaded files.
What gets deleted
- Your profile (name, email, avatar, password hash)
- Your workspace memberships and roles
- Workspace data you own, including: connected ad accounts and their cached metrics, creatives and tagged metadata, AI insights and recommendations, client profiles, briefs, brand resources, growth plans, and feedback you have submitted
- OAuth tokens for any connected platforms (Meta, Google, TikTok, Shopify, etc.) - these tokens are also revoked at the source where the provider's API allows
- Files you have uploaded to private storage buckets (creatives, brand resources, client documents, screenshots)
What may be retained
We may retain a limited amount of information after deletion where required by law or for legitimate business purposes, including:
- Invoices and tax records (typically up to 7 years), as required by tax authorities
- Security and audit logs needed to detect fraud and abuse
- Aggregated, de-identified statistics that cannot be linked back to you (for example, anonymous platform benchmarks)
What gets deleted, source by source
A verified full deletion removes all of the following from our production systems:
- Identity and profile: name, email, avatar, password hash, sessions and multi-factor enrolment
- Workspace and client records: brands, goals, margins, targets, budgets and settings you configured
- Connections: OAuth access and refresh tokens, API credentials and connection metadata, revoked at the provider first
- Synced platform data: campaign, ad set, ad, keyword, search term and performance records pulled from Google, Meta, Microsoft, LinkedIn, TikTok, GA4, Search Console and Merchant Centre
- Creative assets: uploaded and synced images and video, plus derived tagging, colour analysis and scoring
- First-party tracking: events, sessions and pseudonymous visitor identifiers collected by our script
- AI artefacts: stored recommendations, briefs, chat history with Hook AI, and the AI memory learned for your workspace
- Reports and exports: generated PDFs, CSVs and scheduled report definitions
Choose the scope of your request
- My account only - removes you as a user. The workspace and its data continue to exist for your colleagues. Use this when you are leaving a team.
- A single client or brand - removes one brand and everything synced against it, leaving the rest of the workspace untouched.
- A single connection - removes one platform connection and the data synced through it.
- The entire workspace - removes every client, connection, asset and user record. Only a workspace owner can request this, and it cannot be undone.
Deletion for people who are not our users
If you are a visitor to a customer's website and believe Hookology holds tracking data about you, the website operator is the data controller and you should contact them first. If you contact us directly we will identify the relevant customer, pass the request on, and support them in actioning it within the statutory timeframe.
Deletion requests from Meta and other platforms
Where a platform (for example Meta) sends us an automated data deletion callback for a user who signed in through them, we treat it as a verified request, revoke the associated tokens and delete the linked records on the same schedule set out below.
Timeframe
We action verified deletion requests within 30 days. Backups are rotated on a rolling basis and any residual copies of your data are removed within 90 days of the original deletion.
Verifying your request
To protect your account, we only action deletion requests sent from the email address on file, or from inside the account itself. If we cannot verify ownership we may ask for additional information before proceeding.
Third-party platforms
Deleting your Hookology data does not delete the original data inside the third-party platforms you connected (Meta, Google, TikTok, Shopify, etc.). To delete data from those services, follow their own data-deletion processes. Hookology will revoke the access tokens we hold so we can no longer read from those accounts.
Self-service alternative
If you would prefer not to delete everything, you can also:
- Disconnect individual ad or commerce platforms from the Data page in-app
- Leave a workspace without deleting your account
- Export your data on request before deletion
Legal basis and your rights
This process implements your right to erasure under Article 17 of the UK GDPR, alongside your rights of access, rectification, restriction, portability and objection. Requests are free of charge unless they are manifestly unfounded or excessive. We will confirm in writing once deletion is complete. If you are not satisfied with how we handle your request you can complain to the Information Commissioner's Office at ico.org.uk.
Full detail on what we hold and why is in the Data Policy and the Privacy Policy.
Contact
Data deletion and privacy enquiries: privacy@hookology.ai.
We will confirm receipt and action verified requests within 30 days.
Email a deletion requestRelated policies