PRIVACY POLICY
Effective Date: August 10, 2026 | Forge Analytics & Systems Inc.
This Privacy Policy describes how Forge Analytics & Systems Inc. ("we", "us", or "our") collects, uses, and shares information when you use Hogmatix ("the Service"), available at hogmatix.com. By using the Service, you agree to the practices described in this policy.
1. Who We Are
Hogmatix is operated by Forge Analytics & Systems Inc., incorporated in Ontario, Canada. For privacy inquiries, contact us at [email protected].
2. Information We Collect
Account Information: When you sign up, we collect your email address and a hashed password to authenticate your account.
Connected Platform Accounts: When you connect a social media account (such as X/Twitter, TikTok, or YouTube), we receive and store OAuth access tokens that authorize Hogmatix to post on your behalf. We do not store your social media passwords.
TikTok Data: When you connect your TikTok account via the TikTok API, we collect and store:
- Your TikTok Open ID (a platform-specific identifier)
- Your TikTok display name and username
- OAuth access tokens and refresh tokens required to publish content
- Content you submit through Hogmatix for publishing to TikTok (text, images, videos)
- Post status and publish results returned by the TikTok API
- Public TikTok video IDs returned for the videos you publish through Hogmatix
YouTube / Google Data: When you connect your YouTube channel via Google OAuth and the YouTube Data API, we collect and store:
- Your YouTube channel ID, channel title, and channel thumbnail
- OAuth access tokens and refresh tokens required to upload videos on your behalf
- Videos and their metadata (title, description, visibility, and "made for kids" status) that you submit through Hogmatix for upload to YouTube
- Upload status and the resulting video ID returned by the YouTube Data API
Content You Create: We store posts, schedules, and content you create within the Service, including drafts, media you upload for publishing, and published post history. If you generate AI videos for TikTok, we also store their prompts, asset provenance, approval records, and public-video attribution.
AI Processing: When you use AI generation features, the prompts, source images, and generated media needed for the requested operation may be sent to Google Gemini and xAI. We use their responses to generate creative assets; deterministic application rules—not an AI model—enforce publishing approval.
Usage Data: We collect standard server logs including IP addresses, browser type, pages visited, and timestamps for security and debugging purposes.
3. How We Use Your Information
- To authenticate you and maintain your account session
- To connect to social media platforms and publish content on your behalf
- To schedule and automate posts according to your preferences
- To detect and prevent duplicate content
- To generate and quality-check creative media you request
- To attribute videos you publish through Hogmatix to the public TikTok video IDs TikTok returns for them
- To improve the reliability and performance of the Service
- To respond to your support requests
- To comply with legal obligations
4. TikTok API Data — Specific Disclosures
- We do not sell TikTok user data to any third party.
- We do not use TikTok data for advertising targeting on any platform.
- We do not share TikTok data with any third party except infrastructure providers strictly necessary to operate the Service (see Section 6).
- TikTok data is used solely to provide account connection, creator-approved posting and scheduling, and public-video attribution within Hogmatix.
- We do not claim to collect TikTok watch time, completion rate, retention, or follower-conversion data when TikTok has not supplied those fields.
- How to disconnect: You can revoke Hogmatix's access to your TikTok account at any time using the Disconnect TikTok button on the TikTok tab inside Hogmatix. This calls TikTok's token revocation endpoint, deletes your access and refresh tokens from our store, and cancels any pending scheduled uploads. You may also revoke access from TikTok directly at tiktok.com → Settings → Manage app permissions.
- How to delete all your data: Email [email protected] from the address associated with your account and we will permanently delete your Hogmatix account, OAuth tokens, scheduled-upload records, and post history within 30 days. We will reply to confirm completion.
- We retain post-history metadata (titles, publish timestamps, content hashes) for duplicate detection for up to 12 months after account deletion, then permanently delete it.
5. YouTube API Data — Specific Disclosures
Hogmatix uses YouTube API Services to upload videos to your channel on your behalf. By connecting your YouTube channel you agree to the YouTube Terms of Service. Information Hogmatix obtains from the YouTube and Google APIs is also handled in accordance with the Google Privacy Policy.
Limited Use. Hogmatix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We request only the scopes needed to provide the Service:
youtube.upload (to upload the videos you submit) and youtube.readonly (to display your channel name and avatar in our UI).
- We do not sell Google or YouTube user data to any third party.
- We do not use Google or YouTube data for advertising or to serve targeted ads.
- We do not transfer or share Google or YouTube data with third parties except infrastructure providers strictly necessary to operate the Service (see Section 6), or where required by law.
- We do not use Google or YouTube data for any purpose other than uploading and scheduling the videos you submit through Hogmatix.
- We do not allow humans to read this data unless you give explicit consent for specific data, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized.
- How to disconnect: Use the Disconnect YouTube button on the YouTube tab inside Hogmatix. This revokes the token with Google, deletes your access and refresh tokens from our store, and cancels any pending scheduled uploads. You may also revoke access directly at myaccount.google.com → Third-party apps & services.
- How to delete all your data: Email [email protected] from the address associated with your account and we will permanently delete your Hogmatix account, OAuth tokens, scheduled-upload records, and upload history within 30 days.
6. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Social media platforms: Content you schedule is transmitted to the respective platform APIs (X/Twitter, TikTok, YouTube, etc.) to fulfil your posting requests.
- Application hosting: Hogmatix application workers and its PocketBase database run on a company-operated Mac mini located in Canada.
- Cloudflare: Cloudflare terminates public HTTPS traffic and carries requests to our private origin through Cloudflare Tunnel. Cloudflare therefore processes request content and standard connection metadata such as IP addresses. Private Cloudflare R2 buckets temporarily store media you upload and durable copies needed for immediate or scheduled publishing. Neither bucket has a public development URL or public custom domain.
- AI service providers: We send the inputs needed for AI features to Google Gemini and xAI to generate images, videos, structured ideas, or quality-review results you request.
- Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of our users.
7. Data Retention
- Account data is retained for the duration of your account plus 30 days after deletion.
- OAuth tokens for connected platforms are deleted immediately upon disconnecting an account or within 30 days of account deletion.
- Post history and content logs are retained for up to 12 months after account deletion for deduplication purposes, then permanently deleted.
- AI video prompts, asset provenance, approval records, and public-video attribution are retained while your account is active and for up to 12 months after account deletion, unless you request earlier deletion where applicable.
- Managed source images and preview videos are normally deleted after posting, cancellation, or terminal failure; a 30-day cleanup backstop removes stale managed media. Content hashes and non-media provenance may remain for the metadata-retention period above.
- Incomplete multipart uploads and completed temporary-upload objects in our private R2 staging bucket are configured to expire after seven days. Cloudflare applies lifecycle deletion asynchronously, so removal may occur later than the exact seven-day mark.
- Private durable media is not subject to an age-based bucket lifecycle. Unclaimed immediate-upload media becomes eligible for deletion after seven days. Claimed media is retained while queued, uploading to a platform, or scheduled; scheduled media may remain through the scheduled time and for up to 30 days afterward. Media with an ambiguous platform outcome is retained until an operator resolves that outcome so an uncertain post is not automatically retried or its evidence destroyed.
- Final submission and idempotency records are retained for at least 90 days after completion and until associated media has been safely removed. These small records prevent a delayed browser retry from creating a duplicate platform post.
- Server logs are retained for up to 90 days.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for data processing
- Lodge a complaint with a data protection authority
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Cookies and Tracking
Hogmatix uses session cookies strictly necessary for authentication. We do not use third-party analytics cookies or advertising tracking cookies.
10. Security
We store OAuth tokens encrypted at rest. Access to production systems is restricted to authorized personnel only. We use HTTPS at the public edge, an encrypted Cloudflare Tunnel to a loopback-only origin, and private storage for uploaded media. Despite these measures, no system is completely secure — if you discover a security issue, please report it to [email protected].
11. Children's Privacy
Hogmatix is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
12. International Data Transfers
If you access Hogmatix from outside Canada, your data is transferred to and processed in Canada. Cloudflare and the social-media and AI providers described above may also process data in the United States or other countries where they operate. Our R2 buckets use Cloudflare's Automatic/default placement rather than a guaranteed regional data-residency jurisdiction.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
14. Contact
Forge Analytics & Systems Inc.
Ontario, Canada
Email: [email protected]
Website: hogmatix.com