Privacy Policy
Version of 10 October 2026
Draft. This document has not been reviewed by a lawyer yet and may change before launch. Values in square brackets will be filled in later.
In short: we work only through the official Threads API and only with your permission, we never post anything on your behalf, we keep finds for a limited time, we do not sell anyone's data and we do not use it to train AI.
This is a translation. The Ukrainian version prevails where legally relevant.
1. Who is responsible for your data
The data controller under the GDPR is Andrii Piddubnyak IT Services, a sole trader (JDG), woj. MAZOWIECKIE, pow. Warszawa, gm. Warszawa, miejsc. Warszawa, ul. Ludwika Rydygiera, nr 15, lok. 70, 01-793, NIP: 5243034450. For any question about your data, write to hello@hukny.app or on Telegram to @hukny_support.
2. What data we process
Your account
- your e-mail address; if you sign in with Google, also the name and e-mail address from your Google profile;
- settings: time zone, display name, plan and subscription status.
Threads data (through the official Threads API)
- the ID and username of your Threads account and the access token (stored encrypted), which we receive when you grant the "basic profile information" and "keyword search" permissions;
- public posts found for your searches (finds): the text, link, author's username and time of publication, plus the result of the AI check (type of post, city).
We have no access to your password, direct messages or followers, and no right to post on your behalf.
Your searches and texts
- phrases, stop words, cities, the description of yourself and your offers used for drafts, and your "Relevant / Not relevant" ratings.
Telegram
- your Telegram chat ID and username, so that we can send you alerts.
Payment
- payment details (card, billing address) are processed by Paddle. We receive only the subscription status, plan, country and payment amounts. We never see your card number.
Technical data
- IP address, browser type and request logs for security and abuse prevention; essential cookies for signing in to your account; your theme choice stored in the browser. We do not use advertising trackers.
3. Why we process data and on what legal basis
- Providing the service (searching for posts, AI checks, alerts, drafts, payment): performance of a contract, Art. 6(1)(b) GDPR.
- Security, abuse prevention and spam protection: legitimate interest, Art. 6(1)(f) GDPR.
- Accounting and tax: legal obligation, Art. 6(1)(c) GDPR.
- Service e-mails (sign-in, changes to terms, important notices): performance of a contract. Marketing e-mails are sent only with your separate consent, which you can withdraw at any time.
4. Data of authors of public posts
The service shows users public posts from Threads search so that they can reply to a person who is looking for a service. The legal basis is the legitimate interest of users and of the authors themselves in getting a reply (Art. 6(1)(f) GDPR). We:
- process only posts that Threads shows in public search;
- do not build profiles of people, do not collect contact details and do not sell any data;
- automatically delete finds after the retention period (see section 6);
- at an author's request, stop showing their posts and delete the ones already stored. This can be done on the For post authors page.
For the "What Hukny found" block on the home page, we store only the number of posts found and short excerpts that the AI retells in its own words, without names, contact details or any details that could identify a person. Original texts, usernames and links are not stored for this block, and the excerpts are deleted after 14 days.
5. Who we share data with
Only with providers the service cannot work without, and only to the extent necessary:
- OpenAI (AI provider, data processor under a data processing agreement): the texts of finds and your description for drafts, to filter out noise and write drafts. Under OpenAI's terms, data sent through the API is not used to train models. In the event of an outage, we may temporarily use a backup provider, [Google Gemini API], on the same terms.
- Supabase (database and account sign-in, servers in the EU [region to be confirmed]) and [hosting provider] for the server side.
- Meta Platforms: requests to the Threads API on behalf of your account.
- Telegram: delivering alerts to your chat.
- Paddle: the seller (Merchant of Record), which takes payments, issues invoices and handles refunds as an independent controller of payment data.
We do not sell or rent out personal data and do not share it with advertising networks.
Where data is transferred outside the European Economic Area (for example, to OpenAI in the US), we rely on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
6. How long we keep data
- Finds: depending on your plan, 7 days (Free), 30 days (Solo) or up to 90 days (Pro), after which they are deleted automatically. Posts marked "Not relevant" or hidden are deleted after 24 hours.
- Account, searches and settings: for as long as you use the service. Searches on the Free plan are paused after a long period of inactivity.
- Technical logs: up to 30 days.
- Payment records: for as long as Polish tax law requires (usually 5 years).
7. Deleting your data
- You can delete your account and all related data in your dashboard: "Settings" - "Account" - "Delete account". You will then receive a code to check the status of the deletion.
- Disconnecting Threads in your dashboard stops searching; you can also delete all finds straight away. If you remove access in your Threads or Meta settings, Meta notifies us and we delete the related data.
- Step-by-step instructions: Data deletion.
8. Your rights
Under the GDPR, you have the right to:
- access your data and get a copy of it;
- correct inaccurate data;
- have your data erased (the "right to be forgotten");
- restrict processing;
- receive your data in a convenient machine-readable format (portability);
- object to processing based on legitimate interest;
- withdraw your consent where processing is based on consent;
- lodge a complaint with a supervisory authority: in Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), or the authority in the country where you live.
To exercise a right, write to us at hello@hukny.app. We will reply within 30 days.
9. Security
Data is transmitted only over encrypted connections (TLS), Threads access tokens are stored encrypted, and only the service and the administrator have access to the database. We regularly delete data we no longer need.
10. Automated processing
AI automatically determines whether the author of a post is looking for a service and which city they are in. This only affects which posts you see and has no legal effect on anyone. Uncertain posts do not disappear: they go to the "Maybe" tab.
11. Children
The service is not intended for people under 18, and we do not knowingly collect their data.
12. Changes
We will tell you about material changes to this policy in your dashboard or by e-mail before they take effect.
This policy is published in Ukrainian and English. In case of any discrepancy, the Ukrainian version prevails, unless mandatory law requires otherwise.