Privacy Policy, HAI Social Agency
Version: 2.3 · Effective date: 19 August 2026 · Last updated: 14 August 2026 Languages: English (below) · Suomeksi (from "Tietosuojakäytäntö")
Who we are
HAI Social Agency Oy
Business ID (Y-tunnus): 3631226-8
Malminkaari 23, 00700 Helsinki, Finland
matti@haisocialagency.com
We are an AI coaching service that helps professionals write and publish LinkedIn posts. You talk to HAI on WhatsApp. HAI helps you shape your thoughts into posts and, when you approve them, publishes them to your LinkedIn.
This policy tells you what we collect, where it lives, who can reach it, and what you can ask of us. We have tried to write it so that every sentence is something we could prove on request.
What we collect
To provide the service
| What | Why |
|---|---|
| Your WhatsApp phone number | It is how we recognise you. It is also your account identifier. |
| Your messages: text, voice notes, images | The raw material for your posts. |
| Your drafts and published posts | So you can come back to them, and so HAI learns your style. |
| Notes on your writing style | AI-generated observations about how you write, so drafts sound like you. |
| Authorisation to post on LinkedIn | Granted by you through LinkedIn's own permission screen. |
| A record of your consents | When you accepted these terms, which policy version was in force, and whether you turned proactive messages on or off. Kept as a history that only accepts new entries, not just a current setting. |
You give us during signup
Your name, company, job title, industry, LinkedIn profile URL, preferred language, and optionally a description of your brand voice.
At signup we also run a short background search on your name and company using public web sources, so that HAI's first message can name something true about you. It uses no data beyond what you have already given us, and it does not open your LinkedIn profile page.
If you join the waitlist
If you sign up on our website before becoming a user, we store your email address, where the signup came from, and the fact that you consented to marketing email. That is all. You can unsubscribe from any email we send, or write to us, and we will remove you.
Generated automatically
Timestamps, message counts, and operational records (how long a request took, whether it succeeded, what it cost us to run). These contain no message content.
Other people in your content
A photo or a voice note you send can include other people, like a colleague in a picture or a client you mention. We use that content only to draft your post. We never build profiles of those people, and the same retention and deletion rules apply to it as to everything else you send. Use your own judgment about what you share, as you would in any conversation.
We do not collect passwords, payment card details, or your LinkedIn password. We will never ask for your LinkedIn password, and you should never give it to anyone.
Why we use it
- To draft your posts.
- To sound like you, by learning your vocabulary and rhythm over time.
- To keep context, so you can say "make that shorter" without explaining again.
- To publish the posts you have approved.
- To keep the service working: spotting failures and watching costs.
We do not sell your data, run advertising, share your style notes with anyone, or use your content to train AI models for other customers.
Legal basis
- Contract: the processing needed to deliver the service you asked for.
- Consent: for the personal style profile that makes HAI feel like yours, for proactive messages, and for marketing email if you joined the waitlist. Each consent is recorded with its own timestamp and the policy version that was in force, and you can withdraw any of them at any time.
- Legitimate interest: keeping the service reliable and secure, in a form that does not identify you.
How we protect it
Encryption. Everything you send travels encrypted (HTTPS), and our hosting provider encrypts the database at rest. Your LinkedIn authorisation sits in a separate secrets vault whose key is managed outside the database. A copy of the database alone would not contain a usable credential.
No public access to the database. The public API roles have no rights to any table. We checked this table by table, and we also changed the database defaults so that new tables get no rights either. Only our own backend can reach your data, using a server key that never leaves it.
Your LinkedIn credential never touches our automation layer. Publishing happens in one dedicated function. It checks the caller with a shared secret and refuses the request if the secret is missing. The automation platform only ever sends an instruction naming you and the post, never the credential.
A change log we cannot rewrite. Since 4 August 2026, every change to your profile or posts goes into an audit log that only accepts new entries. It records what changed, when, and by which system. It never stores the content itself, and no entry can be altered once written, not even by our own application. Entries expire after 12 months. Individual reads are not logged separately; those are covered by our hosting provider's platform logs.
Backups. Our hosting provider keeps daily backups for 7 days. Separately, every night we take our own encrypted copy and store it outside the platform, so your data survives even if we lost the whole hosting account. Those copies are encrypted with a key our storage provider never holds, which means what sits there is unreadable to anyone but us. Nightly copies are kept for 90 days and a snapshot on the first of each month is kept for 12 months, after which it is deleted automatically. When you delete your data, it disappears from live systems immediately and from backup copies as they expire.
Access. Your data is read by our automated backend to run the service, and by one person: our founder, for support and maintenance. No other founder, employee or contractor has access to the database, and no outside party has access for its own purposes. Our accounts with the services that hold your data are protected with two-factor authentication, so a stolen password on its own is not enough to reach anything.
An AI assistant helps with that maintenance work, and it can read your data. We would rather tell you than let you find out. From 19 August 2026 it connects to the database in read-only mode: it can look at what is there, and it cannot change it, delete it, or publish anything. Until that date it can also make changes, because it has been doing the development work that built this service, and we would rather say so than describe a limit that is not in place yet. Changes to the system are decided by a named person. Every change to your profile or posts is written to a log that cannot be rewritten, so if something had been altered, it would show. On the rare occasions the assistant needs to make a change once the restriction is in place, it is lifted deliberately and the change appears in that same record.
What we are still building. The database does not yet enforce per-user isolation internally. It is on our roadmap and recorded in the security architecture document we maintain internally. We tell you this rather than imply protections we have not finished.
Where it is stored
Our database is in Stockholm, Sweden, inside the European Union.
We have data processing agreements in place with our main providers, including the EU standard contractual clauses. Google transcribes your voice notes and describes your images under its paid API terms. Those terms forbid Google from using your content to train its models and from showing it to human reviewers. Google does not limit that processing to the EU, so we do not claim that your voice notes and images never leave the EU.
MailerLite, which sends our waitlist email, is a US company, so its data processing addendum includes the EU standard contractual clauses and took effect when we accepted its terms. The email addresses themselves sit in a Google Cloud data centre in the Netherlands, and MailerLite holds an ISO 27001 certification. If MailerLite discovers a breach affecting our data, it has to tell us within 48 hours.
Our nightly off-platform backup is stored on GitHub, a US company, under a data processing agreement that includes the EU standard contractual clauses. What GitHub holds is ciphertext: the file is encrypted before it leaves our systems, with a key GitHub never receives and cannot derive. The only file we store there unencrypted is a description of the database structure, which contains no personal data.
One thing is still open, and we would rather say so than imply otherwise. n8n, which runs our automation, has not yet confirmed in writing where it processes data. We asked on 4 August 2026 and will update this section when they answer.
We would rather tell you exactly how things are than claim more than we can prove.
How long we keep it
| What | How long |
|---|---|
| Conversation history | Deleted automatically after 90 days. A job runs every day at 00:05 UTC and permanently removes anything older. |
| Your drafts | Kept until you delete them or close your account. |
| Posts you published | We keep our copy. The live post on LinkedIn is yours and stays until you remove it. |
| Your profile and style notes | Kept while you are a user. Deleted when you ask. |
| Request records (no message content) | 30 days. |
| Error records | 90 days. |
| Usage, cost and audit records | 12 months. |
| Data export files | 7 days. Both download links expire and the files themselves are deleted by the same daily job. |
| Consent records and rights requests | 24 months. These are the evidence that you gave permission and that we answered you, so they outlive the rest. |
| Waitlist email address | Until you unsubscribe or ask us to remove it. |
The same daily job also bounds every other table that holds your data, and reports back exactly how many rows it removed from each. Deleting your account does not remove posts already published to LinkedIn. Those are your property, live on LinkedIn's servers, and only you can take them down.
Your rights
Under GDPR you can:
Get a copy of everything. Ask HAI directly in the chat and you get two files. The first is a web page you can open on your phone and read as it is: who you are to us, what HAI has learned about your writing, your posts, your conversations, your consents, and a summary of the technical records we keep. The conversations on that page have HAI’s internal instructions stripped out of them, so what you read is the exchange itself rather than the machinery around it. The second file is the same information as machine-readable JSON, complete and unedited, including the consent history and operational records in full. Both are generated on the spot and delivered as private links that stop working after 7 days, so that a forwarded message cannot expose your data.
Have it deleted. We permanently delete your profile, drafts, scheduled posts, conversation history, style notes, pending messages, per-user records and your stored LinkedIn authorisation. Deletion is deliberately not automated: a request logs itself, starts the clock and goes to a human, because an irreversible action should not fire from a mistyped message. The deletion produces a report for each storage location, so when we confirm, we can show exactly what was removed. Two things survive on purpose. Aggregate reliability, cost and security records are kept, but stripped of any link to you. And your consent history and the record of your deletion request are kept, because they are how we prove you asked and we complied; they expire on their own after 24 months. We last tested the whole procedure with a test account on 4 August 2026.
Correct it. If something we hold about you is wrong, tell us and we will fix it.
Restrict processing. Ask us to stop using your data without deleting it. Useful if you want to pause and come back.
Take it elsewhere. The JSON file is yours to bring to any other service.
Object. You can object to the profiling we do to learn your writing style. That profiling is what makes HAI useful, so objecting may mean the service no longer works well for you. The choice is still yours.
How: tell HAI in the chat, or email matti@haisocialagency.com. Either way the request is logged with the time it arrived. We acknowledge within 5 days and act within 30 at the latest, usually much sooner. You never have to explain why.
Who else is involved
Building this alone would mean building a phone network, a speech recogniser and a language model from scratch. Here is every outside service and exactly what it receives.
| Service | What it receives | Why |
|---|---|---|
| WhatsApp (Meta) | Your messages, in transit | It is the channel you talk to us through |
| Anthropic | Your messages and recent conversation context. At signup, your name, company and title for a short public web search | The AI that writes and edits your drafts, and the background search behind your first message. Under our commercial terms it does not train on your content. It retains inputs and outputs for 30 days for safety and security, after which they are removed. We asked Anthropic whether that window could be reduced to zero; it is offered only on enterprise contracts, which we are not yet large enough for, so we will revisit it as we grow |
| Your voice notes and images | Transcription and image description. Paid API terms: not used to train models, no human review | |
| Supabase | Your stored data | Hosts our database (EU, Stockholm) |
| n8n | Message content, in transit. Successful runs store nothing; failed runs are kept briefly for debugging, then expire | Runs the automation connecting these pieces |
| GitHub | An encrypted nightly copy of the database, which it cannot read | Stores our off-platform backup so your data survives the loss of our hosting account |
| MailerLite | Your email address, only if you joined the waitlist | Sends our waitlist email. Stored in the Netherlands. Receives nothing from the service itself |
| Vercel | Your first name (shown on the signup success page) and standard technical logs | Hosts our sign-up pages |
| The post text and image, when you publish | Publishing your approved posts |
None of these are advertising or behavioural analytics companies, and none of them receive your messages, drafts or style notes for their own purposes. One narrow exception is worth naming rather than glossing over: MailerLite and GitHub each reserve the right to use technical and account-level data about how we use their service for their own business purposes, such as support and product development. That covers our accounts with them, not the content of what you send us.
We used a separate search provider, Tavily, until 7 August 2026. It has been removed and now receives nothing.
Automated decision-making
HAI drafts and suggests. It does not decide.
- Nothing is published without your explicit instruction. HAI will not post on its own or on a schedule you did not set.
- If HAI is unsure which draft you mean, it stops and asks. Publishing the wrong thing under your name is the mistake we have worked hardest to prevent.
- You can ignore anything it suggests, and you can always reach a human at the address above.
We do build an AI-generated profile of your writing style and professional context. It is used only to make your drafts sound like you.
Cookies and tracking
We use no third-party analytics, no tracking pixels, no advertising networks and no behavioural profiling services. Our sign-up pages set no tracking cookies.
We look at aggregate usage patterns, like how many messages and how many posts, to understand whether the service works. That analysis happens inside our own database and is never sent to an advertising or analytics company.
Children
HAI is not intended for anyone under 18. We do not knowingly collect data from children, and will delete it immediately if we discover we have.
Changes to this policy
We update this policy when the system changes. If a change is material, we tell you on WhatsApp rather than quietly editing the page. Every version carries a version number and date at the top.
Changed in version 2.2 (10 August 2026): We audited this policy line by line against the running system and corrected it where the two had drifted apart. Tavily was removed from the service on 7 August and is no longer a processor; the background search now runs through Anthropic. Version 2.1 implied Anthropic retained nothing, which was not accurate: it retains inputs and outputs for 30 days for safety and security, and we now say so. We asked whether that window could be reduced to zero and it cannot at our size, so the policy states the position rather than leaving the question open. MailerLite was added for waitlist email, and GitHub, which stores our encrypted off-platform backup, was never listed at all; both are now described along with the one thing each reserves for itself. Version 2.1 said our audit log could not be deleted by us; entries cannot be altered, but they do expire after 12 months, and the wording now reflects that. The retention table gives the real period for each category instead of one figure for all operational records. Consent records and rights requests now survive account deletion on purpose, because they are the proof that you asked and we complied. Data rights requests can be made directly to HAI in the chat: access requests are fulfilled immediately through a private link that expires in 7 days, while deletion goes to a human deliberately. And we have corrected who can reach your data: one person, not three.
Changed in version 2.3 (published 11 August 2026, takes effect 19 August 2026): We now say plainly that an AI assistant helps with development and maintenance and can read your data, and we describe the limits it works under. From 19 August it connects in read-only mode and cannot change, delete or publish anything; until then it can also make changes. That it can read your data was true before and was simply not written down, and a policy that describes who reaches your data should not leave one of them out. Alongside it we made the audit log genuinely unalterable at the database level rather than only for the application, so the claim in "How we protect it" is now enforced rather than promised.
Added to version 2.2 on 11 August 2026, before this version took effect: The data export now arrives as two files rather than one. Alongside the machine-readable JSON, which is unchanged and still complete, there is a readable web page organised into sections: who you are, what HAI has learned about your writing, your posts, your conversations, your consents, and a summary of the technical records. The conversations shown on that page have HAI’s internal instructions removed, so you read your own exchange rather than the scaffolding our system wraps around it. The JSON keeps the complete stored form, which is the one to take to another service. Both files expire together after 7 days.
Changed in version 2.1 (4 August 2026): The audit log that version 2.0 described as unfinished is now live, and we describe it as what it is: a log of changes, not of reads. Backups now exist and are described. The provider table now says precisely what each service receives; version 2.0 said too little. We also recorded that Google may not use your content for training.
Contact and complaints
Questions or requests: matti@haisocialagency.com Report a privacy concern: same address, subject "Privacy Incident"
If you believe we have mishandled your data, you can complain to the Finnish Data Protection Ombudsman:
Tietosuojavaltuutetun toimisto · tietosuoja.fi · +358 29 566 6700
In short
- We collect your phone number, your messages, your drafts and notes on your writing style
- Our database is in the EU. Google processes voice notes and images partly outside the EU, under terms that forbid training on them, and we say so openly
- Conversations delete themselves after 90 days. Drafts stay until you remove them
- No provider trains AI models on your content. Anthropic holds inputs and outputs for 30 days for safety checks, which is the shortest window available to a company our size
- Your LinkedIn credential is encrypted in a separate vault and never passes through our automation layer
- Our nightly backup leaves the EU, but it is encrypted with a key the storage provider never holds
- One person can reach the database. Every change to your data is logged in a form nobody can rewrite
- HAI never posts without your say-so, and asks when it is unsure
- No tracking, no ads, nothing sold. Ever
- Ask HAI, and we send you everything or delete everything