Legal

Privacy Policy

Hypelio is a tool for writing, approving, scheduling and reporting on LinkedIn posts across several accounts. Because of that, this policy concerns two different groups of people, and it is worth being clear about which is which.

Customers. The person or company who holds a Hypelio subscription. Usually an agency, a ghostwriter, or an in-house communications team.

Connected account holders. The people whose LinkedIn accounts are connected to a customer's workspace. Often the customer's clients or colleagues. They authorise the connection themselves and can withdraw it themselves.

For data belonging to connected account holders, the customer decides what is published and why. Hypelio processes that data on the customer's instructions. For data about the customer's own account and use of the service, Hypelio decides how it is handled.

Account details. Name, email address, password hash, company name and billing details. Payment card numbers are handled by our payment processor and never reach our servers.

LinkedIn data, via authorised access. When someone connects a LinkedIn account we receive the profile and post data that the connection permits: profile name and photo, posts published through Hypelio, and the performance figures LinkedIn returns for them. We do not scrape LinkedIn, we do not use browser automation, and we do not ask for or store anyone's LinkedIn password.

Content you create. Drafts, comments, voice notes, uploaded media and approval decisions, including who approved what and when.

Usage data. Pages visited, features used, device and browser type, and IP address, used to keep the service working and to understand which parts of it are useful.

To run the service you asked for: drafting and scheduling posts, publishing them to the accounts you have authorised, routing drafts for approval, and reporting on results. To build a voice profile per connected account, using that account's own published posts and the edits you make. To take payment, provide support, keep the service secure, and tell you about changes that affect you.

We do not sell personal data. We do not use your content or your clients' content to train models that serve other customers.

We rely on contract for everything needed to deliver the service you have subscribed to, legitimate interests for security, product improvement and service messages, consent where required, such as marketing email and non-essential cookies, and legal obligation for tax and accounting records.

We use a small number of service providers to run Hypelio: cloud hosting, a payment processor, an email provider, error monitoring, and the AI providers used to generate drafts. Each is bound to use the data only to provide their service to us.

We publish the current list of sub-processors and will give notice before adding a new one that handles customer content. We share data with law enforcement only where legally required, and we will tell you unless prohibited from doing so.

Account and content data is kept for as long as your subscription is active. When a workspace is archived or a subscription ends, its content and analytics stay exportable for 90 days, after which they are deleted from live systems. Backups are cycled out within a further 30 days. Invoices and tax records are kept for as long as the law requires.

A connected account holder can revoke access from their own LinkedIn settings at any time without going through the customer. When they do, we stop receiving new data for that account immediately.

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and is logged. Because we use authorised access rather than stored credentials, there is no database of LinkedIn passwords at Hypelio to lose. No system is perfectly secure, and we will notify affected users and any relevant regulator promptly if a breach occurs.

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, port it elsewhere, and withdraw consent. Under the UK and EU GDPR you may also complain to your data protection authority.

If you are in California, you may request disclosure of the categories of personal information collected, request deletion, and you have the right not to be discriminated against for exercising those rights. We do not sell personal information as that term is defined there.

If you are a connected account holder and want your data removed, you can ask us directly, though in most cases the fastest route is to revoke access in LinkedIn and ask the customer whose workspace you were in.

Our providers may process data outside your country. Where data leaves the UK or EEA we rely on adequacy decisions or Standard Contractual Clauses.

We use cookies that are necessary to sign you in and keep the service working, and analytics cookies to understand usage. Non-essential cookies are set only with consent, and you can change that choice at any time.

Hypelio is not intended for anyone under 18, and we do not knowingly collect their data.

If we change this policy materially we will tell account holders by email before it takes effect. Questions, requests or complaints can be sent to the contact address published on our site.