Privacy Policy

Last updated 1 September 2026

This policy explains what HerculeRadar does with two very different kinds of data: the account data you give us, and the publicly available social content we collect on your behalf. They are handled differently and are described separately below.

1. Account data

When you sign up we store:

  • your email address, and your name and avatar if you sign in with Google;
  • your projects, monitors, keywords and alert rules;
  • usage counters, so we can enforce plan limits;
  • billing identifiers returned by Stripe — never your card number.

We use this to operate the service, enforce quotas, send the alerts you configured, and contact you about your account. We do not sell it and we do not use it to train models.

2. Publicly available social content

The core of the service is collecting posts that are already public on X, Reddit and YouTube and that match keywords you chose. For each match we store the post text, its public URL, the public author name or handle, the publication timestamp and public engagement counts.

We do not collect private messages, protected accounts, private communities or anything that requires a login to view. We do not attempt to identify, enrich or cross-reference the authors of public posts beyond the public profile identifier attached to the post itself.

If you are the author of a post we have collected and you want it removed from our systems, email us with the post URL and we will delete it and suppress future collection of it. You do not need an account with us to make that request.

3. AI processing

Each collected mention is sent to a large language model to produce a category, a sentiment, an urgency score and a one-sentence summary. Only the post text and your monitor’s keywords are sent — never your account details. Our model provider processes this as a data processor and, under their API terms, does not use it to train their models.

4. Subprocessors

We rely on the following providers, each processing data on our instructions:

ProviderPurpose
SupabaseDatabase, authentication and file storage
VercelApplication hosting and edge network
ApifyRetrieval of public posts from X and Reddit
Google (YouTube Data API)Retrieval of public YouTube metadata
OpenAIClassification and summarisation of mentions
ResendTransactional and alert email
StripePayments and subscription management

5. Retention

  • Mentions are retained while your project exists and for 30 days after deletion.
  • Scan job records and cost telemetry are kept for 12 months.
  • Account records are deleted within 30 days of account closure.
  • Invoices are kept as long as tax law requires.

6. Your rights

You can access, export, correct or delete your data at any time. Export is available through the REST API; deletion is available in settings or by email. If you are in the EU or UK, you also have the right to object to processing and to lodge a complaint with your supervisory authority.

7. Security

Data is encrypted in transit and at rest. Every table is protected by row-level security, so one account cannot read another’s rows even if application code is wrong. API keys are stored only as HMAC digests — a leaked database row cannot be replayed against the API.

8. Changes and contact

We will announce material changes by email before they take effect. Questions, deletion requests and security reports: see Terms for contact details.