Contents

  1. Who we are
  2. What we collect
  3. Why we use it, and our lawful basis
  4. AI processing
  5. Social account connections
  6. Prospect data (outreach add-on)
  7. Who we share data with
  8. International transfers
  9. How long we keep it
  10. Security
  11. Your rights
  12. Children
  13. Changes

1. Who we are

Hanu AI Solutions LLC (LLC), trading as MyInfluence AI, is the controller of the personal data described in this policy, except where section 6 says otherwise. Our registered address is 1191 Clearwater Dr Frisco TX.

For anything in this policy, write to [email protected].

2. What we collect

Account data

Your email address, and your name if you sign in with Google or supply one. Passwords are handled by our authentication provider, Supabase — we never see or store your password. If you sign up through an invite, we store the invite code you used.

When you accept these policies we record which document versions you accepted, the time, the channel you accepted through (web form, Google sign-in, email sign-in link, or our Telegram onboarding assistant) and the IP address the acceptance came from. That record exists so we can both prove what was agreed.

Brand and content data

Everything you tell us about the brand you are marketing: business name, website, industry, target audience, tone and strategy notes, content pillars, and any media you upload. Plus everything the Service produces for you — scripts, hooks, captions, generated video and images, posting schedules, and the performance metrics returned by the platforms you publish to.

Connected accounts

If you connect a social account, we store the access and refresh tokens issued by that platform, the account or page identifier, and the display name. If you connect a Telegram bot for approvals, we store the bot token and the chat identifier. See section 5.

Conversations with our agents

The Service is operated through conversational agents — Aria on Telegram for onboarding, and in-app chat. We store the full transcript of those conversations, because the agents need the history to work at all. Do not paste passwords, payment card numbers, or other sensitive credentials into a chat; our agents are instructed never to ask for them.

Billing data

Your plan, subscription status, trial end date, and any add-ons. Payments are processed by Stripe — we never receive or store your card details. We store the Stripe customer and subscription identifiers so we can tell what you are entitled to.

Waitlist data

If you join the waitlist on our marketing site we collect your name, email address, brand name, phone number, budget preference and any comments you write, along with the fact and version of your consent.

Product usage data

We record first-party funnel events — a randomly generated session identifier, the step you reached, and (once you are identified) your email address — so we can see where sign-up breaks down. We do not use any third-party analytics product for this. Web server logs include IP addresses, which we read for rate limiting and abuse prevention and do not retain in our database.

3. Why we use it, and our lawful basis

PurposeDataLawful basis
Provide the Service — generate, schedule and publish contentAccount, brand, content, connected accountsPerformance of a contract
Bill you and manage your subscriptionAccount, billingPerformance of a contract
Send service, approval and account emails and messagesAccount, connected accountsPerformance of a contract
Support, debugging and incident responseAll of the aboveLegitimate interests — running a working service
Improve prompts, scheduling and qualityContent, performance metricsLegitimate interests — improving our product
Security, rate limiting, fraud and abuse preventionIP address, usageLegitimate interests — protecting the Service
Waitlist and marketing contactWaitlist dataConsent, which you may withdraw at any time
Meet legal, tax and accounting obligationsBilling, accountLegal obligation

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use your brand's content or conversations to train our own models, and the AI providers listed in section 7 are engaged under terms that do not permit training on data we send them.

4. AI processing

Generating content necessarily means sending your inputs to third-party AI providers. Specifically:

Automated decision-making. The Service decides what to post and when, largely without a human in the loop — that is the product. These decisions concern content and scheduling. They do not produce legal or similarly significant effects on any individual. You keep an approval step available at all times and can require manual approval before anything is published.

AI-generated output can be wrong, derivative, or unsuitable. You are responsible for what is published under your brand — see the Terms of Service.

5. Social account connections

Publishing is brokered through Zernio, which holds the platform integrations for TikTok, Instagram, YouTube, Facebook, LinkedIn, Pinterest, Bluesky, Threads and X. When you connect an account, the platform issues tokens that we store so the Service can post on your behalf.

Those tokens grant access to your accounts. We restrict access to them, transmit them only over encrypted connections, and use them solely to publish content you have configured and to read back the resulting performance metrics. You can disconnect any account at any time from your dashboard, which deletes the stored tokens for that account. You should also revoke our access from within the platform itself if you want to be certain.

Your use of each platform remains governed by that platform's own terms and privacy policy.

6. Prospect data (outreach add-on)

If you were contacted by one of our customers and want your details removed: use the unsubscribe link in the email you received, or write to [email protected] and we will suppress your address and pass the request to the customer who holds the record.

Customers who buy the outreach add-on can have the Service find and contact businesses. To do that, the Service searches business directories and search engines for businesses matching the customer's stated target profile, then visits each business's own public website and extracts the contact address it publishes there. We store the business name, that contact address, phone number, website, location, a short summary, and public social profile links.

We do not buy contact lists and we do not extract addresses from anywhere other than the business's own published pages.

For this data, our customer is the controller and we are their processor. The customer decides who is targeted and what is sent; we provide the tooling and act on their instructions. Our Data Processing Addendum governs that relationship, and our Acceptable Use Policy sets out what customers must and must not do. Every message carries the sending customer's physical postal address and a working unsubscribe link. Unsubscribes are recorded per customer and are checked both before a prospect is enriched and again before anything is sent.

7. Who we share data with

We share personal data with the sub-processors listed at /legal/subprocessors/, each engaged under a written agreement limiting them to processing on our instructions. That page is the authoritative, current list; the summary here is for orientation:

We also disclose data where we are legally required to, to establish or defend legal claims, or — with notice to you where we are permitted to give it — in connection with a merger or acquisition.

8. International transfers

Our sub-processors operate globally, so your data will be processed outside your own country, including in the United States. Where data leaves the UK or EEA we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable to the recipient. Ask us at [email protected] for details of the safeguards for a specific transfer.

9. How long we keep it

DataRetention
Generated video and image files in object storage7 days after creation, then deleted automatically
Content records, job history and related rows90 days, then purged automatically
Account, brand and connected-account recordsFor as long as your account is open
Consent recordsLife of the account plus six years, as evidence of what was agreed
Billing and tax recordsAs required by tax law, typically six to seven years
Unsubscribe suppression listsIndefinitely — deleting them would let us contact you again
Waitlist entriesUntil you ask us to remove them, or 24 months of no contact

The two automatic periods above are configurable defaults for our production environment. Ask us if you need the values in force on a particular date.

10. Security

All traffic to the Service is encrypted with TLS. Data at rest sits in managed infrastructure (Supabase and Cloudflare) that applies disk-level encryption. Access to production data is restricted to the small number of people who need it, and administrative actions are logged.

Being precise about credentials. Third-party credentials you supply or authorise — social platform tokens, and any email sending credentials you enter for the outreach add-on — are stored in our database protected by access controls and the underlying platform's encryption at rest, but they are not separately encrypted by us at the application layer. We are telling you this rather than implying stronger protection than we currently apply. Use a dedicated sending account with limited privileges for outreach, and revoke access from the platform's own settings when you stop using the Service.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and any relevant supervisory authority as required by law.

11. Your rights

Depending on where you live, you may have the right to:

We do not sell or share personal data as those terms are defined under US state privacy laws, so there is nothing to opt out of. We will not discriminate against you for exercising any right.

How to exercise them. Email [email protected] from the address on your account. There is currently no self-service export or delete button in the dashboard — these requests are handled by our team. We will verify your identity and respond within 30 days, and will tell you if we need longer.

12. Children

The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes

This policy is version 1.0, effective 2026-07-27. If we make a material change we will increment the version, publish it here, and email account holders at least 30 days before it takes effect; continued use after that date means you accept it. Adding a sub-processor to the disclosure list updates that page and the "last updated" date.