Privacy Policy
Last updated July 20, 2026This Privacy Policy explains how Anthony Casauria (sole trader) (trading as HyperDM, “we”, “us”) collects, uses, and shares personal data in connection with the HyperDM website and service (the “Service”). It applies to visitors of our site, merchants who create an account, and the end-customers whose messages the Service processes on a merchant’s behalf.
01Our two roles
As a controller — for our own site visitors and account holders (merchant users), we decide how and why we process that data (e.g. account, billing, support, security).
As a processor — when the Service reads and replies to a merchant’s direct messages, we process end-customers’ message content and identifiers on the merchant’s instructions. The merchant is the controller of that data; our processing is governed by our Data Processing Agreement. If you are an end-customer with a request about your data, please contact the merchant you messaged; we will assist them as their processor.
For our own site and accounts we’re the controller; for your customers’ DMs, you’re the controller and we only process on your instructions.
02Data we process
Merchant account data (we are controller)
- Identity & contact: name, email, password hash.
- Workspace & connection data: connected Instagram/WhatsApp/TikTok and Shopify accounts, access tokens (encrypted at rest), catalog and knowledge you ingest.
- Billing: plan, subscription status, and payment metadata (card data is handled by Stripe — we never store it).
- Usage & device: log data, IP address, pages viewed, and cookies (see §7).
End-customer DM data (we are processor for the merchant)
- Message content sent to/from the merchant’s connected channels.
- Platform-provided identifiers (e.g. the sender’s platform-scoped ID, username, profile image) and consent/opt-out state.
We take your account details and the DM data you connect — and nothing from channels you haven’t connected.
03Why we process it, and our legal bases
- Provide the Service (contract): operate accounts, connect channels, generate and send replies, show your inbox and analytics.
- Billing (contract): manage subscriptions and payments.
- Security, fraud prevention, and compliance (legitimate interests / legal obligation): rate-limiting, abuse prevention, honoring messaging-window and consent rules.
- Support and communication (legitimate interests / contract).
- Product improvement (legitimate interests): we do not use end-customer DM content to train third-party foundation models; DM content is sent to our AI sub-processor only to generate that conversation’s reply.
Everything we collect is to run your agent, bill you, and keep it secure — never to sell.
04Sub-processors
We share data with the vendors below strictly to run the Service. Each is bound by a data-processing agreement. A current list is maintained in our DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | United States |
| OpenAI | Reply generation & embeddings (no model training on your data) | United States |
| Meta Platforms | Instagram messaging API; WhatsApp (not yet active — coming soon) | United States / global |
| TikTok | Messaging API (not yet active — coming soon) | Global |
| Stripe | Payment processing | United States |
| Vercel | Application hosting | United States |
A short, contracted list of vendors helps us run the Service; the current list lives in our DPA.
05International transfers
We are based in Victoria, Australia and our sub-processors are primarily in the United States. Where we transfer personal data out of the UK/EEA, we rely on appropriate safeguards — the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses — a copy of which is available on request.
If data leaves the UK/EEA, it travels under the standard SCCs / UK IDTA safeguards.
06Retention
Merchant account data is kept while your account is active and for a limited period afterward to meet legal, tax, and security obligations. End-customer DM data is retained for the merchant per their settings and our DPA; on account deletion or a valid erasure instruction, we delete or de-identify the associated data within a commercially reasonable period, except where retention is legally required.
We keep data while your account is active and delete it on a reasonable timeline after you leave.
07Cookies
We use strictly-necessary cookies (e.g. session, theme). We do not currently run third-party advertising cookies. If we introduce analytics, we will update this policy and, where required, seek consent.
Strictly-necessary cookies only. No third-party advertising trackers.
08Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal data, to object to certain processing, and to withdraw consent. California residents may request access/deletion and to opt out of “sale”/“sharing” — we do not sell personal data. To exercise rights over data we control, contact us at hello@hyperdm.app. You may also complain to your local supervisory authority. For DM data a merchant controls, contact that merchant.
Ask to access, correct, delete, or export your data and we’ll handle it. We don’t sell personal data.
09Security
We apply technical and organizational measures including encryption in transit, encryption of stored channel access tokens, strict tenant isolation (row-level security), signed-webhook verification, and least-privilege access. No method of transmission or storage is perfectly secure.
Encryption in transit, encrypted channel tokens, tenant isolation, and least-privilege access.
10Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
The Service isn’t directed to under-16s, and we don’t knowingly collect their data.
11Changes & contact
We may update this policy; we will post the new effective date here and, for material changes, notify account holders. Questions or requests: Anthony Casauria (sole trader), St Helena, Victoria 3088 (full registered address available on request), Victoria, Australia — hello@hyperdm.app.
If this policy changes we’ll post the new date and, for material changes, tell account holders.