Privacy Policy

Last updated: April 21, 2026

This Privacy Policy explains how Hotbox (“Hotbox”, “we”, “us”) collects, uses, shares, and protects information when you use our website and services (the “Service”).

1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address and optional name. During onboarding, you may provide business context such as what you sell, your ideal client profile, and communication preferences.

1.2 Instagram Data

When you connect an Instagram professional account, we collect and store information needed to operate the Service on your behalf, including your profile information, conversations and messages, stories and story analytics, comments on your posts, published media, and information about people who interact with your account.

1.3 Payment Information

If you subscribe to a paid plan, our third-party payment processor collects and processes your payment details on our behalf.

1.4 Usage Data

We collect analytics data about how you use the Service, including pages viewed, features used, and general device and browser information. We also use session recording tools to understand how users interact with the interface.

2. How We Use Information

  • Provide, operate, and maintain the Service (authentication, syncing conversations, displaying your inbox)
  • Fetch, organize, and display your Instagram conversations, stories, comments, and media
  • Provide AI-assisted features including conversation prioritization, suggested replies, and content analysis
  • Process comment and message automations you configure
  • Process payments and manage subscriptions
  • Send transactional emails (follow-ups, reminders)
  • Detect abuse, prevent fraud, and secure the Service
  • Analyze usage to improve the Service

3. How We Share Information

We do not sell your personal information. We share information with third-party service providers only as needed to operate the Service:

  • Authentication and database providers, to store and secure your data
  • AI model providers, to generate conversation analysis, suggested replies, and content descriptions. This involves processing message text and other relevant context.
  • Cloud storage providers, to persistently store media files such as story images, videos, and thumbnails
  • Payment processors, to handle subscription billing
  • Email delivery providers, to send transactional emails on our behalf
  • Analytics providers, to understand aggregate usage and improve the Service
  • The Instagram and Meta APIs, to fetch your data and send messages and replies on your behalf

These providers are permitted to use your data only to perform services on our behalf and are contractually obligated to protect it.

We may also disclose information if required by law, legal process, or government request, or to protect the rights, property, or safety of Hotbox, our users, or others.

4. Advertising and Conversion Tracking

We use conversion tracking pixels on our marketing pages to measure the effectiveness of our advertising. These tools may collect hashed identifiers (such as a hashed email address) to attribute conversions. This tracking applies to our marketing site and does not apply to message content or Instagram data within the Service.

5. Cookies and Similar Technologies

We use cookies and similar technologies for authentication, analytics, session recording, and advertising attribution. You can manage cookie preferences through your browser settings.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. If you request deletion, we will delete or de-identify your information, subject to legal and operational requirements such as backup retention periods.

Some data from Instagram, such as story analytics, is stored persistently because it is only available from Instagram for a limited time.

7. Data Deletion

You can request deletion of your data at any time:

You can also revoke Hotbox’s access from within your Instagram account settings. Note that revoking access does not automatically delete data already stored in Hotbox. Please use the deletion request above to remove stored data.

8. Security

We use reasonable administrative, technical, and physical safeguards to protect your information. While no system can guarantee absolute security, we are committed to protecting your data.

9. Children

The Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We take steps to ensure your data receives a level of protection consistent with applicable data protection laws.

11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request portability of your data
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact support@hotbox.app.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the date at the top of this page and, where appropriate, through the Service or by email.

13. Contact

Questions about this policy? Contact support@hotbox.app.