Privacy Policy
Last updated September 7, 2026This Privacy Policy explains how Anthony Casauria (sole trader) (trading as HyperDM, “we”, “us”) collects, uses, and shares personal data in connection with the HyperDM website and service (the “Service”). It applies to visitors of our site, merchants who create an account, and the end-customers whose messages the Service processes on a merchant’s behalf.
01Our two roles
As a controller — for our own site visitors and account holders (merchant users), we decide how and why we process that data (e.g. account, billing, support, security).
As a processor — when the Service reads and replies to a merchant’s direct messages, we process end-customers’ message content and identifiers on the merchant’s instructions. The merchant is the controller of that data; our processing is governed by our Data Processing Agreement. If you are an end-customer with a request about your data, please contact the merchant you messaged; we will assist them as their processor.
For our own site and accounts we’re the controller; for your customers’ DMs, you’re the controller and we only process on your instructions.
02Data we process
Merchant account data (we are controller)
- Identity & contact: name, email, password hash.
- Workspace & connection data: connected Instagram/WhatsApp/TikTok and Shopify accounts, access tokens (encrypted at rest), catalog and knowledge you ingest.
- Billing: plan, subscription status, and payment metadata (card data is handled by Stripe — we never store it).
- Usage & device: log data, IP address, pages viewed, and cookies (see §7).
End-customer DM data (we are processor for the merchant)
- Message content sent to/from the merchant’s connected channels.
- Platform-provided identifiers (e.g. the sender’s platform-scoped ID, username, profile image) and consent/opt-out state.
- Voice messages. If an end-customer sends a voice message, we retrieve the audio and convert it to text so the merchant’s agent can understand and answer it. The audio itself is never stored: it is transcribed in memory and discarded in the same operation, and only the resulting text is retained — as part of the conversation record, on the same terms and for the same retention period as any typed message. We do not perform voice or biometric identification, and we do not use voice data to train any model.
Media the merchant uploads
- Voice recordings, video and documents a merchant creates or uploads to send in their own automations. These are the merchant’s own content, stored in their workspace until they delete them, and are transcribed for search and accessibility.
We take your account details and the DM data you connect — and nothing from channels you haven’t connected.
03Why we process it, and our legal bases
- Provide the Service (contract): operate accounts, connect channels, generate and send replies, show your inbox and analytics.
- Billing (contract): manage subscriptions and payments.
- Security, fraud prevention, and compliance (legitimate interests / legal obligation): rate-limiting, abuse prevention, honoring messaging-window and consent rules.
- Support and communication (legitimate interests / contract).
- Product improvement (legitimate interests): we do not use end-customer DM content to train third-party foundation models; DM content is sent to our AI sub-processor only to generate that conversation’s reply.
- Speech-to-text (contract): a voice message sent to a merchant is transcribed so their agent can read and answer it — the same purpose a typed message serves. Audio is discarded once transcribed and is never used for training or for voice identification.
Everything we collect is to run your agent, bill you, and keep it secure — never to sell.
04Sub-processors
We share data with the vendors below strictly to run the Service. Each is bound by a data-processing agreement. A current list is maintained in our DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | United States |
| OpenAI | Reply generation, embeddings & speech-to-text for voice messages (no model training on your data) | United States |
| Meta Platforms | Instagram messaging API; advertising measurement — the Meta Pixel in your browser and a report from our server (hashed email, IP, user agent, click and browser ids — see Cookies & analytics and Advertising measurement); WhatsApp (not yet active — coming soon) | United States / global |
| TikTok | Messaging API (not yet active — coming soon) | Global |
| Stripe | Payment processing | United States |
| Vercel | Application hosting | United States |
| Resend | Transactional email (escalation and handoff notifications to your team) | United States |
| Sentry | Error monitoring and alerting | United States |
| PostHog | Product analytics — how merchants and visitors use our site and app, under the consent rules in Cookies & analytics (opt-in where the law requires consent, opt-out elsewhere). Never receives end-customer message content or identity | United States |
| Ahrefs | Site traffic counts — which pages are visited and where visitors came from. Cookieless: sets nothing on your device and holds no visitor identifier (see Cookies & analytics). Never receives end-customer message content or identity | Singapore |
A short, contracted list of vendors helps us run the Service; the current list lives in our DPA.
05International transfers
We are based in Victoria, Australia and our sub-processors are primarily in the United States. Where we transfer personal data out of the UK/EEA, we rely on appropriate safeguards — the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses — a copy of which is available on request.
If data leaves the UK/EEA, it travels under the standard SCCs / UK IDTA safeguards.
06Retention
Merchant account data is kept while your account is active and for a limited period afterward to meet legal, tax, and security obligations. End-customer DM data is retained for the merchant per their settings and our DPA; on account deletion or a valid erasure instruction, we delete or de-identify the associated data within a commercially reasonable period, except where retention is legally required.
We keep data while your account is active and delete it on a reasonable timeline after you leave.
07Cookies & analytics
Strictly-necessary cookies (no choice involved)
We use strictly-necessary cookies to run the site — your sign-in session, your light/dark theme preference, a record of the analytics choice you make below, and a two-letter note of which consent rules apply to you (worked out from the country your connection comes from, at our edge network, and holding no identifier of any kind). These are first-party and cannot be switched off without breaking the Service or the choice mechanism itself.
How we ask, and why it depends on where you are
The two tools below both store an identifier in your browser and share data about your use of this site with a third party. We ask about them in one of two ways:
- If you are in the EU/EEA, the UK or Switzerland — opt-in. Nothing under the next two headings runs until you choose Allow. Until then the PostHog script and the Meta Pixel are not downloaded and not executed, no advertising or analytics cookie is set, and nothing about your visit is sent to either company. Declining is one click, is remembered, and we do not ask again.
- Everywhere else — opt-out. The two tools run when you arrive, a notice tells you so, and Opt out stops them at once and is remembered: analytics and session recording stop, the Meta Pixel is told to send nothing further and its two cookies are removed. Scripts already downloaded cannot be unloaded until the next page, and neither company receives anything more.
We honour Do Not Track and Global Privacy Control everywhere. If your browser sends either signal we never ask, never load either tool, and never send anything. You can change your mind at any time: clear this site’s data in your browser and the notice returns, or contact us at hello@hyperdm.app and we will exclude you.
Product analytics (PostHog)
Subject to the choice above, we use PostHog — a third-party product-analytics provider — to understand how people move through our site and app, so we can find the steps where people get stuck. We are specific about it:
- What it records: pages viewed, clicks, and the milestones you reach (for example: signed up, connected a channel, created an automation), plus your device type, browser, approximate location from your IP, and a random ID stored on your device. When you create an account, that random ID is linked to your account’s own random identifier — never to your email address or name — so we can see the path from a first visit to a signup.
- Session replays. Subject to the same choice, PostHog records a reconstruction of your screen so we can watch where a flow breaks down. Everything you type is masked — passwords, forms and message boxes are never recorded.
What PostHog never receives
Your customers’ direct messages are never sent to PostHog. On every screen that displays end-customer content or identity — your inbox, contacts, activity, broadcasts, sequences, segments and dashboard — session replay is switched off automatically and on-screen text is masked before any event is sent. We also strip email addresses, record identifiers and authentication tokens out of page addresses before they leave your browser. As a merchant’s processor we do not use their end-customers’ data for our own purposes, and product analytics would be exactly that.
Advertising measurement in your browser (the Meta Pixel)
Subject to the same choice, our pages load Meta’s pixel — a script from Meta (Facebook and Instagram) that tells Meta which of our adverts lead to real signups. It sets two cookies on hyperdm.app: _fbp, a random browser identifier (kept for 90 days), and _fbc, the click identifier from a Meta advert link you followed, if you followed one (also 90 days). It reports to Meta the pages you view on this site and two signup milestones — the signup form submitted or a sign-in provider chosen, and an account created — each with a random event number. It does not send anything you type, and we have switched off Meta’s “automatic” collection of button text and form fields. Our server sends a second copy of the same two milestones; the next section says exactly what that copy contains and why there are two.
Site traffic counts (no cookies, no consent needed)
Regardless of the choice above, we use Ahrefs Web Analytics to count visits to our public website and see which pages are read and where visitors arrive from (for example, a search engine or a link in a post). We use it to understand which of our articles are found and read. It is built to work without identifying anyone: it sets no cookie and stores nothing on your device, keeps no identifier for you, and records only the page address, the referring site, and your browser type, device type and country. It cannot recognise you across visits and it never sees anything you type. We rely on our legitimate interest in knowing how our website is used; because nothing is stored on your device, no consent is asked for. You can object at any time by contacting us at hello@hyperdm.app.
Our own signup funnel
Separately, and regardless of the choice above, we measure our own signup funnel so we can see where people abandon the form. This part is first-party and self-hosted — it goes to our own database. It records which step was reached and when, identified by a random id held in your browser’s session storage (not a cookie) that is discarded when you close the tab. It never includes your email address, your IP address, your browser details, or anything you type. We rely on legitimate interests for it, and you can object at any time.
Strictly-necessary cookies always. Product analytics (PostHog) and advertising measurement (the Meta Pixel) run only if you say yes where the law requires consent — the EU/EEA, the UK and Switzerland — and run when you arrive everywhere else, with a one-click opt-out that is honoured at once. Plus a cookieless page-view count that identifies nobody. Your customers’ messages are never part of any of it.
08Advertising measurement
We advertise HyperDM, and we need to know which adverts bring people who go on to actually use the product — otherwise we are spending money blind. So when you arrive from one of our adverts and then submit the signup form, create an account, connect a channel, or send your first automated reply, we report that milestone to the advertising platform the advert ran on. Today that is Meta (Facebook and Instagram) only.
Two copies, counted once. The first two milestones are reported twice: once by the Meta Pixel in your browser (previous section) and once by our server. Both carry the same random event number, and Meta uses it to count the milestone once. Browser reports are often lost to ad blockers and browser privacy features; the server copy is what makes the count reliable. The last two milestones are reported by our server only, once an hour, from account records we already hold.
What our server sends, in full:
- which milestone happened, when, and its random event number;
- a hashed form of your email address — a one-way SHA-256 digest, so the platform can recognise an account it already knows and cannot read your address out of it;
- the advert-click identifier: the pixel’s
_fbccookie when the pixel is running, otherwise the identifier that was in the link you followed, held for that browser tab only; - the browser identifier: the pixel’s
_fbpcookie when the pixel is running, otherwise a random identifier we generate ourselves and keep in your browser’s local storage so the platform can tell a returning browser from a new one. Either way it holds nothing about you, and it persists between visits until you clear this site’s data; - your IP address and your browser’s user-agent string (the browser and operating system it reports), as your browser sent them when you signed up;
- the address of the page the signup happened on.
We do not send your name, your password, your message content, your customers’ data, or anything you type into the product. We do not build or keep a separate advertising profile: each milestone is reported once, and that is the end of it.
Your choice covers the server too. Where consent is required, none of this — pixel or server report — happens unless you chose Allow; elsewhere it happens unless you opted out. Your browser passes your choice to our server at the moment you sign up, and the server sends nothing when the answer is no.
Our lawful basis is your consent where the law requires it, and otherwise our legitimate interest in measuring the effectiveness of our own advertising. You can object or withdraw at any time — see “Your rights” below — and we will exclude your account from this reporting.
If you arrive from one of our adverts, we tell Meta which adverts lead to real signups — from the pixel in your browser and from our server, both under the consent rules above. What leaves: a hashed form of your email, your IP and browser details, and the click and browser identifiers. No name, no password, no message content, and each milestone is counted once.
09Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal data, to object to certain processing, and to withdraw consent. California residents may request access/deletion and to opt out of “sale”/“sharing” — we do not sell personal data. To exercise rights over data we control, contact us at hello@hyperdm.app. You may also complain to your local supervisory authority. For DM data a merchant controls, contact that merchant.
Ask to access, correct, delete, or export your data and we’ll handle it. We don’t sell personal data.
10Security
We apply technical and organizational measures including encryption in transit, encryption of stored channel access tokens, strict tenant isolation (row-level security), signed-webhook verification, and least-privilege access. No method of transmission or storage is perfectly secure.
Encryption in transit, encrypted channel tokens, tenant isolation, and least-privilege access.
11Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
The Service isn’t directed to under-16s, and we don’t knowingly collect their data.
12Changes & contact
We may update this policy; we will post the new effective date here and, for material changes, notify account holders. Questions or requests: Anthony Casauria (sole trader), St Helena, Victoria 3088 (full registered address available on request), Victoria, Australia — hello@hyperdm.app.
If this policy changes we’ll post the new date and, for material changes, tell account holders.