Privacy Policy
Last updated 8 September 2026
Hoarda is a personal archive for the posts you save across social platforms. This policy covers the website (hoarda.app), the app (app.hoarda.app), and the Hoarda browser extension. It explains what we collect, why, who else touches it, and how you stay in control. We've kept it in plain English on purpose.
The short version
- We collect only what's needed to run your library and your account.
- Your library is private unless you choose to share a collection.
- No advertising, no behavioural tracking, no analytics on hoarda.app, and we never sell your data.
- We never collect the passwords for your social accounts.
- You can export everything at any time, and deleting your account removes everything, immediately.
What we collect
Your account. Your email address and a password (stored only as a one-way hash — we can't read it), or, if you use Sign in with Google, the name, email, and profile picture Google shares with us. We also keep your plan and subscription status.
The posts you sync. The items you have saved or bookmarked on your own accounts: the post's text, the author's name, handle, and avatar, the link, the date, like counts, and a thumbnail or image. They reach Hoarda one of two ways — the browser extension reads them from your own logged-in session, or, for X, through X's official sign-in. If you turn on likes sync, your X likes are included too. If you ask Hoarda to capture a thread, the author's posts in that thread are saved with it.
What you add. Your tags, notes, and collection names. Questions you ask Ask Hoarda are processed to produce an answer and aren't stored. AI-tagging preferences (your interest keywords and limits) are kept in your browser, not on our servers.
What we derive. For search by meaning we store an “embedding” — a numeric representation — of each post's text. Tag suggestions from AI are only saved if you apply them. On Pro, we keep our own copy of images and avatars so cards don't break when the original vanishes.
Payment. Handled entirely by Stripe. We store a Stripe customer reference and whether your subscription is active — never card numbers.
Technical. Standard server logs (IP address, browser type, timestamps, and the request made), kept briefly by our hosting provider for security and fixing problems. The extension stores its settings locally in your browser.
What we don't collect: your social-platform passwords, your private messages, your browsing history, or anything from pages you haven't asked us to sync. We don't run advertising or behavioural analytics anywhere.
How we use it
- To store, organise, search, and display your library — the whole point of Hoarda.
- To sync from the accounts you've connected, when you ask us to (or automatically, on Pro, if you've turned that on).
- To provide the AI features you choose to use.
- To take payment and manage your plan.
- To keep the service secure, prevent abuse, and fix what breaks.
- To contact you about your account or important changes to the service. We won't send you marketing without asking first.
- To meet our legal obligations.
The browser extension
The extension does one thing: read the items you have already saved on platforms you're logged into, and copy them into your own Hoarda account. It reads from your existing session in your own browser — the same data you can see yourself on those sites — and only when you trigger a sync. It never sees or stores your platform passwords, never reads private messages or your browsing history, and never touches any page other than the saved-items data you asked for.
Why each browser permission is needed
- Access to specific sites
- To read your saved items on the platform you're syncing (X, Instagram, LinkedIn, Reddit, Substack, TikTok, Truth Social, Bluesky, and your Mastodon instance) — and only those.
- Cookies / logged-in session
- So a sync uses your existing login instead of ever asking for your password.
- Scripting
- To read the data inside the platform's own page — required for sites like TikTok that only expose saved items to their own page.
- webRequest
- To detect the parameters the platform's own page uses when it loads your saved list, so the sync can page through it. Read-only — it never modifies or blocks your traffic.
- Tabs / storage
- To find the right open tab and remember your settings, which stay in your browser.
AI features
Some features send the text of your saved posts to an outside AI provider to do their job. When you use AI tag suggestions or Ask Hoarda, the relevant posts' text and author handles go to Anthropic (Claude), which returns tags or an answer. For search by meaning, post text goes to Voyage AI (or OpenAI, if that's what we're using) to create the embedding we store. We send only what the feature needs — never your account details, email, or payment information.
These providers process your content only to return a result to Hoarda, and under their standard API terms they do not use it to train their models. If you'd rather your content never leave Hoarda's own systems, simply don't use the AI features; the rest of your library works without them.
Who else touches your data
We don't sell your data, share it with advertisers, or hand it to anyone who isn't needed to run the service. These are the providers that are:
- Supabase
- Runs the database, your login, and the file storage where your library and any archived images live.
- Vercel
- Hosts hoarda.app and the app, and runs the code that syncs, searches, and exports your library.
- Stripe
- Takes payment for Pro. Your card details go straight to Stripe; Hoarda only keeps a customer reference and your subscription status.
- Anthropic (Claude)
- Generates tag suggestions and Ask Hoarda answers from the text of the relevant posts, only when you use those features.
- Voyage AI (or OpenAI)
- Turns post text into the “embeddings” that power search by meaning.
- Only if you choose Sign in with Google — Google tells us your name, email, and profile picture.
- X (Twitter)
- Only if you connect X — X's official sign-in gives Hoarda a token to read your bookmarks and profile, and to mirror removals.
Beyond these, we'd only disclose your data if the law required it, or to protect someone's safety or our legal rights. If Hoarda were ever sold or merged, your data would move with it under protections at least as strong as these, and we'd tell you.
Sharing, public collections, and archived media
Everything in your library is private by default. If you make a collection public, it becomes viewable by anyone who has the link, and on Pro through its RSS feed. You can make it private again whenever you like.
One thing to know about archived images and avatars: they're stored in a location that is readable by anyone who has the exact link. The links aren't listed or discoverable, but they aren't locked to your login either — so treat archived media as “visible to anyone with the link”. Deleting the post or your account removes the copies.
Where your data lives
Hoarda is operated from Australia, but the providers above run in data centres that may be outside Australia, including in the United States. That means your data can be stored and processed overseas. We choose established providers with strong security practices and contractual protections, and by using Hoarda you agree to this.
How long we keep it
For as long as your account exists — that's what an archive is for. You can delete any individual item at any time. Deleting your account removes everything, immediately: your posts, tags, notes, collections, embeddings, archived media, any X connection tokens, your profile, and your login. Copies may linger in our providers' routine backups for a short period before they expire. Disconnecting X deletes its tokens straight away, and removing the extension removes its local settings.
Security
Data travels over encrypted connections (HTTPS) and is stored encrypted at rest by our providers. Passwords are hashed, so no one at Hoarda can read them, and we never handle the passwords for your social accounts at all. Access to production systems is limited to what's needed to run the service. No system is perfectly secure, though — if you ever spot something that worries you, please tell us and we'll act on it quickly.
Your choices and rights
- See and take it: export your whole library as PDF, CSV, Markdown, or JSON at any time, from inside the app.
- Fix it: edit your tags, notes, collections, and account details yourself.
- Delete it: remove individual items, or your entire account, from inside the app — no need to ask us.
- Limit it: disconnect X, switch off likes sync, skip the AI features, or remove the extension whenever you like.
- Ask us: if you'd like a copy of the personal information we hold about you, want something corrected, or have a question, email us and we'll respond promptly.
If you're in Australia, you can also raise a concern with the Office of the Australian Information Commissioner. If you're in the UK or EU, you have equivalent rights of access, correction, erasure, portability, and objection, and we'll honour them.
Children
Hoarda is for people aged 13 and over, and anyone under 18 should have a parent or guardian's permission. We don't knowingly collect information from anyone under 13; if you believe we have, contact us and we'll delete it.
Cookies and local storage
We use only what's strictly necessary: your login session in the app, and a few settings stored in your browser (your view preferences, AI-tagging preferences, and a local cache of your library so it opens fast). There are no advertising cookies and no third-party tracking, on the website or in the app. Sites we link to have their own policies.
Changes to this policy
We'll update this page as Hoarda grows, and the date at the top will change when we do. If a change meaningfully affects how we handle your data, we'll tell you by email or in the app before it takes effect.
Contact
Questions, requests, or concerns: ben@activedesign.com.au