[ Privacy policy ]
Privacy Policy
Last updated: 30 April 2026
This policy explains what data HyperControl collects, why, where it is stored, and what rights you have over it. We try to collect the minimum we can ship a product with.
Who is the data controller
HyperControl is a product of Hyperlink. For the purposes of GDPR, Hyperlink is the data controller for personal data submitted by HyperControl account holders. Reach us at [email protected] for any privacy enquiry.
What we collect
From you, the account holder
- Email address, used for sign-in via magic link and for service notifications.
- Account name if provided.
- Stripe customer ID and subscription details if you subscribe to a paid plan. Card data is held by Stripe; we never see or store it.
- IP address and user agent at sign-in time, kept in authentication logs by Supabase, our auth provider.
From the WordPress sites you connect
- Site hostname, plugin / WordPress / PHP versions, and last sync timestamps (used to show you the online/offline status in your dashboard).
- The IP address each agent reaches our server from, stored in heartbeat rows and used for rate limiting and security investigations.
We do not collect content from the connected WordPress sites: no posts, no comments, no user data, no traffic logs. The agent only reports its own state and version metadata.
Agent secrets
Each agent secret is generated server-side, shown to you exactly once, and stored encrypted at rest with AES-256-GCM. The encryption key (HC_SECRETS_KEY) is held in our hosting provider's secret manager and never written to logs or backups.
Why we collect it
- Service operation. We need your email to log you in, your subscription status to enforce plan limits, and the agent metadata to provide the dashboard.
- Security. Authentication logs and agent IPs let us rate-limit and investigate misuse.
- Billing. Stripe needs your billing details to charge the subscription.
We do not use any of this for marketing, profiling, advertising, or sale to third parties.
Where it lives
- Supabase (Postgres + Auth) — primary database, hosted in the EU.
- Vercel — application hosting and edge network.
- Stripe — billing.
These are our subprocessors. Each has its own infrastructure security and is GDPR-compliant.
How long we keep it
- Account data: kept while your account exists. Deleted within 30 days of account deletion, except where we have a legal obligation to retain it (e.g. invoices for tax).
- Heartbeat rows: pruned after 30 days.
- Agent nonces: pruned after 5 minutes.
- Audit log: kept for the lifetime of the account.
Your rights
Under GDPR you can request:
- A copy of the personal data we hold about you.
- Correction of inaccurate data.
- Deletion of your account and associated data.
- Restriction of processing or objection to specific uses.
- Data portability for the data you provided.
Email [email protected] and we will respond within 30 days.
Cookies
HyperControl sets a small number of strictly-necessary cookies to keep you signed in (set by Supabase Auth) and to verify webhook requests from Stripe. We do not use marketing or analytics cookies.
Data breaches
If we discover a personal-data breach that puts you at risk, we will notify you within 72 hours of becoming aware of it, with the details we have at that point.
Changes
If this policy changes materially we will email all account holders.
Contact
Privacy enquiries: [email protected].