Privacy & data use
Updated 25 September 2026
Account and workspace data
Hooka Relay stores your email address, display name and workspace memberships. Email/password accounts use a password hash. If you choose GitHub or Google sign-in, we use your provider identity and verified email to sign you in. We store the provider account identifier, not its access or refresh token. Linking an existing account requires signing in first.
Webhook delivery
The service stores application and endpoint configuration, event payloads and delivery logs to deliver webhooks, retry failures and support replay. Each event, endpoint, and webhook source belongs to one customer; that customer's private portal link shows only its endpoints and history. Keep portal links private and ask the application owner to rotate or revoke a compromised link. API keys are hashed; endpoint signing secrets and configured custom headers are encrypted at rest. Workspace members can see data according to their roles.
Service providers
Vercel hosts the web application, Railway runs the worker, and Postgres and RabbitMQ provide storage and delivery scheduling. Resend sends account verification, recovery, invitations and operational alerts. Grafana receives filtered operational traces and metrics; payloads, credentials and receiver URLs are excluded from that telemetry.
AI features
Support questions and a bounded conversation history may be sent to Groq to answer product questions grounded in documentation. Automatic failure diagnosis sends recent attempt metadata and short receiver-response excerpts to Groq. Do not place passwords or secrets in support questions or receiver error messages. AI advice can be incomplete.
Cookies and preferences
Authentication uses cookies. The application may store interface preferences in your browser. Vercel Analytics and Speed Insights measure usage and performance; capability-link pages such as invite, portal and recovery pages exclude these integrations.
Access, retention and contact
Event payloads, inbound request bodies and delivery logs have a 30-day default retention period. Completed history older than that is removed in batches; unfinished delivery, routing, live forwarding and recovery work is retained until complete. Replay and idempotency lookup stop working once an event is removed. Monthly workspace usage totals remain after detailed history expires for manual invoicing. Account, application and endpoint configuration remains until deleted; provider backups can have separate retention periods. Workspace owners can delete their workspace and associated application data. For account access, deletion or privacy questions, contact waelfezari@gmail.com. This service does not sell account or webhook data.