LEGAL

Privacy Policy

What we collect, why, and the choices you have.

Last updated 26 September 2026

Who we are

HookRipple ("we", "us") is an online tool for sending API requests and inspecting webhooks, operated from South Africa. Questions about this policy or your data can be sent to hello@hookripple.com.

Information we collect

Account information from Google or GitHub when you sign in: an account identifier, your name, email address and profile picture. Workspace content you create or receive: requests, collections, environments, credentials, headers, bodies, responses and webhook payloads. Basic technical data needed to run the service, such as request timestamps and error logs; we do not log webhook URLs, query strings or payload bodies.

How we use it

To authenticate you, store and run the requests you ask us to run, capture webhooks sent to your endpoints, provide replay and history, keep the service secure, prevent abuse, and communicate important service changes. We do not sell your personal information. Workspace payloads are never used for advertising and are never sent to AI services.

Advertising on our public pages

Our public pages (such as the home page, documentation and these policies) may show ads served by Google AdSense. Google and its partners use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalised advertising at adssettings.google.com, and learn more at policies.google.com/technologies/ads. Ads are not shown inside the signed-in workspace, and workspace content is never shared with advertisers. Where required by law, we ask for your consent before personalised ads are shown.

Service providers

We rely on a small number of providers to run HookRipple: Hostinger (server hosting, data centre in Jakarta, Indonesia), Cloudflare (network delivery and protection), Google and GitHub (sign-in), and Google AdSense (ads on public pages). Your data may therefore be processed outside your country, with safeguards appropriate to the nature of the data.

Retention

Captured webhook payloads and request history are deleted automatically after 24 hours by default, or the period you choose in Settings. Collections, environments and endpoints remain until you delete them. Database backups are kept for up to 14 days and then deleted.

Security

Workspace content is encrypted at rest with AES-256-GCM, isolated per workspace and transmitted over TLS. See our security overview for details.

Your rights

You can export collections, download or delete captured deliveries, clear workspace history and revoke sessions at any time. Depending on where you live, including under South Africa's POPIA and the EU/UK GDPR, you may have the right to access, correct or delete your personal information and to object to certain processing. To make a request, including full account deletion, email us from the address on your account. You may also lodge a complaint with your local data-protection authority, such as South Africa's Information Regulator.

Children

HookRipple is intended for developers and is not directed at children under 16. We do not knowingly collect their personal information.

Changes

We will update this page when our practices change and revise the date above. Significant changes will be announced in the app.