Privacy
Last updated 27 July 2026
What we collect, and why
- Your email and name, through Clerk, so you can sign in and so we can reach you about your account.
- A Stripe customer id and billing metadata if you subscribe. Card details never touch Blackhat — they go straight to Stripe.
- Usage events — which metered actions you took and when — because that is how plan caps are enforced.
- IP addresses, for rate limiting and abuse prevention. On the logged-out demo the address is hashed, never stored in the clear.
- Chat messages you send to the assistant, so it can answer and so you can read the thread later.
- Error reports, so we can fix crashes.
The video data
Everything in the library comes from publicly visible posts and their public metrics. We never access private accounts, private messages, or anything behind a login on another platform, and we do not buy data from anyone who does.
Who processes it
- Vercel — Hosting, edge network and Blob storage for re-hosted thumbnails
- Neon — The Postgres database
- Clerk — Sign-in and account management
- Stripe — Payments and subscription billing
- Inngest — Background job execution
- Anthropic — Enrichment and chat model calls
- Groq — Transcription and fast model calls
- Voyage AI — Search embeddings
- Resend — Transactional email
- Sentry — Error reporting
- ScrapeCreators — Collection of publicly visible posts
- Apify — Standby collection provider (currently disabled)
We will update this list before adding anyone to it.
We do not sell your data
We do not sell personal information, we do not share it with data brokers, and we do not run advertising on Blackhat.
How long we keep it
- Account data — for the life of the account.
- Usage events — 12 months, then pruned.
- Chat messages — until you delete them or delete your account.
- Error reports — for as long as our error-reporting plan retains them.
Deleting your data
Email hello@blackhat.ink from your account address, or delete your account in settings. We respond within 30 days.
What gets deleted: your profile, your collections, your chat history, your API keys and your usage events. Your public reports are unpublished.
What does not: the indexed video data itself. Publicly scraped posts by other people are not your personal data, so they stay cached. Billing records are kept for as long as tax law requires.
If you are a creator asking to have your own videos removed from the index, that is a takedown request — see the takedown section of the terms.
Your rights
You have rights under the Australian Privacy Act to access the personal information we hold about you and to have it corrected. If you are in the EU, the UK or California, we honour access, correction, deletion and portability requests on the same path and in the same timeframe — email us and say what you want.
If we have not resolved a complaint to your satisfaction, you can escalate to the Office of the Australian Information Commissioner.