Privacy Policy

Last updated: September 16, 2026

Data controller: HustleGrow AB ("we", "us", "our")
Contact: info@hustlegrow.com

This policy covers TrafficOS AI — the web dashboard, the TrafficOS AI Chrome extension, our support portal, and any white-label edition of the product operated under another brand name. It explains what we collect, who it is about, why, and how long we keep it.

1. The short version
  • We collect data about you (our customer) to run your account and campaigns.
  • When you run campaigns, our extension also collects data about other people — the public social-media users whose posts and profiles it reads on your instruction, some of which is saved to your "My Leads" list. Those people are not our users; you decide when this collection happens and what you do with it.
  • To write comments and posts for you, we send content to OpenAI. We never sell personal data.
2. Data about you (the account holder)

We collect this directly from you or from the marketplace you bought through:

  • Account: your name, email address, and password (stored as a one-way hash — we cannot read it), plus an API key that links your extension to your account.
  • Purchase: the transaction ID and purchase details passed to us by JVZoo or WarriorPlus. We never see or store your card or bank details — the marketplace handles payment.
  • Your business setup: the companies/offers you add — name, description, website, affiliate link, and the keywords you target — and your campaign settings (which actions run, daily limits, tone and style preferences).
  • Optional integrations you switch on: your own OpenAI API key if you choose "bring your own key"; your Telegram chat link if you connect the Telegram bot for notifications; browser-profile names if you use that feature.
  • Activity history: a log of what the extension did on your behalf — which action ran, when, whether it succeeded, the target URL, and a short preview of the content it posted.
  • Support: if you contact support or use our help portal, your name, email, and the contents of your tickets.
  • Technical: a session cookie to keep you signed in, your IP address and browser type in standard server logs, and the extension version you are running.
3. Data about other people (collected by the extension on your instruction)

This is the part most tools gloss over, so we want to be clear. When you activate a campaign, the extension runs inside your own browser, using your own logged-in social-media accounts, and reads the public pages you point it at on Facebook, Reddit, YouTube, Quora, X (Twitter), Instagram, and LinkedIn. In doing so it processes content posted by third parties — people who are not our customers:

  • Read to act: the public text of posts and comments that match your keywords, so it can like, comment on, or reply to them.
  • Saved as leads (when you use lead features): a person's public display name and handle, their profile URL, and — where shown publicly — their job title and location, together with the public post or comment they wrote, its URL, and the keyword that matched. This is stored in your "My Leads" list so you can follow up.
  • Messaging records: if you use direct-message features, the handles you messaged and the conversation link, so the extension does not message the same person twice.

You control this collection. It only happens for the keywords, platforms, and actions you choose, at the limits you set, and you can delete any lead or your whole list at any time. Because you decide whom to collect and how to use it, you are responsible for using lead data lawfully — including complying with each platform's rules and with privacy and anti-spam laws that apply to you (for example GDPR, UK GDPR, CCPA, CAN-SPAM). See our Terms of Service.

4. What the Chrome extension can access, and why

Chrome shows you a list of permissions when you install. Here is what each one is actually used for:

PermissionWhat we use it for
Access to facebook.com, reddit.com, youtube.com, quora.com, x.com, instagram.com, linkedin.comTo read the pages you target and to type and click on your behalf. Nothing runs on any other website.
CookiesOnly to check whether you are signed in to a platform, by detecting whether its login cookie exists. We do not read, store, or transmit the cookie's value.
DebuggerTo send real keystrokes and clicks, because these platforms ignore simulated typing. This is why Chrome shows a "started debugging this browser" bar while the extension works. It is not used to inspect or capture anything.
Tabs, scripting, storage, alarms, notificationsTo open worker tabs, run the automation, remember progress between runs (so it never comments on the same post twice), schedule the next run, and notify you of problems.

Stored locally in your browser (never sent to us): run progress, the list of posts already engaged today, and — on Reddit — your account's age and karma, read from Reddit's own API purely to set safe daily limits for your account.

5. How we use the data
  • To run the campaigns and actions you set up, and show you the history of what was done.
  • To generate the comments, posts, questions, and messages you asked for (see section 6).
  • To create and secure your account, and to bill you via the marketplace.
  • To answer support requests and send service notices (including optional Telegram alerts).
  • To keep the service working and safe — for example, detecting when a platform has signed you out.

Where GDPR applies, our legal bases are: performance of our contract with you (Art. 6(1)(b)); our legitimate interests in operating and securing the service (Art. 6(1)(f)); your consent for optional integrations you switch on (Art. 6(1)(a)); and legal obligations (Art. 6(1)(c)).

6. AI processing (OpenAI)

Content is written by OpenAI's models, not by us. To do that, we send OpenAI: your keywords, your company/offer description, your tone and style settings, and the text of the third-party post or message being responded to. When the extension cannot find a button or text box on its own, it may also send OpenAI a structural snapshot of the page's visible elements (labels, roles, positions — not screenshots) so the AI can decide what to click.

If you use your own OpenAI key, this content is sent under your own OpenAI account and their terms apply to you directly. In either case, OpenAI's API terms state that data sent via the API is not used to train their models. We do not use your content to train anything.

7. Who we share data with

We do not sell personal data. We share it only with service providers who process it for us under contract, or when the law requires:

  • OpenAI — AI content generation (section 6).
  • JVZoo / WarriorPlus — payment and order processing. They send us your name, email, and transaction ID; we never receive card details.
  • Hostinger — hosting for the dashboard and database.
  • Telegram — only if you link the notification bot.
  • Email delivery provider — for account and support emails.
  • The social platforms themselves — the actions the extension takes (likes, comments, messages) are posted publicly or sent on those platforms under your account, subject to their policies.

White-label editions: if you use TrafficOS AI under a reseller's brand, that reseller can see and manage the accounts they sold; the data is still stored and processed by HustleGrow AB under this policy.

8. How long we keep it
  • Account and business data: for as long as your account is active, then deleted or anonymised within [CONFIRM: e.g. 90 days] of closure, except where we must keep records for tax or legal reasons.
  • Leads and activity history: until you delete them or close your account.
  • Data stored in your browser by the extension: until you clear it or uninstall the extension; the "already engaged today" memory clears itself daily.
  • Support tickets: [CONFIRM: e.g. 2 years].
9. Security

Passwords are stored as one-way hashes, traffic is encrypted with HTTPS, and access to customer data is limited to staff who need it for support. No system is perfectly secure, so we cannot guarantee absolute security, but we will notify you as required by law if a breach affects your data.

10. Your rights

Depending on where you live (including the EU/EEA, UK, and California), you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent for optional features at any time. You can delete leads, offers, and campaigns yourself inside the dashboard. For anything else, email info@hustlegrow.com; we will verify your identity and respond within the time the law allows. EU/EEA and UK users may also complain to their local data protection authority.

11. If you are not our customer, but our software collected your data

If one of our users engaged with your public post or saved you as a lead, that user — not us — decided to collect your information and is responsible for it. You can email info@hustlegrow.com; we will pass your request to the user concerned and help remove your data from our systems where we are able to.

12. Cookies

The dashboard uses a session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. The extension's cookie access is described in section 4.

13. International transfers

Our providers may process data outside your country, including in the United States (OpenAI, JVZoo, WarriorPlus). Where EU/UK data leaves the EEA or UK we rely on appropriate safeguards such as Standard Contractual Clauses.

14. Children

The service is for business use by adults. We do not knowingly collect data from anyone under 18.

15. Changes

We will post any changes here and update the date at the top. Material changes will be announced in the dashboard or by email.

16. Contact

HustleGrow AB — info@hustlegrow.com


Back to Dashboard Terms of Service