Privacy and retention
HookFork stores account details, encrypted provider credentials, webhook payloads, resource relationships, and delivery history.
The tenant owner controls project access. The operator can access infrastructure for support and recovery. HookFork does not claim end-to-end encryption or certification.
Retention contract
Terminal payloads have a seven-day default. Pending or paused payloads remain held until resolution or an explicit owner expiry. Event metadata, delivery records, and deduplication records remain until the operator explicitly deletes the tenant.
Minimal relationship evidence also remains until tenant deletion. The service does not infer safe retirement from current Subscription state or event order. Retained metadata counts against the tenant event limit. It cannot recreate an expired payload.
Beta access requests expire after 30 days. The operator processes tenant deletion and account recovery. Backup expiry and actual recovery limits must appear in each deployment's operations record before activation.
Infrastructure
HookFork uses Stripe, Cloudflare, and the operator's Kubernetes infrastructure. Infisical supplies infrastructure secrets. Source and destination applications retain their own data responsibilities.
Do not send production customer data until the operator confirms the service acceptance gates for your tenant.