FastHook dashboard showing webhook delivery records
FastHook logoFastHook

Legal

Privacy Policy

How FastHook handles personal data across the website, dashboard, APIs, MCP integration, and browser extension.

Last updated: July 19, 2026Terms of Service

No sale of personal data

FastHook does not sell personal data and shares it only where needed to operate, secure, or comply.

Extension scope is narrow

The stats extension is limited to showing FastHook request and event counters for an authorized team.

Google Limited Use

FastHook states that use of information received from Google APIs follows the Limited Use requirements.

This policy explains the data FastHook needs to provide webhook delivery infrastructure, account access, MCP tools for ChatGPT and other compatible clients, operational statistics, support, security, and the fasthook.io stats Chrome extension.

1. Scope

This Privacy Policy applies to www.fasthook.io, dashboard.fasthook.io,mcp.fasthook.io, FastHook APIs, the FastHook ChatGPT plugin and MCP integration, and thefasthook.io stats Chrome extension.

2. Data We Collect

  • Account and authentication data: email address, profile details, and identity tokens required to sign in (including Google Sign-In credentials).
  • Workspace and team data: team identifiers and access control context needed to return your request and event statistics.
  • Operational usage data: API requests needed to show webhook request and event counters, selected time range, and response metadata.
  • Webhook and routing data: request methods, paths, query values, headers, payload bodies, delivery status, destination responses, saved fixtures, and replay instructions supplied by you or by services you connect to FastHook. This data may contain personal data chosen by the sender of the webhook.
  • MCP and ChatGPT integration data: the FastHook workspace you authorize, requested OAuth scopes, tool inputs, and the minimum FastHook records needed to answer the tool request. Authentication secrets and sensitive header values are not returned in MCP tool results.
  • Technical data: server logs, IP address, browser/extension version, and diagnostic error information for security and reliability.

3. How We Use Data

  • Authenticate users and protect account access.
  • Provide webhook request and event statistics in the dashboard and extension.
  • Inspect, trace, save, and replay webhook records when you explicitly invoke an MCP tool.
  • Operate, secure, and improve FastHook services.
  • Investigate abuse, fraud, and security incidents.
  • Comply with legal obligations.

4. Chrome Extension Specifics

The fasthook.io stats extension is limited to one purpose: showing FastHook request and event counters for an authorized team.

  • It stores extension settings and session token in Chrome extension storage so the widget can load data.
  • It uses Google OAuth only to authenticate the user and obtain access to FastHook services.
  • It does not collect browsing history, page content, keystrokes, personal communications, or unrelated website data.

5. Google API Limited Use Disclosure

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

6. Sharing and Disclosure

We do not sell personal data.

We may share data only when necessary with:

  • Infrastructure and hosting providers that operate FastHook services.
  • Authentication providers used for sign-in.
  • OpenAI or another MCP client provider when you connect FastHook and invoke its tools. The client receives only the sanitized tool result needed to answer your request and processes it under its own terms and privacy policy.
  • Destinations you configure, such as an HTTP endpoint, Slack, Telegram, or Google Sheets, when you route or replay webhook data to that destination.
  • Legal authorities when required by law, regulation, or valid legal process.

7. Data Retention

We retain account, webhook, routing, and MCP authorization data only as long as needed for service delivery, the retention settings of the applicable FastHook plan or feature, security, legal compliance, and legitimate business operations. Temporary request bins state their shorter expiry in the product. OAuth access tokens are short lived; refresh access can be revoked by disconnecting FastHook from the MCP client or revoking the authorization. Extension-local data remains in your browser profile until removed, overwritten, or the extension is uninstalled.

8. Security

FastHook uses technical and organizational safeguards to protect data, including encrypted transport (HTTPS/TLS), access controls, and monitoring designed to reduce unauthorized access and misuse.

9. Your Choices and Rights

  • You can stop using the extension at any time by uninstalling it.
  • You can request account or data-related support by contacting FastHook.
  • You can revoke Google access in your Google account permissions panel.
  • You can disconnect FastHook from ChatGPT or another MCP client to revoke its ongoing access.

10. Children's Privacy

FastHook services are not intended for children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date on this page.

12. Contact

For privacy questions or requests, contact us at support@fasthook.io.

You can also access FastHook services at dashboard.fasthook.io.