Legal Center
Last updated: January 14, 2026
security 1. Data Collection & Usage
HogInsight is a mobile client that connects directly to your PostHog instance. We do not operate any intermediary servers. Your API key and all analytics data travel exclusively between your device and your PostHog server over HTTPS/TLS 1.3.
- check_circleAPI keys stored in hardware-backed iOS Keychain (whenUnlockedThisDeviceOnly) — never in UserDefaults or plaintext.
- check_circleZero third-party analytics SDKs — no Firebase, Mixpanel, Amplitude, or IDFA/IDFV collection.
- check_circleNo data passes through HogInsight servers. All requests go directly to your PostHog Cloud or Self-Hosted instance.
visibility 2. Analytical Transparency
We adhere to the "Intelligent Observer" principle. Our app provides a read-only window into your PostHog data. We do not sell, share, or process your analytics data. All data processing occurs within your own PostHog environment.
Compliance Note
We are fully compliant with GDPR and CCPA. The app does not track across apps or websites, so App Tracking Transparency (ATT) permission is not required. Users can request data export or account erasure at any time.
key 3. Your Data Sovereignty
You retain full ownership of all data in your PostHog instance. HogInsight never caches raw event data locally beyond the current session. You can purge, export, or audit your analytics at any time through the PostHog Management Console.
lock 4. App Security
HogInsight provides multiple layers of security to protect your PostHog access:
- check_circleOptional 4-digit PIN code lock with configurable auto-lock timer (1 min to 1 hour).
- check_circleFace ID / Touch ID biometric authentication using iOS LocalAuthentication framework.
- check_circleBackground-to-foreground re-lock: app automatically locks when returning from background if auto-lock interval has elapsed.
mail 5. Contact
For privacy-related inquiries, data access requests, or account erasure, contact us at support@hogsignal.com. We will respond within 30 days as required by GDPR.