Legal

Privacy Policy

Effective 3 September 2026

This policy explains what personal data Hubiq collects, why, how long we keep it, who we share it with, and the rights you have over it. It applies to the website at hubiq.tech, the waitlist, and the Hubiq products and services, including content you choose to transfer to Hubiq from other platforms.

1. Who we are

The data controller is Hubiq, a company registered in the Republic of Bulgaria (referred to as "Hubiq", "we" or "us").

2. What we collect

2.1 Waitlist

If you join the waitlist we collect your email address. To prevent abuse we also process your IP address for rate limiting and a bot-protection token issued by Cloudflare Turnstile. The IP address is kept only for as long as the rate-limit window requires.

2.2 Account

When you create a Hubiq account we collect the sign-in identifier you use (typically an email address) and the account identifiers issued by our authentication provider. We do not store your password.

2.3 Content you transfer to Hubiq

Hubiq builds a private "vault" from content you author on other platforms. You decide which sources to connect. Depending on the source, this content can include:

We import your own content only. Private messages, other people's content, contact lists and browsing or ad histories are discarded if they are present in a source export, and are never requested from a platform.

2.4 Platform authorisation tokens

When a platform sends your data to Hubiq through an authorised transfer (for example Meta's "Transfer your information" tool), that platform holds an access token issued by Hubiq. We store the token identifiers and revoke them when the transfer completes or when you disconnect the source.

2.5 Usage and technical data

We collect product analytics (pages and features used, device and browser type) and error and performance logs so that we can keep the service working and improve it. Server logs include IP addresses and are retained for up to 90 days.

3. Why we process it and on what legal basis

PurposeDataLegal basis (GDPR Article 6)
Notify you about early accessWaitlist emailConsent (6(1)(a))
Provide your account and build your vault and appsAccount data, transferred contentPerformance of a contract (6(1)(b))
Import content from a platform you connectTransferred content, authorisation tokensConsent (6(1)(a)), given when you start the transfer
Analyse your content with AI models to produce summaries, personas and app ideasTransferred contentPerformance of a contract (6(1)(b))
Keep the service secure and prevent abuseIP address, logs, bot-protection tokensLegitimate interests (6(1)(f))
Understand how the product is usedUsage analyticsLegitimate interests (6(1)(f))
Comply with legal obligationsRecords we are required to keepLegal obligation (6(1)(c))

We do not use your data for advertising, we do not sell it, and we do not use it to build profiles of you for anyone else.

4. Transfers from other platforms

You can bring content into Hubiq in three ways: by uploading an export file the platform gave you, by pointing Hubiq at a public source such as your blog, or by starting a transfer inside the platform and choosing Hubiq as the destination.

Meta (Facebook, Instagram, Threads). Transfers from Meta are started by you inside Meta's Accounts Center using the "Transfer your information" tool. You choose which data types and which date range to send. Meta then delivers that data to Hubiq over an authorised connection. Hubiq receives only what you selected, uses it solely to build your vault, never posts to your Meta accounts, and never shares it back with Meta or with advertisers. You can stop a recurring transfer at any time in Accounts Center, and you can disconnect the source in Hubiq, which revokes Meta's access token.

You are responsible for making sure you have the right to transfer the content you connect, and for complying with the terms of the platform you transfer it from.

5. AI processing

To build your vault Hubiq sends your transferred content to third-party large language model providers for analysis. We use these providers under commercial API terms that prohibit them from training their models on our customers' data. The outputs (summaries, topic maps, personas, app ideas) are stored in your vault and belong to you.

6. Who we share data with

We share personal data only with service providers that process it on our behalf and under our instructions:

CategoryProvidersLocation
Hosting and infrastructureGoogle Cloud, VercelEU and US
AuthenticationPrivyUS
Databases and storageSupabase, Google CloudEU
AI model providersAnthropic, OpenAI, GoogleUS and EU
Product analytics and error monitoringPostHog, SentryEU and US
EmailGoogle WorkspaceEU
Bot protection, rate limiting, waitlist storageCloudflare, Upstash, FormspreeEU and US

We may also disclose data where the law requires it, to protect our rights or the safety of others, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.

7. International transfers

Hubiq is established in the European Union. Where a provider processes data outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses or on an adequacy decision such as the EU–US Data Privacy Framework.

8. How long we keep data

When you delete your account we delete your data within 30 days. Copies in encrypted backups are overwritten within a further 30 days. We keep records we are legally required to keep (for example invoices) for the statutory period.

9. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email privacy@hubiq.tech from the address linked to your account. We respond within one month. Step-by-step deletion instructions are on our data deletion page.

You also have the right to lodge a complaint with a supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни), cpdp.bg. You may instead complain to the authority in the EU country where you live or work.

10. Security

We protect data with encryption in transit and at rest, access controls limited to staff who need it, two-factor authentication on administrative accounts, and monitoring of our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

If you believe you have found a security vulnerability in Hubiq, please report it to security@hubiq.tech. We acknowledge reports within 3 business days and will not take legal action against good-faith research that respects users' privacy and does not disrupt the service.

11. Children

Hubiq is not intended for people under 16. We do not knowingly collect data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the product evolves. The effective date at the top shows the latest version. For material changes we will notify account holders by email before the change takes effect.

13. Contact

Hubiq, Republic of Bulgaria. Email privacy@hubiq.tech for anything relating to this policy or your personal data.