Legal
Privacy Policy
This policy explains what personal data Hubiq collects, why, how long we keep it, who we share it with,
and the rights you have over it. It applies to the website at hubiq.tech, the waitlist, and
the Hubiq products and services, including content you choose to transfer to Hubiq from other platforms.
1. Who we are
The data controller is Hubiq, a company registered in the Republic of Bulgaria (referred to as "Hubiq", "we" or "us").
- Privacy and data protection requests: privacy@hubiq.tech
- Security issue reports: security@hubiq.tech (see also security.txt)
- General enquiries: hello@hubiq.tech
2. What we collect
2.1 Waitlist
If you join the waitlist we collect your email address. To prevent abuse we also process your IP address for rate limiting and a bot-protection token issued by Cloudflare Turnstile. The IP address is kept only for as long as the rate-limit window requires.
2.2 Account
When you create a Hubiq account we collect the sign-in identifier you use (typically an email address) and the account identifiers issued by our authentication provider. We do not store your password.
2.3 Content you transfer to Hubiq
Hubiq builds a private "vault" from content you author on other platforms. You decide which sources to connect. Depending on the source, this content can include:
- your posts, captions, articles and their titles, text and publication dates;
- photos and videos you posted, and links to them;
- public URLs of your posts and your public profile name and handle;
- engagement counts on your posts (for example likes or comments totals), where the source provides them.
We import your own content only. Private messages, other people's content, contact lists and browsing or ad histories are discarded if they are present in a source export, and are never requested from a platform.
2.4 Platform authorisation tokens
When a platform sends your data to Hubiq through an authorised transfer (for example Meta's "Transfer your information" tool), that platform holds an access token issued by Hubiq. We store the token identifiers and revoke them when the transfer completes or when you disconnect the source.
2.5 Usage and technical data
We collect product analytics (pages and features used, device and browser type) and error and performance logs so that we can keep the service working and improve it. Server logs include IP addresses and are retained for up to 90 days.
3. Why we process it and on what legal basis
| Purpose | Data | Legal basis (GDPR Article 6) |
|---|---|---|
| Notify you about early access | Waitlist email | Consent (6(1)(a)) |
| Provide your account and build your vault and apps | Account data, transferred content | Performance of a contract (6(1)(b)) |
| Import content from a platform you connect | Transferred content, authorisation tokens | Consent (6(1)(a)), given when you start the transfer |
| Analyse your content with AI models to produce summaries, personas and app ideas | Transferred content | Performance of a contract (6(1)(b)) |
| Keep the service secure and prevent abuse | IP address, logs, bot-protection tokens | Legitimate interests (6(1)(f)) |
| Understand how the product is used | Usage analytics | Legitimate interests (6(1)(f)) |
| Comply with legal obligations | Records we are required to keep | Legal obligation (6(1)(c)) |
We do not use your data for advertising, we do not sell it, and we do not use it to build profiles of you for anyone else.
4. Transfers from other platforms
You can bring content into Hubiq in three ways: by uploading an export file the platform gave you, by pointing Hubiq at a public source such as your blog, or by starting a transfer inside the platform and choosing Hubiq as the destination.
Meta (Facebook, Instagram, Threads). Transfers from Meta are started by you inside Meta's Accounts Center using the "Transfer your information" tool. You choose which data types and which date range to send. Meta then delivers that data to Hubiq over an authorised connection. Hubiq receives only what you selected, uses it solely to build your vault, never posts to your Meta accounts, and never shares it back with Meta or with advertisers. You can stop a recurring transfer at any time in Accounts Center, and you can disconnect the source in Hubiq, which revokes Meta's access token.
You are responsible for making sure you have the right to transfer the content you connect, and for complying with the terms of the platform you transfer it from.
5. AI processing
To build your vault Hubiq sends your transferred content to third-party large language model providers for analysis. We use these providers under commercial API terms that prohibit them from training their models on our customers' data. The outputs (summaries, topic maps, personas, app ideas) are stored in your vault and belong to you.
6. Who we share data with
We share personal data only with service providers that process it on our behalf and under our instructions:
| Category | Providers | Location |
|---|---|---|
| Hosting and infrastructure | Google Cloud, Vercel | EU and US |
| Authentication | Privy | US |
| Databases and storage | Supabase, Google Cloud | EU |
| AI model providers | Anthropic, OpenAI, Google | US and EU |
| Product analytics and error monitoring | PostHog, Sentry | EU and US |
| Google Workspace | EU | |
| Bot protection, rate limiting, waitlist storage | Cloudflare, Upstash, Formspree | EU and US |
We may also disclose data where the law requires it, to protect our rights or the safety of others, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.
7. International transfers
Hubiq is established in the European Union. Where a provider processes data outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses or on an adequacy decision such as the EU–US Data Privacy Framework.
8. How long we keep data
- Waitlist email: until we launch and you either create an account or unsubscribe, or until you ask us to delete it.
- Account data: for as long as your account exists.
- Transferred content and vault outputs: for as long as your account exists, or until you delete the source or the vault.
- Platform authorisation tokens: revoked when a transfer completes or you disconnect the source.
- Server logs and analytics: up to 90 days for logs; analytics are aggregated or deleted after 12 months.
When you delete your account we delete your data within 30 days. Copies in encrypted backups are overwritten within a further 30 days. We keep records we are legally required to keep (for example invoices) for the statutory period.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict processing in certain circumstances;
- data portability: receive your data in a structured, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting processing that took place before withdrawal.
To exercise any of these rights, email privacy@hubiq.tech from the address linked to your account. We respond within one month. Step-by-step deletion instructions are on our data deletion page.
You also have the right to lodge a complaint with a supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни), cpdp.bg. You may instead complain to the authority in the EU country where you live or work.
10. Security
We protect data with encryption in transit and at rest, access controls limited to staff who need it, two-factor authentication on administrative accounts, and monitoring of our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
If you believe you have found a security vulnerability in Hubiq, please report it to security@hubiq.tech. We acknowledge reports within 3 business days and will not take legal action against good-faith research that respects users' privacy and does not disrupt the service.
11. Children
Hubiq is not intended for people under 16. We do not knowingly collect data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product evolves. The effective date at the top shows the latest version. For material changes we will notify account holders by email before the change takes effect.
13. Contact
Hubiq, Republic of Bulgaria. Email privacy@hubiq.tech for anything relating to this policy or your personal data.