Hubters WebAI Privacy Policy
Last Updated: March 9, 2025
Introduction
HubtersAI, LLC ("we", "our", "us", or "HubtersAI") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Hubters WebAI services, including our website, npm package, and related services (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with any part of this policy, please do not use our Services.
1. Information We Collect
We collect several types of information for various purposes to provide and improve our Services to you:
1.1 Personal Information
When you register for an account, we collect:
- Basic profile information (such as your name, email address, username and your profile picture)
- Payment information (processed securely through Stripe)
1.2 Usage Data
We collect information about how our Services are used, including:
- Download statistics of AI models through your integration
- Features and pages of our Services that you visit
- Analytics data through Google Analytics
1.3 Future Collection
In the future, we may collect device information such as:
- Browser type and version
- IP address
- Operating system
- Device identifiers
We will update this Privacy Policy if we begin collecting such information.
1.4 Data Not Collected
We do not collect:
- Information about your end users or customers who interact with applications using our AI models
- Data processed by the AI models, as all AI processing occurs client-side in the browser
- Cookies or other similar tracking technologies
2. How We Use Your Information
We use the collected information for various purposes, including to:
- Provide, operate, and maintain our Services
- Process and complete transactions, and send related information including confirmation and invoices
- Calculate usage-based billing according to our pricing model
- Send administrative information, such as updates, security alerts, and support messages
- Respond to comments, questions, and requests, and provide customer service and support
- Monitor usage patterns and analyze trends to improve our Services
- Detect, prevent, and address technical issues
- Comply with legal obligations
3. How We Share Your Information
We may share your information with third parties in the following situations:
3.1 Service Providers and Data Processors
We share information with carefully vetted third-party service providers who help us operate our business and deliver services. All subprocessors are bound by data processing agreements that ensure appropriate security measures and confidentiality obligations:
- Stripe for payment processing (PCI DSS compliant)
- Google Analytics for website analytics
- Amazon Web Services for cloud infrastructure (SOC 2 Type II certified)
These service providers are authorized to use your personal information only as necessary to provide services to us and are required to maintain the confidentiality of your information.
3.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
3.3 Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.
3.4 With Your Consent
We may share your information with third parties when we have your consent to do so.
4. Data Security and Architecture
4.1 Client-Side Processing Model
Our unique architecture provides enhanced privacy protection:
- AI models run entirely in the user's browser (client-side)
- End-user data processed by AI models never leaves the user's device
- We have no access to data processed by the AI models in user applications
4.2 Security Measures
We implement appropriate technical and organizational security measures to protect your personal information:
Technical Safeguards:
- End-to-end encryption for data in transit using TLS 1.3
- Encryption at rest for all stored data
- Multi-factor authentication for administrative access
- Regular security assessments and penetration testing
- Automated security monitoring and incident detection
Organizational Safeguards:
- Privacy by design principles in all system development
- Access controls based on the principle of least privilege
- Regular staff training on data protection and security
- Documented data handling procedures and incident response plans
- Regular audits of data processing activities
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
5. Data Retention
We will retain your personal information only for as long as necessary to fulfill the purposes for which it was collected.
Retention Periods:
- Account Data: Retained while account is active + 180 days after closure
- Usage Data: Retained for 3 years for billing and analytics purposes
- Payment Records: Retained for 7 years as required by tax regulations
- Support Communications: Retained for 2 years for service improvement
In some circumstances, we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.
6. Your Data Protection Rights
Depending on your location, you may have certain rights regarding your personal information:
6.1 Under the General Data Protection Regulation (GDPR)
If you are a resident of the European Economic Area (EEA), you have the following rights:
Access & Portability
Request copies of your personal data in a machine-readable format
Rectification
Request correction of inaccurate or completion of incomplete data
Erasure
Request deletion of your personal data
Restriction & Objection
Limit or object to processing of your personal data
6.2 Under the California Consumer Privacy Act (CCPA)
If you are a California resident, you have the following rights:
- Right to know - Request disclosure of personal information we collect, use, disclose, and sell
- Right to delete - Request deletion of personal information
- Right to opt-out - Opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination - Non-discrimination for exercising your CCPA rights
6.3 Other Jurisdictions
We monitor and comply with applicable data protection laws in all jurisdictions where we provide services, including but not limited to Canada's PIPEDA, Brazil's LGPD, and other regional privacy regulations.
6.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before responding to your request.
You may also manage or delete your account directly through our dashboard interface. Account deletion will remove your personal information from our active databases, though some information may remain in backups or for legal compliance purposes.
7. International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. When transferring personal data outside your jurisdiction, we implement appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where available
- Additional security measures based on transfer impact assessments
By using our Services, you consent to the transfer of your information to the United States and other countries where HubtersAI operates.
8. Incident Response and Breach Notification
In the event of a data security incident:
- We will assess the risk and scope within 24 hours
- Regulatory authorities will be notified within 72 hours if required
- Affected individuals will be notified if there is a high risk to their rights
- We will document all incidents and remediation measures
9. Third-Party Services
Our Services may include links to third-party websites, products, or services. These third parties have separate and independent privacy policies. We have no responsibility or liability for the content and activities of these linked sites.
We encourage you to review the privacy policies of any third-party services you access through our Services.
10. Children's Privacy
Our Services are not intended for use by children under the age of 13 (or the applicable age of digital consent in your country). We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we can take necessary actions.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this page.
For significant changes, we will provide a more prominent notice, which may include an email notification. We encourage you to review this Privacy Policy periodically for any changes.
Your continued use of our Services after any changes to this Privacy Policy constitutes your acceptance of such changes.
12. Contact Information
If you have any questions about this Privacy Policy, data protection concerns, or our data practices, please contact us at:
General Contact
HubtersAI, LLC
5214f Diamond Heights Blvd
San Francisco, CA 94110
United States
Phone: (628) 218-5459
Regulatory Authority Contacts
If you believe we have not adequately addressed your privacy concerns, you may contact the relevant data protection authority:
- EU: Find your local Data Protection Authority at edpb.europa.eu
- California: California Privacy Protection Agency (cppa.ca.gov)
- UK: Information Commissioner's Office (ico.org.uk)
- Canada: Office of the Privacy Commissioner (priv.gc.ca)
