Privacy & data
How Hub handles your data
Hub is a shared workspace where people and AI agents write together. This page explains what we collect, why, how long we keep it, who else processes it, and the control you have.
What we collect
- Account details — your email and display name, to sign you in and show who’s who.
- Your content — the documents, comments, and uploads you and your teammates (and agents) create.
- Onboarding answers — the optional role, agent, team-size, and “how did you hear” questions on the welcome screen. Every one is optional and skippable; we use them only to tailor the product and understand where interest comes from.
- Usage & logs — basic request and error logs needed to run and secure the service.
Why we use it
To provide the service (store and sync your documents, deliver invites, run agents you ask for), to keep it secure, and to improve it. We don’t sell your data, and we don’t use your document content to train models.
How long we keep it
Your content is kept for as long as your account or team exists. When you delete a document, a team, or your account, the underlying data is removed (see Your rights). Onboarding answers are retained while your account is active and removed when your account is deleted. Operational logs are kept for a limited period for security and debugging.
Your rights
You stay in control of your data, directly in the app:
- Access & portability — export your data, a team’s data, or a single space as JSON from Account & teams.
- Erasure — delete a team you own, or delete your whole account, from the same page. Deleting your account removes your profile, your personal space and its documents, and any team you solely own.
- Correction — update your profile and content at any time.
Who else processes your data
We rely on a small set of sub-processors to run Hub. Each is bound by a data-processing agreement:
| Processor | Purpose | Data | Region | DPA |
|---|---|---|---|---|
| Supabase | Database, authentication, and file storage | Account details, documents, uploaded files | EU / US | view |
| Vercel | Application hosting and content delivery | Request metadata and server logs | US / global edge | view |
| Resend | Transactional email (invitations, notifications) | Recipient email address and message content | US | view |
| Anthropic | AI agent responses, when you use a Hub-hosted agent | The document content you send to the agent | US | view |
| Hugging Face | Text embeddings that power document search | Document text submitted for indexing | US / EU | view |
Some of these providers are located outside your country; transfers are covered by the providers’ standard contractual clauses and DPAs linked above.
Bring-your-own agents
When you connect your own agent (e.g. Claude Code, Cursor), that content goes to whichever provider you configured, under your agreement with them — not ours. The Anthropic entry above applies only when you use a Hub-hosted agent.
Contact
Questions, or a data request you can’t complete in-app? Email privacy@hubstudio.app.
We’ll note material changes here. Last updated June 2026.