Last updated: 14 September 2026
Privacy Policy
This policy explains how Hubbla ("we", "us" and "our") handles personal information when you visit our website, use the Hubbla web or Mac app, or contact us.
Information we collect
We collect information you provide, information from your sign-in provider, and technical information generated when you use Hubbla:
- Account information, such as your name, email address, profile picture, account identifier and workspace membership.
- Workspace content you or your organisation provide, including documents, messages, prompts, table records, workflow instructions, approvals and run history.
- Audio and transcripts when you choose to use voice features or upload a recording. Microphone access requires your permission.
- Support enquiries and other information you send us.
- Technical and security information, such as IP addresses, browser and device details, request timestamps, errors and authentication events.
Only provide information you are entitled to share. If you use an organisation's workspace, its administrators may provide account information and manage your access.
Google sign-in
When you choose Continue with Google, Google shares your basic account identity with our authentication provider, WorkOS: your name, email address, profile picture and Google account identifier. WorkOS uses this information to authenticate you and provides Hubbla with the account information needed to recognise you and manage access. Authentication records and session information are stored to maintain your account and sign-in.
Google sign-in requests only basic email and profile permissions. It does not give Hubbla access to Gmail messages, Google Drive files, Google Calendar events or your Google password. We use Google account information for sign-in, account administration, support and security. We do not sell it, use it for advertising, or use it to train general-purpose AI models.
You can remove Hubbla's access through your Google Account connections. Removing the connection prevents future use of that connection but does not automatically delete your Hubbla account or workspace records. Contact us to request deletion. Our handling of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements where applicable.
How we use information
We use information to provide and secure Hubbla, authenticate users, manage workspace access, store and display content, process your requests, run workflows, respond to support enquiries, investigate errors and abuse, and meet legal obligations. Workflow actions can create or update records in the workspace and in services you choose to connect. We do not sell personal information.
AI, voice and workflow processing
When you use AI features, relevant prompts, conversation history, workspace context and tool results may be sent to OpenAI to generate responses or perform requested work. Voice features send audio to OpenAI for transcription or real-time processing. AI processing can produce operational traces containing inputs, outputs and tool activity. Workflow services process the instructions and records needed to execute your workflow and preserve its progress.
AI results may be inaccurate. Review outputs and proposed actions before relying on them. Do not submit sensitive information unless its processing is appropriate for your use and authorised by your organisation. Provider retention depends on the service and account settings; we do not promise that all processing has zero retention.
Who receives information
We share information where needed to operate the service, including with:
- WorkOS for account authentication and session management.
- Vercel for website and application hosting, request delivery and operational logs.
- Supabase for application data storage, including workspace records and workflow history.
- OpenAI for the AI, audio and operational tracing described above.
- Inngest for background workflow execution and execution history.
- Your organisation's authorised users and administrators, and services you instruct Hubbla to interact with.
We may also disclose information when required by law, to protect rights and security, to professional advisers, or in connection with a business transfer subject to appropriate confidentiality protections. External websites and services have their own privacy practices.
Cookies and external website content
Hubbla uses cookies and local device storage for sign-in, security and interface preferences. Blocking these can prevent the app from working correctly. Our current website does not use advertising trackers, and optional product analytics is not enabled. Some website media is loaded from external hosts, which receive request information such as your IP address and browser details when that media loads. Our homepage currently loads video from getindigo.ai.
Storage, security and international processing
We use access controls, encrypted connections and authentication protections to help protect information. No system can guarantee absolute security. Hubbla's application database is hosted in Australia. Other providers may process account information, requests, content or logs overseas, including in the United States and other locations used by their infrastructure and support teams. Australian database hosting does not mean all processing stays in Australia. Contact us for information about the providers and locations relevant to your use.
How long we keep information
We keep personal information for as long as reasonably needed to provide the service, maintain your account and workspace, meet legal obligations, resolve disputes and protect security. Retention depends on the information, its purpose, your organisation's instructions and applicable provider settings. Deleting a connection or signing out does not delete workspace content. Copies may remain for a limited period in logs, backups or provider systems according to their retention arrangements. Contact us to discuss deletion and applicable limits.
Your choices and privacy requests
You can choose whether to use Google sign-in or voice features, manage browser permissions, and ask us to access, correct or delete personal information. Depending on where you live, you may also have rights to object to or restrict processing, withdraw consent, or request a copy of your information. We may need to verify your identity and consider legal or contractual restrictions before acting on a request.
For an organisation-managed workspace, contact its administrator about workspace records and access. We may refer requests to that organisation where it controls the relevant data. Contact ash@hubbla.ai for privacy requests or complaints. We will investigate and respond. If you are dissatisfied, you can contact the privacy regulator in your jurisdiction, including the Office of the Australian Information Commissioner in Australia.
Children and policy updates
Hubbla is a business service and is not directed at children. Contact us if you believe a child has provided personal information without appropriate authorisation. We may update this policy as the service or our practices change. We will publish the updated policy here with a revised date and provide additional notice where required.
Privacy contact: ash@hubbla.ai.