Hubitos collects only the information needed to operate the workspace and connected publishing workflows.
- Account information such as name, email address, user identifier, and workspace preferences.
- User-provided content such as prompts, draft posts, captions, uploaded attachments, generated files, and workflow configuration.
- Authorization metadata from connected services, including provider name, granted scopes, connected account identifiers, and token status.
- Basic product usage and diagnostic information such as feature events, error logs, device or browser information, and app version.
Data is used to deliver Hubitos features, protect user sessions, and provide support.
- To create, save, reopen, and synchronize conversations, workflows, toolkits, generated files, and user preferences.
- To process user instructions and attachments so AI assistants can draft, summarize, transform, and organize user-requested work.
- To authenticate users, prevent misuse, investigate errors, and maintain reliable service behavior.
- To respond to support requests, troubleshoot reported issues, and communicate important product or policy updates.
When a user connects a Meta family service, Hubitos uses the granted permissions only for user-directed workspace and publishing actions.
- Hubitos requests only the permissions required for the feature the user chooses, such as identifying the connected account or preparing and publishing user-approved content.
- Authorization data may be used to display connected account status, draft or publish content, read permitted publishing metadata, and keep the user-requested workflow connected.
- Hubitos does not sell Meta authorization data and does not share it with third parties except service providers needed to operate the product or when required by law.
Access tokens are treated as sensitive credentials.
- Hubitos may store access tokens only when needed to maintain a user-authorized connection or complete a user-requested workflow.
- Stored tokens are protected using reasonable technical controls and are not exposed in public pages, logs intended for users, or marketing material.
- Tokens are retained only while the connection is active or as needed to complete requested actions, then removed or invalidated when access is revoked or no longer necessary.
Users remain in control of connected accounts.
- Where available, users can disconnect a provider inside Hubitos account authorization or settings surfaces.
- Users can also revoke Hubitos access from the relevant Meta, Facebook, Instagram, or Threads account settings for connected apps and websites.
Users may request deletion of personal data associated with their Hubitos account or connected social authorization.
- Send a deletion request to the support email listed below and include the Hubitos account email plus the connected provider to identify the data.
- Hubitos will process verified deletion requests within a reasonable period and confirm completion when the request is resolved.
- Some information may be retained when required for security, fraud prevention, legal compliance, billing records, or backup integrity.