Hubort Privacy Policy
The short version. Hubort has no server for your conversations. They are read from the AI service you are already signed in to, and written to a database on your own computer. Nothing about them is sent to us, and there is nothing for us to sell, share, or lose. The only conversation data that ever leaves your machine does so because you switched on an optional feature, and it goes to your account with that provider, not to ours. If you buy a licence, that purchase is the one thing we do receive — an email address and a record of what you bought, and nothing else. A licence bought once never makes the app contact us about it, not even to check that it is valid. A subscription makes one check a day, sending its licence key and nothing else, so that it can renew itself. And if you send us a problem report, or switch on usage reports, those reach us too — each only because you chose it, each shown to you in full, and neither containing your conversations. The same goes for leaving your address for reminders on our website, and for buying through a friend's referral link (section 15).
This policy covers both parts of Hubort: the browser extension (Chrome, Edge and other Chromium browsers, and Firefox) and the Hubort desktop application for Windows, which runs the local server the extension talks to. They are designed to work together and are described together here.
1. Who we are, and why this policy is short
Hubort is built and published by Muhammad Faizan Raza (“we”, “us”). You can reach us at [email protected].
Hubort is local-first software. We do not operate an account system or a data warehouse, and there is no analytics unless you switch on usage reports. There are three parts to what that means, and each is absolute rather than hedged.
Your conversations: still nothing, still nowhere. We never receive your conversations, your search queries, your account labels, or any identifier tied to them. Most of what a privacy policy normally has to explain — how long we keep your data, who we share it with, how to request deletion — does not apply to any of it, because we never hold it in the first place.
Your purchase, if you make one. Hubort is free for two accounts, and starts with 14 days of Pro that need nothing from you. A subscription or a one-time purchase lifts the limit. If you buy, the checkout runs on Paddle's own page, in your browser: Paddle is the seller of record and receives your name, email address, country and payment details. From that we receive an email address and a licence record, and we send you a licence key. We never see card details. We never link a purchase to conversation data, because we have none to link it to. If we give you a licence instead, we keep your name beside the same record. Section 6 sets out exactly what that involves.
What you choose to tell us. A problem report, the one question Hubort asks after a week, the one question after an uninstall, and the optional daily usage report reach us only when you send them or switch them on. None of them contains your conversations, their titles, your searches or your accounts' names, and each shows you what it holds before it goes. Section 12 says exactly what each one does, where it goes and how long it is kept.
2. What the browser extension reads
Once you install the extension in a browser profile, it uses that profile's existing signed-in session to read your own conversation data from each AI service you switch on in the extension — Claude, ChatGPT, Gemini, Grok, or any combination — the same data the website itself loads when you open your chat sidebar. Every service is off until you tick it, and your browser asks your permission before the extension can read that service's site at all. Specifically:
- Your conversation list: titles, conversation IDs, and created/updated timestamps.
- The full text of the messages in each conversation, both yours and the assistant's.
- The filenames of files attached to a conversation. The contents of attached files are not read.
- The titles and descriptions of tool or “steps” cards shown inside a conversation.
- Your current usage-limit status (how much of your rate limit is used, and when it resets), for Claude and Grok only.
- Each service's internal identifier for your account, and for you as the person signed in to it, so Hubort can recognise the same account when another browser syncs it. For Claude these come from the account details claude.ai's own website loads; for Gemini, from the page Gemini's own web app loads; for Grok, from the sign-in details grok.com's own website loads. In each case the name and email address in that answer are not kept.
ChatGPT. To read your conversations on chatgpt.com, the extension asks it for the short-lived access token its own website uses. That token is held in memory for the length of one sync and sent only back to chatgpt.com. It is never stored, and never sent to the Hubort app or anywhere else. The same answer from chatgpt.com also contains your session token, which the extension does not keep or use. Unticking a service withdraws its permission and stops all reading of its site; conversations already copied stay on your computer until you delete them.
Gemini. Gemini has no sign-in of its own to Hubort: the extension reads your conversations from gemini.google.com with the Google session that browser profile already holds. Every one of those reads has to carry the short-lived page token that Gemini's own web app puts in its page, so the extension reads that token from the page, holds it in memory for the length of one sync, and sends it only back to gemini.google.com. It is never stored, and never sent to the Hubort app or anywhere else. From the same page the extension reads Google's own numeric identifier for the account, which is how Hubort recognises that account when another browser syncs it. One browser profile can be signed in to several Google accounts at once, and you choose which of them Hubort syncs: when you open that list in the extension, it reads each signed-in account's email address purely so that the list can show you which account is which. That address is shown in the extension and nowhere else — it is not stored, not sent to the Hubort app, and not part of what identifies the account. The extension signs you into nothing, requests no Google account permissions, and reads no Google service other than Gemini.
Grok. The extension reads your conversations from grok.com with the session that browser profile already holds, and reads no token of any kind. From the sign-in details grok.com's own website loads, it keeps only xAI's identifier for you and, if your account belongs to a team, the team's; your name, email address and any X account linked to it, which the same answer contains, are not kept. It also asks grok.com how much of your account's query limit is used and when it resets, the same figure grok.com shows you when you reach it. Grok conversations held on X (x.com) are a separate history, and the extension does not read x.com at all.
While Claude is switched on, the extension also runs a small script on Claude's pages (claude.ai), and on no other site, that looks at exactly two on-screen elements — the “upgrade to keep chatting” dialog and the message composer's usage banner — solely to read the time a rate limit resets. It does not read the rest of the page, and it never reads your conversation transcript from the page.
If you enable the optional instant-sync feature, the extension additionally observes the address and success status of Claude's own conversation requests, and of ChatGPT's, Gemini's and Grok's while those services are switched on, so that it knows to re-check when you create, rename, pin, archive or delete a chat. It does not read the contents of those requests or responses.
3. Where that data goes
To exactly one place: the Hubort server running on your own computer, at
http://127.0.0.1 on port 8787 — or, if another Windows account on the same
computer is already using that port, the next free one up to 8796. Alongside the conversation
data, the extension sends the account label you gave that account in its popup,
so the app can tell your accounts apart; which service each conversation came
from, with that service's own identifiers for the account it was read from and for the person
signed in to it, so two accounts on one service are never mixed up and one account synced from
two browsers is recognised as one; whether each sync worked, as a short error
code and never the error's text, so the dashboard can tell you when an account has stopped
syncing; and the pairing token your Hubort
app issued to that browser profile, so the app only accepts data from browsers you have paired
with it.
127.0.0.1 is the loopback address — traffic to it never touches a network. It
cannot leave your computer, and it is not reachable by anyone else, including us.
4. What the desktop app stores, and where
The desktop app keeps everything in a single SQLite database file, hub.db, in
your local application-data folder (on Windows,
%LOCALAPPDATA%\com.hubort.desktop). It holds your synced conversations and
messages, the search index built from them, when each account last synced, and anything you create in the dashboard —
collections, notes, pins, ordering and settings. If you connect Google Drive (section 5), the
credentials for that live in a separate drive-config.json beside it.
If you use Related Chats, the database also holds what the app works out,
on your computer, about what each conversation is about: a list of numbers per conversation, and
the vocabulary it learnt them from, which is made of words from your own conversations. It is
worked out from nothing but your archive, sent nowhere, and erased with hub.db. If
you use Live Sync, its settings — the folder you chose and, for Notion, your
integration token and your consent — live in a separate live-sync.json beside the
database, and a Live Sync folder receives a Markdown copy of each conversation, inside a
Hubort folder in the place you picked. Those copies are ordinary files on your
computer: anything else that reads that folder, such as a note-taking app or a sync service you
have set up for it, reads them too.
Beside those is hub-identity.json: a random identifier and secret, created on
your computer, that let the app tell its own server apart from another Windows account's and
decide which browsers and dashboard windows it answers. The database also records each browser
you have paired, but only as a one-way hash of its token, never the token itself. None of this
ever leaves your computer.
If you use the MCP Connector (section 5), the database also records each AI app you connect, with only a one-way hash of its key, and what each one searched for and which conversations it read, so Settings can show you. That record stays on your computer, is kept for 90 days, and goes when you remove the app. When you choose Add Hubort to an app, Hubort adds one entry, holding that app's key, to the app's own settings file on your computer, keeps a copy of the file as it was, and changes nothing else in it; removing the app takes the entry out again.
The database also keeps a log of what happens in Hubort, as counts and dates: that the dashboard was opened, that a ChatGPT sync started failing and with which error code, which setup steps are done, which tips you have seen. Accounts in it are numbers, like “chatgpt#1”, never their names, and it never records conversation text, titles, searches, or the names of accounts, folders or notes. It keeps 90 days, and it stays on your computer: it is what a problem report's diagnostics and the optional usage report are made from, and nothing of it leaves unless you send one of those (section 12).
These files are yours. Deleting hub.db erases the entire archive.
5. The only nine things that use the internet
Everything above is local. These nine are the complete list of ways Hubort contacts anything outside your machine, and what each one involves.
A licence bought once adds nothing to this list: the checkout happens in your browser on Paddle's page, the key arrives by email, and the app checks it on your own computer. The trial and the free version add nothing either. A subscription adds the last row, a daily check for its renewed key, and only while the key you entered is a subscription (see section 6). Referrals and reminders add nothing to this list: the app works out a buyer's referral link on your own computer, and joining the reminders happens on our website, in your browser (section 15). Neither does asking for the download link to be emailed to you, or joining the Mac waiting list, which are forms on our website too.
| Feature | Default | What is transmitted, and to whom |
|---|---|---|
| Update check | On | The desktop app asks GitHub whether a newer release exists. GitHub receives what any web request reveals — your IP address and the app's version. No conversation data, no account data, nothing about your usage. We do not receive this; it is a plain download from a public releases page. |
| Ask Your Archive | Off | Only if you set it up with your own API key and turn it on. The search of your local
archive always happens on this computer. Two requests then go to the AI provider
you choose — Anthropic or OpenAI today — using
your own API key, billed to your own account with them. The first sends
your question on its own, to ask for a few related words to search for (Settings → Ask,
“Search related words too”, on by default, and you can switch it off); for a very
short follow-up it also sends your previous question. The second sends your question and a
handful of short excerpts from the matching conversations, to write the answer; for a
follow-up it also sends your last few questions and the answers you were given (at most
three of each, the answers cut short), so the provider can follow the thread. Hubort ships
with no key of its own and has no server of its own to route either through, so the
connection is directly between your computer and the provider you picked. Anything in an
excerpt that reads like a password, an API key or a card number is masked first. Your key is stored in its own file, ai-config.json, kept apart from
your conversation archive (hub.db); deleting that file, or using "Turn off
and forget every saved key" in Settings, removes it immediately, even while the app is
running. An offline "Mock" mode is also available, which sends nothing anywhere, for
trying the feature at no cost. |
| Live Sync to Notion | Off | Only if you set it up with an integration token you create in your own Notion
workspace, share a page with that integration, and then say yes to sending. From
then on, the conversations you chose — all of them, or those in folders you pick — are
copied into a database under that page, one page per conversation: its title, service,
account label, dates, link, Hubort folders and messages, kept up to date as they change.
They go to Notion Labs, Inc., which hosts your workspace, directly from
your computer; Hubort ships with no Notion credentials and nothing passes through us. A
conversation deleted from Hubort has its page moved to your Notion trash. Your token is
stored in its own file, live-sync.json, kept apart from your archive; "Stop and
forget the token" in Settings deletes it immediately, even while the app is running, and
leaves what is already in Notion for you to keep or delete there. Related Chats and Live
Sync to a folder send nothing anywhere and are not on this list. |
| Google Drive backup | Off | Only if you set it up. It uploads a copy of your hub.db archive — which
contains your conversations — to your own Google Drive, into the hidden
per-app storage area that only Hubort can see. It uses Google credentials
you create in your own Google Cloud project: Hubort ships with none,
so the connection is between your computer and your Google account, and no part of it
passes through us. Hubort requests only two permissions, to manage its own app-data
files and to show you which Google account is connected. You can disconnect it in the
app or revoke it at myaccount.google.com. |
| Error reports | Off | If the app, its local server or its dashboard window hits an error, it can send a diagnostic report. Nothing is ever transmitted without you explicitly saying yes when asked, and you can change that answer any time from the tray menu. That check sits on the app's connection to the provider itself, so no part of the app can send anything around it. A report holds the type of error, its message, the chain of function names that led to it, the local server's exit status, the app version, and your operating system's name and version. Before it can be sent it is stripped of your computer name, user account, file paths, email addresses, URLs, IDs and tokens; the server's own error output is filtered through a strict allow-list that keeps only error types, codes and route names and discards everything else, precisely so that a failed search cannot carry your search terms out with it; and the trail of actions leading up to an error keeps only what kind of action each was and when, never what was on screen. Like any connection to a website, a report reaches the provider from your IP address. The app marks every report as carrying no address, so none is attached to it and no location is looked up from it, and our account with the provider is set not to store IP addresses. Memory snapshots, usage pings and log forwarding are compiled out of the application entirely rather than merely switched off. Reports go to Sentry, an error-monitoring provider, not to a marketing or analytics service. |
| Problem reports | Only when you send one | When you choose Report a problem — in the dashboard's Help menu, beside an
account that has stopped syncing, on a failed action's notice, in the tray menu, after an
error report, or in the extension's popup — and press Send. Everything it holds is
shown to you first: what you wrote, your email address only if you type one, a screenshot
only if you add one, and diagnostics — the versions of Hubort, your browser and your
operating system, error codes, counts, settings that change how it behaves, the local
server's filtered error output, and each account as a number such as
“chatgpt#1”, never its name. From the app, the Hubort app sends it to our report
service at hubort.app. The extension sends nothing: it opens our report page in
your browser with its diagnostics after the # in the address, which a browser
never sends to any server, and the report goes only when you press Send on that page. The
one question Hubort asks after a week of use goes the same way, with only a random install
id and the app's version beside your answer. Section 12 says where reports go and how
long they are kept. |
| Usage reports | Off | Only if you turn on Share usage reports in Settings → Privacy. Once a day
the desktop app sends a summary of the log described in section 4: how many times each
kind of thing happened each day (the dashboard opened, a folder made, a ChatGPT sync that
started failing and its error code), how many accounts there are on each service, and when
each setup step first happened, with a random install id and the app's version, to our
service at hubort.app. Never conversation text, titles, searches, the names of
accounts, folders or notes, email addresses or keys. A beta tester who ticks attach my
beta licence adds that licence's id, so we can ask them what happened if setup stalls.
See what's sent, beside the switch, shows exactly what went last. Kept 12
months. |
| The question after an uninstall | When you uninstall | Uninstalling the extension or the desktop app opens a page on hubort.app in
your browser that asks one question: why. Opening it tells us which part was removed and its
version, and, as any web page does, reaches our host from your IP address, which we do not
record. Your answer is sent only if you give one. |
| Subscription check | Only with a subscription | Once a day, while the licence key entered in Hubort is a subscription's, the desktop
app sends that key to our licence service at hubort.app — the key and
nothing else: no identifier, no app version, nothing about this computer or how you use
Hubort. The service answers with the renewed key when there is one, or with nothing once
the subscription has ended, and then the app stops asking. The key holds your licence id,
email address and dates, all of which we already keep (section 6). Like any web
request, it reaches our service, which runs on Cloudflare, from your IP address; we record
neither the address nor the check. A licence bought once, the trial and the free version
never make this request. |
The MCP Connector (off by default) is not on that list, because Hubort itself sends nothing for it, but it is a way your conversations can leave your computer, so it belongs here. It lets AI apps on this computer that you connect yourself, such as Claude Code, Cursor or Codex, search and read your synced conversations by asking Hubort's local server. What such an app reads becomes part of its own conversation and goes wherever that app sends it: for most, the AI provider behind it, under that app's own terms. With an app that runs its model on this computer, it stays here. It is off until you switch it on in Settings → MCP Connector and agree to exactly that. Each app you connect gets its own key, sees only the accounts and folders you allow it, and can only search and read: it can never change, delete or export anything, or reach a setting. Anything in what it reads that looks like a password, an API key or a card number is masked first, as for Ask Your Archive. Settings lists every app you connected and what each one read, and removing one stops its key at once.
6. Buying a licence
Everything above applies whether or not you ever pay for anything. This section covers the one part of Hubort that involves us at all.
Where the checkout happens. On hubort.app, in your own
browser, on a page operated by Paddle.com Market Ltd, who act as the merchant
of record — that is, they are the seller, they take the payment, and they handle sales tax and
VAT. They receive your name, email address, country and payment details, and they process that
data as their own controller. Their privacy policy is at
paddle.com/legal/privacy.
There is no payment field anywhere inside the Hubort app, and never will be.
What we receive and keep. When a purchase completes, Paddle tells our licence service — a small hosted endpoint that exists only to answer that message — the transaction, what was bought, and (on our asking Paddle for it) the buyer's email address. We keep the email address, a licence id, what was bought, and the dates. For a subscription, Paddle also tells the service when it renews, changes plan, or is cancelled or paused, and we keep that status beside the licence so the daily check can answer. That is the whole record, and it is kept in our licence service's own storage on Cloudflare, which hosts it. We do not receive card details, a postal address, or anything about how you use Hubort. If you bought through a friend's referral link, or someone buys through yours, we also keep what section 15 describes. Our lawful basis is the contract between us; we keep the purchase record for as long as tax law requires invoices to be kept, and delete anything beyond that on request (see section 8).
Renewing or upgrading. These pay for a licence you already have, so the
checkout has to know which one. When you choose Renew or Upgrade to Pro in
Hubort, it opens our page in your browser with your licence key after the # in
the address — the part of an address a browser never sends to any server. The page hands the key
to Paddle's checkout, and Paddle passes it to our licence service with the purchase, which checks
it and sends the renewed or upgraded key to the address the licence belongs to. The key holds your
licence id, email address and dates, all of which we already keep. The app itself still makes no
network request: opening the page is your click.
How the key reaches you, and what it does. We email you a licence key, sent through Resend, an email delivery service, which receives your email address and the message in order to deliver it, and nothing else. You paste it into Hubort, which checks its signature on your own computer, against a key built into the app. For a licence bought once, the app makes no network request for licensing at any point — not when you enter a key, not when it starts, not ever. It does not phone home, count installs, or report which computer it is on, and a subscription's key does none of that either beyond its one daily check. Very little paid software can say that, and we would rather say it than have a convenient way to switch your copy off.
Subscriptions. A subscription is billed by Paddle, monthly or yearly,
until you cancel it. You change or cancel it in Paddle's customer portal, which
Manage subscription in Hubort opens in your browser (through
hubort.app/manage); cancelling stops the next charge, and what you have paid for
runs to its end. Its key renews itself: once a day the app sends the key to our licence service
and takes back the renewed one, as the last row of the table in section 5 describes. When
the subscription ends the check stops, and the key runs out on its own date, a few days after
the last period paid for.
The free trial. Every copy of Hubort starts with 14 days of Pro, counted on your computer from the first account it syncs. Nothing is sent to anyone to start it or to end it, and no email address or card is asked for: when it ends, Hubort goes back to the free version by itself.
A licence we give you. Sometimes we give a licence by hand rather than sell one: to someone testing Hubort before launch, or as a thank-you. (A licence earned through referrals is section 15's.) Then we keep your name and email address, the licence id, what it is, when we gave it and when we emailed it, in the same storage as the purchase records above. We keep it so that resend my key on our website can send the key again if you lose it, and so we know who we have given licences to. Nothing else goes with it, and nothing about how you use Hubort is added to it. The key is emailed through Resend, as a bought one is. Our lawful basis is our agreement to give you the licence. We keep the record until you ask us to delete it. The key itself keeps working after that, because Hubort checks it on your computer, but we can no longer send it again.
Refunds and support. If you write to us about a purchase, we hold that correspondence as any business does. Our refund policy and licence terms are in the Terms of Sale.
7. What never happens
- We never receive your conversations, message text, titles, search queries, notes, collections, or account labels. There is no server to receive them. A problem report carries only what you write in it and the diagnostics it shows you. The exceptions are yours to turn on (section 5): Ask Your Archive sends a few short excerpts of matching conversations — directly from your computer, using your own API key — to the AI provider you chose; Live Sync to Notion copies the conversations you chose into your own Notion workspace, with your own integration token; and with the MCP Connector, an AI app you connect on your computer reads the conversations it is allowed to and sends what it read wherever that app sends things. Never to us; we have nothing to do with any of those connections.
- Your session cookie is never read, stored, or transmitted by Hubort. Your browser attaches it to requests to the AI service exactly as it does when you browse there yourself. The one credential the extension handles is ChatGPT's short-lived access token, held in memory for one sync and sent only back to chatgpt.com, as described in section 2.
- Nothing is ever written back to your AI account. Hubort never sends, edits, renames, archives or deletes anything there. It only reads.
- There is no advertising, no analytics, no telemetry, no tracking pixel, and no fingerprinting anywhere in the extension, and nothing in the app that sends usage data unless you switch on usage reports.
- Your data is never sold, rented, shared with third parties, used to train any model, or used for any purpose other than showing it back to you in your own dashboard.
- The extension does not read pages other than the AI services it supports, does not access your browsing history, bookmarks, downloads, or passwords, and — beyond the conversation-request observation described in section 2, which only runs for a service you've switched on if you also turn on instant sync — does not observe any other network requests.
- The extension loads no remote code. Everything it runs ships inside the reviewed, published package.
8. Your control
- Stop all reading: remove the extension from that browser profile, or turn off syncing in its settings. Either takes effect immediately.
- Erase the archive: delete
hub.db, or uninstall the desktop app and remove its data folder. - Remove a single account: delete it from the dashboard, which removes that account's conversations, messages and search entries. A browser that is still syncing that account puts its conversations back on its next sync, so remove the extension from that browser profile first if you want the account gone for good.
- Disconnect Google Drive: disconnect in the app, and revoke access at myaccount.google.com. Note that revoking access also deletes the backups Google was holding for the app.
- Stop error reports: turn off Send Error Reports in the tray menu. Any reports still waiting are deleted.
- Stop usage reports: turn off Share usage reports in Settings → Privacy; nothing more is sent. Reset the install id there to cut the link between anything sent before and anything sent after.
- Have a problem report deleted: write to [email protected] quoting its reference, such as HB-0142, and we delete it, its screenshot and its copy on GitHub.
- Stop Ask Your Archive: choose Forget this key in Settings → Ask Your Archive. Your API key and your consent are deleted from this computer and the feature switches off; without a key it can send nothing, and it never could before you set one.
- Stop Live Sync: choose Stop and forget for the folder, or Stop and forget the token for Notion, in Settings → Data. Hubort stops updating it at once and, for Notion, deletes your token and consent from this computer. What it already wrote stays where it is — the files in your folder, the database in your Notion workspace — for you to keep or delete.
- Stop the MCP Connector: switch it off in Settings → MCP Connector, and every app you connected stops reading at its next request; or remove one app there, and its key stops working at once and its record of what it read is deleted. What an app already read is in that app's own history, under its own controls.
- Remove your licence key: delete it in Settings → Licence, or from the tray. Hubort goes back to the free version, nothing on your computer is deleted, and a subscription's daily check stops with it.
- Cancel a subscription: Manage subscription in Settings → Licence opens Paddle's customer portal. Cancelling stops the next charge, and the daily check stops once the subscription has ended.
- Stop reminders: use the unsubscribe link in any of them, or your email program's own Unsubscribe button. Every reminder stops at once. To have your address deleted from the list as well, write to [email protected].
Of your conversation data we hold nothing, so there is nothing for us to export or delete on your behalf, and no account for you to close. If you are in a jurisdiction with statutory data rights, this is our answer to them: we are not a controller or processor of your conversation data, because it never reaches us.
If you have bought a licence, we do hold your email address and the record of that purchase, with a subscription's status (section 6). Ask, and we will tell you exactly what that is, correct it, or delete it — with one honest exception: invoice records we are legally required to keep for a set number of years, which we keep and use for nothing else. Paddle holds its own copy of the purchase as the seller of record; their policy covers that. A licence we gave you has no invoice, so its record, your name included, is deleted whenever you ask.
9. Automated access to AI services — please read
Hubort works by reading the AI service's own web interface automatically, on a schedule, using your signed-in session. That is what allows it to keep an up-to-date searchable copy of your conversations without you exporting them by hand.
The terms of service of AI providers commonly restrict automated or scripted access to their services, and reserve the right to act against accounts that use it. Using Hubort may therefore be inconsistent with your provider's terms, and any consequence of that would apply to your account with that provider, not to your Hubort installation. We cannot indemnify you against that, and we would rather you know it before you install than after.
You can reduce automated activity by lengthening the sync interval in the extension's settings, up to once an hour, or stop it for a service altogether by unticking that service in the extension.
10. Not affiliated with any AI provider
Hubort is an independent product. It is not affiliated with, endorsed by, sponsored by, or connected to Anthropic, OpenAI, Google, xAI, or any other AI provider. All product names and trademarks belong to their respective owners and are used only to describe what Hubort is compatible with.
11. Children
Hubort is not directed at children under 13, and we do not knowingly collect information from anyone — which, as described above, includes not collecting information from adults either. Purchases are for adults: to buy a licence you must be old enough to enter a contract where you live, and the checkout is governed by Paddle's own terms as the seller.
12. Problem reports and usage reports (only when you send them)
What a problem report contains is in section 5's table, and you see all of it, as the exact text that will be sent, before it goes. Your email address is in it only if you type it, and is used to acknowledge the report and to reply to you, nothing else.
Where it goes. To our report service on Cloudflare, at
hubort.app, which keeps it, and any screenshot, in its own storage there. The report,
without your email address or your screenshot, is also filed as an issue in a private GitHub
repository that only we can read, where reports about the same problem are grouped together;
GitHub hosts it. If you gave an address, Resend delivers our acknowledgement
with the report's reference, and we reply from [email protected]. An address is acknowledged at
most once a day, however many reports name it, so the form can't be used to mail someone over and
over; to know that, the report service keeps a one-way hash of the address for 24 hours, then
forgets it. We may use AI tools on our own computers to help read reports; no AI service is part
of the report service itself.
How long. A report, its screenshot, and its copy on GitHub are deleted 12 months after it was sent, automatically. To have one deleted sooner, write to us quoting its reference, such as HB-0142. The one question asked after a week, and the one asked after an uninstall, are kept the same 12 months, with no name or address beside them.
Usage reports are stored one per install per day, under the random install id, and deleted after 12 months. Turning the switch off stops them at once; resetting the install id means nothing sent before can be connected to anything sent after. Our basis for keeping any of this is your choice to send it.
13. Changes to this policy
If we change this policy we will update the date at the top of this page. If a change ever means Hubort starts transmitting something it did not transmit before, we will say so plainly here and in the application, and where the change concerns your personal data we will ask before it takes effect rather than assume.
What changed, 7 October 2026. This is the kind of change this section exists for. Hubort gained the MCP Connector, a Pro feature that lets AI apps on your computer that you connect yourself, such as Claude Code, Cursor or Codex, search and read your synced conversations. Hubort sends nothing anywhere for it, so the list of nine things in section 5 is the same, but what a connected app reads goes wherever that app sends it, usually its AI provider. It is off until you switch it on and agree to that. Section 5 describes it, section 4 what it records on your computer, and section 8 how to stop it.
What changed, 6 October 2026. Section 15 now describes Hubort's Climb, a game in the dashboard whose discount is claimed on hubort.app and joins the reminders list. The application's own behaviour is unchanged: it still makes no request about licences or discounts, and the list of nine things in section 5 is the same.
What changed, 1 October 2026. Nothing about the app or the extension, and nothing new leaves anyone's computer. When we give someone a licence by hand rather than sell one, we now keep a record of it, with their name and email address, so resend my key can find it. Section 6 says what is kept, and section 8 how to have it deleted. Until now such a licence was emailed by us personally and not recorded by our licence service at all.
What changed, 30 September 2026, later the same day. A correction to section 5's row for Ask Your Archive, and no change to what the app does. It said that finding what might answer your question always happens on your computer, and that the provider receives your question with the excerpts. Both are true of the search and of the answer, but the app also sends your question on its own, first, to ask the provider for related words to search for, unless you switch that off. It also sends, for a follow-up, your last few questions and the answers you were given, which are drawn from earlier excerpts. The row now says both, and where the switch is. No excerpt is sent in that first request.
What changed, 30 September 2026. Nothing about the app or the extension. Our
website gained a form, Email me the link, for someone who finds Hubort on a phone:
you give an address, we email a link to confirm it is yours, then email the download page once,
and delete the address. Section 15 says what we keep while that happens. It also gained a
Mac waiting list, at hubort.app/mac, described in section 15,
with the date it ends: 30 September 2028 at the latest. The website's
download button now goes through hubort.app/download/latest, which counts presses as
a total for the day and for the version and nothing else; section 14 describes it.
What changed, 29 September 2026. A correction to section 9. It said scheduled syncing could be turned off entirely; the extension has never had that setting. It now says what you can do: lengthen the interval to up to an hour, or untick a service to stop syncing it. Nothing about what is sent or kept changed.
What changed, 28 September 2026. Only a name: the app's button that opens our reminders and referral page is now called Get my link. Nothing about what is sent or kept changed.
What changed, 26 September 2026. Two optional things on our side, and nothing about the app's network use. You can leave your address on our website for reminders (before your trial ends, and a month before a licence bought once stops covering new releases) and a referral link; and a purchase made through someone's referral link is now recorded with that link's code, so its owner can be rewarded. Section 15 says what we keep for each, and how to stop it. Buyers of a licence bought once also get the one reminder about their updates ending, with an unsubscribe link. The app shows a buyer's referral link without asking anyone, and opens our website for the rest.
What changed, 25 September 2026. The website is live, and section 14 now describes it: cookieless visit counting with Cloudflare Web Analytics, and Cloudflare Turnstile on its forms. Nothing about the app or the extension changed.
What changed, 24 September 2026, later the same day. This is the kind of change this section exists for. Hubort can now send us things you choose to send: problem reports, from the app or from the extension (whose report opens our page in your browser rather than sending anything itself), and the one question asked after a week; an optional daily usage report, off until you turn it on; and, after an uninstall, a page with one question. Each has its own row in section 5's table, and section 12 says where they go and how long they are kept. The app also now keeps a log of what happens in it, as counts and dates, on your computer (section 4); it leaves only inside a report you send or a usage report you switched on.
What changed, 24 September 2026. Two new Pro features, and one of them is the kind of change this section exists for. Live Sync can keep your own Notion workspace up to date with your conversations: it is off until you create an integration in Notion, give Hubort its token, and say yes to sending, and it has its own row in section 5's table. Live Sync can also keep a folder on your computer up to date with Markdown copies, which sends nothing anywhere (section 4). Related Chats works out which of your conversations are about the same thing, entirely on your computer, and sends nothing anywhere either (section 4 says what it keeps).
What changed, 23 September 2026. This is the kind of change this section exists for, in one narrow place. Hubort now sells monthly and yearly subscriptions beside the licence bought once, and a subscription's key renews itself: once a day, and only while the key you entered is a subscription's, the app sends that key, and nothing else, to our licence service for the renewed one. It is the last row of section 5's table. Until now this policy said the app makes no network request for licensing at all. That is still true of a licence bought once, of the trial and of the free version; a subscription makes its check because you chose one, and Hubort says so in its Licence settings and in the email that brings the key. The trial also became automatic: 14 days of Pro from the first account you sync, with no email asked for (section 6). (24 September 2026: the email service that delivers keys, Resend, is now named in section 6, and the contact address is [email protected].)
What changed, 22 September 2026. Two things, and one of them is the kind of change this section exists for. Hubort gained Ask Your Archive, the first feature that can send anything drawn from your conversations anywhere: it is off until you set it up with an API key of your own, and then it sends your question and short excerpts to the AI provider you chose and pay — never to us. It has its own row in section 5's table, which describes exactly what goes and what is stripped out first, and section 8 says how to switch it off for good.
Hubort also gained a paid tier, so this policy gained section 6: buying a licence means Paddle receives your payment details as the seller of record, and we receive an email address and a record of the purchase. Nothing about how the application handles your conversations changed for it, and the application still makes no network request for licensing. (23 September 2026: a Personal licence can now be upgraded to Pro, and renewing or upgrading gives our checkout page your key, as section 6 describes.)
14. The website, hubort.app
The website is separate from the app and the extension, and nothing on it can read your conversations. It is hosted by Cloudflare, which, like any web host, sees your IP address and browser in order to serve the page.
Counting downloads. The download button on hubort.app/download is
a link to hubort.app/download/latest, which sends your browser on to the newest
installer on GitHub. It adds one to a running total for the day and for the version, and keeps
nothing about you: no address, no browser details, no record of which request it was. Requests
that say they come from a crawler or a link checker are sent on without being counted. GitHub, which
serves the installer, sees the request as it would from any download link (section 5's first
row). The plain link to the releases page under the button goes straight to GitHub.
Counting visits. We use Cloudflare Web Analytics to see which pages are read, which site sent people to them, roughly where visitors are (by country), what kind of device and browser they use, and how quickly pages load. It sets no cookies, stores nothing in your browser and does not fingerprint you, so it cannot recognise you from one visit to the next or follow you to other sites: we see totals, not people. There is no advertising and no cross-site tracking on the site.
What else a page loads. Fonts are served from hubort.app itself.
The pricing, renewal and upgrade pages load Paddle's checkout (section 6), and only once you
reach for a buy button. A referral link (hubort.app/r/…) keeps its code in
your browser's local storage for 60 days, so that the pricing page can apply your friend's
discount: it is not a cookie, only our own pages read it, and it goes to Paddle with your
checkout (section 15). The report page, the question after an uninstall, the reminders form,
the form that emails the download link, the Mac list's form and the form that re-sends a licence key use
Cloudflare Turnstile to tell people from automated
abuse; it checks your browser, usually without asking you anything, and is not used to track
you. The download-link form loads Turnstile only when you open it. What those forms send is
described in sections 6, 12 and 15.
15. Reminders, referrals, the download link, the Mac list and the game (only if you use them)
Reminders. On hubort.app/remind you can leave your email address
for a few reminders. Hubort's Get my link button only opens that page in your browser,
with your trial's end date after the # in the address, the part a browser never
sends anywhere; the app itself sends nothing, and you type the address in yourself. We then email
a link to confirm it is yours, and send nothing else until you do. After that you get your own
referral link, a reminder three days before your trial ends and one the day after (not if you
have bought by then), and a note when a friend's purchase through your link counts. There is no
newsletter. If you bought a licence once, we also email you once, a month before its twelve
months of updates end, whether or not you joined. Every one of these emails has an unsubscribe
link, and your email program's own Unsubscribe button works too.
For this we keep your email address, the date your trial ends if the page was given one, whether you confirmed, a random token for your confirm and unsubscribe links, your referral code and how many referrals have counted. It is kept in our licence service's storage on Cloudflare, and the emails are sent through Resend, as licence keys are (section 6). Our lawful basis is your consent, and for the reminder about a licence's updates, our legitimate interest in telling a customer about what they bought, which you can refuse with one click. When you unsubscribe we stop at once, and keep only what honouring that and any reward you have earned needs; ask, and we delete the rest.
Email me the link. Hubort is a Windows app, so someone who finds it on a
phone can leave an address on hubort.app, on the home page or the download page, to
have the download page emailed to them. We email a link to confirm the address is theirs, and
when they use it, one more email with the link to the download page. Nothing else is ever sent
because of this: it is not a list, and it does not sign you up for reminders or anything else. For
this we keep the address, and a random token for the confirm link, in our licence service's
storage on Cloudflare, and the emails are sent through Resend, as licence keys
are (section 6). We delete the address and the token the moment the second email has been
sent, and Cloudflare's storage deletes an address that was never confirmed after seven days. Our
lawful basis is your request. Resend keeps its own record of the two messages it delivered, as
section 6 describes for licence emails.
The Mac waiting list. Hubort is Windows only today. On hubort.app/mac
you can leave an address to be told the day a Mac version exists. We email a link to confirm the
address is yours, and when you use it, one email saying you are on the list, with a link to leave
it. After that we write once, when a Mac version can be downloaded, and never otherwise. It is
not a newsletter and it is not the reminders list. We keep the address, a random token for the
confirm and leave links, whether it is confirmed and the dates, in our licence service's storage
on Cloudflare, and a running count of confirmed addresses, which is how we tell whether a Mac
version is wanted. The emails go through Resend (section 6). An address that
is never confirmed is deleted by that storage after seven days. Leaving deletes the address at
once, and nothing is kept in its place. How long the list lasts: we keep an
address until we have written to you about the Mac version, or you leave, or
30 September 2028, whichever comes first, and we delete the whole list
then if no Mac version has been released. We look at the list on 30 September 2027, and
if we have decided by then not to build a Mac version, we delete it that day. Our lawful basis is
your consent.
Referral links. A buyer's link is worked out from their licence id, on their own computer; someone on the reminders list gets a random one. When a friend opens a link, our site keeps its code in their browser (section 14), and if they buy, the code goes to Paddle with their checkout and on to our licence service with the purchase. With that purchase we then keep the code, a one-way hash of the buyer's email address, so that each friend counts once and nobody can refer themselves, and when the purchase counts: once its 30-day refund window has passed. We tell the link's owner that a referral counted, and never who bought.
Rewards. We give them through the same systems as a purchase. A licence bought once gets a new key with later updates, emailed to you. A subscriber's free month is a discount our licence service asks Paddle to put on your subscription's next renewal. A reward for someone who hasn't bought yet is a single-use discount code created in Paddle, and at four referrals a year of Hubort Personal, as a licence key. Paddle, as the seller, sees these discounts as part of the purchase; nothing else about you goes to anyone.
Hubort's Climb. Hubort's Climb is a small game in the dashboard, free for
everyone. It runs on your computer and sends nothing, and what it remembers (which rooms you have
cleared, and the key presses of one winning attempt at each) stays in the dashboard's storage on
this computer. If you have cleared enough rooms, a button offers a discount on a first payment.
It only opens hubort.app/play in your browser with those key presses after the
#, the part a browser never sends anywhere, so the app itself still sends nothing.
You type your email address into that page yourself. Our licence service replays the key presses,
which is how it knows what you cleared, and ignores everything else in the request. We then email
a link to confirm the address, and when you press its button the address also joins the
reminders list described above, with its referral link and its unsubscribe link, and a
single-use discount code for a first payment is emailed to you. A bigger rung later replaces the
code. For this we keep, in addition to what the reminders list keeps, the best rung you have
claimed and its code, and a one-way hash of each claim, so one claim pays one address; we do not
keep the key presses themselves once they have been replayed. The lawful basis, retention and
deletion are as for the reminders list, and the code is created in Paddle, as above. The game's
discount is not a referral and does not count towards one.
16. Contact
Questions about this policy, or about anything above: [email protected].