Version: 1.21.0 Effective date: September 10, 2026 Contact: hello@freesocialhub.app
Production privacy notice for FreeSocial Hub. Have qualified counsel review for your jurisdiction.
1. Who we are
FreeSocial Hub (“we”, “us”) provides Hubly — free AI Agents for browser work under watch-and-takeover (Chrome, Edge, Firefox including Android, and Safari on iPhone/iPad/Mac) — plus the Hub app (website and optional PWA) to manage specialists, chat, queue work, and review site runs. Phone and the Hub app manage and queue; execution happens in a browser that can run the Hubly extension, not inside the installed Hub app. You may bring your own AI provider keys (BYOK), including multiple keys per provider, and choose models. Contact: hello@freesocialhub.app.
2. Data we collect
- Account: name, email, optional profile photo (you upload it, Google may provide one if you continue with Google, or we show our default icon), age verification timestamp, ToS/Privacy/AUP version accepted; optional authenticator (TOTP) factors managed by our auth provider when you enable 2FA
- Optional device unlock: if you turn on Face ID / Touch ID / Windows Hello for Hub (website/PWA) or a local Hubly panel PIN, unlock keys or a PIN hash stay on that device/browser only — we do not receive biometric templates or your PIN
- Workspace content: Brand Kit / AI profiles, knowledge Sources, specialist briefs and schedules, specialist chat messages, Hub Chat / queued goals, agent session/action/timeline metadata, agent memory notes (host, intent, viewport size, selectors) for adaptive assist, work-log metadata (hosts, titles, statuses, summaries), Teach abilities (private recipes keyed to domain + subdomain), unique Title/Body campaign drafts, and related workspace utilities you use
- Connected accounts: OAuth tokens (when a Hub OAuth path is enabled), account IDs, scopes, and BYOK API keys you provide (encrypted at rest). You may store multiple keys per AI provider; we may store a label, fingerprint, health/status, and last-used timestamp — never the secret in logs or in the run meter
- Hubly (browser extension): session access token stored locally in your browser to call Hub APIs; community/group/channel names and URLs you explicitly extract or add from pages you are already viewing (user-confirmed); campaign work-queue URLs you queue; unique Title/Body drafts for a run (workspace/session only — never public recipe copy); Source text and visible form field labels/types/options you choose to Check & Fill on non-restricted sites (not passwords or payment fields; never auto-submit); agent plans/actions you initiate; which ability/Source/specialist IDs you @ mention or pin; pending specialist inbox items queued from Hub for Act specialists. When you use Teach, Hubly records clicks and field names and stores a private workspace ability keyed to domain + subdomain. Typed copy, emails, passwords, cookies, and message bodies are stripped. A sanitized public recipe (names/roles/actions only) may be shared. The Hubly run meter may show model name, a key label or fingerprint (not the secret), and success/failure. Hubly does not background-scrape browsing history. Hubly does not automate on restricted government, healthcare/patient-portal, banking, or adult hosts — see §3b. Full Auto Ask preferences are stored locally in the extension. On agent, specialist, and Teach runs (not personal conversation archives), Hubly may capture key screenshots of the active tab and send them only to the Hub/BYOK model for that call. Screenshots are not stored in our database, not written into public abilities, and not shared with other users. Personal conversation archives never send chat pixels or message bodies to AI. The same Hubly software is packaged for Chrome, Microsoft Edge, Firefox (desktop and Android), and Safari (iOS, iPadOS, macOS).
- Personal conversation archive: if you ask Hubly to export a conversation you are a party to, Hubly can save a transcript and files into your browser Downloads. That copy stays on your device. We do not upload message bodies, attachments, or inbox contents to FreeSocial Hub, and we do not send them to Hub/BYOK AI. You confirm before the export. Full-account dumps use each platform’s official takeout tools.
- Hub / PWA: device and display mode (browser vs installed app) used to show whether Hubly can execute on this device; Web Push subscription endpoints/keys when you enable notifications; notification preference categories (e.g. agent due, specialists finished). Signing out clears this device’s push subscription so alerts stop here; other signed-in devices keep theirs
- Usage: first-party cookieless product analytics (page view, scroll depth, section id, CTA label, UTM/referrer as present). No advertising cookies. No visitor id in cookies, localStorage, or sessionStorage. The server may derive a daily rotating hash from IP and user-agent for abuse/ops. Global Privacy Control / Do Not Track reduces some engagement events. IP for security/abuse
- Billing: Stripe customer/subscription IDs when paid plans are enabled (card data handled by Stripe)
- Growth / referrals: referral codes, redemptions, bonus Hub AI credit balances, and optional soft Pro unlock windows
- Hub AI credits: monthly credit balances, daily usage counts, and feature labels for Hub-paid AI actions (BYOK usage is not stored in this ledger)
- Specialist packs: if you publish a Hubly specialist or team, we store a snapshot of names, standing briefs, tags, rhythm, work class, optional start URL, and share visibility. Public catalog pages show names and descriptions only. Importers copy briefs into their own workspace. We do not share your runs, chats, API keys, or OAuth tokens. Ratings are 1–5 stars from accounts that imported the pack. You can revoke a link anytime.
- Activation checklist: workspace milestone timestamps used to guide setup
Optional or legacy Hub tools (if you still use them via API or older clients) may also store contacts, community dossiers, campaign drafts, or messaging drafts you create — private to your workspace.
3. How we use data
Provide the Service; authenticate; AI assistance and media generation; Hubly chat/agent assist, Sources retrieval, Teach/abilities, unique campaign drafts, specialist chat, queue/claim of Hub jobs, and work-log views; adaptive agent memory; collaboration invites; specialist pack share/import/ratings; referral rewards; activation guidance; push notifications; fraud prevention; legal compliance; improve the Service (aggregated/de-identified where possible).
3a. Chrome Web Store Limited Use
When you use Hubly, the use of information received from Google APIs and page content you choose to extract, Check & Fill, Teach, or automate under watch-and-takeover will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell user data, use it for personalized ads, or transfer it to data brokers. Community extract, Sources fill, Teach demos, and agent steps are user-initiated (or scheduled by you) on the active tab. Field schemas, selected Sources, pinned ability IDs, specialist context, compact page observations, and optional key screenshots of the active tab for the current agent call may be sent to Hub/BYOK AI solely to provide that agent feature — screenshots are not stored in our database. Hubly never submits forms or completes high-risk actions without confirmation. Saving Sources, abilities, and schedules requires your FreeSocial Hub account.
3b. Restricted sites (government, healthcare, banking, adult)
To reduce legal risk and protect you and us:
- Government sites (hostnames ending in `.gov` or `.mil`, or containing `.gov.`, including portals such as login.gov): Hubly refuses agent automation, Check & Fill, and all form submission — including benefit applications. Complete those forms yourself in your browser.
- Healthcare / patient portals: Hubly refuses automation and Check & Fill. FreeSocial Hub is not a HIPAA business associate for covered-entity clinical workflows; we do not process protected health information (PHI) from those pages through Hub/BYOK AI.
- Banking / payment hosts: Hubly refuses automation.
- Adult / explicit hosts: Hubly is off (no navigation, drafts, or search through those sites).
These blocks are enforced in the Hubly extension and Hub APIs. Prompts, drafts, media, search, and agent work may be refused when they request sexual content, content involving minors, suicide or self-harm assistance, graphic violence, or other illegal uses. Full Auto Ask preferences and a one-time Full Auto acknowledgment are stored locally in the extension.
3c. Scheduled runs
Specialist schedules (on-demand, daily, or always-on) are stored in your workspace. Page clicks still execute only in a browser with Hubly installed and open. Cloud jobs mark a specialist as due and may send a Web Push if you enabled notifications. Browser alarms and push do not wake a sleeping computer or closed laptop lid. The Hub website and installed app can chat and queue; they cannot operate third-party sites. You may leave a computer on with Hubly, including a machine you host yourself. We do not run a hosted cloud browser for you.
3d. Reports
To report illegal content on the Service (including child sexual exploitation or non-consensual intimate imagery), email hello@freesocialhub.app. We will review and, where required, remove promptly. Where required by law, we may report apparent child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC) or other authorities.
4. Legal bases (GDPR)
Contract, consent (e.g., optional analytics cookies, marketing, push notifications), legitimate interests (security, product improvement), legal obligation.
5. Sharing
- Subprocessors: Supabase (auth, database, storage), Cloudflare (hosting, CDN, Workers), Resend (transactional email), Stripe (when billing is enabled), Google (Gemini / APIs), and other AI or platform providers you choose to connect with your own keys
- Team members you invite to a Workspace
- Law enforcement when required
We do not sell personal information. CCPA/CPRA and similar laws: “Do Not Sell or Share” is the default. Requests and cookie choices: https://freesocialhub.app/legal/privacy-choices or hello@freesocialhub.app.
6. Contacts & optional messaging data
If you use optional contact or messaging features, that data is private to each Workspace by default. We do not force contribution to any shared database. You must only import contacts you are lawfully allowed to use. Where SMS/gateway paths exist, you confirm sends; Hub does not auto-send SMS on your behalf without your action.
7. AI processing
Prompts, attachments, Sources you select or @ mention, form field schemas (not passwords/payment values), compact page observations for agent planning, optional key screenshots of the active tab for the current agent/specialist call (not retained in our database; never from a personal conversation archive), short web-search queries, pinned Teach ability IDs, specialist chat messages, unique Title/Body drafts you request, and relevant workspace context may be sent to Hub Gemini or your BYOK providers to generate outputs. We may store Hub AI credit consumption events to enforce plan limits. Free-tier Gemini and third-party providers have their own data-use terms—review those policies. Do not put secrets you cannot share with processors into Sources.
8. Cookies
Essential cookies for auth/session and preferences (including theme). First-party product analytics on the marketing site and in-product are cookieless (no advertising cookies; no stored visitor id). Marketing cookies, if introduced, only with consent where required. Manage via the cookie banner or Privacy choices. California residents: we do not sell or share personal information for cross-context behavioral advertising.
9. Retention
Account, workspace, profile photo, Hubly cloud session metadata, BYOK key material, and related personal data are kept while the account is open. After you delete the account we erase that data without undue delay and within 30 days (GDPR / UK GDPR Art. 12 and 17), except where a shorter product path already completed the erase immediately.
We may retain hashed deletion records (no name, no email, no photo) to prove the request was honored. Stripe may retain invoices, tax, and anti-fraud records under US and other financial-record rules (typically up to 7 years). Security/abuse logs that cannot identify you after hashing may be kept up to 24 months. Legal holds override erasure only to the extent the law requires.
Hubly installed in a browser keeps a local session token and optional panel PIN on that device until you remove the extension or clear site data. We cannot remotely wipe a copy that only exists on your phone or computer.
10. Account and data deletion
You can delete your account regardless of country. This is a real erase — not a freeze or pause.
In the product (Hub website, PWA, and Hubly’s linked Hub Settings): Settings → Delete account. Type DELETE. If you turned on authenticator 2FA, confirm the code first.
On the open web (no app install required): https://freesocialhub.app/account/delete — sign in to delete immediately, or enter your email for a 24-hour confirmation link. You may also email hello@freesocialhub.app from the account address with the subject “Delete my account.”
What is deleted: your profile (name, email on our records, photo), workspaces you own and their content, specialist packs and playbooks you published, Hubly cloud transcripts and work logs we store, BYOK API keys we encrypted, push subscriptions, referral codes tied to you, and Hub AI credit ledgers. Teammates keep workspaces they own; your membership there is removed and your name/photo stop appearing.
What may remain: Stripe invoices and payment-processor records required by tax/finance law; hashed deletion-log rows; information you posted on third-party sites while using Hubly (those sites are not us — delete there separately); files Hubly saved into your computer’s Downloads.
We cancel paid Hub subscriptions at deletion so you are not billed afterward. Apple/Google in-app purchases, if any in a future store listing, remain managed on those stores.
EU/EEA/UK: erasure under GDPR/UK GDPR. California and other US state privacy laws: deletion/know/correct/opt-out. Brazil LGPD, Canada PIPEDA, and Australia Privacy Act requests use the same form. We do not require you to live in a specific region.
11. Your rights
Access, rectification, deletion, portability, restriction, objection, withdraw consent. Use Settings, Privacy choices, account deletion, or hello@freesocialhub.app. EU/UK users may complain to a supervisory authority. California residents: CCPA/CPRA rights including know/delete/correct/opt-out of sale/share (we do not sell or share).
12. International transfers
Data may be processed in the US and other countries with appropriate safeguards (SCCs where required).
13. Children
Service is 18+ only. We do not knowingly collect data from anyone under 18. We do not generate sexual content involving minors (including fictional depictions) and we refuse related agent work.
14. Security
Encryption in transit; encrypted tokens/keys at rest; row-level security where applicable; access controls. Optional account 2FA (authenticator app) and optional local device unlock are available in Hub Settings → Security; sensitive account actions may require a fresh authenticator confirmation when 2FA is enabled. Report: hello@freesocialhub.app.
15. Changes
We will update this Policy and bump the Privacy version shown in-product. Material changes notified in-product or email.
16. Contact
hello@freesocialhub.app