Skip to main content
← Back to RetroHub AI

Privacy Policy

Last updated: May 5, 2026

Retro Hub AI Inc. ("we," "our," or "us"), a corporation incorporated in British Columbia, Canada (Business Number 719420036RC0001), operates the RetroHub AI platform available at retrohubai.com and dev.retrohubai.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this policy carefully. By using RetroHub AI you agree to the practices described here.

1. Data We Collect

Account Information

When you create an account we collect your name and email address. If you sign in via a third-party OAuth provider (Google or GitHub) we receive the profile data those providers share with us — typically your name, email address, and profile picture.

Social Media OAuth Tokens

If you connect social media accounts (LinkedIn, Twitter/X, Facebook/Meta) to use our Social Suite features, we store the OAuth access tokens issued by those platforms. All tokens are encrypted at rest using AES-256-GCM before being written to our database. We never store your social media passwords.

AI Generation Data

We store the inputs you submit to AI features (prompts, context, uploaded content) and the outputs generated, so you can access your history and saved documents. This data is scoped to your account and not shared with other users.

Billing Information

Payment processing is handled by NMI (Network Merchants Inc.). We never receive or store raw card numbers, CVVs, or full payment card data. Our system stores only the vault/token ID returned by NMI, which references your payment method on NMI's PCI-compliant infrastructure.

Usage & Log Data

We collect usage data such as which features you use, timestamps of AI generation requests, and token/cost metrics. For security and abuse prevention we log IP addresses; however, IPs are hashed (salted) before storage — we do not retain raw IP addresses in our analytics tables.

2. How We Use Your Data

  • To create and manage your account and authenticate you securely.
  • To deliver AI-powered features and services you request.
  • To process payments and manage your subscription or usage credits via NMI.
  • To connect your linked social media accounts and schedule or publish content on your behalf.
  • To improve platform quality, model routing, and cost efficiency through aggregated, anonymised usage analytics.
  • To detect fraud, abuse, and security incidents through audit logging.
  • To send transactional emails (password resets, billing receipts, generation nudges). We do not send unsolicited marketing email without your consent.

3. Third-Party Services

We integrate with the following third-party services. Each has its own privacy policy.

ServicePurposeData Shared
Google OAuthSign-inName, email, profile picture
GitHub OAuthSign-inName, email, profile picture
NMI (Network Merchants)Payment processingBilling details (not stored by us)
Twitter/X APISocial Suite publishingYour posts & OAuth token (encrypted)
LinkedIn APISocial Suite publishingYour posts & OAuth token (encrypted)
Meta (Facebook) APISocial Suite publishingYour posts & OAuth token (encrypted)
Ollama / AI model providersAI content generationYour prompts (sent for inference)
Cloudflare TunnelSecure infrastructure routingNetwork traffic metadata

4. Data Storage & Security

Your data is stored in a PostgreSQL database hosted on our private infrastructure (a QNAP NAS device located in a secured facility). The server is not directly accessible from the public internet — all traffic is routed through Cloudflare Tunnel with TLS encryption in transit.

Social media OAuth tokens are encrypted with AES-256-GCM before being written to the database. IP addresses used for security logging are hashed with a static salt and are not stored in plaintext. We use timing-safe comparison functions for all secret verification to prevent timing-based attacks.

While we take reasonable technical and organisational measures to protect your data, no method of transmission over the internet is completely secure. We cannot guarantee absolute security.

5. Data Retention

We retain your account data for as long as your account is active. AI generation history is retained to power your saved documents sidebar; you may delete individual saved documents at any time. Archived workflow sessions are automatically cleaned up after 30 days. Audit logs are retained for security and compliance purposes and survive account deletion (the user ID reference is set to null on deletion to anonymise the record).

6. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request deletion of your account and associated personal data. Contact us at [email protected].
  • Portability — request an export of your AI generation history and saved documents.
  • Disconnect social accounts — you may revoke OAuth connections at any time from your profile settings, which will delete the stored (encrypted) token.

7. Cookies & Local Storage

We use cookies strictly for authentication. Auth.js v5 sets a session cookie after you sign in to keep you logged in across page loads. This cookie is HTTP-only, Secure, and SameSite=Lax. We do not use advertising or tracking cookies.

Our Progressive Web App (PWA) may store data in your browser's local storage for offline functionality. This data stays on your device and is not transmitted to our servers unless you explicitly take an action that does so.

8. Children's Privacy

RetroHub AI is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at [email protected] and we will take steps to delete it.

9. International Data Transfers

Retro Hub AI Inc. is based in British Columbia, Canada, and our infrastructure is operated in a private facility. Personal information processed by us is subject to Canadian privacy law (PIPEDA). Third-party AI model providers and OAuth providers may process data in various jurisdictions. By using RetroHub AI you consent to your data being processed in the countries where our service providers operate.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes we will notify you via email or a prominent notice on the platform. Your continued use of RetroHub AI after changes are posted constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Retro Hub AI Inc.
Vancouver, BC, Canada
Business Number: 719420036RC0001
Email: [email protected]
Website: retrohubai.com

HomeTerms of Service© 2026 Retro Hub AI Inc. All rights reserved.