Pre-release document for the invite-only alpha · a lawyer-reviewed version will follow before general availability
<!-- Operator-approved 2026-07-04 · requires lawyer review before GA -->
Privacy Statement
Pre-release draft — last updated July 4, 2026
RetroHub AI is operated by RETRO HUB AI INC., a company incorporated in
British Columbia, Canada (incorporation number BC1589989). This statement is
written in plain language and covers the pre-release alpha of RetroHub AI
at retrohubai.com. The platform is invite-only; things will change before
general availability, and this statement will change with them.
Privacy questions or requests: [email protected] (general support: [email protected]).
1. What we collect
- Account information. When you register (with an invite code) we create an
account through Firebase Authentication. Depending on how you sign in
(Google, GitHub, or email/password), we receive your name, email address,
and profile picture from the provider you chose. We never see or store your
password for third-party sign-ins.
- Your content. The prompts, briefs, projects, brand-voice settings, and
other inputs you provide, and the AI-generated drafts and outputs the
platform produces for you. This is the product — we store it so you can keep
working with it.
- Bug reports. If you file a bug report from inside the app, it may include
a screenshot of your current screen and session context (what you were doing
when the bug happened). You can review a bug report before sending it.
- Error telemetry. We use Sentry to capture application errors so we can
fix them. Error events can include technical context such as your browser
type and what the app was doing when the error occurred.
- Social account tokens. If you connect a social account for publishing
features, the access token is encrypted (AES-256-GCM) before it is stored.
We never store social media passwords.
- Basic usage records. Timestamps, feature usage, and generation records
tied to your account, used to operate the service and (in demo mode)
simulate billing.
We do not collect payment card details in the alpha. Billing runs in
demo mode only — no real charges are made and no real card data is entered
or stored (the payment form is an NMI sandbox demonstration).
2. Why we collect it
- To run the product: authenticate you, store your work, generate content you
ask for, and keep your workspace in sync across devices.
- To fix problems: bug reports and error telemetry exist so the operator can
reproduce and repair issues during the alpha.
- To operate honestly: usage records let us enforce fair-use limits and show
you what the platform did on your behalf.
We do not sell your data. We do not show ads. We do not use advertising or
tracking cookies.
3. AI processing
RetroHub AI generates content two ways:
- On your device. Some drafting runs locally in your browser when your
hardware supports it. Those inputs are processed on your machine.
- Cloud AI providers. Other generation is sent to third-party cloud AI
providers (multiple providers are used). Your prompt and relevant project
context are transmitted to the provider to produce the output. Providers
process this data under their own terms; we send only what is needed for
your request.
4. Where your data lives
Your data is stored in a PostgreSQL database on company-operated servers
located in Canada. Traffic between your browser and our servers is encrypted
in transit (TLS). Social tokens are encrypted at rest as described above.
5. Retention and backups
- Your account data and content are kept while your account is active.
- We take nightly backups. Daily backups are retained for 30 days, and
monthly backups for 12 months. Data you delete may persist in those
backups until they age out on that schedule.
6. Who can see your data
During the pre-release alpha, access is limited to the operator (the
company's principal). There is no wider staff, no analytics vendors beyond the
error telemetry described above, and no data sharing with advertisers or
brokers. Cloud AI providers see the prompts sent to them for generation, as
described in section 3.
7. Cookies
We use a single first-party authentication cookie (__session) so you stay
signed in across RetroHub AI subdomains. It is set only for authentication.
The app may also use your browser's local storage for offline functionality;
that data stays on your device.
8. Your rights
Consistent with Canada's PIPEDA, you can at any time:
- Access — ask for a copy of the personal data we hold about you.
- Correct — ask us to fix inaccurate information.
- Delete — ask us to delete your account and associated personal data.
Deletion removes live data promptly; backup copies age out per section 5.
- Withdraw — disconnect social accounts (which deletes the stored
encrypted token) or stop using the service.
Email [email protected] and the operator will action the request.
9. Changes
This is a pre-release document. When it changes we will update the date at the
top; for significant changes we will notify account holders. A lawyer-reviewed
version will replace this draft before general availability.
10. Contact
RETRO HUB AI INC. (BC1589989)
British Columbia, Canada
Privacy: [email protected] · Support: [email protected]