Privacy Policy
Last updated: 23 April 2026
1. Introduction
CommsHub.ai ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it when you use our Service at commshub.ai.
This Privacy Policy should be read alongside our Terms of Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect the following categories of information:
- Account information: Your name, email address, and profile picture when you register, whether via email/password or Google OAuth.
- Organisation details: Organisation name and role information you provide during onboarding or in your profile settings.
- Content you create: Documents, analyses, library items, and log entries you generate or upload through the Service.
- Usage data: Pages visited, features used, and actions taken within the Service, collected to improve functionality and security.
- Technical data: IP address, browser type, device identifiers, and access timestamps collected automatically via server logs.
3. How We Use Google User Data
When you sign in with Google, we receive only the information you authorise Google to share — typically your name, email address, and profile picture. We use this data solely to:
- Create and authenticate your CommsHub.ai account.
- Pre-populate your display name and avatar in the Service.
- Send you transactional emails related to your account (e.g., access approval).
We do not request access to your Google Drive, Gmail, Calendar, or any other Google service beyond basic profile information. We do not sell or share your Google user data with third parties for advertising or marketing purposes.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Authenticate your identity and manage your account.
- Process AI document generation and content analysis requests.
- Respond to your support enquiries.
- Monitor usage and detect security incidents or policy violations.
- Comply with legal obligations, resolve disputes, and enforce our Terms of Service.
We process your content solely to provide the functionality of the Service, including AI-assisted drafting and analysis. We do not use your content for advertising purposes or to train general-purpose AI models.
5. Data Sharing & Third Parties
We do not sell your personal data. We share it only in the following limited circumstances:
- Service providers: We engage trusted third-party providers (including Supabase for database hosting and authentication, and OpenAI for AI processing) to operate the Service. These providers process data strictly on our behalf, under contractual obligations, and only to the extent necessary to provide the Service.
- Legal requirements: We may disclose your information if required to do so by law or in response to valid requests from public authorities.
- Business transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.
7. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These include encrypted data transmission (HTTPS), access controls, and regular security reviews.
While we take reasonable steps to protect your data, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
8. Cookies & Tracking
The Service uses session cookies and local storage to maintain your authentication state and preferences. We do not use third-party advertising cookies or cross-site tracking technologies.
9. Data Location and Transfers
Your data may be processed and stored in regions where our service providers operate. Where data is transferred internationally, we take appropriate measures to ensure it is protected in accordance with applicable data protection laws.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data ("right to be forgotten").
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing of your data for certain purposes.
To exercise any of these rights, contact us at privacy@commshub.ai. We will respond within 30 days.
11. Restricted Use
The Service is intended for use by professionals acting on behalf of organisations and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe such data has been provided, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date above. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
13. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
- Email: privacy@commshub.ai
- General support: support@commshub.ai