Hub
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
States that third-party service providers are contractually bound to handle user information securely and only as instructed by the platform, establishing a protective obligation on subprocessors limiting their independent use of personal data.
Prohibits cross-app tracking, participation in advertising networks, and sharing user data with third parties for tracking purposes outside the services, and specifies non-use of device advertising identifiers — all protective restrictions on data sharing and tracking practices.
Defines the deletion procedure and associated retention limitations: personal account information is deleted within 30 days; certain information is retained where legally required; uploaded content already included in datasets licensed to enterprise clients cannot be retracted from those clients' copies because the user consented to its use at upload, though future licensing of that content ceases — establishing both an obligation of timely deletion and an exception carving out previously licensed content.
How to read this page: Overall risk rates what Hub's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 38 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 38 citationsstaticLast captured 2026-09-21
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines the categories of financial data collected (wallet address, transaction history) and explicitly states what financial identifiers are not collected, establishing the scope of data collection obligations and restrictions.
" Wallet address — the EVM-compatible cryptocurrency wallet address you provide to receive USDC payouts on the Base network. You can edit this at any time. Transaction history — records of rewards earned, bonuses, and payouts processed thro..."
Defines the deletion procedure and associated retention limitations: personal account information is deleted within 30 days; certain information is retained where legally required; uploaded content already included in datasets licensed to enterprise clients cannot be retracted from those clients' copies because the user consented to its use at upload, though future licensing of that content ceases — establishing both an obligation of timely deletion and an exception carving out previously licensed content.
" When you delete your account: We delete your personal account information (email, profile data, wallet address) within 30 days. We retain certain information where required by law (e.g., transaction records for tax and regulatory purpose..."
Identifies Didit as a third-party KYC subprocessor that collects identity documents (government ID, selfie, liveness check) on Hub's behalf during verification; states Hub does not store identity documents and only retains verification status and date; directs users to Didit's own privacy practices. Protective in that it limits Hub's own retention to status/date only.
" If you choose to verify your identity, we use Didit , a third-party KYC provider, to perform verification. During verification, Didit collects identity documents (government ID, selfie, liveness check) and processes them on our behalf. H..."
Grants the platform permission to include uploaded content in licensed AI training datasets shared with enterprise clients, and restricts demographic metadata sharing to anonymized or aggregated form only, while prohibiting sharing of personally identifying information such as name, email, wallet address, and account credentials.
" Hub licenses AI training datasets to enterprise clients (such as research labs and technology companies). When we share data derived from your uploads: Uploaded content (the images, videos, audio you submitted) may be included in these da..."
Clause A broadly disclaims responsibility for third-party privacy practices, while Clause B states a third party processes user identity documents 'on our behalf,' which implies the platform *is* responsible for that specific processing activity, creating an opposing claim.
" The Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party service you interact with. Key third parties we integrate with: Didit (identity verification) — https://didit.me/privacy Google (OAuth sign-in) — https://policies.google.com/privacy Discord (OAuth sign-in) — https://discord.com/privacy "
" If you choose to verify your identity, we use Didit , a third-party KYC provider, to perform verification. During verification, Didit collects identity documents (government ID, selfie, liveness check) and processes them on our behalf. Hub does not store your identity documents. We only store the verification status (verified / not verified) and the date of verification. For Didit's own privacy practices, see https://didit.me/privacy ."
Within one documentClause A states the platform is not responsible for third-party privacy practices, but Clause B specifies that Didit processes identity documents 'on our behalf,' which implies the platform *is* responsible for that specific data processing activity.
" The Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party service you interact with. Key third parties we integrate with: Didit (identity verification) — https://didit.me/privacy Google (OAuth sign-in) — https://policies.google.com/privacy Discord (OAuth sign-in) — https://discord.com/privacy Meta Platforms (custom audiences and ad measurement) — https://www.facebook.com/privacy/policy "
" If you choose to verify your identity, we use Didit , a third-party KYC provider, to perform verification. During verification, Didit collects identity documents (government ID, selfie, liveness check) and processes them on our behalf. Hub does not store your identity documents. We only store the verification status (verified / not verified) and the date of verification. For Didit's own privacy practices, see https://didit.me/privacy ."
Within one documentClause A states the company does not participate in advertising networks and does not share data for tracking activity outside the Services, while Clause B explicitly lists integration with Meta Platforms for custom audiences and ad measurement, which are functions of an advertising network and involve sharing data for advertising purposes.
" We do not track you across other companies' apps or websites. We do not participate in advertising networks, and we do not share your data with third parties for the purpose of tracking your activity outside of the Services. The Hub App does not use Apple's IDFA or Google's Advertising ID."
" The Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party service you interact with. Key third parties we integrate with: Didit (identity verification) — https://didit.me/privacy Google (OAuth sign-in) — https://policies.google.com/privacy Discord (OAuth sign-in) — https://discord.com/privacy Meta Platforms (custom audiences and ad measurement) — https://www.facebook.com/privacy/policy "
Within one documentClause A states all third-party providers are contractually bound to handle information 'only as instructed by us,' while Clause B refers users to a specific provider's 'own privacy practices,' implying potential independent data handling that may not be solely dictated by the platform's instructions.
" We share information with third-party service providers who help us operate the Services. These providers are contractually bound to handle your information securely and only as instructed by us. They include:"
" If you choose to verify your identity, we use Didit , a third-party KYC provider, to perform verification. During verification, Didit collects identity documents (government ID, selfie, liveness check) and processes them on our behalf. Hub does not store your identity documents. We only store the verification status (verified / not verified) and the date of verification. For Didit's own privacy practices, see https://didit.me/privacy ."
Within one documentClause A states all third-party providers are contractually bound to handle information 'only as instructed by us,' while Clause B refers users to a specific provider's 'own privacy practices,' implying potential independent data handling that may not be solely dictated by the platform's instructions.
" We share information with third-party service providers who help us operate the Services. These providers are contractually bound to handle your information securely and only as instructed by us. They include:"
" If you choose to verify your identity, we use Didit , a third-party KYC provider, to perform verification. During verification, Didit collects identity documents (government ID, selfie, liveness check) and processes them on our behalf. Hub does not store your identity documents. We only store the verification status (verified / not verified) and the date of verification. For Didit's own privacy practices, see https://didit.me/privacy ."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We share information with third-party service providers who help us operate the Services. These providers are contractually bound to handle your information securely and only as instructed by us. They include:"
States that third-party service providers are contractually bound to handle user information securely and only as instructed by the platform, establishing a protective obligation on subprocessors limiting their independent use of personal data.
AI-generated interpretation, not legal advice.
" We do not track you across other companies' apps or websites. We do not participate in advertising networks, and we do not share your data with third parties for the purpose of tracking your activity outside of the Services. The Hub App does not use Apple's IDFA or Google's Advertising ID."
Prohibits cross-app tracking, participation in advertising networks, and sharing user data with third parties for tracking purposes outside the services, and specifies non-use of device advertising identifiers — all protective restrictions on data sharing and tracking practices.
AI-generated interpretation, not legal advice.
" Profile data you provide may be associated with your uploads to add demographic context to datasets, but only in anonymized or aggregated form (see Section 4)."
Permits association of profile demographic data with uploads for dataset context but restricts this use to anonymized or aggregated form only, limiting how personally identifiable profile data may be shared.
AI-generated interpretation, not legal advice.
" We do not use advertising or marketing cookies. We do not serve third-party ads on the Services. You can manage or disable cookies through your browser settings. Disabling strictly necessary cookies may prevent you from using certain features of the website."
Prohibits the use of advertising or marketing cookies and prohibits serving third-party ads, and states that users can manage or disable cookies via browser settings — protective restrictions limiting data collection to functional and analytics purposes only.
AI-generated interpretation, not legal advice.
" When you delete your account: We delete your personal account information (email, profile data, wallet address) within 30 days. We retain certain information where required by law (e.g., transaction records for tax and regulatory purposes). Uploaded content that has already been included in datasets licensed to enterprise clients cannot be retracted from those clients' copies, since you agreed to its use in datasets at the time of upload. Future use is stopped, and any unfulfilled licensing of that specific content ceases."
Defines the deletion procedure and associated retention limitations: personal account information is deleted within 30 days; certain information is retained where legally required; uploaded content already included in datasets licensed to enterprise clients cannot be retracted from those clients' copies because the user consented to its use at upload, though future licensing of that content ceases — establishing both an obligation of timely deletion and an exception carving out previously licensed content.
AI-generated interpretation, not legal advice.
" We may share information for other purposes with your explicit consent. We do not sell your personal information to third parties. "
Permits sharing of information for other purposes with the user's explicit consent, while also expressly prohibiting the sale of personal information to third parties — a user-favorable restriction on data monetization.
AI-generated interpretation, not legal advice.
" This Privacy Policy explains how Hub Data Inc. (" Hub ," " we ," " our ," or " us "), a Delaware corporation, collects, uses, shares, and protects your personal information when you use our mobile application (the " App "), our website at platform.hub.xyz , and any related services (collectively, the " Services "). By using the Services, you agree to the practices described in this Policy. If you do not agree, please do not use the Services."
Introductory clause defining the scope of the Privacy Policy — identifies the data controller, the covered services (App, website, related services), and incorporates user agreement to described practices as a condition of use; cross-references all downstream obligations in the policy.
AI-generated interpretation, not legal advice.
" Send transactional notifications (upload approved, reward credited, etc.)"
Grants the platform permission to send transactional notifications using contact information collected from users.
AI-generated interpretation, not legal advice.
" Hub Data Inc. is the data controller for personal information collected through the Services. Legal entity Hub Data Inc. Jurisdiction Delaware, United States Contact privacy@hub.xyz Mailing address 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, USA For questions about this Policy or to exercise your privacy rights, contact us at the email above."
Defines Hub Data Inc. as the data controller for personal information collected through the Services and provides contact information for privacy inquiries and exercise of privacy rights; establishes the responsible party and a procedure for rights requests.
AI-generated interpretation, not legal advice.
" OAuth identifiers (Google or Discord) when you sign in via a third-party provider"
Identifies OAuth identifiers from third-party sign-in providers as a category of personal information collected when users authenticate via those providers.
AI-generated interpretation, not legal advice.
" This information is optional but enables eligibility for a broader set of tasks. You control what you share and can edit or delete profile fields at any time. All physical descriptors (such as skin tone, hair color, and eye color) are voluntarily self-reported by you and are not derived through biometric analysis, facial recognition, or any automated measurement."
Grants users the right to control, edit, or delete their profile fields at any time; clarifies that physical descriptors are voluntarily self-reported and not derived through biometric analysis, facial recognition, or automated measurement — user-favorable disclaimer protecting against automated sensitive-data inference.
AI-generated interpretation, not legal advice.
" Photos, videos, and other media you submit through the App as part of completing tasks"
Identifies photos, videos, and other media submitted through the App as part of task completion as categories of personal information collected.
AI-generated interpretation, not legal advice.
" When you choose to upload from your camera roll, the App accesses photos you select. We do not access photos you have not selected. When you use in-app capture (camera or video recording), the App accesses your device's camera while recording. You can revoke these permissions at any time in your device settings."
Clarifies the scope of camera roll and camera access — only photos the user selects and camera access during active recording; grants users the right to revoke these permissions at any time via device settings, limiting Hub's access to user-initiated actions only.
AI-generated interpretation, not legal advice.
" Wallet address — the EVM-compatible cryptocurrency wallet address you provide to receive USDC payouts on the Base network. You can edit this at any time. Transaction history — records of rewards earned, bonuses, and payouts processed through the Services. We do not collect bank account information, credit card numbers, or government-issued financial identifiers."
Defines the categories of financial data collected (wallet address, transaction history) and explicitly states what financial identifiers are not collected, establishing the scope of data collection obligations and restrictions.
AI-generated interpretation, not legal advice.
" Analyze how users interact with the App to identify bugs, performance issues, and opportunities for improvement"
Grants the platform permission to analyze user interaction data to identify bugs, performance issues, and improvement opportunities.
AI-generated interpretation, not legal advice.
" Notify you of important account changes, policy updates, or service announcements"
Grants the platform permission to use contact information to notify users of account changes, policy updates, and service announcements.
AI-generated interpretation, not legal advice.
" We use automated systems to support the operation of the Services, including: Task matching — algorithms determine which tasks you are eligible for based on your profile information, location, device capabilities, and task requirements. Reliability scoring — automated systems calculate a reliability score based on your submission history, review outcomes, and platform activity. This score affects the tasks available to you and your standing on the platform. These automated processes are necessary for the efficient operation of the Services. If you have questions or concerns about how automated processing affects your account, contact us at privacy@hub.xyz ."
Grants the platform permission to use automated systems for task matching and reliability scoring based on profile, location, device, and activity data, and states these processes affect task availability and user standing on the platform.
AI-generated interpretation, not legal advice.
" Depending on where you live, you may have the following rights regarding your personal information:"
Introduces a conditional grant of rights to users regarding their personal information, noting that available rights depend on the user's location.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Hub's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Hub's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Hub's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Hub requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Hub's published policies yet.
What the policies actually cover
0 topicsNone of Hub's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause provides a deletion or time-bounded retention path.
“When you delete your account: We delete your personal account information (email, profile data, wallet address) within 30 days. We retain certain information where required by law (e.g., transaction records for tax and regulatory purposes). Uploaded content that has already been included in datasets licensed to enterprise clients cannot be retracted from those clients' copies, since you agreed to its use in datase...”Open source citation
The clause provides a deletion or time-bounded retention path.
“When you delete your account: We delete your personal account information (email, profile data, wallet address) within 30 days. We retain certain information where required by law (e.g., transaction records for tax and regulatory purposes). Uploaded content that has already been included in datasets licensed to enterprise clients cannot be retracted from those clients' copies, since you agreed to its use in datase...”Open source citation
The clause permits sale of personal data or information.
“We may share information for other purposes with your explicit consent. We do not sell your personal information to third parties.”Open source citation
The clause permits sale of personal data or information.
“You have the right to know what personal information we collect, use, share, or sell You have the right to delete personal information we have collected from you”Open source citation
The clause permits sale of personal data or information.
“You have the right to opt out of the "sale" or "sharing" of personal information (we do not sell personal information) You have the right not to be discriminated against for exercising your privacy rights”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | audit rights dpa residency | worsens | HIGH | 2 |
| All applicable tiers | data retention | worsens | HIGH | 2 |
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 5 |
| All applicable tiers | training use | worsens | HIGH | 2 |
| Enterprise | data retention | improves | LOW | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing improved from high/sale or sell to medium/third party or vendor sharing.
“We may share information for other purposes with your explicit consent. We do not sell your personal information to third parties.”Before citation
“We do not track your activity across other companies' apps or websites, and we do not share your data with advertising networks so that third parties can advertise to you. The only sharing with advertising platforms is the one described in Sections 4.6 and 10.1: reaching existing users with our own communications and measuring our campaigns. The Hub App does not use Apple's IDFA or Google's Advertising ID.”After citation
Latest stance: sale or sell on privacy data use
“You have the right to opt out of the "sale" or "sharing" of personal information (we do not sell personal information) You have the right not to be discriminated against for exercising your privacy rights”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We do not track your activity across other companies' apps or websites, and we do not share your data with advertising networks so that third parties can advertise to you. The only sharing with advertising platforms is the one described in Sections 4.6 and 10.1: reaching existing users with our own communications and measuring our campaigns. The Hub App does not use Apple's IDFA or Google's Advertising ID.”Open timeline citation
Latest stance: sale or sell on data retention
“To reach people who already use the Services with communications about our programs and bonuses, we may send advertising platforms, such as Meta (Instagram and Facebook), a list of contact details of existing users: email, phone number, name, city, state, postal code, and country. These values are converted to hashes (SHA-256) before they leave our systems. The platform uses the hashes only to identify which users hold an account with it and to show them our communications; it does not receive the data in readable form and, under its terms, deletes the hashes once matching is complete. We never send uploaded content, earnings, identity-verification data, or tax identifiers. We do this on the basis of our legitimate interest in communicating with existing users about programs they already take part in. You can object at any time via the unsubscribe link in our emails or at privacy@hub.xyz, in which case you are removed from subsequent lists. You can also hide Hub's ads in the platform's own ad settings. We do not sell your personal information to third parties.”Open timeline citation
Latest stance: training permitted on training use
“Uploaded content (images, videos, audio, and accompanying metadata) is the core data product of the Services. With your consent provided through these Terms, we use this content to: Build and improve AI training datasets”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-09-21· verified 2026-09-21
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
76 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Hub's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Hub's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Hub's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.