Privacy

Privacy policy

Last updated

This policy covers this website, the offices we host, and the Hubble apps: in your browser, on your computer, and on iPhone, iPad and Android. We’ve kept it in plain English. If anything’s unclear, ask us.

The short version

  • Your team’s data belongs to your team. We use it to run your office, and for nothing else.
  • No ads, no tracking across other apps and websites, and we never sell personal information.
  • Your camera and microphone are used only during calls. Calls go directly between devices, and we don’t record them.
  • Agents run on the Claude connection your office’s admins choose, under your office’s own account.
  • You can delete your account at any time, and owners can delete their office.

Who we are and what this covers

This policy explains how Hubble (“we”, “us”) handles personal information when you:

  • visit this website, hubbleoffice.com;
  • use an office we host at app.hubbleoffice.com (a “hosted office”);
  • use the Hubble apps: Hubble in your web browser, the desktop app in your computer’s menu bar, and the mobile app for iPhone, iPad and Android.

For your account (who you are and how you sign in), we decide how the information is used and we’re responsible for it. For the content inside an office, we handle it on behalf of the organization that runs the office, following its instructions. If you’re a member of someone else’s office, that organization is responsible for how its office is used, so please contact it first about that content.

Self-hosted Hubble

Hubble can also run on an organization’s own server. Self-hosted Hubble servers are run by their operators, not by us. If your office’s address isn’t on hubbleoffice.com, the organization running that server decides what happens to your data there, and its own privacy policy applies. We don’t receive the data on self-hosted servers. (If such a server sends notifications to the mobile app, they travel through the push services described under Notifications.)

What we collect

Your account

Your name, email address, the identifier your sign-in provider (Google, GitHub or Microsoft) gives us, and your profile picture if your provider shares one. We never see your passwords for those services. If you sign in with a code sent by email, we only need your email address.

Your offices

Which offices you belong to, your role and display name in each, invitations you send or accept, and how your avatar looks.

What you and your team create

The content of your office: conversations with agents, tasks and their activity logs, deliverables, bulletin posts, to-dos, whiteboards, shared files, clients and contacts, scheduled meetings, meeting notes, and the office’s layout. Meeting transcripts exist only when transcription is turned on for a meeting (see Meeting transcription).

Credentials your office connects

The Claude API key or cloud credentials, integration tokens and calendar connections your office sets up. They’re encrypted before they’re stored.

Presence

Whether you’re online, your status (Available, Busy or Away), whether you’re on a call, where you are in the office, and whether you’re on your computer or your phone, so teammates know how to reach you.

Your device, for notifications

When you turn on notifications in the mobile app, the app gets a push token (an address for your device) from Expo’s push service and sends it to your office, along with whether it’s iOS or Android, a phone or a tablet, and which notifications you want.

Usage and logs

How much Claude usage your office’s agents consume, so admins can see spending and set a monthly budget. And basic technical data, such as IP addresses, browser or app version and server logs, which we use for security, rate limits, preventing abuse and fixing problems.

On this website

If you request early access, the email, name and team size you enter and anything you tell us about your plans, which go to the service that collects our sign-ups. Otherwise the website collects nothing about you: it sets no cookies, runs no analytics and serves its own fonts. Like any web host, ours keeps standard request logs, including IP addresses, for security and operations.

What we don’t do

  • We don’t show ads, and there are no ad networks or advertising identifiers in our apps.
  • We don’t track you across other companies’ apps and websites.
  • We don’t sell personal information, or share it for cross-context behavioral advertising.
  • We don’t use your office’s content to train AI models.
  • We don’t run third-party analytics or tracking scripts on this website, in hosted offices or in the apps.

Camera, microphone and calls

  • The apps ask for your camera and microphone for calls and meetings, and use them only while you’re in one (and, in the mobile app, when you take a photo to share). You can turn either off during a call, or take away access in your device’s settings.
  • Call audio, video and screen sharing travel directly between participants’ devices (peer-to-peer, using WebRTC), encrypted. When a direct connection isn’t possible, they pass through a relay (a TURN server) that forwards the encrypted media without being able to read it.
  • Hubble doesn’t record calls. Our servers only carry the messages that set up a call and keep track of who’s in it while it lasts.
  • The mobile app only sees the photos you choose to share.

Meeting transcription

  • Transcription is off unless a meeting’s host or an office admin turns it on, or the office makes it the default. Everyone in the meeting can see that it’s being transcribed, and guests are told before they join.
  • Each person’s own device turns their speech into text, using the speech recognition built into their browser or device (which may use the speech service of that browser or operating system’s maker), or Deepgram if the office has connected it.
  • The transcript is saved with the meeting’s record. When the meeting ends, the office’s Claude connection writes a summary (without one, a simple built-in summarizer does). A record is visible to the host and the teammates who were in the meeting (and office admins); one filed under a client is visible to whoever can see that client.

AI processing by Claude

Your office’s agents run on Claude, by Anthropic, through the connection your office’s admins set up: an Anthropic API key, Amazon Bedrock, Google Cloud Vertex AI or Microsoft Foundry. Admins choose the provider; we don’t. When an agent works on something, the content it needs (your request, relevant context and notes from the office, and results from tools and integrations) is sent to that provider under your office’s own account, and that provider’s terms and privacy policy govern how it’s processed and kept. The same connection writes meeting summaries and answers guests in the waiting room.

Without a Claude connection, agents run in a demo mode and nothing is sent to an AI provider. Agents can also look things up on the web and in the integrations your office connects, when their settings allow it; those services receive the requests agents make to them.

Notifications

  • The mobile app can let you know about things while it’s closed: calls, meeting invitations and reminders, TV videos, door knocks, guests waiting, approvals and meeting summaries (and, if you turn them on, shared files and bulletin posts).
  • Your office’s server sends them through Expo’s push service, which delivers them through Apple Push Notification service on iPhone and iPad, or Firebase Cloud Messaging (Google) on Android. A notification carries its text, such as who’s calling or the name of a meeting, and a small reference so the app opens the right screen.
  • Turn any kind off in the app under Settings → Notifications, or all of them in your device’s settings. Signing out removes the device’s push token from your office.
  • Notifications in the browser and the desktop app come from the open page or app itself, without a push service.

Who we share it with

We share personal information only with service providers that help run Hubble, and only what they need:

  • Anthropic, or the cloud provider your office chose for Claude (Amazon, Google or Microsoft), to run your agents.
  • Render, which hosts the Hubble service and stores its data, and Vercel, which hosts this website.
  • Resend, which delivers our emails, such as sign-in codes, invitations and meeting follow-ups your office sends.
  • Google, GitHub and Microsoft, when you choose to sign in with them or connect your calendar.
  • Expo, Apple and Google, to deliver notifications to the mobile app.
  • Call and backup infrastructure: a relay (such as Cloudflare) for calls that can’t connect directly, and storage for off-site backups.
  • Deepgram, for meeting transcription, if your office connects it.
  • Integrations your office connects (for example GitHub, Linear, Notion, Slack, Stripe or a custom MCP server), which receive the requests agents make.
  • The service that collects early-access sign-ups from this website.

Inside an office, other members see what you share there, such as your name, look and status, where you are in the office, your messages to agents, posts, files and whiteboard edits. Guests your team invites see only what the office lets them. We may also disclose information when the law requires it, to protect people’s safety or our rights, or as part of a merger or acquisition, in which case this policy keeps applying to it.

Cookies and storage on your device

  • This website sets no cookies and stores nothing on your device.
  • Hosted offices use one essential cookie, hubble_session, to keep you signed in. Page scripts can’t read it, it lasts up to 30 days from your last visit, and signing out removes it. There are no analytics, advertising or tracking cookies.
  • The apps remember a few things on your device: your sign-in (in the mobile app, in the system’s secure storage: the iOS Keychain or the Android Keystore), your office’s address, and preferences such as your notification settings or the name and look you last used. Signing out removes the sign-in.

How long we keep it, and deleting it

  • Your account stays until you delete it. To delete it, open your office on the web, choose Your offices from your status menu (or go to app.hubbleoffice.com), open the menu with your name and choose Delete account. If you own an office, transfer it or delete it first. You can also email us from the address you sign in with and we’ll do it for you. We delete your account details and memberships; what you created inside an office stays with that office, because it belongs to the organization.
  • Offices stay until their owner deletes them. A deleted office is kept for 7 days in case it was a mistake, then permanently deleted with all its data and files.
  • Shared files expire 12 or 24 hours after they’re shared (whoever shares one picks), and the file is deleted then.
  • Backups are taken nightly and kept for 7 days, so deleted data leaves the backups within a week.
  • Credentials are deleted as soon as your office disconnects the Claude connection or the integration.
  • Push tokens are kept until you sign out on that device, or until the push service tells us the device is no longer registered.
  • Sign-in codes and links expire within 15 minutes; sessions end after 30 days without use, or when you sign out.
  • Early-access sign-ups are kept until you ask us to remove them, or until we no longer need them.
  • Logs are kept for a short time, for security and fixing problems.

Security

  • Everything travels encrypted: HTTPS for the website, the service and the apps, and encrypted media for calls.
  • Secrets are encrypted at rest: Claude credentials and integration and calendar tokens are encrypted on the server (AES-256-GCM), used only there to run your office, and never sent to browsers or apps.
  • Session tokens are stored only as hashes, and sign-in attempts and emails are rate limited.
  • Inside an office, access follows roles (owner, admin, member), and agents can’t send, publish or spend without a person approving.

No service is perfectly secure. If you’ve found a vulnerability, or think someone has got into your account, please write to hello@hubbleoffice.com right away.

Your choices and rights

  • Change your name and look, turn notifications and camera or microphone access on or off, and sign out of any device.
  • Delete your account as described above. Office admins can export an office’s data, and owners can delete it.
  • Depending on where you live (for example in the EU, the UK or California), you may have the right to access, correct, delete or get a copy of your personal information, to object to or restrict how it’s used, and to complain to a data protection authority. To make a request, email us. For content in an office run by another organization, we’ll pass your request on to it or help it respond.
  • We won’t treat you differently for using any of these rights.

Children

Hubble is a tool for work and isn’t meant for children. You must be at least 13 to use it, or 16 in the European Economic Area and the United Kingdom, and we don’t knowingly collect personal information from anyone younger. If you think a child has given us personal information, let us know and we’ll delete it.

International transfers

We and our providers may process information in the United States and other countries, which may have different data protection laws from where you live. Where the law requires it, we rely on appropriate safeguards, such as standard contractual clauses, for these transfers.

Changes to this policy

We’ll update this page as Hubble changes, and the date at the top always shows the latest version. If a change is significant, we’ll let you know in advance, for example by email or in the app.

Contact us

Questions or requests about privacy? Write to hello@hubbleoffice.com. For help with the apps, see Support.