Hub · Private publishing test

Hub Privacy Policy

Effective September 23, 2026 · Private publishing test

Hub is operated by Davis Larsen, based in Utah, United States. For privacy questions, complaints, or requests, email davis@davispeps.com.

This policy covers Hub's apps, supporting services, and hubking.us. Hub helps you record, edit, organize, and prepare videos. Social-account connection and publishing features are in private testing with the operator's own accounts. Publishing is available only where it is explicitly enabled in the app; a public creator release is not being offered by this test.

Information we handle

We use this information to provide the features you request, synchronize work, authenticate accounts and devices, carry out approved posts, investigate problems, and protect the service from misuse.

Services that receive information

Cloudflare hosts Hub's website, API, database, and private publishing-video storage. When you select cloud script preparation, Hub sends script text to Cloudflare Workers AI. Cloudflare describes its handling in its Privacy Policy and Workers AI data-usage documentation.

Hub's website also uses Cloudflare Web Analytics for page-view and performance measurements. Cloudflare adds its measurement script through the hosting service. Its Web Analytics documentation describes the collection and reporting of browser performance metrics. This website measurement is separate from social-account authorization and publishing data.

TypeSafe/JEV receives reference scripts, clip transcripts, and audio-analysis measurements when you select Auto edit, so it can suggest editing decisions. That editing request does not send raw video to JEV. See TypeSafe's Privacy Policy and data-processing terms. Its published policy states that prompts and other inputs are not used to train or fine-tune models. Hub does not promise zero retention by that provider.

Apple handles Sign in with Apple and speech recognition. Speech recognition runs on-device when supported; otherwise Apple may process audio remotely. Camera, microphone, speech, and photo access depend on the features and permissions you choose. See Apple's Privacy Policy.

Connected platforms receive authorization requests and the account API requests needed for your selected features. After posting authorization, TikTok and Instagram can retrieve your selected video through a temporary signed link; YouTube receives it through an authenticated upload. Signed links permit retrieval without a Hub login while valid and expire within one hour. Your chosen platform receives the video, caption, and posting options and handles the resulting post under its own rules. Loading an account photo also contacts its image host.

Other destinations you choose receive selected material when you transfer between devices, export files, or open media in another editor. External tools you authorize to import scripts can submit content to your Hub library; their own processing is governed by their policies. Links to TestFlight, GitHub downloads, and other websites open those services. The Hub homepage loads fonts from Google, which receives the associated network requests; the privacy and terms pages use local assets and system fonts.

The operator and service providers may access information as necessary to run the service, respond to a request you authorize, investigate a security problem, or comply with law. Additional restrictions on Google API data are described below. This private posting flow does not include advertising placements or advertising trackers.

Google and YouTube data

Hub uses YouTube API Services. Read the Google Privacy Policy. Hub requests account/channel identification for connections and requests upload permission separately when you choose an enabled publishing feature. It uses that information to identify the correct channel, display its profile, upload the video you approve, and check the result.

Hub's use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including its Limited Use requirements. Google API data is not sold, used for advertising, or sent to Hub's editing AI. Human access is limited to your specific permission, security investigation, legal requirements, or aggregated internal operations allowed by that policy. A business-transfer use of this data would require the prior consent required by Google's policy.

You can disconnect YouTube in Hub and revoke Hub's access through Google's connected-app security settings. You can also request deletion of Hub's stored account data by email. Removing data from Hub does not delete a YouTube video or data held by Google; manage those copies through YouTube or Google.

Your controls

You can manage device permissions, delete supported library items, disconnect social accounts, discard a publishing upload, and delete your Hub account in account settings. You can also contact davis@davispeps.com to request access, correction, or deletion, or to raise a privacy complaint. We may need to verify your request using information reasonably necessary to confirm account ownership. Do not send passwords or verification codes.

Signing out preserves saved work for your return. Disconnecting disables Hub's use of that connection and starts permission cleanup. If a platform does not confirm removal, cleanup can remain pending; you can also remove Hub in the platform's settings. Account deletion removes account-linked records from Hub's active database and disables retrieval of its publishing uploads. It does not erase local recordings, device preferences or drafts, exports, paired-device copies, or content already held by a platform. Remove those copies separately if you want them deleted.

Retention and deletion

Hub keeps account settings, synced creative work, layouts, and saved plans to provide your workspace until you delete the supported item or account. Local files and drafts remain under your device's storage controls. The publishing and connection services use these retention settings:

These periods describe Hub's active service and its scheduled cleanup. They do not mean every copy disappears immediately. Hosting-provider logs and database recovery history have separate retention controls; database recovery copies can outlast an active-record deletion. Some rate-limit records are separate from account records and are not automatically removed by account deletion. Support correspondence can also remain while a request is being handled. Contact us about those records or a specific deletion request. We retain information required for a legal obligation only as applicable to that obligation.

Device storage, cookies, and security

Hub stores local project data and preferences and uses the device Keychain for app credentials. Social authorization uses a temporary security cookie to bind the browser response to the connection you started. Platform sign-in pages have their own cookies. Hub uses HTTPS, access controls, and encryption for stored social grants. No system can guarantee complete security.

Hub is operated from the United States. Its service providers may process information in the United States and other countries where they operate; this policy does not promise that all data stays in one region. Their published privacy and processing terms provide further details.

Age, changes, and contact

The private publishing test is for adults 18 or older and is not directed to children. Contact us if you believe a child has supplied personal information through the test.

We will date updated policies and provide notice of material changes. Where required, including a new use of Google API data, Hub will ask for agreement before that new processing starts. A future public release may have additional features and disclosures.

Davis Larsen · Utah, United States · davis@davispeps.com