← Hubuk

Privacy

Last updated 15 September 2026

Hubuk holds personal religious reflection, so the short version matters more than the long one: what you write belongs to you, you can download all of it or delete it at any time, and the app measures how it is used without recording what you wrote.

What is stored

  • Your account — name and email address. If you sign in with Google, your name and email come from Google; no password is stored for that account. Email passwords are stored only as a one-way hash, never as text.
  • What you write — tags, reflections, questions, links, favourites, passages, concepts, articles, journal entries, chat conversations, and any sources you import. This is your work; it is stored so you can come back to it.
  • Usage records — which page was opened, which feature was used, which surah an annotation was on, how many results a search returned, and how quickly the server answered.
  • Error reports — when something breaks, the technical details of the failure, so it can be fixed.
  • AI usage — how many tokens each AI request used, which is what the daily limits are counted from.

What is never recorded

Usage records carry shape, never content. The text of your reflections, questions, tags, articles and chats is never put into them, and neither is verse text, your name or your email. There is no mouse tracking, no keystroke logging and no session replay.

One deliberate exception: when a search returns nothing, the words searched for are recorded. A search that matched nothing has by definition matched none of your own writing, and it is the clearest signal of what the app cannot yet find.

Where your words go

When you use chat or an AI feature, the message you send and the verses and notes needed to answer it are sent to an AI provider (currently Anthropic) to produce the reply. That is how those features work; nothing is sent to them unless you use an AI feature.

If an audio or video file is uploaded for transcription, it is sent to OpenAI for that purpose. Transcription is limited to administrator accounts.

Nothing you write is sold, and nothing is shared for advertising. There is no advertising here.

Email

Your address is used to confirm your account, to let you reset a password, and for messages about the service itself. There is no marketing mail.

Stored in your browser

Your sign-in token and display preferences (which translations you show, font sizes) are kept in your browser's local storage so you stay signed in and the app looks the way you left it. They are not advertising cookies.

How long things are kept

  • What you write: until you delete it, or delete your account.
  • Usage records: 180 days.
  • Error reports: 30 days.
  • Backups: encrypted copies are taken daily so the service can be restored after a failure. A deleted account may persist in a backup until that backup ages out.

Taking your work with you, and deleting it

Open Account and choose Download my data to get everything you have written as a zip of JSON files. Your password and sign-in tokens are never in the export.

Deleting your account removes it and everything in it from the server: tags, reflections, questions, links, favourites, passages, concepts, articles, journal entries, chats, imported sources and API keys. It cannot be undone, so download your data first if you want to keep it.

Security

Traffic is encrypted in transit. Passwords are hashed. Backups are encrypted before they leave the server. No service can promise perfect security, but access to the database is limited, and the AI assistant's ability to read the database is restricted to a role that cannot read accounts, passwords or sign-in tokens.

Changes

If this changes in a way that affects what is collected, the date at the top will change and the change will be noted here.

Contact

A contact address will be published here shortly, once the project's own domain is in place. Until then, contact the person who gave you access to this instance.

See also Terms of use and Credits & attribution.