Quick Commitments
We built InfiNet Hub with privacy by design. These pillars guide every product decision.
Minimal data first
We collect only what we need to verify your identity, personalize workspaces, and provide AI-powered assistance.
No data sales ever
We never sell or lease personal data. Information is only shared with vetted processors that help us deliver the service.
Security obsessed
Passwords are hashed, data in transit is encrypted, and infrastructure is monitored 24/7 on Contabo-secured servers.
1. What Data We Collect
We collect information in three primary ways — directly from you, automatically through your devices, and from trusted partners. This section complies with App Store and Google Play Store disclosure requirements.
A. Information you provide
- Account Information: Name, email address, company name, phone number (optional), role/title, profile avatar image.
- Authentication Data: Hashed passwords, email verification codes, password reset tokens, two-factor authentication codes.
- User Content: AI chat messages and prompts, Creator form inputs (blog topics, social media posts, image prompts), uploaded images and files, voice recordings (for AI voice features), support tickets, feedback submissions.
- Payment Information: Purchase confirmations, invoices, billing addresses (processed securely through third-party payment processors; we do not store full credit card numbers).
B. Automatically collected (iOS & Android)
- Device Information: Device model, operating system version (iOS/Android), app version, unique device identifiers (IDFV on iOS, Android ID on Android), device language and region settings.
- App Usage Data: Feature usage, navigation paths, timestamps, session duration, screen views, button taps, AI feature interactions.
- Performance & Diagnostics: Crash logs, error reports, performance metrics, memory usage, network request logs.
- Network Information: IP address, network type (WiFi/cellular), approximate geographic location (derived from IP), user agent, referrer URLs.
- Mobile-Specific Data: Push notification tokens (for iOS and Android), Expo/React Native device identifiers, locally cached AI responses and generated content stored on your device.
- Permissions Data: Camera access (for image generation features), microphone access (for voice messages), photo library access (for saving QR codes and images), storage access (for file management).
C. From service partners
- App Stores: Apple App Store and Google Play Store provide purchase status, subscription information, crash analytics, and app review data.
- Email Services: Email delivery platforms (SendGrid, Twilio) provide delivery confirmations, bounce reports, and suppression lists.
- Analytics Providers: Google Analytics and other analytics tools provide aggregated usage statistics and engagement metrics (no personally identifiable information is shared).
- AI Service Providers: Google Gemini API and OpenAI DALL·E receive prompt content and generation requests (see Section 5 for details).
2. How We Use Information
- Account creation, sign-in, multi-factor email verification, and password recovery.
- Operating the AI Studio Assistant, Creator (blog, social, prompt, and image requests), and automation blueprints.
- Routing prompts to Google Gemini models and OpenAI's DALL·E image endpoint, while limiting payloads to what is necessary for generation.
- Syncing activity history across devices, maintaining recent projects, and showing relevant recommendations.
- Sending transactional emails, push notifications, and critical product announcements.
- Monitoring uptime, detecting abuse, preventing fraud, and securing accounts.
- Complying with legal obligations, enforcing policies, and responding to lawful requests.
3. Legal Bases for Processing
If you are located in the European Economic Area, United Kingdom, or any jurisdiction that requires a legal basis, we rely on:
- Contract necessity — to provide the services you request (projects, AI workflows, account management).
- Legitimate interests — to protect users, improve products, and prevent abuse (balanced against your rights).
- Consent — for optional marketing, analytics, and certain data sharing with AI partners.
- Legal obligations — to maintain tax records, respond to government authorities, or comply with platform rules.
4. How We Share Information
We disclose personal data only when necessary to run InfiNet Hub or comply with the law. This disclosure meets App Store and Google Play Store requirements.
- Service Providers & Infrastructure: Contabo (cloud hosting in EU), PM2 (process manager), Apache reverse proxy, database and storage vendors. These providers process data under strict contractual agreements.
- AI & Creative Engines (Third-Party Data Sharing):
- Google LLC (Gemini API): Receives chat messages, prompts, and conversation context to generate AI responses. Google's privacy policy applies: https://policies.google.com/privacy
- OpenAI, LLC (DALL·E): Receives image generation prompts and parameters to create AI-generated images. OpenAI's privacy policy applies: https://openai.com/policies/privacy-policy
- We strip personally identifiable information from prompts when possible before sending to AI providers.
- App Store Platforms: Apple App Store and Google Play Store receive app usage analytics, crash reports, and purchase data as part of their standard app distribution services.
- Communications Services: Email and push notification platforms (Apple Push Notification Service, Firebase Cloud Messaging) deliver verification codes, alerts, and reports.
- Analytics & Diagnostics: Tools that help us measure feature adoption, crashes, and performance receive pseudonymized metrics (no personally identifiable information).
- Compliance & Safety: We may share information when required by law, during security investigations, or in connection with a merger, acquisition, or financing.
5. AI Studio & Creative Tools (Third-Party AI Services)
To deliver AI-powered experiences, we use third-party AI services. This section discloses how your data is processed by these services, as required by App Store and Google Play Store policies.
- Google Gemini API: When you use the AI Assistant chat feature or voice messages, your messages and conversation context are sent to Google's Gemini API to generate responses. Google processes this data according to their privacy policy. We do not share your account information with Google, only the conversation content.
- OpenAI DALL·E: When you generate images using our Image Creator feature, your image prompts and parameters are sent to OpenAI's DALL·E service. OpenAI processes this data according to their privacy policy. Generated images are stored temporarily on our servers and cached in the app.
- Data Minimization: We strip personally identifiable information (email, name, account details) from prompts whenever possible before forwarding them to AI providers.
- Content Storage: Chat conversations and Creator prompts are temporarily logged to maintain conversation history, improve responses, and surface recent activity. You can delete this data at any time.
- Image Caching: Image generation results are cached on our servers and within the mobile app until you save or clear them. You can clear cached content from the app settings.
- Safety Measures: We enforce content filters and rate limits to prevent abusive or unsafe generations. We do not use your content to train AI models without your explicit consent.
6. Data Retention
- Account data is stored for as long as your account remains active or as required by law.
- Email verification codes, OTPs, and reset tokens expire within minutes and are purged within 30 days.
- AI prompts, chat logs, and Creator outputs are retained until you delete them, clear cache, or request erasure.
- Backups and server logs are retained for up to 12 months for disaster recovery and security auditing.
7. Security & Data Protection
We implement industry-standard security measures to protect your data, as required by App Store and Google Play Store security guidelines:
- Encryption: All data in transit is encrypted using Transport Layer Security (HTTPS/TLS). Data at rest is encrypted using industry-standard encryption methods.
- Password Security: Passwords are hashed using bcrypt and other industry-standard algorithms; we never store plain-text passwords.
- Access Controls: Access to production systems is restricted to authorized personnel via SSH keys, multi-factor authentication, and role-based access controls.
- Secure Infrastructure: Our servers are hosted on Contabo's secure EU data centers with regular security updates and monitoring.
- Monitoring & Logging: Regular monitoring (PM2, Apache logs, custom alerts) detects suspicious behavior, security threats, and uptime issues.
- App Security: The InfiNet Hub mobile app uses secure storage for sensitive data, certificate pinning for API communications, and follows iOS and Android security best practices.
- Incident Response: We have procedures in place to respond to security incidents and will notify affected users and authorities as required by law.
8. Your Rights & Choices
Depending on your location, you may have the right to (as required by GDPR, CCPA, and App Store/Google Play Store policies):
- Access: Request a copy of the personal information we hold about you.
- Correction: Update or correct inaccurate information directly in the app or by contacting us.
- Deletion: Request deletion of your account, chat history, AI-generated content, or specific data points.
- Data Portability: Request a copy of your data in a machine-readable format.
- Opt-Out: Opt out of marketing communications by using the unsubscribe link or contacting us.
- Device Permissions: Revoke app permissions (camera, microphone, storage) through your iOS or Android device settings at any time.
- Push Notifications: Disable push notifications through the app settings or your device notification settings.
- Object to Processing: Object to processing of your data where we rely on legitimate interests.
- Withdraw Consent: Withdraw consent for data processing where consent is the legal basis.
To exercise any right, email admin@infinet.services or submit a request from the InfiNet Hub profile screen. We will respond within 30 days (or sooner where required by law).
9. International Data Transfers
InfiNet operates from infrastructure located in the European Union (Contabo data centers in Germany). However, we use third-party services that may process data in other countries:
- Google LLC (Gemini API): Processes data in the United States and other countries where Google operates. Google complies with GDPR and uses Standard Contractual Clauses for international transfers.
- OpenAI, LLC (DALL·E): Processes data in the United States. OpenAI complies with GDPR and uses appropriate safeguards for international transfers.
- Apple App Store & Google Play Store: Process app data according to their respective privacy policies and may transfer data internationally.
When personal data moves across borders, we rely on Standard Contractual Clauses (SCCs), service-provider certifications, adequacy decisions, or comparable safeguards to ensure an adequate level of protection as required by GDPR and other data protection laws.
10. Children's Privacy
InfiNet Hub is intended for users who are 13 years of age or older (as required by Google Play Store) and 16 years of age or older in the European Economic Area (as required by GDPR). We do not knowingly collect information from children under 13. If you are a parent or guardian and believe we have unintentionally collected data from a child under 13, please contact us immediately at admin@infinet.services so we can delete it promptly.
If you are between 13 and 16 years old (or the age of consent in your jurisdiction), you must have your parent's or guardian's permission to use InfiNet Hub.
11. Changes to This Policy
We will update this Privacy Policy whenever we launch significant new features, change how we process data, or to comply with evolving regulations (including App Store and Google Play Store policy updates). We will notify you through:
- In-app notifications when you open the app
- Email notifications to your registered email address
- Website announcements on infinet.services
- Updated "Last Updated" date at the top of this policy
Material changes will be communicated at least 30 days before they take effect. Please review this page periodically for the latest information. Continued use of InfiNet Hub after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, privacy requests, or concerns, reach out to us:
Email: admin@infinet.services
Website: https://infinet.services
Prefer in-app? Open Profile > Privacy & Data Protection inside the InfiNet Hub app.