Policy

Privacy policy

Version 1.0 · Last updated 11 September 2026

1. Who is responsible for your data

1.1 The controller of the personal data described here is PowerHub Inc., registered as EIN: 38-4357318, at 1111B S GOVENORS AVE STE 34162 DOVER, DE 19904-6903-117. Privacy questions and requests go to legal@powerhub.dev.

1.2 We are the controller for your account, your pledges, your campaign, your feedback and your use of our website.

1.3 For the content of the AI requests you send through our inference endpoint we are an intermediary: we forward the request to the provider you addressed and we do not retain it (section 5). Where that request contains someone else's personal data, you are the controller of it and the provider is your processor or sub-processor under their terms, not ours. Do not send personal data through the endpoint unless you have a lawful basis for doing so.

2. What we collect

2.1 Account

Email address, screen name, password (stored only as a hash by Supabase Auth, never in readable form), profile text, avatar, the roles you hold, whether you have set up two-factor authentication, sign-in timestamps. If you sign in with Google or GitHub, we receive your email address, name and avatar from that provider, not your password.

2.2 Campaigns and rounds

Everything you type into a campaign or a round: title, summary, description, category, media you upload, round goals and deadlines, requested providers and models, milestones, updates, and any playable link you publish. Campaign media is stored in a public storage bucket. Anyone with the URL can open it, so do not upload anything private.

2.3 Pledges and money

The campaign and round you backed, the amount, the currency, the time, whether you paid by card or from your wallet, the pledge's status, your wallet and ledger entries, and refund requests with their reasons and outcomes.

We never see or store your card number. Card payments happen on Stripe's own hosted checkout page. We send Stripe the amount, the currency, the campaign's title, your email address, and our own pledge, round and backer identifiers. Stripe sends us back a payment reference, the payment's status, and the fee it charged. That is all we get.

2.4 Inference requests

For each request through the endpoint: the time it started and settled, the campaign, the key id, the provider, the model, the endpoint path, the status, the number of input, cached and output tokens, the amount reserved, the amount charged, and an error message if it failed.

2.5 Feedback

The page you were on, an optional score from 1 to 5, your note, and your user id if you were signed in. Feedback can be left signed out, in which case there is no user id. Feedback you leave on a backer-only build is linked to your account and is visible to that campaign's creator.

2.6 Launch interest

If you ask to be told when a category opens: the category, your email address, and optionally your name and a note.

2.7 Technical data

Our servers and those of our infrastructure providers process the usual request data (IP address, user agent, URL, timestamp, response status) to serve pages, apply security headers, rate-limit abuse and diagnose faults. Your IP address is sent to Cloudflare when the Turnstile "I am human" check is verified; we do not write it into our own records for that purpose. Application logs record what happened, not who you are, and we do not log the contents of forms.

2.8 Analytics and product measurement

We use Google Analytics 4 to understand how people move through PowerHub. It records the pages you view, the page you came from, the type of device and browser you use, an approximate location derived from your IP address, and a small number of named events that tell us a step was completed: page_view, sign_up, pledge_start, pledge_complete, campaign_submit, key_issued, rate and share_click. The same tag, with the same measurement id, runs on the pages of our own game PowerPlex (powerplex-sandbox.powerhub.dev and, once released, powerplex.powerhub.dev); there it always runs with storage denied, so it counts the visit and writes nothing to your browser.

How it is configured, exactly:

  • The tag loads only on deployments where we have set a measurement id. Where none is set, no analytics script is loaded at all.
  • It starts with Google Consent Mode v2 and every storage type denied: analytics_storage, ad_storage, ad_user_data and ad_personalization. Nothing is stored on your device until you accept.
  • We ask you once, in a banner at the bottom of the page. Accept, and analytics storage is switched on for you. Decline, and Google still receives a cookieless, unattributed count of the visit, with no identifier written to your browser. Your choice is remembered in your browser's local storage and you can change it at any time; section 9.3 says where.
  • Your IP address reaches Google with the request, as it does with any web request. Google Analytics 4 uses it to work out an approximate location and does not log or store it, and there is no setting that changes that. (The anonymize_ip flag of the previous version of Analytics is ignored by Google Analytics 4, so our tag does not send it.)
  • Automatic page-view collection is turned off; we send one page-view per route ourselves, so no page is counted twice.

Where a campaign lists pledge levels, pledge_start carries one more thing: the title of the level you picked, so we can see which levels get chosen. It carries no pledge id, no campaign id and nothing that says who paid. If you did not pick a level, it carries nothing extra.

One of those events carries a number: pledge_complete is sent with the amount of that pledge in whole dollars and the currency, which is how the analytics property counts what was pledged. It carries no pledge id, no campaign id and nothing that says who paid.

Two of them are about a campaign, and neither says which one. rate is sent when you score a campaign out of 10; it carries no score and no campaign id, only the fact that somebody rated. share_click is sent when you press one of the sharing buttons and carries only the name of the network you pressed (x, bluesky, threads, reddit, linkedin, whatsapp, telegram, email, copy or system), never the campaign, the link or the text you shared. The UTM parameters on a shared link (utm_source, utm_medium=share, utm_campaign) travel in the link itself and identify the campaign and the network, never the person who shared it.

We send Google no name, email address, user id, campaign id or any other value that identifies you. Event names are verbs and event values are small counts or, in the one case above, an amount.

We may add other product-measurement services later. If we do, we will list the service in section 8, describe it here, and ask before it loads where the law of your country requires consent for it.

We do not sell your personal data, we run no advertising networks, and we set no cross-site advertising cookies.

2.9 What we do not collect

We do not ask for your date of birth, your address, your phone number, or any government identifier, unless a legal obligation forces us to verify a specific creator's identity. We do not collect special-category data. We do not knowingly collect anything from a person under 18.

2.10 Pledge levels

Where a campaign lists pledge levels: the level you chose on a pledge; the delivery records for it (the link, key or note the creator sent, and whether you have opened it); and, where you entered one, the credit name you want shown. Your credit name is visible to the campaign's creator, and, if the creator publishes credits in their game, to anyone who plays it. A campaign's creator can export a CSV of their own backers listing screen name, level, amount, date and credit name, never your email address.

WhatWhyLegal basis (GDPR / UK GDPR)
Account dataTo create and secure your account, sign you in, contact youPerformance of a contract (Art. 6(1)(b))
Campaigns and roundsTo publish and run your campaignPerformance of a contract
Pledges, wallet, refundsTo take payment, settle rounds, refund you, keep booksPerformance of a contract; legal obligation for accounting records (Art. 6(1)(c))
Inference metadataTo meter spending exactly, bill against a balance, find faults, investigate abusePerformance of a contract; legitimate interests in preventing abuse and running the service (Art. 6(1)(f))
Pledge levels (level chosen, delivery records, credit name)To run the level you chose, deliver what the creator owes you, and show a credit name where you give onePerformance of a contract
Turnstile, rate limits, fraud screeningTo keep bots, fraud and card abuse outLegitimate interests; legal obligation where anti-fraud rules apply
FeedbackTo improve PowerHub, and to pass a build's feedback to its creatorLegitimate interests; consent where you volunteer it
Launch interestTo tell you when a category opensConsent (Art. 6(1)(a)); withdraw it any time
Transactional emailTo tell you about funding, keys, refunds and securityPerformance of a contract
Google AnalyticsTo count visits, see which pages work and find where people get stuckConsent (Art. 6(1)(a)); asked in a banner before anything is stored, withdrawable at any time
Security logsTo detect and investigate attacks and outagesLegitimate interests
Your analytics choice (ph_consent)To honour the answer you gave and stop asking againLegal obligation (Art. 6(1)(c)) and legitimate interests

4. Who we share it with

4.1 We share personal data only with the service providers listed in section 8, and only as far as each needs it to do its job for us. Each of them is bound by a contract that limits what they may do with it.

4.2 We also disclose data where the law requires it, to respond to a valid legal request, to establish or defend a legal claim, to enforce our Terms, and to a provider investigating abuse of its models. In that last case we disclose the request metadata in section 2.4, never a prompt, because we do not have prompts.

4.3 If PowerHub is acquired or merged, data may transfer to the acquirer, subject to this policy or one at least as protective. We will tell you.

4.4 We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act. Google Analytics runs with every advertising storage type denied and none of Google's advertising features enabled, so it is used for measurement only.

5. What happens to your prompts

5.1 We do not store the content of your requests, and we do not store the content of the provider's answers.

5.2 A request arrives at our endpoint, is checked against the campaign's balance and limits, and is forwarded to the provider unchanged. The answer is streamed back to you as it arrives. While a response streams, our Worker keeps at most 64 KB of it in memory so it can read the provider's usage figures out of the stream; that memory is discarded when the request ends and is never written to disk or to our database.

5.3 The only record left behind is the metering row in section 2.4. There is no field in it for a prompt or a completion.

5.4 What the provider does with your request is governed by that provider's terms and its agreement with us. See Third-party AI providers, section 3.2.

6. How long we keep it

6.1 This is what we apply. Where two rows could cover the same record, the longer period wins.

DataKept for
AccountWhile your account exists, then deleted or anonymised within 30 days of closure, except records section 6.2 requires us to keep
Campaigns and public contentWhile published; removed content stays in backups for up to 30 days
Pledges, ledger entries, refunds, fee recordsAs long as accounting and tax law requires; commonly 6 to 10 years depending on the jurisdiction
Inference request metadataFor the life of the campaign, as the record of what its budget bought
Endpoint availability probes30 days (the code deletes older rows on every probe run)
Background job runs7 days
FeedbackUntil we have acted on it and no longer need it
Launch interestUntil the category opens, or until you ask us to remove you
Security and access logsShort retention set by our infrastructure providers, typically days to weeks
Google AnalyticsThe retention set on our Analytics property. Google's default for user and event data is 14 months; write to us for the setting in force

6.2 We keep what we must: money records for accounting and tax, and the minimum needed to defend a legal claim or to satisfy an anti-fraud obligation. Closing your account does not erase those, and it does not erase the ledger entries that make the books balance. Those are pseudonymised rather than deleted.

7. Where your data goes

7.1 We are based in State of Delaware, USA. Our service providers operate globally, including in the United States, so your data is processed outside your country.

7.2 For transfers out of the European Economic Area, the United Kingdom or Switzerland we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum and the Swiss amendments where they apply, incorporated into our agreements with the providers in section 8. Some of those providers are additionally certified under the EU–US Data Privacy Framework.

7.3 Google LLC is in the United States. Analytics data reaches it under the EU–US Data Privacy Framework, with the Standard Contractual Clauses in Google's own data processing terms as the fallback basis. Because analytics storage is denied until you accept, a visitor who declines is counted without an identifier being written to their browser.

8. Sub-processors and service providers

8.1 These are every company that processes personal data for us, each under a written data processing agreement that limits them to our instructions.

ServiceCompanyWhat it does for usData it sees
SupabaseSupabase, Inc.Database, authentication, file storageAccount, campaigns, pledges, ledger, feedback, uploaded media
CloudflareCloudflare, Inc.Hosting (Workers), the inference endpoint, Turnstile, network securityRequest data, IP address, the request stream in transit
StripeStripe, Inc.Card payments and refundsYour email, the amount, the campaign title, our identifiers, your card details (which Stripe holds, not us)
ResendResend, Inc.Transactional emailYour email address and the message
OpenAIOpenAI OpCo, LLCAI model requestsThe content of requests you address to its models
AnthropicAnthropic, PBCAI model requestsThe content of requests you address to its models
GoogleGoogle LLCAI model requestsThe content of requests you address to its models
Google (sign-in)Google LLCOptional sign-inYour email, name and avatar, if you use it
GitHubGitHub, Inc.Optional sign-inYour email, name and avatar, if you use it
Google Analytics 4Google LLC (United States)Product analytics, under Consent Mode v2 with storage denied until you acceptPage views, referrer, device, your IP address (used for an approximate location, not stored), the eight event names in section 2.8, the network name that share_click carries and the pledge amount that pledge_complete carries

8.2 We update this list when we change providers. The AI model rows above are the providers the inference endpoint serves today; the current list, with each company’s terms, usage policy and privacy policy, is the generated table in section 2 of Third-party AI providers. Write to legal@powerhub.dev to be told when it changes.

9. Cookies and similar technologies

9.1 PowerHub uses the smallest set of cookies that lets it work.

CookieSet byPurposeType
sb-*-auth-token and its chunksSupabase Auth, on our domainKeeps you signed in and refreshes your sessionStrictly necessary
Turnstile challenge cookiesCloudflare, on challenges.cloudflare.comRuns and validates the "I am human" check on our formsStrictly necessary
Theme preferenceUs, in your browser's local storageRemembers light or dark modeStrictly necessary
ph_consentUs, in your browser's local storageRemembers whether you accepted analytics, so we stop askingStrictly necessary
_ga, _ga_*Google AnalyticsCounts visits and distinguishes returning browsers; set only after you acceptAnalytics; consent-based

9.2 Strictly necessary cookies and storage do not require your consent, and PowerHub does not work without them. The ph_consent entry is in that category because it exists only to record and honour your answer.

9.3 Analytics is consent-based. The banner appears once, before any analytics storage is written. If you decline, Google Analytics still counts the visit without writing anything to your browser. You can change your mind at any time from the control at the bottom of this page. Turning it off is one click, exactly like turning it on.

9.4 We set no advertising cookies and we run no cross-site tracking. Google's advertising storage types are denied in our configuration and we never switch them on.

9.5 Your browser can block or delete cookies. Blocking the auth cookie will sign you out; blocking Turnstile will stop the sign-up, sign-in and reset forms working.

9.6 Our web fonts are served from our own domain, so loading a page does not tell a font provider that you visited us.

9.7 Embedded videos. A campaign can link a video that is hosted on YouTube or Vimeo. Opening the campaign page requests nothing from either of them: you see the campaign's own cover image with a play button. The player loads only when you press play: YouTube in its privacy-enhanced mode (youtube-nocookie.com), Vimeo with do-not-track set. From that moment the provider's own privacy policy applies to whatever it stores or collects in your browser. We upload nothing to them and they tell us nothing about you.

10. Your rights

10.1 Wherever you live, you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to a use of it; and receive it in a portable format. Where we rely on consent you can withdraw it at any time, without affecting what we did before.

10.2 If you are in the EEA, the UK or Switzerland, those are your rights under the GDPR or UK GDPR, and you may complain to your national supervisory authority.

10.3 If you are in California, you may ask what we collected, used and disclosed in the past 12 months; ask us to delete it; ask us to correct it; and opt out of sale or sharing, although, as section 4.4 says, we do neither. We will not discriminate against you for exercising a right. An authorised agent may act for you with written proof.

10.4 How to exercise a right. Write to legal@powerhub.dev from the address on your account, or from another address with enough detail for us to identify you safely. We answer within one month, and we will tell you if we need longer because the request is complex.

10.5 Some data we cannot delete on request: money records the law requires us to keep, and ledger entries that would break the books. We restrict and pseudonymise those instead, and we tell you which ones.

10.6 We do not make decisions about you by automated means that produce a legal or similarly significant effect. Fraud screening may flag a payment, but a person decides what happens next.

11. Security

11.1 Every database table denies access by default, and access is granted by explicit rules tied to your account. Money commands are database functions with their own checks, not general write access, and each one writes an audit row.

11.2 Operator accounts require two-factor authentication before any money action in production. Sign-up, sign-in and password reset are behind Cloudflare Turnstile.

11.3 Pages are served with a Content-Security-Policy carrying a per-request nonce, plus HSTS, X-Content-Type-Options, Referrer-Policy, X-Frame-Options and Permissions-Policy.

11.4 API key secrets are stored encrypted in the database's vault, readable only by the campaign's own owner and only through an audited command; revoking a key deletes the stored secret. Every other secret lives in the platform's secret store, never in our code.

11.5 No system is perfectly secure. If a breach affects you and the law requires it, we will tell you and the relevant authority within the time the law allows.

12. Children

12.1 PowerHub is for adults. You must be 18 or older to hold an account, because our AI providers require it. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete it and close the account. Write to legal@powerhub.dev if you believe a child has given us data.

13. Changes to this policy

13.1 The version and effective date are at the top of this page. We will tell you by email or in the app before a material change takes effect, including before we add any analytics or tracking service beyond the one described in section 2.8, or change what an existing one is allowed to store.

14. Contact

14.1 legal@powerhub.dev, or by post to PowerHub Inc., 1111B S GOVENORS AVE STE 34162 DOVER, DE 19904-6903-117.

Your analytics choice

Section 9 of this policy explains what the analytics cookies do. This is the switch.

Analytics cookies: not chosen yet

Who operates PowerHub

Operator
PowerHub Inc.
Registered as
EIN: 38-4357318
Address
1111B S GOVENORS AVE STE 34162 DOVER, DE 19904-6903-117
Governing law
State of Delaware, USA
Contact
legal@powerhub.dev