Privacy Policy
Last updated: June 6, 2026
This Privacy Policy explains how Hubble (“Hubble”, “we”, “us”) collects, uses, stores, and shares information when you use the Hubble application and website (the “Service”). Hubble is an AI advertising tool for ecommerce brands that connects to your Shopify store and Meta (Facebook/Instagram) ad account to generate, manage, and measure ad creatives.
If you have any questions about this policy or your data, contact us at hello@hubble.co.
Information we collect
- Account information. When you sign up we collect your name and email address via our authentication provider (Google sign-in or email/password).
- Workspace & brand information.Brand details, brand “DNA”, creative briefs, and ideas you create in the Service.
- Shopify data. With your authorisation, product catalog data (products, variants, images, pricing) and order/line-item data used to compute per-product sales metrics. We request read-only access.
- Meta (Facebook/Instagram) data. With your authorisation via Facebook Login, we access your ad accounts, your Facebook Pages list, ad and ad-creative data, and ad performance insights. We store a Meta access token to make these calls on your behalf. We request the ads_read, ads_management, and pages_show_list permissions (plus your public profile). We use ads_management only to create paused ads in your own ad account at your explicit request; we never publish a live ad without your action.
- Billing data. Subscription and payment processing is handled by Stripe. We do not store full card numbers; we store a customer/subscription reference and a usage-credit ledger.
- Generated content inputs. The brand, product, and brief inputs you choose are sent to our AI model providers to generate ad images and copy.
- Usage & diagnostic data. Product analytics events and error reports to operate and improve the Service.
How we use your information
- To provide the Service: generate ad creatives and copy, analyse your existing ads, and surface insights.
- To create paused ads in your connected Meta ad account when you choose to publish.
- To compute product and ad performance metrics shown back to you.
- To process subscriptions and meter usage credits.
- To operate, secure, debug, and improve the Service.
We do not sell your personal information, and we do not use your Shopify or Meta data to train foundation models.
How we share information (sub-processors)
We share data only with service providers that help us run the Service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Shopify — source of your catalog and sales data (at your authorisation).
- Meta Platforms — source of your ad data and destination for ads you publish.
- Stripe — subscription billing and payments.
- AI model providers (via OpenRouter, including Google Gemini, Anthropic, and OpenAI models) — to generate ad images and copy from the inputs you provide.
- Resend — transactional email.
- PostHog (product analytics) and GlitchTip (error monitoring).
Data retention
We retain your account and workspace data for as long as your account is active. You can remove a connected platform at any time (see Data Deletion) and can request deletion of your account and associated data. When you disconnect Meta, the stored Meta access token and connection record for that workspace are deleted immediately. Backups are purged on a rolling basis.
Your choices and rights
- Disconnect Shopify or Meta at any time from Settings → Integrations.
- Request access to, correction of, or deletion of your personal data by emailing us.
- Close your account, which initiates deletion of your data as described in our Data Deletion page.
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and provide the rights above to all users regardless of location.
Security
We use industry-standard measures including encryption in transit, scoped access tokens, row-level security on our database, and restricted internal access. No system is perfectly secure, but we work to protect your data.
Children
The Service is for businesses and is not directed to anyone under 18.
Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, notify you in-app or by email.
Contact
Questions or requests: hello@hubble.co.