Privacy Policy

Last updated: October 2, 2026 · Belgian-registered, EU-based

1. Who We Are

SevinHub is operated by Sergiu Vincze, sole proprietorship registered in Belgium under enterprise number 1042.245.006, seat Blivensstraat 43 bus 101, 2100 Antwerpen, Belgium. This policy explains what personal data I collect, why, and your rights under the General Data Protection Regulation (GDPR).

Data Controller contact: admin@sevinhub.com (support requests: contact@sevinhub.com)

2. Data We Collect

Account Data

When you register: name, email address, username, and password (stored as a secure hash, never in plain text).

Purchase Data

When you make a purchase: payment method details (processed securely by Stripe, we never store full card numbers), order information, and download records.

Support & Communication

When you contact support: name, email, message content, and any attachments you provide.

Technical Data

IP address (for security logging and rate limiting), browser type, pages visited, and session data. This is used to prevent fraud and improve security.

Optional Game Profile and Scores

If you use SevinHub section games while signed in, you may set a separate public game name for leaderboards and lobbies. This does not change your account username or full name. When you post a leaderboard result, SevinHub stores your user ID, game, board variant, score or time, session elapsed time, and post timestamp.

Climate Action Badge

Public SevinHub pages display one active official 1ClickImpact climate badge at a time. When it loads, your browser contacts 1ClickImpact's content and API services and sends the normal network request information, including your IP address, browser request metadata, and the SevinHub origin or referrer. The badge records an aggregate impression toward its configured environmental-impact threshold. Its requests omit browser credentials, and the badge does not set or use a tracking cookie through SevinHub.

When configured, 1ClickImpact sends SevinHub a signed lifecycle webhook after an impact action starts. SevinHub uses it to rotate the active badge. We retain only a one-way event hash, the impact type, badge identifier, processing result and timestamp. We do not retain the full webhook payload, customer email, customer name or provider tracking identifier for this badge rotation.

Optional ExplainHub AI Data

ExplainHub works locally without AI. If you deliberately select SevinHub AI and start an AI analysis, the source text and its locally prepared semantic candidates are sent through our server to 1min.ai solely to return the requested structure. The source is not stored as a SevinHub cloud project. We retain only a usage record containing your user ID, or a one-way hash of your IP address for guests, the provider model, success status, and timestamp.

ExplainHub Local Project Files and Images

ExplainHub can open project files, PDF, DOCX, PPTX, Markdown, HTML, text, images, and vector asset-pack files that you deliberately choose from your device. Document text extraction, local project content, image assets, vector packs, themes, reusable brand kits, logo images, local font choices, interface and output language preferences, page formats, layouts, and exports are processed inside your browser and stored only in your browser or in files you save. SevinHub does not upload or retain these local files, brand settings, language preferences, or extracted text. Selecting a hosted AI route sends source text and the selected output-language code only after your separate deliberate analysis action and does not send image assets, logos, brand kits, or vector packs. Any future image-analysis action will require a separate explicit choice and privacy disclosure before transmission.

Optional ExplainHub Android Private Model

The ExplainHub Android app can optionally download a clearly identified open model after you review its exact download size, working-storage requirement, source, license, and privacy behavior and give explicit consent. The model host receives the normal file-download request, but the request contains no project source, labels, images, brand assets, or generated structure. Android keeps resumable download progress, verifies the completed file against a fixed byte count and SHA-256 checksum, and installs it in app-private storage. Private-model analysis runs inside the Android application process and does not upload source content. Removing the model deletes the model, partial download, and runtime cache without deleting ExplainHub projects. The full editor and Rules route continue to work without this model.

Optional ExplainHub Cloud Shares and Comments

ExplainHub cloud publishing is optional and requires a signed-in account. New cloud snapshots are private by default. If you deliberately publish an unlisted link, anyone who receives that hard-to-guess link can view the published copy. A cloud snapshot can include source text, labels, protected facts, layouts, themes, pages, embedded images, logos, brand settings, output-language choice, and the asset packs used by the project. Snapshots are encrypted at rest. They are not sent to an AI provider merely because they are published.

If comments are enabled for a share, a signed-in commenter sends their account ID, displayed author name, comment text, and timestamp to SevinHub. We also keep a one-way IP hash with the comment for rate limiting and abuse prevention. Share owners can disable comments, remove comments, or delete the complete shared snapshot. Commenters can remove their own comments.

Optional Jarvis ZEN Private Relay

Jarvis ZEN can optionally download the identified Gemma 4 E2B model from Hugging Face after the user reviews its 2.59 GB size, approximate 4 GB free-storage requirement, source, and local privacy behavior and explicitly starts installation. The model host receives the normal download request, but no voice audio, transcript, prompt, contact, calendar data, or Jarvis memory is included. Android keeps resumable progress, verifies the fixed file size and SHA-256 checksum, and stores the model in Jarvis private application storage. Ordinary Gemma inference then runs on the device.

Jarvis ZEN works with local device commands without an online account. If the owner deliberately pairs a device with the private relay, SevinHub stores the device name, application version, revocable device-token hash, pairing and last-contact timestamps, request status, route, and response latency. The device token itself is encrypted on the Android device using Android Keystore. The relay does not retain raw audio, speech transcripts, prompts, model answers, contacts, calendar contents, or precise location by default.

When Jarvis routes a question to online intelligence, the submitted prompt, the locally configured display name, and the bounded in-memory conversation context required for that answer are sent through the SevinHub relay to 1min.ai. Current-information questions may enable 1min.ai web search. The display name is stored in the app's local settings and is not saved as a Jarvis server profile. Request metadata is retained for quota control and reliability, but prompt and answer text is not written to the Jarvis database or application logs. Pairing is owner-controlled, single-use, time-limited, and revocable.

Jarvis weather commands use Open-Meteo directly and do not use 1min.ai credits. If the user names a city, that city name is sent to Open-Meteo's geocoding service. If no city is named and the user has granted Android Location permission, the app sends the phone's last available latitude and longitude directly to Open-Meteo to request current conditions. SevinHub does not receive or retain the city, coordinates, or weather response. Weather access occurs only after an explicit weather request.

On a paired Jarvis device, the app automatically keeps up to 10 pending sanitized diagnostic reports in private application storage and sends them to the SevinHub relay when a connection is available. A report contains a random event identifier, failure category, exception and cause class names, sanitized code stack frames, thread name, app version, Android version, device manufacturer and model, and timestamps. Reports do not contain exception messages, voice audio, speech transcripts, prompts, answers, API keys, contacts, calendar contents, the configured display name, or precise location. They are visible only in the authenticated Jarvis owner panel and are retained for up to 30 days.

3. Legal Basis for Processing (GDPR)

  • Contract performance: Processing necessary to fulfill your purchase and provide account services
  • Legitimate interests: Security logging, fraud prevention, and site analytics
  • Contract performance and consent: Optional section-game leaderboards, public game name, and posted scores that you choose to submit
  • Legitimate interests: Counting climate-badge impressions so SevinHub page views can contribute toward funded environmental impact
  • Consent: Marketing communications (only if you opt in)
  • Consent: Optional ExplainHub hosted AI processing when you select that route and start an AI analysis
  • Consent: Optional Jarvis ZEN relay pairing and online intelligence when the owner enables and uses that route
  • Consent: Jarvis ZEN live weather lookup when the user explicitly asks for weather, including optional use of Android Location permission
  • Legitimate interests: Sanitized Jarvis ZEN crash diagnostics from paired devices, used to diagnose failures and improve reliability
  • Contract performance and consent: Optional ExplainHub cloud snapshots, unlisted sharing, and collaboration features that you deliberately enable
  • Legal obligation: Retaining transaction records as required by Belgian law

4. How We Use Your Data

  • Fulfill and manage your purchases and download access
  • Send transactional emails (purchase confirmations, password resets, support replies)
  • Prevent fraud, abuse, and unauthorized access
  • Improve the Platform and fix technical issues
  • Provide optional ExplainHub cloud sharing and review comments
  • Show optional section-game leaderboards, lobbies, and public game names
  • Authenticate paired Jarvis ZEN devices, enforce AI quotas, and return requested online answers
  • Return live weather without consuming hosted AI credits
  • Diagnose Jarvis ZEN crashes and protected background-task failures without collecting conversation content
  • Comply with legal obligations

5. Data Sharing

We do not sell your personal data. We share data with:

  • Stripe: Payment processing. Their privacy policy applies to payment data: stripe.com/privacy
  • Hosting provider: For server infrastructure (data stored in the EU where possible)
  • Rybbit (app.rybbit.io): Privacy-focused, cookie-free web analytics. Its script loads on public pages and records page views, referrer, device type and country derived from your IP address. It does not set cookies and does not receive your account, purchase or support data. Their privacy policy: rybbit.io/privacy
  • 1min.ai: Optional AI processing for ExplainHub when you select SevinHub AI, and for Jarvis ZEN when a paired device uses online intelligence. Their privacy terms apply to data processed by their service.
  • Open-Meteo: Live Jarvis ZEN weather and geocoding requests sent directly from the Android device. Their service receives the requested city name or coordinates and the normal network request metadata.
  • 1ClickImpact: Climate badge delivery, aggregate impression counting, and environmental-impact tracking. Their privacy policy applies to requests handled by their service: 1clickimpact.com/privacy-policy

We will disclose data if required by Belgian or EU law enforcement with a valid legal request.

6. Data Retention

  • Account data: retained while your account is active and for 2 years after deletion request
  • Transaction records: retained for 7 years as required by Belgian tax law
  • Security logs: retained for 90 days
  • Support tickets: retained for 3 years
  • Game profile and posted leaderboard scores: retained while your account exists. You can clear your game name, and posted scores can be removed by admin on request.
  • ExplainHub hosted AI source text: not retained by SevinHub after the response completes
  • ExplainHub AI quota and security records: retained for up to 30 days
  • ExplainHub cloud snapshots and comments: retained until the share owner deletes the share, or the commenter or owner removes an individual comment
  • Jarvis ZEN prompt and answer text: not retained by SevinHub after the response completes
  • Jarvis ZEN paired-device records: retained until the owner revokes and deletes the device
  • Jarvis ZEN quota and reliability records: retained for up to 30 days
  • Jarvis ZEN sanitized crash diagnostics: retained for up to 30 days

7. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data (subject to legal retention requirements)
  • Portability: Receive your data in a machine-readable format
  • Restriction: Request we limit processing of your data
  • Object: Object to processing based on legitimate interests
  • Withdraw consent: For any processing based on consent

To exercise any right, email contact@sevinhub.com. We respond within 30 days.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).

8. Cookies

We use a single session cookie (sevinhub_sess) required for login and CSRF protection. This is a strictly necessary cookie, no consent is required. We do not use advertising or tracking cookies.

9. Security

We implement technical and organisational measures including: bcrypt password hashing, CSRF protection on all forms, rate limiting on authentication, input validation, and HTTPS enforcement in production.

10. Children's Privacy

The Platform is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has provided data, contact us and we will delete it.

11. Changes to This Policy

We may update this policy. Material changes will be communicated via email or a prominent notice on the site. The "last updated" date at the top reflects the most recent revision.

12. Contact

Privacy questions: contact@sevinhub.com

Terms of Service · Cookie Policy · ← Home
SevinOS Invisible Atlas