Privacy and Security Notice
Effective: August 10, 2026
Hubble AI Corporation provides Individual Access Services under the Trusted Exchange Framework and Common Agreement (TEFCA). This means we help you gather your own health records from your providers and from the national health networks, at your direction. This Notice explains how we access, use, protect, and share the information we collect for you, and the choices and rights you have. We wrote it in plain language on purpose. If anything here is unclear, email us at privacy@hubble.ai and we will explain it.
Request-Only IAS Provider: Hubble does not provide bidirectional services. You will have the ability to request access to your health information via TEFCA Exchange. You will not be able to use Hubble to share your health information with other participants in TEFCA.
How HIPAA applies
Hubble is not a HIPAA covered entity, and is not subject to the Health Insurance Portability and Accountability Act (HIPAA) as a matter of law, when it provides Individual Access Services to you directly. That means HIPAA’s protections do not automatically apply to the information you bring into Hubble. We protect your information using HIPAA-aligned safeguards and commit to the protections described in this Notice regardless.
How we access your information
We only request your records when you ask us to. To search the national networks on your behalf, we first verify your identity to a federal standard (IAL2), so that only your records are returned. We connect to your providers using their own secure login, and we never see or store your provider passwords.
How we use, share, or sell your information
- We never use your information to make a claim against you. Your information cannot be accessed, exchanged, used, or disclosed by Hubble to assert any type of claim against you, except to collect any fees you owe us.
- We do not sell your information, now or in the future. Hubble does not sell your information, does not receive anything of value in exchange for it, and does not use it for targeted advertising.
- Where your information goes.We share your information only with the service providers that help us run Hubble, and only as needed to provide the service to you: an identity verification provider; health data network and connectivity providers; and U.S.-based cloud hosting and managed database providers. Once records are retrieved from a source system, that source system remains outside Hubble’s control; and if you direct Hubble to send a copy of your records to a recipient you name, that recipient’s use is outside Hubble’s control. We do not share your health information with any advertising, analytics, or marketing provider.
- Why we use it. We use your information only to provide Individual Access Services to you: locating, requesting, retrieving, and displaying your records at your direction. We do not use it for any other purpose.
- We do not de-identify your information.
- TEFCA disclosures. Any disclosures we make through TEFCA follow only the permitted and required uses and disclosures in the Common Agreement and applicable U.S. Department of Health and Human Services guidance.
If the government demands your information
- If we receive a subpoena, court order, search warrant, or other legal demand to disclose your information, we will notify you in writing or electronically within three (3) business days, unless we are legally prohibited from telling you. You have the right to object, or to seek a protective order or other remedy allowed by law.
- If we make your information available to law enforcement (including through any sale of data), we will notify you in writing or electronically within three (3) business days, unless prohibited by law.
How we protect your information
Hubble is required to act in conformance with this Privacy and Security Notice, and to protect the security of the information it holds in accordance with its applicable Framework Agreement under TEFCA (its Terms of Participation, which incorporates the requirements of the Common Agreement), which is the source of these security obligations. In practice:
- We use commercially reasonable efforts to protect your information from unauthorized or illegal access, modification, use, or destruction.
- We encrypt all of your information, both in transit and at rest, whether or not it is TEFCA Information.
- If your information has been, or is reasonably believed to have been, affected by a security incident or breach (an “IAS Incident”), we will notify you.
- Our obligations under this Notice continue for as long as we maintain your information.
- We require the service providers that handle your information to keep it confidential, protect it with appropriate safeguards, and use it only to provide services to Hubble.
Your rights and choices
- Access. You can access your information by any of these methods:
- View in Hubble (Recommended). Open the secure Hubble link to see the records we gathered in one place. You can download your records from the Hubble link as a PDF (a readable copy) or as FHIR R4 (a machine-readable copy) so you or an app you choose can read it.

- Email privacy@hubble.ai to request a copy.
- Call us (toll-free): (888) 512-9028.
- View in Hubble (Recommended). Open the secure Hubble link to see the records we gathered in one place. You can download your records from the Hubble link as a PDF (a readable copy) or as FHIR R4 (a machine-readable copy) so you or an app you choose can read it.
- Deletion. You can require that all of your information held by Hubble be deleted completely, to the extent technically feasible, unless deletion is prohibited by law. To request deletion, email privacy@hubble.ai; we will complete it within 30 days. This does not apply to information in our audit logs.
- Incident notice. You will be notified if your information is reasonably believed to have been affected by an IAS Incident.
You control the collection, use, deletion, and disclosure of your information, and we put your choices into effect within a reasonable time.
Because Hubble is a Request-Only IAS Provider, we do not disclose your information in response to requests from other participants through TEFCA Exchange, so there is no outbound-sharing choice to make. We only retrieve records at your direction.
Your consent, and how to withdraw it
Before we access, exchange, use, or disclose your information (other than disclosures required by law), we ask for your express, documented, and informed consent to this Notice. We ask for it at the start of your first use of Hubble, and again before we ever use your information in a materially different way, or make a material change to this Notice. We keep a secured, auditable record of your consent.
You can revoke your consent at any time, by any of these methods:
- Email privacy@hubble.ai. Use a subject line such as “Revoke Consent Request.” In the body, include your First Name, Last Name, Birthdate, Gender, and Address. Clearly state that you are revoking your consent, and describe the scope of your request, including whether you are also requesting deletion of your data or a copy of your information. If we need more information to verify your identity or clarify your request, we will contact you using the email address the request was sent from.
- Call us (toll-free): (888) 512-9028.
- Disconnect directly in the app.

Revoking consent does not undo anything we already did in reliance on your consent before you revoked it. After you revoke consent, you will no longer be able to access Hubble’s services.
How long we keep it
We keep your information only for as long as we need it to provide the service to you. If you revoke your consent, we stop accessing and using your records right away. You can have it deleted sooner at any time by emailing privacy@hubble.ai (see Your rights and choices). We retain information longer only where a law requires it.
Fees
Hubble does not charge you any fees to use Individual Access Services or to exercise your rights, including access, export, or deletion. There are no current fees as of the effective date of this Notice.
If there is a security incident affecting your information
If a security incident or breach affects, or is reasonably believed to affect, your unencrypted information, we will notify you. That notice will include, to the extent possible:
- a brief description of what happened, including the date of the incident and the date we discovered it, if known;
- the types of information involved;
- steps you can take to protect yourself;
- what we are doing to investigate, reduce harm, and prevent it from happening again; and
- how to reach us, including a toll-free phone number, an email address, and a website with contact information.
Consent to Sale
Hubble does not sell your information, does not receive anything of value in exchange for it, and does not use it for targeted advertising or marketing. Because we do not do any of these things, we do not ask you for a separate “Consent to Sale.”
How to reach us, and how to complain
If you have a question about your privacy, or want to file a complaint, contact the Hubble Privacy Team:
- Email: privacy@hubble.ai
- Phone (toll-free): (888) 512-9028
We keep a record of privacy-related complaints, our response, and how each one is resolved. You may also contact the network you accessed through TEFCA.
Changes to this Notice
We keep this Notice current and publicly available at all times, including past versions, and we post it conspicuously in the app and on our website. If we make changes, we post them no later than the change’s effective date, and we conspicuously highlight any Material Changes (changes that affect how we use or share your information in a way you would not reasonably expect). If you are already enrolled, we make reasonable efforts to get updated versions to you in the way you have told us you prefer.
Effective date of this Notice: August 10, 2026
Effective date of most recent Material Change: None (this is the first version).