Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains how Hubble AI Corporation (“Hubble,” “we,” “us”) handles information in connection with the Hubble platform, developer portal, APIs, and related services (the “Services”).

1. Scope: two kinds of data

This policy covers the account and service data we process as a controller to provide and operate the Services. It does not govern the health records and other Protected Health Information (PHI) that flow through the Services on behalf of our customers. That data is processed under HIPAA and the applicable Business Associate Agreement (BAA), where Hubble acts as a business associate / processor rather than the primary controller. Patients using patient-mediated access are also shown the applicable notice within that flow.

2. Information we collect

We collect the information needed to provide, secure, and support the Services. This generally includes:

  • Account and contact information that you or your organization provide, or that your sign-in provider shares, when you register for and use the Services.
  • Usage and log information generated as the Services are used, which we use to operate, secure, support, and improve them.
  • Device and connection information collected automatically when you access the Services.
  • Health data and other information processed for customers, which is handled under HIPAA and the BAA as described above, not under this policy.

3. How we use information

We use this information to provide, secure, maintain, and improve the Services; to authenticate users and prevent fraud and abuse; to communicate with you about the Services; and to comply with our legal obligations.

4. PHI and HIPAA

Where Hubble processes PHI on a customer’s behalf, it does so only as permitted by the applicable BAA and by law, and it does not use PHI for its own purposes except as permitted under HIPAA. We do not sell PHI or personal information.

5. How we share information

We share information with service providers and subprocessors who help us operate the Services, under contracts that require appropriate confidentiality and security safeguards. We may also disclose information when required by law or legal process, to protect the rights, safety, and security of Hubble, our customers, or others, and in connection with a merger, acquisition, or sale of assets. We do not sell personal information.

6. Cookies

Where we provide websites and web applications, we use only cookies and similar technologies that are essential to operate them and keep you signed in. We do not use third-party advertising or analytics cookies.

7. Data retention

We retain information for as long as needed to provide the Services and for legitimate business and legal purposes, and then delete or de-identify it. Retention of health data processed for customers is governed by the BAA and customer configuration.

8. Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit and at rest and role-based access controls. No method of transmission or storage is completely secure, but we work to protect information and to respond promptly to incidents. You can report a security concern to security@hubble.ai.

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or restrict use of your personal information, or to object to certain processing. To make a request about your account and service data, contact us at privacy@hubble.ai. Requests concerning PHI or other data we hold on a customer’s behalf are directed to that customer, who is the controller of that data.

10. Patient data and consent

Patient-mediated access relies on the patient’s authorization, obtained during the access flow. Patients can review the terms shown in that flow and may withdraw their authorization as described there.

11. Where we operate

The Services are operated in the United States, and information is processed and stored in the United States.

12. Children's privacy

The Services are intended for business users and are not directed to children, and we do not knowingly collect personal information from children. Health records that may pertain to minors are processed only on behalf of customers under HIPAA and the BAA.

13. Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide notice through the Services or by other reasonable means, and the “last updated” date above will change accordingly.

14. Contact

Questions or privacy requests can be sent to privacy@hubble.ai.

See also our Terms of Service. Back to sign in.