KleinHub AI
Home
Legal

Privacy Policy

Last updated: July 17, 2026

This Privacy Policy explains how KleinHub AI ("KleinHub AI", "we", "our", or "us") collects, uses, discloses, and safeguards information when you use our AI business operating system, including our websites, dashboards, storefronts, and related services (collectively, the "Service"). This page is maintained by the KleinHub AI team to answer common privacy questions about the platform.

1. Who this applies to

KleinHub AI is a multi-business SaaS platform. It applies to:

  • Operators — the account holders who sign up to build and run businesses on KleinHub AI.
  • End customers — the shoppers, subscribers, and contacts of operators who interact with storefronts, pay-links, and emails powered by KleinHub AI.

When an operator uploads or generates data about their own customers, the operator is the controller of that data and KleinHub AI acts as their processor.

2. Information we collect

Account & authentication data. Email, name, hashed password or OAuth identifiers (e.g. Google), and session tokens — handled by our authentication provider (Supabase Auth).

Business data. Business names, brand info, products, pay-links, storefront content, campaigns, tasks, and settings you create or that AI generates on your behalf.

Customer & contact data. Names, email addresses, and other contact fields that operators add, import, or that end customers submit through storefronts and pay-links.

Payment data. Payments are processed by Stripe (including Stripe Connect). KleinHub AI does not store full card numbers, CVCs, or bank credentials — Stripe handles PCI-DSS compliance. We store non-sensitive metadata such as amounts, currency, order IDs, Stripe customer/account IDs, and payment status.

Email & messaging content. Emails you draft, schedule, or send through KleinHub AI, including recipient lists and delivery status. If you connect your own Resend or SendGrid account, your API key is encrypted at rest and used only to send on your behalf.

AI usage data. Prompts, generated outputs, credit consumption, and action logs used to power the AI CEO, marketing, storefront, and other agents, and to meter credit-based billing.

Technical data. IP address, browser/device info, log data, cookies and similar identifiers used for auth sessions, security, and basic product analytics.

3. How we use information

  • Provide, operate, and secure the Service.
  • Generate AI content (brand, websites, products, marketing, logos, replies) on your instructions.
  • Process payments and platform fees through Stripe Connect.
  • Send transactional and marketing emails you initiate or schedule.
  • Meter subscription tiers (Starter / Growth / Scale) and credit-pack usage.
  • Prevent fraud and abuse, and comply with legal obligations.
  • Improve the Service — we do not sell your personal data.

4. AI processing

KleinHub AI uses AI models to generate business content on your behalf. Inputs and outputs are processed by our AI providers strictly to fulfill your request. Model providers may briefly retain content for safety and abuse monitoring per their own policies. AI output may be inaccurate — you are responsible for reviewing content before publishing or sending.

5. Third-party processors

We share data with the following subprocessors only as needed to run the Service:

  • Supabase — database, authentication, storage, realtime.
  • Stripe / Stripe Connect — payment processing and platform payouts.
  • Resend — outbound email (default provider).
  • SendGrid — outbound email when you connect your own account.
  • AI model providers — for content generation.
  • X (Twitter) — when you connect an account to publish posts.
  • Hosting / CDN — to serve the app and storefronts.

6. Cookies

We use a small number of first-party cookies and localStorage entries for authentication sessions, preferences, and security. We do not use third-party advertising cookies.

7. Data retention

We retain account and business data for as long as your account is active. Order, payment, and email delivery records are retained as required for tax, accounting, and anti-fraud purposes (typically up to 7 years). You may request deletion at any time — residual copies in encrypted backups are purged on our standard rotation.

8. Your rights

Depending on your location (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Operators can manage most data directly in-app; for anything else, contact us at the address below.

9. Security

We use TLS in transit, encryption at rest for sensitive fields (including connected email-provider API keys), role-based access, and Postgres row-level security. No system is 100% secure — please use a strong unique password and enable available account protections.

10. Children's privacy

KleinHub AI is not directed to children under 16 and we do not knowingly collect data from them. If you believe a child has provided personal data, contact us and we will delete it.

11. International transfers

Your data may be processed in countries other than your own, including the United States. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app or by email. The "Last updated" date above always reflects the current version.

13. Contact

Questions or requests: privacy@nexusbiz.app.