Privacy Policy

Effective date: July 5, 2026

This Privacy Policy explains how PairOx Pty Ltd (New South Wales, Australia; 4 Lorikeet St, Glenwood NSW 2768), trading as “CollabHub.ai” (“CollabHub.ai,” “we,” “us,” or “our”) — the data controller — collects, uses, shares, and protects personal data when you use the CollabHub.ai research collaboration platform (the “Service”). It should be read together with our Data-Use Covenant, our binding promise never to sell your data or train AI on your private work without your consent.

1. Information We Collect

  • Account information you provide, such as your name, email address, institution, a securely hashed password, and your chosen data region.
  • Content you create on the Service, including notebooks, datasets, experiments, protocols, and files (“Your Content”).
  • Usage and device data such as log data, IP address, browser or device type, and interactions, which help us operate and secure the Service.
  • Payment information if you subscribe to a paid plan — processed by our payment provider; we do not store full card numbers.
  • Cookies and similar technologies used for authentication and preferences, as described below.

2. How We Use It

We use personal data to:

  • provide, operate, and maintain the Service;
  • authenticate you and enable collaboration and sharing features;
  • secure the Service and detect, prevent, and investigate fraud or abuse;
  • provide customer support and send service communications;
  • power collaboration discovery and search — our synergy, discovery, and knowledge-graph features analyze your content to surface anonymous collaboration matches and to structure your work for search, according to the discoverability setting you control (set it to Private to opt out of synergy scanning; withdrawing is forward-only — it stops future matches and further identity disclosure, but does not remove matches already made or identities already mutually revealed);
  • improve and develop features, using usage and aggregate, de-identified data — not the private contents of Your Content for model training (see our Data-Use Covenant); and
  • comply with legal obligations.

3. What We Never Do

We do not sell your personal data or Your Content. We do not use the private contents of Your Content to train, fine-tune, or improve machine-learning models — ours or any third party’s — without your explicit, revocable consent. We do not serve third-party advertising or build sellable profiles from your research. These commitments are set out in full and made binding in our Data-Use Covenant.

4. Legal Bases (GDPR)

Where the GDPR applies, we rely on the following legal bases: performance of a contract to provide the Service you request; legitimate interests in operating, securing, and improving the Service; consent where we ask for it (which you may withdraw at any time); and legal obligation where processing is required by law.

5. Data Sharing & Subprocessors

We do not sell your personal data. We share it only with: service providers (subprocessors) that host our infrastructure, deliver email, process payments, provide error monitoring, or — only when you enable them — provide AI model inference, each under contractual data-protection obligations; collaborators you choose to invite or share your work with; and authorities or third parties where required by law or to protect rights and safety. If we are involved in a merger, acquisition, or asset sale, personal data may be transferred subject to this Policy and our Data-Use Covenant. We can provide the current list of subprocessors on request and will make reasonable efforts to give notice of a new subprocessor. Business customers acting as data controllers can request a Data Processing Addendum (DPA).

6. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service. When you delete your account or specific content, we delete or irreversibly anonymize the associated personal data within a reasonable period (typically within 30 days), except where we must retain limited records to meet legal, tax, accounting, or security obligations, or to resolve disputes.

7. Your Rights

Subject to applicable law, you have the right to access, rectify, erase, and receive a portable copy of your personal data, and to restrict or object to certain processing. You can exercise the core of these rights directly in the app: use the data export tools to download a portable copy of your data, and use account deletion to erase your account and associated content. You may also contact us to exercise any right, and, if you are in the EEA/UK, you have the right to lodge a complaint with your local data-protection authority.

8. Your Australian Privacy Rights (Privacy Act 1988)

We are an Australian company and handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You may request access to, and correction of, the personal information we hold about you (APPs 12–13), using the in-app tools or by contacting us. If you are not satisfied with how we handle a privacy matter, you can contact us first and then complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

9. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to and deletion of it, to correct inaccuracies, and to be free from discrimination for exercising your rights. We do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive personal information for purposes other than providing the Service. You can exercise these rights using the in-app tools or by contacting us.

10. International Transfers & Data Region

We are based in Australia, and at launch we store your data in the United States — so using the Service involves a cross-border transfer of personal information, which we handle consistently with APP 8. As we add data regions you will be able to choose yours, and where personal data is transferred across borders we rely on appropriate safeguards (such as Standard Contractual Clauses for EEA/UK data). We do not move Your Content between regions except as needed to provide the Service you have configured.

11. Cookies

We use strictly necessary cookies to keep you signed in and to secure your session, and preference cookies to remember your settings. You can control non-essential cookies through your browser or any in-app cookie controls we provide; disabling essential cookies may prevent parts of the Service from working. We do not use third-party advertising cookies.

12. Security

We use technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and support for two-factor authentication. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continuously to protect your data and will notify you of a breach affecting your data as required by law.

13. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

14. Automated Decisions

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. AI assistants run at your request, and our synergy/discovery features run in the background per your discoverability setting to surface anonymous collaboration suggestions; none of these make consequential decisions about you on our behalf.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, for example by email or through an in-app notice, before the changes take effect.

16. Contact

For privacy questions or to exercise your rights, contact our privacy team at privacy@collabhub.ai.