Privacy Policy
This Privacy Policy explains how personal and technical data is handled for Doc Hub — the marketing website, downloads and licensing service, desktop application, paid packs, early email licenses, and related tip jar. It is a product-accurate notice, not legal advice.
We do not sell personal data. We do not run advertising on the Doc Hub marketing site.
1. Who we are
The current data controller for Doc Hub is Maksym Pryimak, an individual in Ukraine. Privacy and product questions: priymak615@gmail.com.
The operator identity (for example a future legal entity or a different contact address) may change. When it does, we will update this section and the Effective date on this page.
2. What this policy covers
This policy applies to:
-
The public marketing site hosted on Cloudflare Pages (currently
dochub-site.pages.dev;
later
doc-hub.appwhen DNS is live). -
The downloads and licensing Worker (currently
dochub-downloads.dochubhq.workers.dev; laterdownloads.doc-hub.app). - The Doc Hub desktop application (local-first launcher).
- Paid pack licensing (including Gumroad checkout webhooks and early license requests by email until 1 September 2026).
- The Carlo Forge Patreon tip jar linked from the site (processed by Patreon under their own policy).
It does not turn local project docs, planning boards, or workspace files on your machine into cloud-hosted personal data unless you deliberately send something (for example by email or by activating a license / syncing an install-set).
An internal operator dashboard may read aggregate download and visit metrics for ops. That dashboard is not shipped to users and is not a product signup flow.
3. Data we process
3.1 Marketing website
- Hosting / edge: Cloudflare may process standard request metadata (IP address, user agent, approximate location, timestamps) to serve pages and protect the network.
-
Optional page analytics (only when configured at
build time):
-
Cloudflare Web Analytics
(
VITE_CF_BEACON_TOKEN) — preferred; no cookies. -
Plausible (
VITE_PLAUSIBLE_DOMAIN) — optional; no cookies. -
Google Analytics 4 (
VITE_GA_MEASUREMENT_ID) — optional; may use Google measurement cookies / signals when enabled. If unset, the site stays on privacy-friendly beacons only.
-
Cloudflare Web Analytics
(
-
Optional waitlist: if
VITE_FORMSPREE_IDis set, the email you submit is sent to Formspree so we can notify you about releases (payload may include a source tag such asdoc-hub-landing). -
Feedback form: messages you submit on the Support
section (topic, optional email, message text) are posted to our
Cloudflare downloads Worker (
POST /feedback), which forwards them to an ops notification workflow (Telegram). We process that content to reply. A mailto fallback to priymak615@gmail.com remains available. - Email contact: if you write to priymak615@gmail.com (feedback, bugs, early pack licenses), we process the content of that message and your email address to reply.
-
Search Console verification: an optional meta tag
(
VITE_GOOGLE_SITE_VERIFICATIONmay be present for Google Search Console; it is not a visitor tracking pixel by itself.
3.2 Downloads and licensing Worker
- Download counters: aggregate hits per platform (mac / win / linux) stored in Cloudflare KV when installers are served through tracked routes.
- Edge / ops metadata: Cloudflare may retain request metadata (for example country or user agent) used for abuse detection and internal funnel metrics. We do not sell this data.
-
Pack licenses (D1): when you buy or activate a paid
pack we may store license key material, pack id, buyer email (for
example from Gumroad), seat count, status (active / revoked), Gumroad
sale id (when applicable), and a
machine_hashbound to activated seats. -
Device install-set (optional sync):
machine_hash, a hasheddevice_token, and pack intent metadata (which packs are enabled / versions / sources). This is not a Doc Hub account and does not include your docs or planning content. Plugin bits still come from the CDN / local extract. -
Feedback intake:
POST /feedbackaccepts topic, optional email, and message text from the marketing site or Doc Hub app, applies a short per-IP rate limit, and forwards the payload to an ops notification workflow (n8n → Telegram). We do not store feedback bodies in Worker KV/D1 in this slice. -
Store proxy: catalog and
.dhpackassets may be proxied from the Pages origin; requests are technical CDN traffic.
3.3 Desktop application
- Local-first by default: workspaces, docs, and planning data stay on your machine. The free baseline does not require an account.
- In-app analytics buffers default to local-only (sync off) unless you turn something on later.
- License activation / seat management and optional install-set push/pull send only the technical identifiers described above to the Worker — not your project documents.
-
A local
device_tokenmay be created under your user config directory for install-set sync authentication. -
The optional Settings → App feedback form posts topic / email / message
to Worker
POST /feedback(see above), not into your local workspace.
3.4 Patreon tip jar
If you join Carlo Forge on Patreon, Patreon is the controller for that membership relationship. See Patreon’s privacy policy. Doc Hub does not receive your card details from Patreon through our own systems.
3.5 Summary table
| Surface | Examples of data | Where it goes |
|---|---|---|
| Website visit | Request metadata; optional analytics events | Cloudflare; optional Plausible / Google |
| Waitlist | Formspree (when enabled) | |
| Feedback form (site / app) | Topic, optional email, message | Downloads Worker → n8n → Telegram ops |
| Email / early license | Email + message content | Inbox at contact address |
| Installer download | Aggregate counters; edge metadata | Worker KV / Cloudflare |
| Paid pack license | Email, key, seats, machine_hash, sale id | Worker D1; Gumroad for checkout |
| Install-set sync | machine_hash, hashed token, pack intents | Worker D1 |
| Desktop docs / board | Project content | Your device (local) |
4. Purposes and legal bases
We process data to:
- Operate and secure the website, CDN, and download routes.
- Understand aggregate usage (visits, OS share, download conversion) and improve the product.
- Fulfil pack purchases and enforce seat limits (contract / legitimate interest in preventing license abuse).
- Answer support, feedback, and early-license email (legitimate interest / steps prior to a contract).
- Send release notifications if you join the waitlist (consent via the form).
Where Google Analytics 4 is enabled, that measurement is optional and configured at build time; treat it as analytics that may rely on consent or similar controls depending on your jurisdiction and browser settings.
5. Cookies and similar technologies
- Cloudflare Web Analytics and Plausible (when used) are designed to work without cookies.
-
Google Analytics 4, if
VITE_GA_MEASUREMENT_IDis set, may set cookies or use similar identifiers. Leave that variable unset to avoid GA4 on the site. You can also use browser controls or blockers. - Essential hosting cookies may be set by Cloudflare for security or network reasons.
This page describes cookies; a separate cookie banner UI is not shipped with the current site. If GA4 is enabled in a jurisdiction that requires prior consent, we will add an appropriate control.
6. Third parties
Depending on which features are enabled, processors / independent services may include:
- Cloudflare — Pages hosting, Workers, KV, D1, R2, Web Analytics.
- Formspree — optional waitlist email capture.
- Plausible — optional analytics.
- Google — optional GA4 and Search Console verification.
- Gumroad — paid pack checkout; sale / email data may flow to our license webhook.
- GitHub — public issues and optional releases fallback for downloads.
- Patreon — tip jar memberships.
7. Retention
- Waitlist emails: kept while useful for release notifications, or until you ask us to delete them.
- Support / early-license email: kept as long as needed to handle the request and ordinary correspondence records.
- License records: kept while the license is active and for a reasonable period afterward for fraud prevention, accounting, or dispute handling; revoked keys remain marked revoked.
- Aggregate download counters: retained as product metrics.
- Device install-sets: retained while sync is used; you can stop syncing locally.
- Local desktop data: under your control (files on disk); deleting the app or workspace removes it from our systems only in the sense that we never held it.
8. Sharing and sale
We do not sell personal data. We share data with service providers only as needed to run the surfaces above, or when required by law. Public GitHub issues you open are public by nature.
9. International transfers
Infrastructure and vendors (for example Cloudflare, Gumroad, Formspree, Google, Patreon) may process data outside Ukraine and the European Economic Area. Those providers apply their own transfer mechanisms and policies. By using the online surfaces you acknowledge that such processing may occur.
10. Security
We take reasonable technical measures for the current architecture, including:
- Hashing device tokens at rest on the Worker.
- Signed license artifacts (
.lic) after activation. - Keeping operator secrets (stats tokens, signing keys, webhook secrets) out of the public website bundle.
No method of transmission or storage is perfectly secure. Protect your machine, license keys, and email account.
11. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to certain processing, and to withdraw consent (for example waitlist). To exercise these rights for data we control, email priymak615@gmail.com with enough detail to locate your data.
For purchases on Gumroad or memberships on Patreon, also use those platforms’ account and privacy tools — they hold checkout or membership records directly.
12. Children
Doc Hub is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child provided data to us, contact us and we will delete it where appropriate.
13. Changes
We may update this Policy when the product or operator details change. The Effective date at the top will be revised. Continued use of the online surfaces after an update constitutes notice of the revised Policy for those surfaces.
14. Contact
Privacy and product contact: priymak615@gmail.com.
You can also open an issue on the public releases repo.