Privacy Policy

Last updated: August 14, 2026

Who we are

Higgs Hub ("we", "us") provides a service that lets you connect your Gmail and Microsoft/Outlook mailboxes and grant AI agents access to them through the Model Context Protocol (MCP). This policy describes what we collect, why, and the choices you have.

What we collect

  • Account data: your name, email address, and a salted hash of your password; workspace names and memberships.
  • Mailbox connection data: the email address of each connected mailbox, the OAuth scopes granted, and the OAuth refresh and access tokens issued by Google or Microsoft. Tokens are encrypted with AES-256-GCM before storage.
  • Audit data: a record of actions taken in your workspace (who connected or disconnected a mailbox, which tools an agent invoked and when), including the IP address and browser user-agent the request came from. Audit entries never contain message content or credentials.
  • Website chat data: if you use the chat assistant on this website, we store what you type and what it replies, along with the page you started from, your browser's user-agent, a one-way hash of your IP address, and the country the request came from. We keep this so we can see what visitors are asking. It is deleted after 90 days.
  • Billing data: subscription status and plan, processed by Stripe. We never see full card numbers.

What we do NOT collect

There is no AI of ours in the path. Higgs Hub runs exactly one assistant — the chat box on our website — and it has no access to any connected account. Nothing on our side reads your mail, files or calendar for meaning, classifies it, scores it, or learns from it. Your data goes to the AI assistant you authorized, and to nobody else.

We do not store the contents of your email. When an AI agent you have authorized reads, organizes, or sends a message, the content passes through our servers in memory for the duration of that one request and is not persisted, logged, or used by us for any other purpose. That applies to outgoing mail as much as incoming: we assemble the message, hand it to Google or Microsoft, and keep none of it. The audit log records that something was sent and to how many people — never the recipients, the subject, or the body.

The same holds for files. When you ask an assistant to read a document, a spreadsheet or an image from your Drive or OneDrive, its contents pass through our servers in memory for that one request and are not persisted, logged, or used for anything else. The audit log records that a file was read, how large it was and what type it was — never its name and never what was in it. Organizing files, which is most of what these tools do, never opens them at all.

Sharing. Your assistant can give someone access to one of your files when you ask, and take it back. Only people you name — it can never create a public “anyone with the link” share. It does not email the person either; you get the link and decide how to pass it on. We record that a file was shared, what level of access was given and the permission id needed to revoke it — never the recipient's address.

This is about the contents of your mailbox and your files. What you type into the chat assistant on this website is a separate thing, and we do keep it — see “Website chat data” above.

How Google user data is used (Limited Use disclosure)

Higgs Hub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the mailbox-management features you request through your authorized MCP clients; it is never used for advertising, never sold, never used to train generalized AI or machine-learning models, and never read by humans except with your explicit consent for support, for security investigation, or where required by law.

How Microsoft user data is used

Data accessed through Microsoft Graph is handled the same way: only to fulfil requests made by MCP clients you authorized, never for advertising, profiling, or model training.

Sharing

We share data only with the subprocessors needed to run the service: Vercel (hosting), Neon (database), Stripe (payments), and WaveSpeed (the model behind the assistant on this website) — and with the MCP clients you connect, which receive mailbox and calendar data in response to their requests. We do not sell personal data.

The assistant on this website answers questions about Higgs Hub itself. It has no access to any mailbox, so no message content is ever sent to WaveSpeed — only what you type into the chat box.

What you type there, and the assistant's reply, are also stored on our servers for 90 days so we can see what visitors are asking about. Please don't put confidential information into it.

Retention and deletion

  • Disconnecting a mailbox deletes its tokens immediately and revokes the grant at the provider where supported (Google).
  • We never delete a connected mailbox automatically. Nothing is removed because a subscription lapsed or because a plan changed — deletion only ever happens when you ask for it.
  • Deleting a workspace or your account revokes and deletes every grant it held.
  • Audit records are retained for as long as the workspace exists, for the benefit of the workspace's own compliance.
  • Website chat transcripts are deleted 90 days after the conversation started.

Security

Tokens are encrypted at rest (AES-256-GCM with key rotation), all traffic uses TLS, access is tenant-isolated on every request, and administrative actions are audited. See our Security page for details.

Your rights

You can delete your data at any time from Settings, and you can request an export by contacting us at privacy@higgshub.pro. Depending on your jurisdiction you may have additional rights (access, correction, portability, erasure); we honor verified requests.

Contact

privacy@higgshub.pro