graph-hub legal

Privacy Policy

This policy describes how GraphHub processes personal data when you create an account, use graph workspaces, manage organizations, or browse public demo content.

Effective date: 2026-08-25

Data we process

Account data can include email address, username, display name, password hash, email verification state, profile fields, and MFA settings.

Workspace data can include graphs, schemas, nodes, relationships, dashboards, reports, saved analyses, data views, access roles, invitations, and audit entries created by users.

Operational data can include authentication sessions, security events, request metadata, diagnostics, and limited logs needed to protect and maintain the service.

Why we process data

We process account and workspace data to provide the GraphHub service, authenticate users, manage access control, render graph data, and preserve user-created configuration.

We process security and diagnostic data to prevent abuse, troubleshoot failures, audit changes, and keep the application reliable.

Where billing or plan limits are enabled, billing metadata is processed to apply entitlement limits and manage subscriptions.

User-generated graph data

GraphHub lets users model and import graph data. Users are responsible for making sure they have a lawful basis for any personal data they add to a graph.

Do not upload special-category or highly sensitive personal data unless you have the required legal basis, permissions, and security controls.

Retention and deletion

Audit entries are designed to be retained only for a limited operational period. Other account and workspace data is retained while the account or workspace remains active, unless deletion is requested or required.

Email verification, password reset, refresh session, and MFA challenge data should be kept only as long as needed for authentication and security.

Your rights

Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete your personal data.

For a portfolio deployment, contact the project operator through the contact details provided on the landing page or repository.