Data protection is of the highest priority for PathHub AI. The use of our website (pathhub.ai) is generally possible without providing personal data. If you wish to use special services of our platform (app.pathhub.ai), the processing of personal data may be necessary. Where the processing of personal data is required and there is no legal basis for such processing, we will obtain your consent.
The processing of personal data is always carried out in accordance with the General Data Protection Regulation (GDPR) and the applicable German data protection regulations. This Privacy Policy informs you about the type, scope, and purpose of the personal data we collect, use, and process, as well as your rights.
The data controller for data processing on this website is:
PathHub AI
Email: hello@pathhub.ai
Our website uses cookies. The cookies we use are:
We do not use any tracking, advertising, or analytics cookies. Detailed information can be found in our Cookie Policy.
Our web server (Nginx) and the CDN service Cloudflare automatically collect information in server log files that your browser transmits:
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security and stable operation of the website). The data is not merged with other data sources.
When registering on our platform (app.pathhub.ai), we collect and store:
The legal basis is Art. 6(1)(b) GDPR (contract performance). Your data is stored server-side in a SQLite database on our Hetzner server in Germany.
After registration, we send you a confirmation email to the email address you provided. The email is sent via the service Resend (Resend, Inc., USA). Your email address and the verification link are transmitted to Resend. The legal basis is Art. 6(1)(b) GDPR (contract performance). Privacy policy of Resend: resend.com/legal/privacy-policy.
After login, a cryptographically secure session token (64 characters, randomly generated) is set as an httpOnly cookie. The token references a server-side session entry in the database. No localStorage and no sessionStorage is used in the browser for personal data. The legal basis is Art. 6(1)(b) GDPR (contract performance).
When you create a Path (project plan), we store the following data server-side:
This data is exclusively assigned to you and is not visible to other users. The legal basis is Art. 6(1)(b) GDPR (contract performance).
Optionally, you can provide information about your company/workspace (company name, industry, team size, stakeholders, challenges). This data is stored as JSON files on the server and serves to improve the AI analysis of your projects.
You can upload documents (PDF, Word, Excel, CSV, TXT) to your workspaces. These are stored as files on the server in a protected directory and are only accessible to you. The files are deleted when the workspace is deleted or upon your request.
Upon upload, the text content of the documents is automatically extracted and stored. With the Max plan, you can activate documents as AI reference. In this case, the extracted text content is transmitted to DeepSeek during AI requests (see Section 5). You decide which documents are used as AI references.
A core component of PathHub AI is AI-powered project planning. Project data is transmitted to external AI services to generate project plans, recommendations, and chat responses.
Important: We only send project data (descriptions, phases, tasks, budgets, company context) and -- if activated by you -- the text content of AI reference documents to DeepSeek. Your personal data such as name, email address, or password is not sent. According to their policies, DeepSeek does not use data transmitted via the API to train their models.
When you contact us by email, your information (name, email address, message content) is stored to process your inquiry. The data is deleted once storage is no longer necessary. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).
For payment processing, we use Stripe (Stripe, Inc., USA / Stripe Payments Europe, Ltd., Ireland).
Stripe may set its own cookies on the Stripe domain during the payment process. Details can be found in Stripe's privacy policy.
For sending system emails (verification, password reset), we use the service Resend (Resend, Inc., USA).
We do not send marketing emails or newsletters. Only transactional emails necessary for the operation of your account are sent.
Our platform is operated on a server of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The server is located in the data center in Falkenstein/Vogtland, Germany. All user data (database, files, uploads) is stored exclusively on this server in Germany.
Our domain uses Cloudflare, Inc. (USA) as a DNS and CDN provider. Cloudflare may process technical access data (IP address, browser information) to optimize traffic and protect against attacks.
Our website loads the "Inter" font from Google servers. A connection to Google servers is established, and Google may receive technical access data (IP address). No cookies are set by Google Fonts.
When using our platform, personal or project-related data may in certain cases be transferred to recipients in third countries (outside the EU/EEA):
The AI features of PathHub AI generate suggestions for project plans, budgets, risks, and recommendations. These suggestions are not automated individual decisions within the meaning of Art. 22 GDPR. They serve solely as support and recommendations. You decide whether and how to incorporate the AI suggestions into your project. All AI-generated content can be edited and deleted by you at any time.
Personal data is deleted once the purpose of its storage no longer applies:
Statutory retention periods (in particular commercial and tax law) remain unaffected.
You have the following rights under the GDPR:
If you have any questions about data protection or wish to exercise your rights, you can reach us at:
hello@pathhub.ai
We reserve the right to update this privacy policy to ensure it always complies with current legal requirements and reflects our actual data processing practices. The current version can always be found on this page.
Last updated: February 17, 2026