← Back to SupportHub

Privacy Policy

Last updated: July 22, 2026 | Effective: July 22, 2026

1. Who We Are

SupportHub is an AI-powered multi-channel customer support platform available at supporthub.cryptiq.network (the "Service").

The Service is developed and operated by YH CONSTRUCTION LTD under the SupportHub / Cryptiq.Network brand.

Legal entity details: YH CONSTRUCTION LTD, registered in England and Wales, company number 16850307, registered office address: 4 Carlisle Street, London, England, W1D 3BJ, United Kingdom.

Company contact: telephone +44 7700 181684, company website cryptiq.network, product website supporthub.cryptiq.network.

For privacy-related questions or requests, contact: privacy@supporthub.cryptiq.network.

Important: YH CONSTRUCTION LTD is the legal operator of SupportHub and acts as the responsible entity for this Privacy Policy.

2. Scope of This Policy

This Privacy Policy explains how SupportHub collects, uses, stores, shares, and deletes personal data when you use the Service, connect third-party platforms, communicate through integrated channels, or interact with support workflows powered by the Service.

This Privacy Policy applies to administrators, workspace owners, invited operators, and end users whose messages are processed through connected channels, subject to applicable law and the role distinctions described below.

3. Roles of the Parties

Depending on the type of data involved, SupportHub may act either as an independent controller or as a service provider processing data on behalf of a customer.

  • YH CONSTRUCTION LTD (SupportHub) as controller: for account registration data, billing and payment records, security logs, direct communications with us, and service administration data.
  • SupportHub as processor / service provider: for customer support conversations, connected-channel messages, user profiles, attachments, and similar content processed on behalf of a customer using the Service.

If you are a business using SupportHub to handle communications with your own customers, you are responsible for ensuring that you have an appropriate legal basis for that processing and for providing any notices required by applicable law.

4. What Data We Collect

CategoryExamplesMain Purpose
Account DataTelegram, Google, or Facebook account identifier, username, email address, name, profile image, and workspace membershipAuthentication, admin access, account management
End-User DataPlatform user ID, chat ID, display name, usernameMessage routing, conversation handling, ticket management
Message ContentMessages, reply history, language information, attachment referencesSupport delivery, automation, conversation history
Knowledge Base DataArticles, snippets, uploaded text, FAQs, workflow instructionsAI-assisted response generation and service customization
Feedback DataRatings, comments, quality signalsService quality monitoring and improvement
Integration DataOAuth tokens, API keys, webhook secrets, platform identifiersConnecting and maintaining third-party integrations
Usage DataFeature usage, AI message counters, timestamps, technical eventsRate limiting, analytics, troubleshooting, billing
Security DataIncident records, abuse signals, and limited message fragments where needed for security reviewAbuse prevention, prompt-injection detection, fraud mitigation
Payment DataOrder ID, plan, amount, payment status, and transaction hash for crypto paymentsSubscription management and accounting
We generally do not intentionally collect: passwords for third-party platforms, government-issued identifiers, full bank card numbers, or precise geolocation data.

5. Sources of Data

  • Directly from you when you sign in with Telegram, Google, or Facebook, configure the Service, contact us, or submit support requests.
  • From third-party platforms that you connect, such as Telegram, Instagram, Messenger, WhatsApp, Threads, YouTube, Discord, LINE, VK, and similar services.
  • Automatically from your use of the Service, including logs, counters, system events, and security telemetry.
  • From content submitted by workspace owners, operators, or end users through connected channels.

6. How We Use Data

  • Provide the Service: route messages, show conversations, and manage tickets, operators, and workspaces.
  • Enable AI features: generate replies, classify messages, translate text, improve workflow quality, and support moderation features.
  • Maintain integrations: authenticate platform connections, receive webhooks, and send replies through connected channels.
  • Protect the Service: detect abuse, prompt injection, spam, fraud, unauthorized access, and service misuse.
  • Billing and records: manage plans, usage limits, invoices, and payment tracking.
  • Communicate with users: provide notices, support responses, and operational updates.
  • Comply with law: comply with legal obligations, lawful requests, and dispute handling.

7. Legal Bases for Processing

Where UK GDPR, EU GDPR, or similar laws apply, SupportHub relies on one or more of the following legal bases:

PurposeTypical Legal Basis
Core automation features and subscription functionalityPerformance of a contract
Service security, abuse prevention, fraud detectionLegitimate interests
Tax, accounting, and compliance recordsLegal obligation
Optional marketing or consent-based communicationsConsent
Processing performed on behalf of business customers for their end usersProcessing on customer instructions and the customer's own legal basis

If a customer uses SupportHub to process personal data of its own users, the customer remains responsible for providing any required notices and obtaining any required permissions.

8. AI Processing

SupportHub uses third-party AI models to generate and support automated responses and related features.

8.1 Private Messages

Before private messages are sent to external AI providers, they are intended to pass through a PII anonymization layer designed to detect and replace common personal identifiers with placeholders such as [PERSON_1] or [EMAIL_1].

No anonymization system is perfect, and some identifiers may remain undetected in certain cases. Users should avoid sending unnecessary sensitive personal data through the Service.

8.2 Public Content

Public comments or other publicly visible content from connected platforms may be processed without anonymization where this is necessary to provide the Service and where the content was made publicly available by the relevant platform user.

8.3 AI Providers and OpenRouter

SupportHub uses OpenRouter as an AI model routing provider. Depending on the selected workflow or model route, OpenRouter may route requests to third-party model providers such as OpenAI, Google, Mistral, Anthropic, or other providers made available through OpenRouter.

Data sent for AI processing may therefore be handled by OpenRouter and by the destination model provider selected through OpenRouter.

AI training statement: SupportHub does not intentionally use customer message content to train its own proprietary AI models. Third-party AI providers process data under their applicable terms and policies; users should review those policies before enabling AI-powered features.

8.4 Automated Assistance

AI outputs are generated automatically and may be inaccurate, incomplete, biased, or inappropriate. Human review is strongly recommended for sensitive, legal, financial, medical, security-related, or high-impact communications.

SupportHub does not intentionally use solely automated decision-making that produces legal or similarly significant effects about a person.

9. Third-Party Platforms

SupportHub may receive data from APIs and services provided by Telegram, Meta platforms, Google/YouTube, Discord, LINE, VK, and other connected providers. Your use of those integrations is also subject to the relevant third-party policies and permissions model.

We access only the data reasonably necessary to provide the requested integration and support automation functions. We do not sell platform data.

Meta Platform Integrations

SupportHub may offer optional Facebook Login using the public_profile and email permissions. When you choose it, Meta may provide an app-scoped Facebook user identifier, name and other basic public-profile fields, and an email address where available. SupportHub uses this information only to create, authenticate, secure, display, and, where you request it, link your SupportHub account. SupportHub does not receive your Facebook password.

SupportHub's official Meta integrations may connect Instagram professional accounts, Facebook Pages and Messenger, WhatsApp Business accounts, and Threads profiles. Depending on the integration and permissions approved by the user, SupportHub may receive and process access tokens; Page, account, profile, phone-number, conversation, message, comment, media, and webhook identifiers; display names and profile images; message or comment content and reply history; timestamps, delivery or read state, attachments or media references; and the technical metadata needed to maintain the connection.

We use this Meta Platform data only to authenticate and display the connected business source; receive and route messages, comments, mentions, and webhook events; let authorized workspace members respond and perform supported moderation actions; provide enabled support, translation, classification, analytics, automation, and security features; and comply with user deletion requests. We do not sell Meta Platform data or use it for third-party advertising.

A user may remove the relevant SupportHub app through Meta's Settings & Privacy > Settings > Apps and Websites controls and may request deletion through Section 13 or the Data Deletion page. SupportHub also accepts and verifies Meta's signed deauthorization and data-deletion callbacks for its supported Meta integrations.

Use of Meta integrations is also subject to the Meta Privacy Policy, applicable Meta Terms, and the permissions and controls presented by Meta.

10. Sharing and Sub-Processors

ProviderRoleRegion
Supabase / AWS infrastructureDatabase and storage infrastructureEU and/or US
Render or similar hosting providersApplication hosting and deploymentUS and/or other supported regions
OpenRouterAI routing providerAs described in provider documentation
Underlying model providers used through OpenRouterAI inference servicesDepends on selected provider and route
Other technical vendorsEmail, logging, analytics, monitoring, or anti-abuse toolingDepends on configured vendor
  • We do not sell personal data to data brokers.
  • We do not provide data to third parties for advertising purposes.
  • We may disclose data where required by law, to enforce our terms, to respond to lawful requests, or to protect users, the Service, or the public.

11. International Transfers

Your data may be processed in countries other than your own, including the United States, depending on your hosting configuration, connected platforms, and selected AI providers.

Where required by applicable law, we rely on appropriate safeguards such as contractual protections, provider commitments, and other recognized transfer mechanisms. Because SupportHub uses third-party infrastructure and AI services, transfer locations may vary over time.

12. Data Retention

Data TypeRetention
Message content and conversation historyUp to 12 months from creation unless deleted earlier by configuration, user request, or legal necessity
End-user profilesUp to 12 months after last activity unless deleted earlier
Security logs and incident recordsGenerally up to 6 months, longer if needed for abuse investigation or legal defense
Feedback and quality recordsUp to 12 months
Admin account dataUntil account deletion or as needed for legitimate account maintenance
Integration credentials and tokensUntil the relevant integration is disconnected, rotated, or deleted
Payment and transaction recordsFor the period reasonably required for accounting, tax, and dispute handling
BackupsRetained for a limited rolling period and overwritten or deleted on the backup schedule

We may retain certain data for longer where necessary to comply with legal obligations, resolve disputes, enforce agreements, investigate abuse, or protect the Service.

13. Data Deletion

You may request the deletion of your personal data at any time. To process your request, please follow these instructions:

  • How to request: Send an email to privacy@supporthub.cryptiq.network with the subject "Data Deletion Request", or use any deletion request flow made available inside the Service.
  • Information to include: Please provide your account identifier (e.g., email address, phone number, or Account/Telegram ID) and specify the channels connected.
  • Identity verification: We may ask you to reply from the email address or account associated with the request to confirm your identity.
  • Review and execution: Deletion requests are reviewed and executed by authorized SupportHub personnel after identity verification and applicable legal or retention checks.
  • Timeframe: We will acknowledge your request within 7 days and complete the deletion within 30 days of verifying your identity.
  • Retention exceptions: Some data may be retained longer if required by law (e.g., financial/billing records for tax purposes or security logs for abuse prevention).
  • Facebook / Meta connection: To remove the connection to our app via Facebook, go to your Facebook account settings: Settings & Privacy > Settings > Apps and Websites, find "SupportHub", and click Remove.

14. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal data, and to withdraw consent.

If you are in the UK, EEA, or another jurisdiction with similar rights, you may also have the right to lodge a complaint with your local data protection regulator.

Requests may be submitted to privacy@supporthub.cryptiq.network. We will respond within a reasonable time and may request information necessary to verify identity and scope.

15. Security Measures

SupportHub uses reasonable technical and organizational safeguards including transport encryption, access controls, secret management, role-based access, logging, webhook verification, abuse monitoring, and security review practices.

No system can guarantee absolute security, and users remain responsible for securing their authentication accounts, connected platform credentials, devices, and operator access.

16. Children's Privacy

SupportHub is not intended for use by children under 16. We do not knowingly design the Service for children or intentionally collect their personal data as a target audience. If you believe that personal data relating to a child has been submitted inappropriately, contact us and we will review the request.

17. Google OAuth 2.0 and YouTube API Disclosure

Google Sign-In

SupportHub offers Google Sign-In through Google OAuth 2.0 using the openid, email, and profile permissions. When you choose this option, Google may provide SupportHub with your Google account identifier, email address and email-verification status, name, profile image, and other basic profile fields included in those permissions. We use this information only to create, authenticate, secure, display, and, where you request it, link your SupportHub account. SupportHub does not receive or store your Google password, and Google Sign-In does not give SupportHub access to Gmail, Google Drive, contacts, calendars, or other Google products.

Connecting a YouTube Channel

Workspace administrators can voluntarily connect a YouTube channel to SupportHub through Google OAuth 2.0 and the YouTube Data API v3. For the YouTube integration, SupportHub requests the https://www.googleapis.com/auth/youtube.force-ssl permission. This permission is required for the channel-management and comment-moderation functions described below. Although the permission can technically allow broader access to YouTube videos, ratings, comments, and captions, SupportHub uses it only for the features described in this Policy and presented in the Service.

Depending on the features you use, SupportHub may access, collect, process, and store:

  • Authorization and connection data: Google OAuth access and refresh tokens, connection status, connection time, and the identifiers needed to maintain the authorized connection.
  • YouTube channel data: channel ID, channel title, channel URL, profile image or thumbnail, and uploads-playlist information.
  • Video data: video IDs, titles, descriptions, thumbnails, publication times, links, and available statistics such as comment, view, and like counts.
  • Comment and reply data: comment and thread IDs, text, author display names, author channel IDs, author profile images, timestamps, like counts, reply counts, and moderation context.

How SupportHub Uses YouTube Data

SupportHub uses YouTube data to verify and display the connected channel; show channel videos, statistics, comments, and replies in the SupportHub workspace; synchronize YouTube comments into the unified inbox; allow authorized workspace members to review and respond to comments; and provide enabled support, classification, translation, moderation, analytics, and automation features.

When an authorized user expressly chooses the corresponding action, SupportHub may use the YouTube API to publish a comment or reply, change a comment's moderation status, or delete a comment authored by the connected channel. The user remains in control of these actions. SupportHub does not upload, edit, or delete YouTube videos; modify captions or ratings; or perform undisclosed actions merely because the broader OAuth permission could technically allow them.

If a workspace administrator enables an AI-assisted feature for the YouTube source, relevant comment text and limited conversation context may be processed by SupportHub and the authorized AI infrastructure providers identified in Section 10 solely to provide that enabled feature, such as drafting or delivering a reply, classification, translation, or moderation assistance. SupportHub does not intentionally use Google or YouTube user data to train its own proprietary or general-purpose AI models.

Storage, Sharing, and Limited Use

OAuth access and refresh tokens are stored in encrypted form and are used only to maintain the connection and make authorized YouTube API requests. SupportHub may store connected-channel metadata and synchronized YouTube conversation data in the workspace database for the periods described in Section 12. YouTube API data that must be refreshed or deleted under YouTube policies is refreshed or deleted within the applicable policy period.

Google and YouTube user data is available only to the authorizing user, workspace members and operators authorized by that user, and service providers that process data for SupportHub under appropriate obligations. We do not sell Google or YouTube user data, use it for advertising, creditworthiness or lending decisions, or disclose it for surveillance. Human access by SupportHub personnel is limited to cases where you give consent, it is required for security or abuse investigation, it is necessary to comply with law, or it is needed for internal operations and the data has been appropriately aggregated or protected.

SupportHub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Your Control, Revocation, and Deletion

You can stop SupportHub's access by removing the YouTube source in SupportHub and by revoking SupportHub in your Google Security Settings. When authorization is revoked, SupportHub will stop making authorized YouTube API requests and delete the associated OAuth tokens and stored Authorized Data as soon as possible and no later than 7 calendar days after SupportHub receives or detects the revocation, except for data that must be retained by law or is permitted to be retained in a securely blocked form.

For anti-abuse, fraud-prevention, ownership-history, and rate-limit enforcement, SupportHub may retain a non-reversible security record derived from the connected channel identifier where legally permitted. This record does not contain an OAuth token, cannot be used to access a Google account or YouTube content, and does not restore deleted Authorized Data.

You may also request deletion through the procedure in Section 13, through the Data Deletion page, or by emailing privacy@supporthub.cryptiq.network. Deleting data stored by SupportHub does not delete content held by YouTube. To delete YouTube content itself, use YouTube directly. SupportHub's comment controls may submit a user-confirmed action affecting the specifically identified YouTube comment.

Applicable Google and YouTube Terms

Use of these integrations is also subject to the Google Privacy Policy, the YouTube Terms of Service, and the YouTube API Services Terms of Service.

18. Changes to This Policy

We may update this Privacy Policy from time to time. If material changes are made, we will post the updated version with a revised date and may provide notice through the Service or by other reasonable means.

19. Contact