Privacy policy
Effective 24 September 2026
Rack Hub is a private tool that Pavlo Kozan runs for his own work. It has exactly one user, its owner, and the only Google account it connects to is his. This policy describes what Rack Hub does with the data it receives from Google.
What Rack Hub reads
Rack Hub asks Google for one permission: read-only access to Gmail (the gmail.readonly scope). It uses that permission only for messages under one label, HUB, which a Gmail filter fills with notifications from Upwork: invitations and offers, client messages, job alerts, contract and payment notices.
For each of those messages it keeps the sender, the subject, the date and the text. It does not read other labels, contacts, calendar or any other Google data, and it never sends, deletes, labels or changes mail.
How the data is used
- To sort each notification by kind, for example an offer, a message or a payment.
- To estimate how well an offer fits the owner's skills and rates, and to draft a reply that the owner reads before anything is sent by hand.
- To notify the owner's phone about what needs attention.
Sorting, estimating and drafting are done by an AI model. The relevant message text is sent to the model provider's API, currently OpenAI, only to get the answer to that one request. Data sent through the OpenAI API is not used to train OpenAI's models.
Where it is kept
The data lives in a database on a private server rented from OVHcloud in Warsaw, Poland. The server is not reachable from the public internet: only the owner's own devices can connect to it, through an encrypted private network. Copies of the database are kept on the same server for 14 days and on the owner's personal computer for about six months.
Who else processes it
- OpenAI, as the AI model provider described above.
- Google Firebase Cloud Messaging, which delivers notifications to the owner's phone. These notifications can include the subject or a short summary of a message.
- ntfy.sh, a backup notification channel. Its notifications carry no names, amounts or message text.
- OVHcloud, which hosts the server.
The data is never sold, never used for advertising and never shared with anyone else.
Google API Services User Data Policy
Rack Hub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve or train generalized AI or machine learning models, and no person other than the owner reads it.
Keeping and deleting
Messages stay in the database while they are useful for the owner's work and can be deleted from it at any time. Access to Gmail stops at once when it is removed at myaccount.google.com/permissions.
Changes and contact
Any change to this policy is published on this page with a new date. Questions go to privacy@rackhub.dev.