Project data confidentiality
Who owns the project data you put into H2Hub, how it is isolated, when AI touches it, and how it is deleted.
Last updated 9 August 2026
Document control
- Version
- 1.1
- Last reviewed
- 9 August 2026
- Next scheduled review
- 9 February 2027
- Scope
- Project data retention & deletion
Reviewed on change as well as on schedule: this document is re-issued whenever an AI model, AI feature, subprocessor, hosting region or transfer mechanism changes.
1. Ownership
You own the project data you create or upload — project definitions, assumptions, scenarios, schematics, documents and notes. We claim no ownership of it. We use it only to operate the service for you and the collaborators you invite.
2. Isolation
Project records are stored per account and protected by row-level security in the database: queries are scoped to the authenticated owner and to team members explicitly granted access. Uploaded files are held in private storage buckets that require an authenticated, authorised session. Public share links are read-only and only exist when you create one; revoking a link ends access.
3. Confidentiality
We do not sell your project data, disclose it to other customers, or publish it. Your data is never merged into the public H2Hub intelligence datasets. Staff access is limited to the minimum needed for support and incident response, and only on request or where necessary to fix a fault.
4. AI processing of your project data
AI features run only when you invoke them. When you do, the relevant project attributes (and, for document analysis, the text you supplied) are sent to the model provider named in the AI transparency notice. Under our API-tier agreements your content is not used to train those providers' models. We do not use your project data to train models of our own.
Please avoid uploading material you are not permitted to share with a US-based processor, and redact personal data that is not needed for the analysis.
5. Retention and deletion
- Project records and files are kept while your account is active.
- Deleting a project removes it from the application immediately and from backups within 30 days.
- Closing your account deletes project data within 90 days, except records we must keep for tax or accounting.
- AI prompt/response logs are deleted after at most 30 days.
- Downgrading a plan never deletes data — scenarios above the new limit become read-only until you upgrade.
To request export or deletion, email contact@reneenergy.com.
6. Security
Data is encrypted in transit (TLS) and at rest by our hosting provider. Access requires authentication; administrative capabilities are server-side and role-checked. We log application and security events and investigate anomalies. No system is risk-free — report suspected issues to the address above and we will respond promptly.
7. Scope of outputs
Analyses built from your project data are preliminary and decision-support in nature. They are not licensed professional engineering services or investment advice and require independent professional review before commercial or investment decisions.