Privacy Policy

Last updated: 12 July 2026

1. Who we are

Pubner ("Pubner", "we", "us") is a multi-tenant platform that lets developers and agencies build and host websites for their own clients. This policy explains what data we handle, why, and the choices you have. It covers our marketing site, the Hub account area, and the platform services.

2. The data we handle

Depending on how you use Pubner, we handle:

  • Account data — your name, email address and a securely hashed password when you register a Hub account, or your name and email received from Google if you choose to sign in with Google.
  • Content you create — templates, pages, assets, database records and settings you build inside the platform.
  • Usage and billing data — logs of platform and AI usage that we use to operate the service and calculate costs, plus your plan, subscription status and transaction references from our payment provider. Full card details are handled by the payment provider and never touch our servers.
  • Optional Telegram link — if you connect the Telegram assistant, we store your chat identifier and username so the bot can message you. Send /stop to the bot (or disconnect in the panel) and the link is removed.
  • Technical data — IP address, browser information, session cookies and server logs needed to run and secure the service.

3. Your data vs. your clients' data

Pubner operates on two levels, and our role differs for each:

  • For your Hub account, we act as the data controller.
  • For data inside the websites you build (your clients' end-users, their records and content), you are the controller and Pubner acts only as a data processor on your behalf. You are responsible for having your own privacy notice for the people who use your sites.

4. How we use data

We use the data above to operate, maintain and improve the platform, to authenticate you, to provide support, to calculate usage and billing, and to send you essential service messages such as account verification, password resets and security notices.

5. AI features and third-party processing

When you use the AI Builder or AI Assistant, the relevant content — such as your templates, records and the prompts you write — is sent to third-party AI (LLM) providers so they can generate a response for you. This content is processed to fulfil your request. We work to use providers that do not train their models on your content, but their own terms ultimately apply. If you do not want content processed this way, do not use the AI features.

The same applies to the optional AI surfaces you can switch on: the visitor chat widget sends visitors' questions (with your published content as context) to an AI provider to compose the answer, and a voice note sent to the Telegram assistant is transcribed by an AI provider. Messages you exchange with the Telegram assistant also pass through Telegram itself under Telegram's own terms and privacy policy.

6. Service providers

We rely on a small set of trusted third parties to run the service: AI (LLM) providers for the AI features, an email delivery provider for transactional email, a payment provider that acts as the merchant of record for paid plans, an anti-bot verification service (Cloudflare Turnstile) that protects our sign-up forms, Google as a sign-in option, Telegram for the optional messaging assistant, and infrastructure/hosting providers. These providers process data only as needed to provide their service to us. Some may be located outside your country, in which case the data is transferred under appropriate safeguards.

7. Cookies

We use a small number of essential cookies — chiefly a session cookie to keep you signed in and a preference cookie for things like your timezone and language. Our anti-bot verification provider may set its own cookie while confirming you are human. We do not use advertising cookies.

Sites hosted on the platform include a built-in, cookie-less visit counter: page views are counted as daily aggregates (page path, view count, an approximate visitor count derived from a one-way hash that is never stored). No identifier is placed on the visitor's device and no browsing profile is built; aggregates are kept for 13 months and are visible only to the site owner.

8. Data retention and deletion

We keep account and content data for as long as your account is active. Deleted sites are first moved to a recoverable "trash" state and can be restored for 30 days before permanent removal. You can ask us to delete your account and associated data at any time.

9. Security

Security is central to how Pubner is built. Each tenant website runs in its own isolated environment with strict data separation, passwords are stored only as secure hashes, and access is restricted on a need-to-know basis. No system is perfectly secure, but we take reasonable measures to protect your data.

10. Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, a copy of your data in a portable format, or object to certain processing. To exercise any of these rights, contact us at support@pubner.com.

11. Changes and contact

We may update this policy as the platform evolves; we will revise the date above when we do. Questions about privacy can be sent to support@pubner.com.