Security
Security is a core design principle.
Our approach includes:
- Local-first architecture where practical
- Encrypted connections using HTTPS/TLS
- Secure authentication
- Regular software updates
- Responsible vulnerability disclosure
- Least-privilege access principles
- User-controlled AI integrations
More information is available in our Security Policy.
Privacy
We believe your data belongs to you.
Whenever practical:
- Projects remain on your device.
Prompt history remains local.
API keys are stored locally.
Files are only transmitted to external services when you explicitly request it.
Our Privacy Policy explains what information we collect and how it is used.
AI & Data Handling
OneHub allows you to connect AI providers of your choice.
Depending on your configuration, prompts and files may be sent directly to providers such as:
- OpenAI
- Anthropic
- xAI
- OpenRouter
- Fal
- Replicate
- and others
OneHub does not claim ownership of your prompts or generated content.
Use of third-party AI services is governed by their respective terms and privacy policies.
Local-First Architecture
OneHub is designed so that, where technically feasible:
- Project files remain on your device.
AI provider credentials remain on your device.
Workflows execute locally.
Customer data is not uploaded to OneHub-operated services unless required for a feature you choose to use.
Cloud-connected features are optional and initiated by the user.
Encryption
Data in Transit
Communications with OneHub-operated services and supported integrations are encrypted using HTTPS/TLS.
Data at Rest
Where OneHub stores customer information, commercially reasonable safeguards are used to protect stored data.
Authentication
Where accounts are required, OneHub supports secure authentication mechanisms.
Customers are encouraged to:
- use strong passwords
- enable multi-factor authentication where available; and
protect API credentials.
Third-Party Services
Depending on your configuration, OneHub may integrate with third-party providers for AI, payments, authentication, cloud storage, or productivity workflows.
A current list of major providers includes:
- OpenAI
- Anthropic
- xAI
- OpenRouter
- Fal
- Replicate
- Stripe
- PayPal
- Clerk
- Vercel
Vulnerability Disclosure
If you discover a security issue, we encourage responsible disclosure.
Please report security concerns to:
- security@onehub.design
Include:
- description of the issue
- reproduction steps
- affected version(s); and
supporting evidence where appropriate.
Please do not publicly disclose vulnerabilities until they have been investigated.
Incident Response
If OneHub confirms a security incident affecting customer data under our control, we will investigate promptly and provide notifications where required by applicable law.
Compliance
OneHub is designed with modern privacy and security practices in mind.
Our documentation includes:
- Privacy Policy
- Terms of Service
- End User License Agreement (EULA)
- Refund Policy
- Acceptable Use Policy
- Cookie Policy
- Security Policy
- Data Processing Addendum (DPA)
We continue to evolve our security and compliance program as the platform grows.
Contact
General Support
support@onehub.design
Privacy
privacy@onehub.design
Security
security@onehub.design
Website:
- https://onehub.design