Privacy Policy for Parahub Instance
Version: 1.3
Effective Date: August 14, 2026
We, Parahub - Associação (NIPC 519 190 904, hereinafter 'Operator', 'we'), managing this Parahub instance (hereinafter 'Service'), are committed to protecting your privacy and digital sovereignty. Parahub is architecturally designed so that users retain full control over their data and cryptographic identity. This Privacy Policy explains what personal data we collect, how we use, process and protect it, as well as your rights regarding your data, in accordance with the General Data Protection Regulation (GDPR).
1. Data Controller
The controller of your personal data is:
Parahub - AssociaçãoNIPC: 519 190 904
Rua das Regueiras 78, Podame, Monção, 4950-670, Portugal
Email for data inquiries: info@parahub.io
2. What Data We Collect and Process
Parahub is designed with a focus on data minimization and user control.
Data you provide directly:
- Account: Your human-readable network alias (HNA, like name@parahub.io), hashed password (if using password authentication).
- Profile: Any information you choose to include in your Parahub profile (e.g., name, description, contacts, skills). You control the visibility of this data.
- Public PGP Key: If you upload or generate one, it will be associated with your profile and available to other users for encrypting messages to you and verifying your signatures. We never have access to your private PGP key.
- Content: Offers, Wants, messages in public or group Matrix chats (if not E2EE), transaction details, reviews, and other content you create on the platform. Messages in E2EE Matrix chats are not accessible to us.
- Web of Trust (WoT): Information about who you have verified and who has verified you.
Data collected automatically:
- System Logs: IP address, browser type, access time, pages visited. This data is used for security, troubleshooting, and service usage analysis (in aggregated and anonymized form where possible). Log retention period: 14 days.
- Session Cookies: To maintain your login session.
- Matrix: Your Matrix User ID (@local_name:instance.domain) for chat functionality.
Data we do NOT intentionally collect:
- We do not require sensitive personal data (racial or ethnic origin, religious beliefs, health data, etc.) to use the Service, and we do not infer such data from your activity. The two optional features that do touch special categories of data are described below.
- Locations you attach to public listings are shown to other users fuzzed to a grid of roughly 100 m. Features whose very purpose is sharing your precise position (live map presence, driver mode, SOS alerts) transmit it only while you actively use them.
- Cryptographic private keys (PGP) are generated and stored exclusively on your device. The server never has access to your private keys — only public keys are stored. This is a fundamental architectural principle, not a policy choice.
Special categories of data (Art. 9 GDPR)
Three optional features process data that the GDPR treats as special-category. All of them operate only if you choose to use them, on the basis of your explicit consent (Art. 9(2)(a) GDPR):
- Civic opinion polls: A ballot you cast may express a political opinion. Opinion ballots are recorded under a one-way pseudonym (keyed hash); the ballot record contains no link to your profile, IP address or keys, published results are aggregates, and your receipt lets you verify your own ballot without revealing it to anyone else. Votes that are open by their nature (household and condominium decisions, delegated governance votes) are attributed to you — the voting page states this before you vote.
- Psychometric profile: If you complete the optional self-assessment, your answers are analyzed (with the help of an AI model — see Section 6) to derive a short characterization. Only the resulting four-word summary is shown publicly; you can update it or request its deletion at any time.
- Voice cloning (voice notes): If you turn on voice cloning, recordings of your own speech are sent to our speech provider (ElevenLabs) and a voiceprint is built from them — biometric data. Only your own recordings are kept, never the other person's; the samples are deleted once the clone is finished, note audio expires after 30 days, and deleting the voice removes it at the provider as well. Voice notes work without a clone, in a standard voice.
3. Mesh Network (WiFi Nodes and Guests)
The Parahub mesh is a network of WiFi nodes run by their owners. Two kinds of data are processed there, and they are kept separate.
- Node data: Each node sends a periodic heartbeat: hardware and MAC identifiers, node keys, firmware version, uptime, connection status and throughput counters. A node appears on the public coverage map only at the location its owner sets, and its owner is named there only if they explicitly opt in.
- Guest devices: The node that terminates the guest network reports the current DHCP leases of connected guest devices: WiFi address (MAC), local IP address, and the hostname the device announces itself under. This is what allows a full-speed pass — bought or earned — to be applied to the right device.
- Retention: Guest lease data is held as current state only: each heartbeat replaces the previous snapshot and nothing is accumulated into a history. We do not log which sites guests visit, and guest traffic is not inspected.
- Internet exit: Guest traffic leaves through a VPN tunnel, so it does not reach the internet from the node owner’s home IP address. Nodes without an internet line of their own (and their owners’ devices behind them) reach the internet the same way, across the mesh and out through the VPN exit. The Association operates the shared exit, whose own final hop is carried by a commercial VPN provider, and processes the minimum connection metadata needed to run it. The radio links between nodes are a shared community medium: as on any open WiFi network, confidentiality on the air comes from end-to-end encryption (HTTPS) and the VPN tunnel.
- Legal basis: Contract (Art. 6(1)(b) GDPR) for delivering a full-speed pass to your device, and legitimate interest (Art. 6(1)(f) GDPR) in operating and protecting the network. The peering terms between node owners are set out in the Mesh Peering Agreement.
4. Legal Basis for Data Processing (under GDPR)
- Consent (Art. 6(1)(a) GDPR): For processing data you voluntarily provide (e.g., profile completion, content publishing). You may withdraw your consent at any time.
- Contract (Art. 6(1)(b) GDPR): To provide you with the Service and fulfill our obligations under the User Agreement (e.g., authentication, facilitating user communications).
- Legitimate Interests (Art. 6(1)(f) GDPR): For ensuring Service security, fraud prevention, usage analysis for Service improvement, logging.
- Legal Obligations (Art. 6(1)(c) GDPR): If we are required to process data by law.
5. How We Use Your Data
- To provide, support, and improve the Service.
- For authentication and account management.
- To facilitate communication between users (including Matrix chats).
- For the reputation system and Web of Trust functionality.
- To personalize your experience (if you provide relevant data and settings).
- To ensure security and prevent abuse.
- For analysis and statistics (preferably in anonymized form).
- To respond to your inquiries and communicate with you.
6. Data Sharing with Third Parties and Federation
- Federation: Parahub is a federated system. When interacting with users on other Parahub or Matrix instances, some of your public data (HNA, public PGP key, public profile, public content) may be transmitted to those instances.
- Matrix: If this instance uses a Matrix server managed by a third party, or you communicate with users on other Matrix servers, data is transmitted according to the Matrix protocol.
- AI features: Some features rely on third-party AI models: the assistant and knowledge search, image analysis for listings, voice support, voice notes, and the psychometric self-assessment. When you use such a feature, the content you submit to it (text, image or voice audio) is sent to the configured provider — currently Google (Gemini) for the assistant, voice and image analysis, OpenAI for listing categorization, and ElevenLabs for speech recognition and synthesis — acting as our processors. These requests do not include your name or account identifiers.
- Push notifications: If you enable push notifications, delivery goes through your platform's push service (Google Firebase Cloud Messaging on Android, Apple Push Notification service on iOS, or your browser vendor's push service), which processes a delivery token for your device.
- International transfers: The AI and push providers above may process data on servers outside the EU, primarily in the United States. Such transfers rely on the EU–U.S. Data Privacy Framework (for certified providers) and/or Standard Contractual Clauses (Art. 46 GDPR). Everything else — your account, your content and all primary storage — remains on our servers in the EU (see Section 7).
- Legal Requirements: We may disclose your data if required by law or in response to a valid legal request from law enforcement (following applicable procedures).
- We do not sell your personal data.
7. Data Storage and Security
- We implement reasonable technical and organizational measures to protect your personal data from unauthorized access, modification, disclosure, or destruction (e.g., HTTPS, password encryption, regular software updates, restricted data access for staff).
- Data at rest is stored on our servers located in the European Union (Germany and Portugal). The only data processed outside the EU is what Section 6 describes: content submitted to AI-powered features and push delivery tokens.
- Data retention periods are determined by their purpose and legal requirements. Data is not stored longer than necessary for the purposes for which it was collected. You may request deletion of your data (see Your Rights).
8. Your Rights (under GDPR)
You have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): Request information about what data of yours we process.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17 GDPR): Request deletion of your data under certain conditions.
- Right to Restriction of Processing (Art. 18 GDPR): Request restriction of your data processing.
- Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format and transmit it to another controller.
- Right to Object (Art. 21 GDPR): Object to processing of your data based on our legitimate interests.
- Right to Withdraw Consent: If processing is based on consent, you may withdraw it at any time.
- Right to Complaint (Art. 77 GDPR): Lodge a complaint with a data protection supervisory authority. In Portugal this is the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt).
Erasure has technical and legal limits (Art. 17(3) GDPR). Cryptographic audit records (timestamps and aggregate voting proofs), signed contract records needed for the establishment or defence of legal claims, and copies of public content already replicated to other federation instances or public mirrors cannot always be removed by us unilaterally. When you request erasure, we delete everything under our control and tell you what remains and why.
To exercise these rights, please contact us at info@parahub.io.
9. Cookies
We use only session cookies necessary for authentication. We do not use tracking or advertising cookies.
10. Changes to Privacy Policy
We may update this Privacy Policy. We will notify you of significant changes by posting the new version on the Service. We recommend checking this page regularly.
11. Contact Information
If you have questions about this Privacy Policy, please contact us:
Parahub - AssociaçãoNIPC: 519 190 904
Rua das Regueiras 78, Podame, Monção, 4950-670, Portugal
Email for data inquiries: info@parahub.io