Privacy Policy
Last updated: 26 May 2026
1. Controller
The data controller for llmdhub.com is:
[Company details will be published here once commercial registration is complete.]
2. Data We Collect
When you use llmdhub, we process the following categories of personal data:
- Account data: email address, display name, and authentication data (managed by Clerk, our authentication provider).
- Transaction data: purchase history, wallet balance, payout records, processed by Stripe and/or PayPal as payment service providers.
- Content data: prompt listings you upload as a seller, reviews you write, feedback you submit.
- Usage data: pages visited, search queries, and interactions with the Platform, collected for service improvement and security monitoring.
- Seller verification data: GitHub username and organization memberships (if you connect your GitHub account for plagiarism verification purposes).
3. Legal Basis for Processing
We process your data on the following legal bases under GDPR Article 6(1):
- Contract performance (Art. 6(1)(b)): processing necessary to provide the marketplace service, execute purchases, process payouts, and manage your account.
- Legitimate interest (Art. 6(1)(f)): fraud prevention, security scanning of uploaded content, and service improvement.
- Legal obligation (Art. 6(1)(c)): tax record-keeping (VAT MOSS), financial reporting, and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)): where separately obtained (e.g., marketing communications).
4. Third-Party Processors
We share your data with the following categories of processors:
- Clerk — authentication and user management
- Stripe — payment processing and seller payouts (Stripe Connect)
- PayPal — alternative payment processing (where available)
- Neon — database hosting (EU region)
- Vercel — application hosting
- Novu — transactional notifications
- Sentry — error monitoring (anonymized where possible)
All processors are contractually bound by Data Processing Agreements (DPAs) in compliance with GDPR Article 28.
5. Data Retention
Account data is retained for the duration of your account. Transaction records are retained for the legally required period (7 years under Austrian tax law). Upon account deletion, personal data is removed or anonymized within 30 days, except where retention is legally required.
6. Your Rights
Under GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data ("right to be forgotten", Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde)
To exercise your rights, contact us at privacy@llmdhub.com.
7. Cookies
llmdhub uses essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Essential cookies do not require consent under the ePrivacy Directive as they are strictly necessary for the service.
8. International Transfers
Some of our processors (Clerk, Stripe, Vercel, Sentry) may process data outside the EEA. Such transfers are safeguarded by EU Standard Contractual Clauses (SCCs) or the processor's participation in an adequacy framework recognized by the European Commission.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on the Platform at least 30 days before they take effect.
10. Contact
Email: privacy@llmdhub.com
See also our Terms of Service.