AI Features & Data Privacy Notice
Last updated: March 27, 2026
This notice describes how AI Parse for notes works, what is sent to OpenAI, and how we protect your data. AI Parse is optional and off unless you turn it on.
Overview
At PMHub.io, we believe you should know exactly how your data is used — especially when AI is involved. This page explains how our AI-powered notes feature works, what data is shared, who it's shared with, and the specific steps we take to protect your information.
What is AI Parse?
When you create a note in PMHub.io, you have the option to enable AI Parse. This is an optional feature — it is off by default and only activates when you explicitly toggle it on before saving your note.
When AI Parse is enabled and you save a note, PMHub.io sends the text of that note to OpenAI's API to perform two tasks:
- Extraction — The AI reads your note and automatically identifies and extracts: stakeholder names mentioned in the note; risks identified or discussed; actions assigned or agreed upon; and decisions made.
- Embedding — The note content is converted into a vector embedding (a mathematical representation of the text) that powers semantic search and contextual AI features within PMHub.io.
The extracted information and the embedding are then saved back to your PMHub.io account, associated with your note, so you can search, reference, and build on them within the application.
AI Parse is entirely optional. Notes created without AI Parse enabled are never sent to OpenAI. Your note content stays within PMHub.io's own infrastructure.
What data is sent to OpenAI?
When you save a note with AI Parse enabled, the text content of that note is transmitted to OpenAI's API for processing.
We apply the principle of data minimization — only the note text required to generate the extraction and embedding is sent. No other personal information (such as your name, email address, account details, or data from other parts of your account) is included in the transmission.
Does OpenAI store or train on my data?
No. PMHub.io operates under a Data Processing Agreement (DPA) with OpenAI. Under this agreement:
- OpenAI does not retain your note data after processing is complete.
- OpenAI does not use your note content to train its models.
- Your data is processed solely to generate the requested output (extraction and embedding) and is then discarded by OpenAI.
We review this agreement annually to confirm these protections remain in place. If anything changes, we will update this notice and notify affected users.
How is my data protected in transit?
All data transmitted between PMHub.io and OpenAI is encrypted using TLS 1.2 or higher — the same standard used for securing data in transit in regulated industries. Your note content is never transmitted over an unencrypted connection.
What about PMHub.io's own logs?
PMHub.io maintains application logs for security monitoring, debugging, and compliance purposes. We apply the following protections specifically to AI-related activity:
- PII is redacted from logs. Personally identifiable information — including names or email addresses — is automatically redacted from log entries related to AI Parse activity. Your note content is not retained in our logs.
- Logs are stored securely. Operational logs are stored in an immutable, encrypted storage container. They cannot be modified or deleted within their defined retention period, protecting the integrity of our audit trail.
- Logs are access-controlled. Only the PMHub.io system administrator has access to application logs. They are never shared with third parties except as required by law.
How long is my data retained?
| Data type | Retention |
|---|---|
| Note text (stored in PMHub.io) | Retained while your account is active. Deleted within 90 days of account deletion. |
| AI-extracted content (stakeholders, risks, actions, decisions) | Retained while your account is active. Deleted within 90 days of account deletion. |
| Vector embeddings | Retained while your account is active. Deleted within 90 days of account deletion. |
| Note text transmitted to OpenAI | Not retained by OpenAI. Discarded after processing. |
| PMHub.io application logs (redacted) | Retained for 12 months for security and compliance purposes. |
When you delete a note, any AI-extracted content and embeddings associated with that note are soft-deleted immediately and permanently purged within 30 days. When you delete your account, all of your data — including AI-processed content — is permanently deleted within 90 days.
Can I use PMHub.io without using AI Parse?
Yes, absolutely. AI Parse is an optional, opt-in feature. Every core feature of PMHub.io — creating and managing projects, tasks, notes, risks, actions, decisions, and stakeholders — works fully without AI Parse. You are never required to enable it.
If you prefer not to have any note content transmitted to a third-party AI provider, simply leave AI Parse toggled off when saving your notes.
Who processes my data?
When AI Parse is enabled, your note content is processed by:
| Provider | Role | Location | Data protection |
|---|---|---|---|
| OpenAI | Processes note text to generate extractions and embeddings | United States | Data Processing Agreement in place; no data retention; no model training on your data |
| PMHub.io (Flint & Steel Ventures, LLC) | Stores and manages your account data and AI outputs | United States | SOC 2-aligned security program; encrypted at rest and in transit |
PMHub.io does not sell your data to any third party, and your note content is never shared with anyone other than OpenAI for the purpose of processing your AI Parse request.
What are my rights?
- Access the data PMHub.io holds about you.
- Delete your data by deleting individual notes, specific extracted content, or your entire account.
- Opt out of AI processing at any time by turning off AI Parse on any note before saving.
- Ask questions about how your data is handled by contacting us through our support page.
Questions About This Notice?
If you have any questions about this AI Features & Data Privacy Notice or wish to exercise your privacy rights, please contact us through our support page.
We aim to respond to all privacy inquiries within 2 business days.