Pubto is a service operated by Vertex AI LLC, a Wyoming limited liability company. This Privacy Policy explains what Pubto collects, why it is used, when it may be shared, how long it is retained, and the choices available to you. It applies to Pubto websites, client applications, accounts, support channels, and Relay services.
Information we collect
We collect information you provide, including your email address, account profile, workspace and project names, support messages, billing contact details, and information you choose to include in a request.
Pubto clients send operational metadata needed to provide and protect the service, including Workspace, Control Device and local Installation identifiers; a one-way system identifier derived on the device without uploading the raw operating-system value; a short credential fingerprint; first and recent client IP addresses and User-Agent values; device status; endpoint lifecycle; Relay and public-address assignments; access settings; command receipts; and application version.
- Account, authentication, and billing contact information
- Device identifiers, client IP, and User-Agent security signals
- Project, endpoint, publication, and public metadata
- Usage totals such as requests, traffic, visitors, duration, and active connections
- Support, sales, abuse, privacy, and security correspondence
Published content and network traffic
A published demo, API, file, folder, website, WebSocket, or TCP stream remains on and is served from the computer and target you selected. Pubto carries the bytes needed to deliver the endpoint; it is not intended to create a permanent cloud-storage copy. Pubto does not use published content to train advertising or generative AI models.
Request and response bytes may pass through the assigned Gateway and Relay path. Pubto does not log request or response bodies by default. Current automated content controls inspect publication names, descriptions, and normalized public source hostnames, not file bytes, response bodies, URL paths, query strings, credentials, or encrypted TCP payloads.
When a publication is reported or presents a credible legal, security, fraud, or abuse risk, authorized personnel may review relevant account records, safety metadata, reported evidence, and content reachable through the reported public endpoint. We limit review to what is reasonably necessary to investigate and respond.
How we use information
We use information to create and secure accounts, enroll devices, assign and operate endpoints, show status and usage, provide support, administer billing when launched, maintain Relay services, investigate failures, prevent abuse, and comply with legal obligations.
We may use aggregated or de-identified statistics to understand reliability, capacity, safety, and feature adoption. We do not sell personal information or use it for cross-context behavioral advertising.
- Operate, maintain, secure, and improve Pubto
- Authenticate users and protect workspaces
- Measure and enforce rate, traffic, connection, duration, and plan limits
- Detect fraud, malware, phishing, unauthorized access, and policy violations
- Communicate service, billing, security, and support updates
Automated decisions and human review
Current automated moderation uses operator-managed rules and dictionaries to block prohibited terms and protected public domains before a publication is authorized. Quota controls separately measure requests, traffic, visitors, connection duration, and concurrent connections. A failed automated check can block or limit an action.
Pubto does not currently represent this metadata gate as comprehensive AI inspection of all content. We may introduce risk models or AI-assisted classification after evaluating privacy, accuracy, and security safeguards. We will not rely solely on an automated classification for a permanent account-level enforcement decision where a reasonable human review is available.
You may ask for review of a content or account restriction by contacting [email protected] with the affected address or account details and relevant context. Do not send passwords or unrelated personal information.
Payments and service providers
Public paid checkout is not active in the current pre-launch release. When activated, Stripe will process payment-card and billing information under its own privacy policy. Pubto will receive transaction identifiers, status, amount, currency, billing contact information, and limited card metadata such as brand and last four digits; Pubto will not store complete card numbers or card security codes.
We otherwise share information only as needed with infrastructure, email, customer-support, payment, and security providers acting for us under appropriate obligations. We may disclose information when required by law or when reasonably necessary to protect users, Pubto, providers, or the public.
Retention
We retain account and workspace records while an account is active and for a reasonable period afterward for security, billing, dispute resolution, abuse prevention, and legal compliance. Endpoint state, command receipts, usage events, payment records, and abuse evidence may have different retention periods based on operational or legal need.
Deleting an endpoint revokes its active route but does not immediately remove limited security, billing, audit, backup, or legal records. Published content is not intended to become a durable Pubto-hosted copy.
International data transfers
Pubto is designed for global use and data may pass through infrastructure outside your country. Relay assignment affects the path used for publication traffic, while account, support, safety, and future payment data may be processed in other countries.
Contact [email protected] before using the preview where a specific processing location or transfer agreement is required.
Your choices and rights
You can stop or delete endpoints and rotate public addresses through the client. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal information.
Send account-closure and privacy requests to [email protected]. We may need to verify your identity before completing a request. Applicable legal exceptions may require us to retain certain billing, security, or abuse records.
Security
Pubto uses technical and organizational measures intended to protect account and service information, including authenticated clients, access controls, encrypted transport, credential handling controls, short-lived publications, revocation, quotas, rate limits, and monitoring. No service can guarantee absolute security.
Keep account credentials, endpoint passwords, and source-service credentials private. Report suspected compromise to [email protected] and revoke affected endpoints or addresses as soon as possible.
Children
Pubto is designed for professional development and collaboration and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact [email protected].
Changes and contact
We may update this policy as Pubto changes. Material changes will be posted here and, when appropriate, communicated through the product or by email. Continued use after the effective date means the updated policy applies.
Questions about privacy can be sent to [email protected]. Security reports should be sent to [email protected], and reports about a published endpoint should be sent to [email protected].
