Version 2026-09-22
HugeOne Privacy Policy
Effective date: 22 September 2026
This policy explains how personal data is used for hugeone.io, registration and early-access services, founders.hugeone.io and free HugeOne app features made available to you. It covers visitors, account holders, founders, startup collaborators, people identified in submissions, prospective users and people who contact us. Descriptions of app processing apply when you use the relevant app features. The current service does not process investments, subscriptions or payments.
Earlier token sales and staking are separate from the current service. This policy does not replace privacy information applicable to those activities or remove participants’ rights. Contact info@hugeone.io for information or a privacy request concerning historical records. Joining the current service does not authorise unrelated reuse of those records.
1 Who is responsible
A.M.K. Ecoleaf Ltd, trading as HugeOne, is the controller of personal data used for the purposes described here. Our Cyprus registration number is HE272640 and our address is 11 Mnasiadou Street, 1065, Nicosia, Cyprus.
For privacy questions or requests, email info@hugeone.io, call +357 99918184 or write to that address. You do not need to use a special form or legal terminology.
This policy does not automatically govern another company’s independent use of information. A startup remains responsible for its own decisions to collect and disclose personal data, including data about its team. We are responsible for our own review, hosting, publication and other processing described below.
2 Information we receive
Account information includes your name, email address, account identifier, sign-in credentials handled by the authentication service, confirmation and recovery records, roles and access permissions. The app offers Google sign-in and Apple sign-in on supported devices; the founder portal offers email/password and Google sign-in. We receive the identity information authorised through the chosen sign-in flow, which may include your name, email and profile image. Apple may provide a relay email address if you choose its email privacy option. We do not receive your Google or Apple password. App profile records also include the sign-in provider and account creation and update timestamps.
Founder submissions may contain company names, locations, websites, logos, descriptions, products, target markets, business models and pricing, funding history and plans, named investors, traction information, biographies, roles, LinkedIn links, pitch decks, financial documents, legal materials, cap tables and other supporting files. Information about a company can also identify individuals. Do not upload unnecessary personal information or documents you are not authorised to share.
The portal also receives introductory videos and other media, milestone titles, proposed outcomes, target dates and planning percentages. Funding information is company background and planning data; collecting it does not mean the MVP executes investments or releases funds.
Collaboration and review information includes invited users’ email addresses, membership permissions, application status, submission snapshots, review feedback, internal notes, document-check results and activity or administrative audit records. Draft changes may be saved before an application is formally submitted.
For social features you use, we process the profile information, videos, updates, comments and interactions you submit, such as follows, likes and saves. We also receive support messages, reports, complaints, privacy requests and correspondence. Available social features vary by service and release.
If you register interest or join an early-access list, we receive the contact details and preferences you submit, such as your name, email address and whether you are interested as a founder or prospective investor. Registering interest does not create an investment account or commitment.
Technical information can include IP addresses, browser and device details, request timestamps, authentication and security events, error information and the browser storage described in our Cookie Policy. Optional analytics, if enabled, are described separately and require the appropriate consent where applicable.
The app records which startups you follow and when, and the star ratings you submit or update, linked to your account identifier. It uses these records to show your followed startups, select their updates and calculate aggregate follow counts, trends and ratings. Aggregate results may appear in startup views; they are not financial assessments.
App diagnostics can include device and app details, error messages, stack traces and diagnostic identifiers through Firebase Crashlytics. Diagnostic processing is separate from optional usage analytics and must be limited to its disclosed purpose.
Where diagnostic technology requires consent to access or store information on your device, we ask for that consent before the relevant collection. Diagnostic data is used to investigate errors and maintain the service, not to assess investment suitability.
We do not request payment-card or bank-account information to use the free MVP. We do not require routine financial KYC or biometric identification under this policy. Do not upload identification documents or special-category personal data unless we specifically explain a necessary, lawful process first. If we receive unnecessary sensitive information, we will assess whether to remove or restrict it.
3 Where information comes from
We receive information directly from you, from your use of the services, from an identity provider you choose, and from people who invite you or include you in a startup submission. Reporters may provide information about other users or content.
If someone adds you as a team member or names you in a submission, we may receive your professional details without you first creating an account. You can contact us to ask what we hold, where it came from, who can see it and whether it can be corrected or removed. Where required, we will provide this privacy information directly within the applicable time limit rather than relying only on the submitter to inform you.
4 Why we use data and our legal bases
We use a legal basis for each purpose, rather than treating registration as consent to everything.
Providing an individual user’s service. We use account information, authentication records and content or interactions you request us to process to create and operate your account, provide requested features and respond to service requests. The basis is performance of our contract with you, or steps you request before entering that contract, to the extent the processing is necessary for that purpose.
Working with company representatives and teams. We use professional contact details, invitations, role information and submissions to administer company accounts and coordinate review. Where the contract is with the company rather than the individual, the basis is our legitimate interests in providing the company service, managing authorised access and communicating with its representatives. Those interests are balanced against the individuals’ rights.
Reviewing startup information. We process submissions, feedback and relevant supporting information to assess completeness, request corrections and manage applications. The basis is contract where necessary to provide a service to the individual applicant; otherwise it is our legitimate interests in maintaining useful, accurate profiles and a manageable review process. This does not establish a financial KYC or investment-screening obligation.
Showing information to its intended audience. We process user posts and approved profile information to provide the publication or interaction requested. This is based on contract for the submitting individual’s requested service. For professional information about other team members, we assess our legitimate interests in presenting authorised, relevant team information against their privacy interests. Founder permission to publish does not replace the need for a lawful basis for each person’s data.
Safety and service reliability. We use proportionate technical records, reports, file checks and audit information to prevent abuse, investigate incidents, moderate content and resolve disputes. The basis is our legitimate interests in protecting users and maintaining reliable services, or a legal obligation where a specific law requires processing. We do not describe all safety activity as legally required.
Registration and early access. We use your submitted contact details and preferences to record your request, respond and notify you about the access you requested. Our basis is taking steps at your request before providing the service, or our legitimate interests in managing enquiries where the request is made on behalf of a company. You can leave an early-access list by emailing info@hugeone.io.
Optional communications and analytics. We use consent for optional promotional communications and optional device-based analytics where consent is required. You can withdraw it without losing access to the core service, using the unsubscribe option in a marketing email or by contacting info@hugeone.io. Necessary account, security and application-status messages are service communications and are not dependent on marketing consent.
Legal requests and claims. We process relevant records where necessary to comply with an applicable legal obligation, and on the basis of legitimate interests to establish, exercise or defend legal claims. Access and retention are limited to what the purpose requires.
Where we rely on legitimate interests, you may object for reasons relating to your situation. We will assess the objection under applicable law. You may object to direct marketing at any time, without giving a reason.
5 Private information and public content
Founder drafts and private supporting files are accessible within the authorised startup team and HugeOne review workflow, and to providers supporting that workflow as necessary. Internal administrative notes are not automatically visible to the startup team.
Submitting an application or choosing a document label referring to investors does not, by itself, make a private supporting document public. We will explain the intended audience and obtain the authorised representative’s publication instruction before sharing private materials outside the review workflow, unless disclosure is otherwise legally required.
Information deliberately published in a public profile, video, update or comment can be viewed and copied by its audience and may be indexed by search engines where publicly accessible. Do not post information you intend to keep private. Contact us about an incorrect or unauthorised disclosure.
6 Providers and other recipients
We share information only as needed for the purposes described, including with authorised personnel, your authorised startup collaborators, the audience of your published content, and providers supplying hosting, authentication, storage, communications, security or support.
The founder portal uses Supabase technology for accounts, database records and file storage, and Lovable authentication tooling for Google sign-in. Choosing Google sign-in involves Google’s separate identity service. Google-hosted fonts cause browser requests to Google that disclose network and browser information, including your IP address, to deliver the font files. This is separate from advertising analytics.
The app uses Google Firebase Authentication for sign-in, Cloud Firestore for user profiles, follows and ratings, and Firebase Crashlytics for diagnostics. Apple supplies the Apple sign-in service where chosen. Hosting and backend infrastructure providers also support delivery of startup and feed content. Communications providers process contact details and message content to deliver registration, account and support messages.
If we introduce an external file-scanning service that receives uploaded files, we will explain that processing before it begins. File validation does not certify the accuracy of a document’s contents.
Providers acting as processors must process personal data under appropriate instructions and contractual safeguards. Some services, such as a chosen external identity provider, also process information for their own purposes under their own policies. We do not describe every recipient as a processor.
We may disclose relevant information to advisers, courts, regulators or law-enforcement bodies where lawfully required or necessary to address a legal claim. We assess the request and limit disclosure where appropriate. Any business transfer affecting personal data would require appropriate safeguards and information to affected people; it would not justify unrelated use of private submissions.
We do not sell personal data under this MVP service or make private founder documents available to other users merely because they are described as prospective investors.
7 International processing
The providers described above operate internationally. Processing and support access may take place outside Cyprus and the European Economic Area, where data-protection rules can differ. Choosing an external sign-in provider also involves that provider’s international services and privacy practices.
Our policy is to permit transfers outside the European Economic Area only where a lawful transfer basis applies. This can be a European Commission adequacy decision covering the recipient or appropriate safeguards, such as the Commission’s Standard Contractual Clauses with additional protection where needed. We do not treat your acceptance of these Terms or this policy as consent to unrestricted international transfers. Contact info@hugeone.io for information about the destinations and safeguards relevant to your data, including how to obtain a copy of applicable safeguards, subject to necessary redactions.
8 Retention and deletion
We retain personal data only for the period justified by the purpose for which it is held. The relevant criteria are the ongoing account or application, the need to preserve a review history, security investigations, applicable legal requirements and the reasonable need to handle an existing or anticipated dispute. Retention is not automatically indefinite because an account has been inactive.
Account and profile information is kept while needed to provide the account or manage an active application. For abandoned drafts, rejected applications and inactive accounts, we assess whether there is a continuing purpose and delete or anonymise information when there is not. Submission snapshots and internal review records are included in this assessment, not treated as exempt from deletion.
Published content is retained while publication remains requested and lawful. Removing a post from the live service may not immediately remove residual backups. Backup data must remain protected and outside ordinary use until it is overwritten or deleted through the applicable backup cycle. Restoring a backup must not undo a valid deletion request.
Security logs, access records, support correspondence and complaints are kept only for the justified security, resolution or legal period. We retain a limited record of an opt-out where needed to respect it, rather than continuing to use the address for marketing.
Early-access contact details are retained while needed to manage your requested registration and access notifications. If you withdraw your request, we stop those notifications and delete or restrict the registration record unless there is a separate justified reason to retain it. Marketing contact details are retained while the relevant consent remains valid; limited suppression records may remain to respect an opt-out.
We may retain specific information longer if required by law or reasonably needed for a particular legal claim. We will restrict its use accordingly and explain any relevant reason if we cannot fully comply with your request.
9 Security
We use technical and organisational measures appropriate to the information and risks, including authorised access and controls around private files. No online service can guarantee absolute security. We do not claim that all information is end-to-end encrypted or that every uploaded file has received an external malware scan.
Protect your own credentials and report suspected unauthorised access to info@hugeone.io. We assess incidents and notify affected people and authorities where applicable law requires it.
10 Your rights
Subject to the conditions in applicable law, you may ask to access your personal data, correct it, erase it, restrict its processing, object to processing based on legitimate interests, and receive or transfer qualifying data in a portable format. You can withdraw consent at any time without affecting processing that was lawful before withdrawal.
You can make a request at info@hugeone.io. We may request proportionate information to verify identity where reasonably necessary, but will not routinely demand an identity document for every request. Requests are normally free. Any lawful fee or refusal for a manifestly unfounded or excessive request will be explained.
We respond without undue delay and normally within one month. Where the law permits an extension because of complexity or the number of requests, we will tell you within the first month and explain the reasons. We will explain any lawful restriction or refusal and how you can challenge it.
You may complain to the Cyprus Commissioner for Personal Data Protection at https://www.gov.cy/dataprotection/ or, where applicable, the supervisory authority in the country where you live, work or believe an infringement occurred. You do not have to contact us first.
11 Automated processing and required information
The founder portal uses rule-based completeness and file-validation checks. A completeness score measures whether required information is present; it is not an investment rating. Technical checks may block incomplete submissions or unsafe files, and you can contact us about a problem.
The app’s following feed filters updates using the startups you have chosen to follow. Your follows determine which startup updates appear in that feed; you can change the selection by following or unfollowing startups. Ratings and follow totals are calculated from user activity and do not make an investment decision for you.
We will explain any new activity-based ranking or materially different automated processing before introducing it. Posting frequency or feed visibility is not a verification of company performance. If an automated check prevents you from proceeding or you wish to challenge a restriction, contact info@hugeone.io to request human review.
Required fields are identified in the relevant form. Without necessary account or application information we may be unable to create an account, allow access or review a submission. Optional information and optional marketing consent are not prerequisites for unrelated core functions.
12 Age and policy changes
Accounts are restricted to people aged 18 or over.
The services are not intended for accounts held by children. If you believe a child has provided personal data, contact us so we can assess and appropriately address it.
We will update this policy when practices change and show the effective date. Material changes will be brought to your attention as appropriate. A policy update alone is not permission to use personal data for an incompatible purpose or a substitute for fresh consent where required.
