Privacy Policy
Last updated August 27, 2026
DW Hub is a private, internal business application operated by Daniel Witzel Consulting (“we”) at hub.danielwitzel.com. It is used by our own staff and contractors to track work, record time, and prepare invoices. There is no public signup: every account is created by an administrator.
This policy describes what the application stores, who it shares data with, and how that data is protected. It applies to the application only.
What we store
- Account details for each authorized user: name, email address, role, time zone, an optional internal cost rate, a one-way hash of the password, and — if the user turns it on — an encrypted two-factor secret and recovery codes.
- Work records created by users: clients, projects, tasks and subtasks, comments, links, and time entries with their durations and billing rates.
- Business contact details for our clients, such as a company name, a contact email address, and the email domains used to file correspondence correctly.
- Meeting records imported from our meeting transcription service, where a meeting is associated with a client or project.
- Invoice records: the periods invoiced, the hours and amounts on each line, and the identifier of the resulting invoice in our accounting system.
- An activity log recording which account made which change, and whether it was made in the application or through an automated integration.
What we do not do
- We do not sell, rent, or trade any data held in this application.
- We do not use it for advertising, and we run no advertising or analytics trackers.
- The only cookie set is the one that keeps you signed in. There are no tracking or third-party cookies.
QuickBooks Online
We connect this application to our own QuickBooks Online company so that recorded time can become an invoice without being retyped. An administrator authorizes that connection through Intuit and can end it at any time.
- What we read: the company name, and the customer and product/service lists, so that a client in this application can be matched to the right customer and income account in QuickBooks.
- What we write: invoices, and nothing else. The application does not create or edit customers, does not record or alter payments, does not void or delete anything, and does not change any accounting settings.
- What we never do: ask Intuit to email an invoice. Every invoice is created in an unsent state; sending is done by a person inside QuickBooks.
- Access tokens issued by Intuit are encrypted before they are stored and are never written to logs. Disconnecting deletes them from our database and revokes them with Intuit.
- The scope requested is limited to accounting. We do not request access to payments, payroll, or personal Intuit profile information.
Service providers
Data reaches these third parties, and no others:
- Hostinger — hosts the application and its database on servers in the United States.
- Intuit (QuickBooks Online) — receives the invoices we create, as described above.
- Fireflies.ai — our meeting transcription service, from which meeting records are imported.
- Anthropic — the application can be connected to Claude so that our own staff can query and update their work by conversation. This connection is authorized per account and can be revoked by an administrator.
- Our email provider — delivers transactional messages such as invitations, password resets, and daily summaries.
How it is protected
- All traffic is served over HTTPS.
- Passwords are stored only as bcrypt hashes and cannot be recovered, only reset.
- Two-factor secrets, recovery codes, and third-party access tokens are encrypted at rest with a key held outside the database.
- Every change is attributed to an account in an activity log, which distinguishes actions taken in the application from those taken through an integration.
- Data exports deliberately exclude password hashes, two-factor secrets, recovery codes, reset and invitation tokens, and integration credentials.
Retention and your choices
Records are kept for as long as they are needed to run the business and to meet our accounting and tax obligations. Deactivating an account ends its access immediately while preserving the work history attributed to it, which is necessary for accurate billing records.
If you are a user of this application, or a client whose details appear in it, you may ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it. Write to the address below.
Children
This is a workplace tool. It is not directed at children and we do not knowingly collect information from anyone under 18.
Changes
If this policy changes materially, the date at the top will change and active users will be told. Continued use after that constitutes acceptance.
Contact
Daniel Witzel Consulting — info@danielwitzel.com