Chronicle House
DigiiHub
Chronicle House
DigiiHub
DigiiHub
Effective date: July 29, 2026
In plain terms
DigiiHub is operated by The Legacy League Creative, LLC, doing business as Chronicle House (“Chronicle House,” “we,” “us”). This policy explains what personal data DigiiHub collects, how it is stored, and the choices you have. It covers the DigiiHub application and the public program hubs it serves.
DigiiHub is a hosted, multi-tenant service. Unlike a local-only tool, the information you and your participants enter is stored in a managed cloud database on our infrastructure so it can be shared across an organization, kept between sessions, and served to public hub visitors.
Each organization’s records are isolated at the database level using row-level security, so one organization cannot read another organization’s data.
We collect the following categories of data:
When an organization uses DigiiHub to manage other people’s information, that organization decides what participant data is collected and why. In that arrangement the organization is the controller of the participant data and Chronicle House acts as a processor handling it on the organization’s behalf.
Organizations that need signed data-processing terms with Chronicle House can request them at the contact below.
We use data to operate and secure the service, provide support, process subscriptions, and serve the public hub pages organizations choose to publish. We do not sell personal data.
We rely on a small number of processors to run DigiiHub: a managed database and authentication provider, a payment processor for subscriptions, an email delivery provider for account and invitation messages, and a hosting provider. Each receives only the data needed for its function.
The information in an organization’s account is retained while that account exists. Cancelling a subscription ends access at the close of the paid period but does not by itself delete stored data. Deletion is available at two levels, and both are real: rows and uploaded files are removed, not just hidden.
An organization’s administrator can delete the whole organization. The public hub goes dark immediately, and after a 7 day grace window everything is permanently deleted, including uploaded files. The administrator can cancel within that window.
A participant can be removed individually, at any time, on request to their organization: their workbook answers, discussion posts and replies, survey records, directory profile, and notification history are permanently deleted right away, without affecting other participants’ content. Where someone else replied to one of their posts, the post is kept only as a placeholder that contains none of their words or identity. Audit records are kept for security with the person’s identity, address, and content removed, and a minimal record that the deletion was performed is retained as proof of compliance.
Audit records are retained indefinitely. We do not currently expire them and there is no fixed cutoff. They are a trail of what happened in the product rather than a record of who anyone is: when a person is erased, their identity, address, and the content of each entry are stripped, leaving only the action, the kind of record it touched, and the time. What remains holds no personal data, so keeping it does not weaken an erasure.
Deletion is immediate on our live systems. When an organization is purged or a participant is erased, the data is removed right away. Encrypted backups are kept for disaster recovery only, and a deleted record is gone from them within 7 days as those backups roll off. If a backup is ever restored, deletions that were already performed are re-applied before service resumes.
Administrators can access and update the data in their organization. Because an organization controls its participants’ data, a participant who wants to access, correct, or remove their information should first contact the organization that entered it. Participants and organizations can also reach us at security@digiihub.app, and we will work with the controlling organization on the request.
Removal requests from participants are carried out by the organization that controls the data, using the deletion capability described above, or by us together with that organization when a request reaches us directly. A person whose account no longer belongs to any organization can delete the account themselves from their account menu.
We protect data with row-level isolation between organizations, encrypted connections, and access controls. No system is perfectly secure, but we work to safeguard the information entrusted to us.
Questions about this policy can be directed to:
The Legacy League Creative, LLC dba Chronicle House