GUBUS Privacy Policy

Effective date: 25 August 2026. Controller: Oleksii Hashynskyi, Holsteiner Chaussee 171, 22457 Hamburg, Germany, operating GUBUS as an independent freelancer. Privacy contact: privacy@gubus.io.

Google data GUBUS accesses

GUBUS reads your Google identity (OpenID identifier, email and basic profile) to authenticate you and bind authorizations to the correct account. With your separate developer or project-owner authorization, GUBUS can:

  • create and manage only Drive folders and files created with GUBUS or explicitly selected for GUBUS through Google Picker (drive.file);
  • read and update the authorized Google Sheets used as project data stores and interfaces;
  • create and update Apps Script projects and deployments used for your automation;
  • list Cloud projects available to you and create or manage service accounts and keys only in the Cloud project you select.

GUBUS does not request whole-Drive access and does not scan arbitrary files in your Drive.

Purposes and AI processing

Google data is used only to provide and secure the GUBUS features you request: project creation, schema and workflow automation, Drive artifact management, Apps Script deployment, service-account administration, troubleshooting and AI-assisted development.

When you invoke an AI feature, relevant instructions, schema definitions, spreadsheet headers, selected values, diagnostic context and prior conversation context may be sent to Google’s billed Gemini API. GUBUS does not use Google Workspace data to train a general or foundation model. Under the production paid-service processing path, Google states that submitted prompts and responses are not used to improve its products. Google may retain prompts and responses for a limited period solely for abuse monitoring unless zero-data-retention requirements are met. AI processing remains subject to Google’s paid Gemini API terms.

Storage and processors

GUBUS stores encrypted OAuth access and refresh tokens while a grant is active, project/file/script identifiers, workflow configuration, encrypted service-account credentials, security/audit records and operational logs. Google Cloud provides Cloud Run, Cloud SQL in Frankfurt (europe-central2), Secret Manager, Cloud Logging and the Gemini API. Vercel delivers the web application. Resend delivers operational email; GUBUS does not intentionally include spreadsheet content in those messages. LangSmith tracing is disabled in production.

Transport uses HTTPS. Secret token and key material is encrypted at rest and access is restricted to service identities and authorized operators. Human access is limited to support, security, legal or incident-response needs.

Retention

  • Active configuration and credentials: while the account or project remains active.
  • OAuth token material: erased from the primary database after successful revocation; the operational target is immediate deletion and no later than 24 hours.
  • Revoked-grant non-secret audit metadata: up to 30 days unless security or law requires longer.
  • Ordinary application logs: 30 days. Required Google security/audit logs: up to 400 days.
  • Deleted primary data in Cloud SQL point-in-time recovery logs: up to seven days; Cloud SQL retains the seven most recent scheduled backups.
  • Google Drive artifacts: retained, moved to Trash or deleted according to your choice and Google Drive’s own lifecycle.
  • Support/privacy correspondence: up to 24 months after the request closes, unless an unresolved dispute or law requires longer.

Revocation and deletion

You can revoke the central GUBUS grant from the developer dashboard or from your Google Account permissions. Successful revocation erases locally stored OAuth token ciphertext. To remove GUBUS account/project data and understand Google-side artifacts, follow Data Deletion or email privacy@gubus.io.

Sharing and Limited Use

GUBUS does not sell Google data, use it for advertising, or disclose it except to provide the requested service, protect users, comply with law, or with your direction.

GUBUS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your rights and contact

For access, correction, deletion, restriction or objection requests, contact privacy@gubus.io. Product support: support@gubus.io. Security: security@gubus.io.