Privacy Policy
Effective September 30, 2026
This policy covers the CUbat website and the CUbat Gmail OAuth integration. The application operator can be contacted at contact@cubat.cloud. CUbat workspaces run on computers or servers managed by their administrators.
Data we access and process
When you connect Gmail, Google issues OAuth credentials that allow CUbat to act within the permission you approve. The Gmail integration requests only https://www.googleapis.com/auth/gmail.send. It processes the sender address, recipient addresses (including CC and BCC), subject, message content, and any attachments included in a message you choose to send. It also processes delivery results and error information.
The Gmail API permission does not provide access to your inbox, existing messages, or contacts. Separately configured IMAP or SMTP features have their own credentials and may process mailbox data according to the workspace features you use. This website itself does not request access to a Google Account.
How data is used
CUbat uses Google user data to establish the connection you authorize, send the messages requested by you or an authorized workspace user, maintain delivery status, and troubleshoot failures. CUbat does not use Google user data for advertising, sale, credit decisions, or training generalized artificial intelligence or machine-learning models.
Storage and access
Workspace settings, account information, templates, and sending records are stored on the computer or server running CUbat. Stored OAuth refresh tokens and client secrets are encrypted by the application. Access tokens may be held temporarily in memory. Workspace administrators control the installation, access permissions, and backups and may have access to stored workspace data. Users should connect accounts only to installations they trust.
There is no fixed automatic deletion period for all workspace data. Records may remain until removed by the administrator, including in backups. Google retains sent mail and related information under its own policies. Revoking Google access stops future use of that authorization; it does not erase previously sent messages or workspace records.
Sharing and service providers
Message data is sent to Google to perform the Gmail API operation and is delivered to the recipients you specify. Network and hosting providers may process connection metadata needed to operate the services. If an administrator configures a proxy, that provider handles the network connection. Google API connections use TLS. We do not sell Google user data or share it with advertising networks.
CUbat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Any additional disclosure must be authorized by you or necessary to comply with applicable law.
Your choices and deletion requests
You may revoke CUbat's access in Google Account connections and ask your workspace administrator to remove the account credentials and associated records from the installation and its backups. For privacy or deletion requests to the application operator, email contact@cubat.cloud. Include the relevant account address, but never send passwords, authentication codes, or OAuth tokens. Verification of your authority over the account may be needed.
Website data
This informational website has no analytics scripts, advertising trackers, or registration forms. The hosting provider may keep standard web-server access and error logs, including IP addresses, requested pages, and timestamps, to operate and protect the website. If you contact us by email, we use that correspondence to address your request.
Changes and contact
We will publish updates on this page with a revised effective date. Questions can be sent to contact@cubat.cloud.