Privacy Policy

Our Privacy Policy

How we handle your personal information, and how we access, use and protect data you connect from Google Workspace.

Effective Date: 6 October 2026

This Privacy Policy describes how Cimba.AI Inc. ("Cimba", "we", "us", or "our") handles personal information that we collect through our website, through our product, and through any other websites that we own or control and which link to this Privacy Policy (collectively, the "Services").

Personal information we collect

Information you submit to us:

  • Contact information, such as your first and last name, phone number, and email address.
  • Feedback or correspondence, such as information you provide when you contact us with questions or feedback.
  • Usage information, such as information about how you use the Services and interact with us.
  • Marketing information, such as your preferences for receiving communications and details about how you engage with them.
  • Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.

Information we obtain from third parties

We may maintain pages on social media platforms, such as Facebook, Instagram, LinkedIn, and other third-party platforms. When you visit or interact with those pages, the platform provider's privacy policy applies to your interactions and their collection, use, and processing of your personal information.

Automatic data collection

We and our service providers may automatically log information about you, your device, and your interactions over time with our Services, communications, and other online services, including:

  • Device data, such as operating system, browser type, device type, IP address, language settings, and general location information.
  • Online activity data, such as pages viewed, time on page, navigation paths, access times, and interactions with marketing emails.

We use cookies, local storage technologies, and web beacons for automatic data collection and analytics.

Google user data

Cimba connects to Google Workspace so you can use your own documents and spreadsheets as a data source inside the product. You start that connection yourself, and Google shows you the exact permissions before you grant them. The sections below describe what we request, why, and what we do with it.

What we request

  • Your basic profile (openid, userinfo.email, userinfo.profile): to identify the Google account you connected and show it back to you in the product.
  • Google Drive, read only (drive.readonly): used by our original Drive connector to read the files you choose as a data source. That connector cannot write to your Drive.
  • Google Drive, full access (drive, drive.file): used by our newer Drive integration, which can act on files on your behalf - for example moving, renaming, sharing, labelling or commenting on a file when you ask an agent to. This access can modify your Drive, and we request it only for that integration.
  • Google Drive file metadata (drive.metadata.readonly): to list and display file names and folders so you can pick the right spreadsheet.
  • Google Drive labels, read only (drive.labels.readonly): to read the labels your Workspace defines, so an administrator can nominate labels - for example a confidentiality label - whose files Cimba must never read, summarise or act on. We use this to keep Cimba out of files, not to reach further into them.
  • Google Sheets, read only (spreadsheets.readonly): to read the contents of the spreadsheets you select.

Two Drive connections, two levels of access

Cimba has two separate Google Drive connections and they do not request the same thing. The original connector is strictly read only. The newer integration requests full Drive access because it can carry out actions you ask an agent to perform, such as moving, renaming or sharing a file. Each is a separate connection that you grant separately, and Google shows you which permissions you are granting at the time.

Choosing narrower access

An administrator can restrict Cimba to specific files instead of granting access to all readable Drive content. In that mode Cimba requests only the narrower drive.file scope, and the restriction is enforced on every request at the point the file is fetched, not only in the user interface.

How we use it

We use the content of the files you connect only to provide the Services to you: to answer the questions you ask of your own data, and to produce the analyses, reports and automations you request. We do not use it for advertising and we do not sell it.

Human access

Cimba personnel do not read content from your connected Google account in the ordinary course of operating the Services. Access is limited to cases where you have asked us for support, where it is necessary to investigate a specific fault, or where the law requires it. Such access is logged.

Machine learning

We do not use content from your connected Google account to train or fine-tune machine learning models. It is not added to training corpora, evaluation sets or prompt-tuning data, and it is not used to improve models for other customers. The model providers we send data to are contractually barred from training on it.

Limited Use

Cimba's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Where it is stored and how it is protected

Content read from your Google account is stored in the United States, in Amazon Web Services (region us-east-2). Files are held in object storage encrypted at rest with AES-256, and the database that holds the surrounding records is encrypted with a customer-managed key. Unencrypted uploads are rejected by the storage layer itself. Traffic is encrypted in transit with TLS.

Your Google OAuth access and refresh tokens are encrypted with AES-GCM before they are written, and are stored only in encrypted form in our application database. They are decrypted in memory for the duration of a request and are never written to disk, logs or analytics in readable form.

How long we keep it

We keep content read from your Google account for as long as you keep the connection. If you delete a document or disconnect the integration, we delete the stored copy and its search index entries. If your contract ends, content is deleted within 90 days of termination.

Deletion does not reach our backups instantly. Database backups are retained for 35 days and expire automatically, so a deleted item can persist in a backup for up to that long before it ages out. Operational logs are retained for 30 days.

How to disconnect and delete

You can disconnect Cimba at any time from within the product, or revoke access directly from your Google Account at myaccount.google.com/permissions. Revoking access at Google stops Cimba reading anything further from your Drive. It does not by itself remove copies of files already imported into Cimba - to remove those, delete the connection or the documents inside Cimba, which deletes the stored copies and their search index entries.

You can also ask us in writing, at security@cimba.ai, to delete the Google data we hold for you. We action such requests within 7 days. Revoking access at myaccount.google.com stops any further reading immediately, but it does not by itself delete what has already been imported — use the in-product deletion or the written request for that.

Who else sees it

We do not sell your Google data and we do not share it for advertising. It is processed by a small set of service providers acting on our instructions: Amazon Web Services and Microsoft Azure for hosting and storage, and the AI model providers that generate answers over your data. Those model providers are contractually barred from training on your content; they may retain it for a short period under their own abuse-monitoring terms before deleting it. We do not send Google content to analytics or advertising tools.

How we use your personal information

To operate our Services:

  • Provide, operate, maintain, secure, and improve our Services.
  • Communicate with you about our Services, including announcements, updates, security alerts, and support messages.
  • Understand your needs and interests, and personalize your experience.
  • Respond to your requests, questions, and feedback.

We may also use personal information for research and development, including creating aggregated, de-identified, or anonymous data to analyze and improve our Services and business. This does not include content from your connected Google account, which is governed by the Google user data section above.

Direct marketing

We may send direct marketing communications as permitted by law. You may opt out as described in the "Your choices" section below.

Compliance and protection

We may use personal information to comply with law, protect rights and safety, enforce terms, and prevent or investigate fraudulent or illegal activity.

How we disclose your personal information

We may disclose personal information to:

  • Affiliates: our parent, subsidiaries, and affiliates for purposes consistent with this Privacy Policy.
  • Service providers: organizations helping us run our Services (for example, hosting, analytics, email delivery, and support providers).
  • Authorities and others: law enforcement, government authorities, or private parties when necessary for compliance and protection.
  • Business transfers: in connection with transactions such as mergers, acquisitions, or asset sales.

Content from your connected Google account is not disclosed under the first, third or fourth of these except where the law requires it.

Your choices

Opt out of marketing communications

You may opt out of marketing emails by using the unsubscribe instructions in those messages. You may still receive service-related and other non-marketing communications.

Online tracking opt-out

You can limit online tracking by adjusting browser cookie settings, using privacy-focused browsers or plug-ins, and installing Google Analytics opt-out tools where available.

Do Not Track

Some browsers send "Do Not Track" signals. We currently do not respond to those signals.

Disconnecting Google

You can disconnect your Google account from Cimba at any time, as described in the Google user data section above.

Other sites and services

Our Services may link to third-party websites, apps, and services. We do not control those third parties and are not responsible for their privacy practices.

Security

We use technical, organizational, and physical safeguards designed to protect personal information. No safeguards are fail-safe, and we cannot guarantee absolute security.

Children

Our Services are not intended for children under 13. If we learn we collected personal information from a child under 13 without required consent, we will delete it.

Changes to this Privacy Policy

We may modify this Privacy Policy at any time. If we make material changes, we will update the effective date and post the updated policy on the website.

How to contact us

Questions or comments about this Privacy Policy can be sent to security@cimba.ai.