Legal
Privacy Policy
Last updated: 2026-09-27
The short version: we collect what we need to run your account and keep the platform safe: your name, email and avatar from Google or GitHub, IP addresses and logs. We don't sell data, show ads or use tracking cookies. Delete everything with cubek account delete --yes.
Who is responsible
[COMPANY LEGAL NAME], [REGISTERED ADDRESS], tax ID [TAX ID], is the controller of the personal data described here. Contact for anything privacy-related: hello@cubek.dev.
We have two roles:
- Controller for data about you as a cubek user and visitor of cubek.dev (this policy).
- Processor for the data your apps store about their own users. You decide what that data is; the Data Processing Terms apply.
What we collect
| Data | Where it comes from | Why |
|---|---|---|
| Email, name, avatar URL, provider account ID | Google or GitHub, when you sign in (we never see your password) | Your account, sign-in, showing who did what |
| Organizations, memberships, invitations (the invitee's email), projects, deploy and change history | You and your team, through the CLI, API or console | Running the service |
| API tokens and sessions | Created when you sign in | Keeping you signed in |
| IP addresses | Every request | Rate limiting, abuse prevention, routing you to the nearest location |
| Logs (time, method, route, status, duration) | Requests to the platform and your apps | Operating, debugging and securing the service |
We do not collect payment data (there is no paid self-serve plan), and cubek.dev has no analytics or advertising trackers.
Location lookup. To route requests to the nearest location we look up the country of an IP address in the DB-IP geolocation database, which runs on our own servers: no IP address is sent to DB-IP.
Cookies and local storage
Only what is strictly necessary; no consent banner is needed for them.
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
ck_session | console.cubek.dev | Keeps you signed in (HttpOnly) | 7 days |
ck_state | console.cubek.dev | Protects the sign-in redirect | 10 minutes |
ck_flash | console.cubek.dev | Shows a one-time message | 60 seconds |
__cubek_pos | Apps hosted on cubek | After a write, makes sure your next reads see it (a signed position, no personal data) | 24 hours |
cubek-theme (local storage) | cubek.dev | Remembers light or dark theme | Until you clear it |
Legal bases
- Contract (GDPR Art. 6(1)(b)): your account and the service you asked for.
- Legitimate interests (Art. 6(1)(f)): security, abuse prevention, rate limiting and logs.
- Legal obligations (Art. 6(1)(c)): when the law requires us to keep or disclose data.
How long we keep it
- Account data: while your account exists.
- Logs: rotated by size; older files are deleted.
- Backups: the write-ahead-log archive for point-in-time recovery and snapshots are kept 7 days.
- Deleted organizations and projects: removed at once; their archive is kept 7 days, then deleted.
Deleting your account
Run cubek account delete --yes or use the Account page in the console. It deletes your sign-ins, sessions and tokens, memberships, invitations to or from you and any waitlist entry, and every organization only you belong to, with its projects (archive kept 7 days). Your email in the history of shared organizations becomes "deleted user".
If you are the only owner of an organization with other members, make someone else owner or delete the organization first. A suspended account cannot be deleted by self-service; write to us.
Who processes it
| Provider | What | Where |
|---|---|---|
| CubePath | Servers that run cubek and store all its data (databases, files, backups, logs) | Spain (EU) and the United States |
Google and GitHub are the sign-in providers you choose; their own privacy policies apply to your account with them. We tell you here before we add a provider.
International transfers
Your data may be stored in, and replicated between, our locations in the EU and the US. Where data leaves the EEA we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
Your rights
You can ask us to access, correct, delete, restrict or port your data, and object to processing based on legitimate interests. Most of it you can do yourself with the CLI or the console; for the rest, write to hello@cubek.dev. We answer within one month. You can also complain to a data protection authority, in [JURISDICTION] or where you live.
cubek is not meant for anyone under 16.
Changes
We publish changes here with a new date and tell account holders about material ones in advance.