Privacy Policy

Last updated: July 29, 2026

Cubite ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website cubite.io, use our platform, or engage our LMS engineering services.

1. Information We Collect

Personal Information

When you create an account, book a consultation, or engage our services, we may collect:

  • Name and email address
  • Organization or company name
  • Phone number (when provided)
  • Billing and payment information (processed securely via Stripe)
  • Project requirements and communications

Automatically Collected Information

When you visit our website, we automatically collect:

  • IP address and approximate location
  • Browser type and version
  • Operating system
  • Pages visited, time spent, and referring URLs
  • Device identifiers

Platform Usage Data

If you use our LMS platform (cubite.io or tenant sites), we collect usage data including course progress, assessment results, login activity, and content interactions to provide and improve our services.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services and platform
  • Process payments and send billing-related communications
  • Respond to inquiries and provide customer support
  • Send service updates and project-related communications
  • Analyze usage patterns to improve user experience
  • Detect, prevent, and address technical issues or security threats
  • Comply with legal obligations

We do not sell your personal information to third parties. We do not use your data for targeted advertising.

3. Data Sharing and Third Parties

We may share your information with:

  • Hetzner - for hosting, databases, and object storage (EU)
  • Cloudflare - for DNS, CDN, and network protection
  • Stripe - for secure payment processing
  • Kushki - for payment processing on sites that select it instead of Stripe
  • Resend - for transactional email delivery
  • Cloudinary - for image storage and delivery
  • Bunny - for hosting and streaming course video
  • Upstash - for background job queuing
  • AI providers (Anthropic, OpenAI, Google) - only for features you actively use, such as AI content drafting or an MCP assistant connection you create. See section 10.

These third parties are contractually obligated to protect your data and use it only for the purposes we specify. We may also disclose information when required by law or to protect our rights.

4. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • TLS/SSL encryption for all data in transit
  • Encrypted database storage for sensitive information
  • Regular security audits and vulnerability assessments
  • Role-based access controls for internal systems
  • Secure payment processing via Stripe (PCI DSS compliant)

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically:

  • Account data is retained while your account is active
  • Site content and learner data is retained while the site is active, and is deleted on request after it closes
  • Project data is retained for the duration of the project plus 2 years
  • Billing records are retained for 7 years for tax and legal compliance
  • Analytics data is anonymized after 26 months
  • API and MCP audit records (the credential id, site id, HTTP method, path, status, caller IP, and timestamp of each write) are kept indefinitely. They deliberately survive revoking the credential and deleting the site, so an incident can still be investigated afterwards. They contain no learner personal data.

You may request deletion of your data at any time by contacting us at hello@cubite.io. We will process deletion requests within 30 days, subject to legal retention requirements.

6. Your Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your personal data
  • Portability — request your data in a machine-readable format
  • Objection — object to processing of your data
  • Restriction — request restriction of processing

To exercise any of these rights, contact us at hello@cubite.io. We will respond within 30 days.

7. GDPR Compliance

If you are located in the European Economic Area (EEA), we process your data under the following legal bases:

  • Contract performance — processing necessary to deliver our services
  • Legitimate interest — improving our services and security
  • Consent — for optional analytics and marketing communications
  • Legal obligation — tax, accounting, and regulatory requirements

You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.

8. Children's Privacy

Our services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.

10. AI Assistants and Third-Party Connections (MCP)

Cubite offers an optional Model Context Protocol (MCP) connection that lets you operate your site from an AI assistant such as Claude (Anthropic), ChatGPT (OpenAI), or Gemini (Google). This is off by default. Nothing is shared with any AI vendor unless you deliberately create a connection.

What becomes accessible

A connection can access only what its permissions allow, and only within the one site you select when you connect. Depending on the permissions you approve, that can include:

  • Course content, pages, blog posts, and site settings
  • Question banks and uploaded xAPI or SCORM packages
  • Learner and member personal data, including names, email addresses, enrollments, and group membership, if you grant the user, member, enrollment, or group permissions

Grant only the permissions you need. If you want help authoring content, the page and course permissions alone do not expose learner personal data.

Who receives it

Data returned to an assistant is processed by the vendor of the assistant you connected, under that vendor's own privacy policy and terms. Cubite is not a party to that processing and does not control it. Cubite never sends your data to an AI vendor on its own initiative through this feature. If you are a data controller for your learners, you are responsible for confirming that the assistant vendor you choose is an acceptable processor for that data.

Credentials and retention

  • Connections authenticate with OAuth 2.1 or a scoped API key.
  • Access tokens expire after one hour. Refresh tokens last up to 30 days and rotate on each use; replaying a rotated token revokes the whole connection.
  • Tokens and API keys are stored only as SHA-256 hashes, so the stored value cannot be turned back into a working credential.
  • Writes made through a connection are recorded against the credential that made them.

Revoking access

You can revoke any connection at any time from your site's Integrations settings in the Cubite admin, or by disconnecting from within the assistant. Revoking takes effect immediately. Removing the connector inside the assistant stops that client from calling Cubite; revoking in Cubite invalidates the credential itself.

11. Contact Us

The data controller for the purposes of this policy is Cubite Technologies Corp, a corporation organized under the laws of the State of Delaware, United States.

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: