Your information

Privacy Policy

This policy explains how Qube Root Media handles information across our public website, client portal, talent workspace, command center, and connected services.

Effective and last updated: September 9, 2026

Who we are and what this covers

Qube Root Media (“Qube Root,” “we,” “us,” or “our”) provides creative-production, project-coordination, content, and collaboration services. This policy applies when you visit our website, submit an inquiry or application, use a Qube Root workspace, or connect a third-party account.

Questions and privacy requests may be sent to support@quberootmedia.com.

Information we collect

  • Account information: name, email address, profile image when supplied by a sign-in provider, account role, organization, location, and authentication records.
  • Project and workspace information: inquiries, briefs, schedules, assignments, availability blocks, messages, approvals, feedback, files, deliverables, portfolio material, and content plans.
  • Talent information: skills, professional biography, portfolio links, travel availability, applications, work history, and payment or rate terms supplied for a project.
  • Billing records: plan, invoice, payment status, and transaction identifiers. Payment processors handle full card or bank-account details; Qube Root does not store those full payment credentials.
  • Connected-service information: account identifiers, permissions, connection status, encrypted authorization credentials, and the limited provider data described below.
  • Technical and security information: device, browser, request, and diagnostic information produced when the service is operated, secured, or troubleshot.

Google user data

Google connections are optional and are requested in context when you choose the relevant feature.

  • Sign in with Google: we receive the Google account identifier and the basic profile information Google makes available, such as your name, email address, and profile image. We use it only to create or authenticate your Qube Root account and route you to the workspace authorized for that account.
  • Google Calendar: with your permission, we access the email address of the connected account, primary-calendar free/busy windows, and Calendar event access. We request busy periods from 30 days before through 180 days after a sync and store only their start and end times as “External busy time.” We do not import calendar event titles, descriptions, guests, or locations. We create, update, and delete only Qube Root booking events associated with accepted assignments, and retain the Google event identifiers required to keep those bookings synchronized.
  • YouTube: if an authorized operator connects YouTube for content publishing, the app requests basic Google profile, YouTube read-only, and YouTube upload access. It currently reads the signed-in channel’s ID, title, and thumbnail so the correct destination can be selected, and uses upload access only to publish videos that have completed the Qube Root approval workflow.

Google access and refresh tokens are encrypted server-side using AES-GCM. Browser clients receive only connection status and account details needed to use the feature, never the stored credential.

We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train general-purpose artificial-intelligence models. Human access is limited to a user’s explicit support request, security or abuse investigation, legal obligations, or appropriately aggregated internal operations.

Qube Root’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How we use information

  • Provide, secure, support, and improve the website and role-based workspaces.
  • Coordinate projects, staffing, scheduling, approvals, delivery, billing, and communications.
  • Process media and prepare or publish content through destinations an authorized user selects.
  • Send authentication codes, service notices, requested updates, and communications you have chosen to receive.
  • Prevent fraud and abuse, enforce access controls, troubleshoot failures, and comply with legal obligations.

When information is shared

We share information only as needed to provide the service: with the client, talent, or Qube Root team members assigned to the relevant work; with infrastructure, hosting, authentication, email, media-processing, payment, and publishing providers acting for us; when you direct a connected platform action; or when law, safety, or a business transaction requires it.

Third-party services process information under their own terms and privacy policies. We do not sell personal information or connected-account data.

Retention, disconnection, and deletion

We retain information only as long as needed for the service, project records, security, dispute resolution, and legal or accounting obligations. After that, information is deleted or anonymized, subject to limited backup cycles.

Disconnecting Google Calendar removes imported busy blocks, synchronization links, the stored encrypted credential, and Qube Root events previously exported to that calendar, and the app attempts to revoke the Google token. Disconnecting a social destination removes its stored credential from Qube Root. You may also revoke access at any time from your Google Account’s third-party connection settings.

To request access, correction, export, or deletion of your Qube Root account and associated personal data, email support@quberootmedia.com from the account address. We may need to verify the request and may retain records where law or legitimate security and contractual obligations require it.

Security, international processing, and children

We use role-based access controls, row-level database policies, encrypted transport, and encrypted connected-account credentials. No system is perfectly secure, so we cannot guarantee that unauthorized access will never occur.

Our providers may process information in countries other than your own. Where required, we use appropriate safeguards for those transfers. The service is intended for businesses and working professionals and is not directed to children under 13.

Changes to this policy

We will update this page when our data practices change. If a change materially affects how previously authorized Google user data is used, we will provide notice and obtain any additional consent required before using that data for the new purpose.