Data security and privacy
Who can see what: permissions are enforced by the backend
GuppyCubed restricts data access at the workspace or organization, project, and folder levels. The backend validates and enforces these permissions; access does not depend only on whether a button is visible in the interface. When AI helps organize information, it can only access the scope you have authorized at that moment. Knowing that data exists does not grant access to it.
File uploads and storage
- Large files upload directly to cloud storage instead of passing through the application server as a complete package, reducing the risk of failed uploads;
- Privacy and sharing scopes can be configured for folders and individual files;
- GuppyCubed backend services and cloud storage retain formal data. It does not exist only inside a temporary AI execution environment.
Authorization before AI reads data
- AI in a standard project conversation is limited to the workspace and project scope authorized for that conversation;
- Tag AI in team conversations has narrower tool permissions and does not automatically read the entire workspace;
- External actions, such as using a connected Google service to read email or create a calendar event, require stricter confirmation and are not performed automatically without approval.
Account security
- Sign in with email or phone verification, Google, or Apple;
- Secure sessions support sign-out and role switching;
- Review authorized connections to Google and other external services regularly, and revoke access you no longer need.
System reliability
- Important background work, including document parsing and AI tasks, displays processing status and supports retries. A failure is clearly marked rather than disappearing silently;
- The platform continues to strengthen data retention and deletion policies, disaster recovery, and fine-grained external service connection management. This page will be updated as those mechanisms become available.
What to do if you have concerns
If data access differs from your expectations or you have a security concern, see Troubleshooting or ask your workspace administrator to review the permission settings.
Check the intended sharing scope
Distinguish internal work, named partners, and public pages. Workspace access does not authorize public disclosure of an original file or personal information. Review names, contact details, participant lists, and other non-public material before publishing.

After an external collaborator joins
Have an administrator review roles and folder sharing. Correct authorization problems rather than copying restricted files into public locations. Review continued access when the work ends.
Screenshots and prompts can disclose information
Use demonstration screenshots or remove real contacts, billing usage, and private records. Keep only necessary context in issue examples. Do not place passwords, verification codes, or access credentials in documents or AI conversations.
Unexpected access
Record time, material type, intended identity, and actual visibility. Avoid further distribution and notify an administrator. Provide the minimum context needed rather than attaching the entire sensitive file.
Access, publication, and consent differ
Workspace access concerns the current role. Publication also depends on purpose, consent, and team rules. A downloadable file is not automatically suitable for onward sharing.
| Version | Typical contents | Review |
|---|---|---|
| Original | Interviews, lists, internal discussion | Destination and necessary access |
| Internal draft | Summary, analysis, actions | Inference and open points |
| Public explanation | Approved process and results | Personal detail and limitations |
Ask another member to inspect the public version and its links. A clean summary may still link to a full private source.
Recordings and external material
Obtain appropriate recording consent and explain use and retention. Confirm permission to use imported material; readability and republication are different. Refer situation-specific legal judgments to the relevant professional.
If material is misplaced
Identify affected content, readers, and links, then restrict sharing through available controls and involve the responsible administrator. Do not amplify exposure by copying sensitive material into broad conversations or tutorial captures.