1. Scope and operator
QToolKit is a multi-application software platform operated by QubitBot through social.qubitbot.cloud. This policy applies to QToolKit’s Telegram FraudShield, SEO Toolkit, Video Studio, Auto Post, shared account services, and public pages. It does not replace privacy terms supplied by connected third-party platforms.
2. Information QToolKit may collect
Depending on the tools and connections you use, QToolKit may collect or process:
- Account details: email address, display name, password hash, workspace, role, app permissions, and session status.
- App activity: navigation, actions, job status, publishing history, workflow results, and feature settings.
- User-created content: messages, campaign material, post drafts, schedules, SEO project inputs, watermark layouts, and generated outputs.
- Uploaded and selected files: media, watermark images, imported consent records, and videos selected for processing.
- Connected-account metadata: provider, account identifiers, display names, email addresses, connection state, scopes, file or folder metadata, and publishing destinations.
- Security and audit information: session timestamps, user agent, hashed network address, authentication events, administrative actions, errors, and abuse-prevention records.
3. How information is used
QToolKit uses information to:
- authenticate users, enforce workspace roles, and provide assigned applications;
- perform user-requested Telegram, SEO, video, and publishing workflows;
- connect and communicate with platforms a user explicitly authorizes;
- save settings, schedules, drafts, processing state, and operational history;
- protect accounts, investigate errors or misuse, maintain service integrity, and meet legal obligations; and
- support users and improve reliable, user-facing QToolKit functionality.
4. Google Drive access in Video Studio
Video Studio connects to Google Drive only after a signed-in user deliberately starts Google’s OAuth flow and approves the permissions shown by Google. QToolKit currently requests the read-only scope https://www.googleapis.com/auth/drive.readonly. That scope can allow QToolKit to view Drive files and metadata; it does not allow QToolKit to edit or delete files in Google Drive.
QToolKit uses this access only to present Drive folders and eligible source videos, let the user choose material, read relevant file metadata and thumbnails, download selected source videos to perform requested watermark processing, and maintain the resulting job state. Access is not used to build advertising profiles, target ads, determine creditworthiness, or independently browse files for unrelated purposes.
QToolKit does not sell Google user data. Its use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is shared only as needed to provide or secure the user-facing feature, comply with law, or with the user’s explicit direction or consent.
5. Credentials and token security
OAuth refresh tokens, API credentials, and connected-platform credentials are encrypted before persistent storage. Google access tokens are obtained when needed, kept in a short-lived server memory cache until expiry, and are not persisted to the application database. Secret fields are write-only where applicable: QToolKit reports whether a credential is configured but does not return or display its plaintext value after saving.
Passwords are stored as one-way hashes. Production session cookies are HTTP-only, same-site restricted, securely transmitted, and tied to revocable server-side sessions. QToolKit also uses access controls, origin checks, encryption at rest, TLS in transit, and user-scoped data isolation. No system can guarantee absolute security.
6. Cookies and local preferences
QToolKit uses essential session cookies to keep users signed in and protect authenticated requests. The interface may store a local theme preference. QToolKit does not currently use advertising cookies on these public legal pages. If materially different analytics or tracking practices are introduced, this policy and any required consent controls must be updated.
7. Third-party integrations and disclosures
QToolKit can interact with Google Drive, Telegram, X, Facebook, Instagram, and infrastructure or service providers needed to host and secure the platform. Information is sent to a connected platform when required to complete the action the user requests, such as reading a selected Drive video or publishing an approved post. Each provider processes information under its own terms and privacy policy.
QToolKit may also disclose limited information to service providers bound to support hosting, security, maintenance, or legal compliance; to protect users and the service; during a lawful business transfer; or when legally required. QToolKit does not sell personal information or connected-platform credentials.
8. Data retention
QToolKit retains account, configuration, content, job, audit, and security information for as long as reasonably needed to provide the service, preserve user-requested history, secure the platform, resolve disputes, and satisfy legal obligations. Retention depends on information type, workspace controls, active integrations, and operational need.
Connected credentials remain until they are replaced, disconnected, revoked, removed, or the associated account is deleted. Temporary source and processing files are retained only as needed for active workflows and operational recovery. Deleted information may remain for a limited period in protected backups, logs, or records QubitBot must retain for security or legal reasons, after which it is removed or rendered inaccessible under normal retention cycles.
9. Your choices and controls
Subject to workspace permissions and applicable law, users can:
- disconnect or remove connected Google Drive and social-platform accounts;
- replace or delete stored platform credentials through available settings;
- revoke provider access directly through the provider’s account controls;
- remove content or files where QToolKit provides a deletion control; and
- request access, correction, account closure, or deletion of eligible data by contacting QubitBot.
Some requests may be limited by another user’s rights, workspace administration, legal duties, fraud prevention, security needs, or records QubitBot must retain. Disconnecting a provider stops future authorized access but does not automatically erase completed job history or content already published to that provider.
10. Policy updates
QubitBot may update this policy when QToolKit’s features, data practices, providers, or legal obligations change. Material changes will be reflected by a new effective date and, where appropriate, an in-product notice or renewed consent before newly using Google user data for a materially different purpose.
11. Contact
Privacy, account, and deletion requests may be sent to support@qubitbot.cloud. Include the QToolKit account or workspace concerned and enough detail to verify and respond to the request. Do not send passwords, OAuth tokens, API secrets, or other credentials by email.