NUBLOIDLocal. Fast. Private.
In this policy

Privacy Policy — Nubloid

Last updated: October 6, 2026

This Policy explains how Nubloid Plus — NubloidPlus, for Android — and Nubloid Desktop, for Windows, collectively referred to as “Nubloid,” access, use, store, protect and share information.

Nubloid prioritizes processing on devices, direct file transfers and user control. Some optional features use Google services, with authorization, to send invitations through Gmail, look up contacts and carry out transfers with temporary assistance from Google Drive.

1. Identification and contact

This Policy applies to the Nubloid applications for Android and Windows and to the integrations described in this document.

2. Features covered

Depending on the platform and version, Nubloid offers:

  • File transfers between devices through direct connections on compatible networks.
  • Transfer authorization through a temporary code, an invitation or a previously authorized session.
  • File organization, search and management in Nubloid Files.
  • Sharing through applications chosen by the user.
  • Optional invitation sending through the Gmail API.
  • Optional Google contact lookup to select recipients.
  • Hybrid transfers, combining direct connections and temporary storage of encrypted files in Google Drive.
  • Mirroring, desktop mode and Pocket PC, when activated by the user.

Local features do not require Gmail or Drive authorization. Google integrations require selecting an account and granting the corresponding permissions.

Nubloid does not maintain its own cloud to store transferred files.

3. Information processed

Depending on the features used, Nubloid may process:

Files and local organization: the contents of selected files, names, formats, sizes, folders, dates and information needed for search, organization and integrity checks.

Transfer information: batch and session identifiers, the designated recipient, progress, results, timestamps, validity periods and data needed to locate and connect devices, such as network addresses.

Google account information: the authorized account’s email address, granted permissions and temporary or renewable authorization credentials.

Contacts: names and email addresses returned by an authorized Google contact lookup, or the address selected by the user in the system contact picker.

Invitations: sender, recipient, batch information, receiving instructions and the access information needed to open the invitation in Nubloid.

Local diagnostics: operation status, failures, technical device information and records needed to identify problems. Exported reports may include file names or paths.

Mirroring and control: screen images, audio and interaction commands needed for the activated mode, depending on the available capabilities and authorizations.

This information is used to perform the requested features, maintain operational continuity, protect transfers and enable diagnostics.

4. Use of Google APIs

4.1 Account identification and authorization

Authorization takes place through Google’s official mechanisms. Nubloid does not request or store the Google Account password.

The account address may be used to identify the sender, verify the recipient of an invitation and remember the account selected for future use.

Remembering an account does not replace authorization: Nubloid needs valid permissions to perform Google operations.

4.2 Gmail — sending invitations

We use the gmail.send permission to send an invitation from the authorized account to the selected recipient, after the user has reviewed and explicitly confirmed it.

The message may include instructions, batch information and a Nubloid invitation file.

This integration:

  • Does not read the inbox or email history.
  • Does not search existing messages.
  • Does not manage drafts or delete messages.
  • Does not use the account for advertising or unsolicited messages.

Gmail processes the message and its attachments to deliver them. The recipient’s email provider may also store them according to its own policies.

4.3 Google Contacts — selecting recipients

We use the contacts.readonly permission through the People API in the optional recipient search feature.

The lookup requests names and email addresses. The results are displayed so that the user can choose who will receive the invitation.

Nubloid does not create, change or delete contacts and does not import the entire address book into its own database. Search results are used temporarily during selection. The chosen address becomes part of the invitation and, when necessary, the transfer record.

Manual recipient entry remains available.

4.4 Google Drive — transfer assistance

We use the drive.file permission to work with files created by Nubloid or specifically authorized by the user for use with the application. This permission does not provide unrestricted access to the entire Drive.

When the user authorizes a hybrid transfer, Nubloid may create a support folder in the sender’s Drive and encrypted records to coordinate the invitation. These records may exist even before uploading file contents to Drive becomes necessary.

When a transfer uses Drive:

  • The batch files are encrypted on the device before upload.
  • Storage takes place in the sender’s Google account.
  • Access to the necessary objects is granted to the Google account designated as the recipient.
  • Receiving requires the authorized account and the access information contained in the invitation.
  • The received contents are verified and saved on the recipient’s device.

Nubloid does not turn these objects into public files accessible to anyone with a link. The support folder remains private; the necessary permissions are applied to the transfer objects.

5. Information sharing

Nubloid shares information only as needed for the selected features:

  • With the recipient device: accepted files and data needed for the transfer.
  • With Google: data needed for authorization, sending through Gmail, contact lookup and Drive operations.
  • With applications chosen for sharing: the invitation, text or files that the user decides to forward.
  • With Nubloid support: information the user voluntarily sends for assistance.

Invitations and codes should be treated as access information. Sharing by email or messenger places a copy of the invitation in that service and on the recipient’s device.

Nubloid does not sell personal data, use it for behavioral advertising or sell contact lists.

The Nubloid team does not automatically receive a copy of the files, Google address book or authorization tokens used by the application.

6. Data protection

Nubloid uses technical measures appropriate to each feature, including:

  • HTTPS/TLS connections to Google APIs, to protect communications in transit.
  • Authenticated encryption for file transfers, with integrity checks.
  • File encryption before upload to Drive, using AES-GCM.
  • Local protection of sensitive transfer queue information: Android Keystore and encryption on Android; protection linked to the Windows user through DPAPI on Windows.
  • Protection of authorization credentials persisted on Windows, without storing the Google password.
  • Limited permissions, requested for the features used.
  • Validation of invitations, recipients, files and paths, along with operational limits and access expiration.
  • Cleanup of temporary files and disposal of transfer secrets when closure can be completed.

Files already delivered to Nubloid Files become local files under the user’s control. Encryption used during transfer does not mean that all local files receive an additional layer of encryption at rest.

The email body and shared invitation are also subject to the protections of the email provider or messenger used.

No system provides absolute protection. Security also depends on protecting accounts, devices and shared invitations.

7. Data retention and deletion

7.1 Google account and authorizations

The selected account address may remain saved locally to make future use easier. Authorization credentials may remain in memory or, when needed for continued access on Windows, be stored with operating system protection.

This data is used for as long as it is needed for the authorized features. The user can revoke access through their Google Account and remove the application’s local data as explained in section 8.

7.2 Contacts looked up

Nubloid does not keep a permanent copy of contact search results. They are used temporarily for selection.

The address actually selected may remain in the sent email and in records needed for the transfer. This does not mean retaining the address book that was queried.

7.3 Temporary files and records in Drive

In the current configuration:

  • The initial window for waiting for a direct transfer is up to eight hours.
  • If Drive is used, the batch may remain available for 48 hours after it becomes available, subject to the total limit of 56 hours from the creation of the hybrid invitation.
  • Confirmed completion, cancellation or expiration triggers the cleanup process for temporary objects belonging to the batch.

Invitation expiration does not guarantee immediate physical deletion in Drive. Cleanup must be performed by the sender’s application, with a valid connection and authorization. If it is turned off, offline, uninstalled or no longer has Google access, the objects may remain until a later cleanup run or until the account holder manually deletes them.

The empty support folder may remain in Drive for reuse in future transfers.

7.4 Local temporary files and records

Temporary sending copies, incomplete parts and auxiliary files are removed by closure and recovery routines. Storage failures or interruptions may delay this cleanup until the next run.

Operational transfer and Inbox histories use a retention period of up to three days, with quantity limits, applied during maintenance routines.

This does not mean that all local data is deleted within that period: settings, auxiliary queue records, diagnostics and exported reports may remain until they are replaced, cleaned up or removed by the user. Access secrets and credentials associated with the batch are removed when its local closure is completed.

7.5 Received files and emails

Files delivered to Nubloid Files, exported or copied to other folders remain on the device until the user deletes them. The end of the transfer does not erase them.

Emails sent through Gmail remain in the accounts involved according to the providers’ settings and policies. Nubloid does not use the Gmail API to delete these emails.

Deleting a batch in Drive does not remove copies that the recipient has already received, exported or shared.

8. Your controls and deletion requests

You can:

  • Choose which files to send and which invitations to accept.
  • Cancel operations and manage files in Nubloid Files.
  • Use local features without authorizing Google integrations.
  • Enter recipients manually without looking up Google contacts.
  • Revoke Nubloid’s access on the Google Account connections page.
  • Manually delete objects created for Nubloid transfers in your Drive.
  • Remove local data using the controls available in the application or operating system.
  • Request information or deletion guidance by email at contato@nubloid.com.br.

Revoking authorization stops API access, but does not automatically delete local files, emails already sent or existing objects in Drive. Revocation may also prevent Nubloid from performing pending remote cleanup.

Before removing application data, export the files you want to keep. Uninstalling may leave exported files or local folders, especially on Windows.

Because files are stored on users’ own devices and in their own accounts, the Nubloid team does not have automatic remote access to erase them. We can provide guidance on removing them. Information sent to support may be subject to a deletion request, taking into account support needs and applicable obligations.

9. Commitment regarding Google data

The use and transfer of information received from Google APIs follow the Google API Services User Data Policy, including the Limited Use requirements, and the rules applicable to Google Workspace APIs.

Data is used for the features described in this Policy, according to the user’s authorization.

We do not use data obtained from Google APIs for advertising, selling information, building commercial profiles or developing, training or improving artificial intelligence or machine learning models.

We do not allow routine human access to Google data. Any exceptional access must respect the applicable authorization, the need for support, security or a legal obligation, and the limits of Google’s policies.

10. System permissions and resources

Depending on the feature used and the Android version, Nubloid may need:

  • Access to the internet, local network and connection status.
  • Wi-Fi, multicast and nearby device capabilities for discovery and connection.
  • Permissions related to Wi-Fi discovery that older Android versions classify as location. Their purpose in Nubloid is to locate compatible devices, not to track the user’s geographic location.
  • Background services and tasks, notifications and sleep control to perform authorized operations.
  • System pickers to access files, folders or the contact selected by the user.
  • Display, audio and input capabilities needed for mirroring and Pocket PC.

ADB debugging, when required by mirroring or control modes, must be enabled and authorized by the user. It is not a general requirement for using Inbox or ordinary transfers.

Permissions are not used for advertising or to collect data intended for sale.

11. Diagnostics and support

Nubloid may keep local technical records to display results and help investigate failures. These records are not automatically sent to the Nubloid team as part of the Gmail, Drive or Contacts integrations.

If you export and send a report to support, it may contain technical information, file names and paths. Share only what is needed for assistance.

Communications received by support are used to respond to the request and retained for as long as needed to provide assistance and meet applicable obligations. Deletion requests can be sent to the contact listed in this Policy.

12. Third-party services

Google, Microsoft, device manufacturers, app stores and services chosen to share invitations have their own privacy policies.

When Google integrations are used, the information needed for the operation is processed by Google’s infrastructure. Using these services may involve processing in other countries, according to the provider’s terms, settings and policies.

Please also consult Google’s Privacy Policy and the policies of the other services used.

Nubloid does not display ads or use Google data for advertising purposes.

13. Children and sensitive content

Nubloid is not intended to collect children’s personal information or exploit sensitive information. However, files selected by users themselves may contain personal or sensitive data.

These files should be shared with authorization and with careful attention to the recipient. Use by minors must follow the rules of the stores and services used, with appropriate supervision by a responsible adult.

14. Open-source components

Nubloid uses open-source libraries and components to provide its features. Applicable information and licenses are made available through the application’s and website’s official channels.

Using these libraries does not change the purposes of data processing described in this Policy.

15. Changes to this Policy

This Policy may be updated to reflect changes in features, integrations, data processing practices or applicable requirements.

The update date will appear at the beginning of the document. Material changes in data use will be communicated through appropriate channels and, when necessary, accompanied by renewed authorization.

16. Contact

For questions, clarification, requests about your data or guidance on revoking permissions and deleting information:

contato@nubloid.com.br