1. Overview
Kübi, developed and operated by Reviver Global, is a secure, enterprise-grade Knowledge Operating System designed to enable organizations to store, manage, and interact with proprietary knowledge through AI-powered systems, including Large Language Models (LLMs).
Kübi may also send workplace notifications to Slack or Microsoft Teams when a company administrator connects those integrations, and it may use Google or Microsoft accounts for sign-in and optional cloud file import.
This policy defines data ownership, access responsibilities, AI handling, how we use third-party integrations, and limitations of liability.
2. Data Ownership and Environment Isolation
All data uploaded, processed, or generated within Kübi remains the exclusive property of the subscribing organization ("Client").
Kübi enforces strict environment-level isolation so that one Client's workspace is not mixed with another Client's workspace. No Client data is used to train or influence models for other Clients.
When a Client enables a third-party integration (for example Slack, Microsoft Teams, Google Drive, or OneDrive), Kübi sends only the data needed to provide that feature to that provider, under that provider's terms and the Client's own workspace permissions. That transfer is requested by the Client. It is not sharing with other Kübi customers.
3. Access Control and Client Responsibility
Kübi provides role-based access control (RBAC) and enforces those roles inside the product, including which documents a user may search or ask about.
The Client remains responsible for user provisioning, role assignment, credential security, and internal governance of who should have access. Reviver Global is not responsible for the Client's internal access decisions.
4. Responsibility for User Actions
All activity is considered authorized under the Client's control.
Reviver Global is not liable for misuse, unauthorized access due to compromised credentials, or internal data exposure caused by improper configurations.
5. AI and LLM Data Handling
All AI interactions are scoped to the Client's isolated Kübi environment and the documents that user is allowed to see.
Kübi may send retrieved document excerpts, prompts, and related metadata to contracted AI providers (currently including OpenAI, Google Gemini, DeepSeek, and Anthropic Claude, depending on the Client's plan) solely to generate answers, summaries, OCR, or analytics the Client requested.
No cross-client learning occurs. We do not use Client documents, Slack data, or Microsoft Teams data to train public AI models for other customers.
Clients are responsible for validating AI-generated outputs before use.
Notification content posted to Slack or Teams is not sent to these AI providers as a training corpus. Those posts are delivered to the Client's own Slack workspace or Microsoft tenant.
6. Subscription Tiers and Support
Kübi is offered on Starter, Growth, Team, and Enterprise plans (names may appear on the billing page or order form). Slack and Microsoft Teams workplace notifications require the Team plan, or another plan that includes those entitlements.
Support hours, response targets, and any uptime commitment follow the applicable Subscription Plan, order form, or separate written service level agreement. Unless a written SLA says otherwise, Kübi is provided on a commercially reasonable availability basis, as described in the Terms of Service.
7. Security Measures
Encryption in transit and at rest, secure infrastructure, and monitoring mechanisms are implemented.
Security is a shared responsibility.
8. Limitation of Liability
Reviver Global is not liable for data loss, misuse, AI output errors, or business decisions based on outputs.
Kübi is a decision-support tool, not a substitute for professional judgment.
9. Compliance and Data Governance
Clients must ensure compliance with applicable laws such as GDPR or industry regulations for the content they upload and the users they invite.
For Customer Data the Client uploads or connects (documents, knowledge, and integration content processed to provide the service), Reviver Global acts as a data processor and the Client acts as the data controller, except where a written data processing agreement says otherwise.
Reviver Global is the data controller for account and service-administration data we collect to operate Kübi, including sign-in identifiers (name, email, profile photo), billing records, security logs, and product analytics needed to run and improve the service.
10. Acknowledgment & Acceptance
By using Kübi, Clients accept full responsibility for data, user management, and risks associated with usage.
11. Google user data
Kübi integrates with Google services in two ways. This section describes how we access, use, store, and share Google user data, as required by Google's API Services User Data Policy.
Sign in with Google: If you choose Google to authenticate, Kübi requests openid, email, and profile scopes. We receive your name, email address, and profile photo URL to create your account, identify your session, and display your profile within your organization. We use this data only to provide authentication and account features visible in Kübi. We do not use Google sign-in data for advertising. Sign-in profile fields (name, email, photo) are not sent to AI models.
Google Drive import (optional): If you connect Google Drive to import documents, Kübi requests drive.file access. We access only files you explicitly select through the Google Picker. Selected files are copied into your organization's isolated Kübi workspace for search and AI features governed by your organization's access rules. We do not read your Drive files for purposes unrelated to the import you requested.
Retention: Drive OAuth tokens are stored server-side in an encrypted short-lived cookie (about one hour by default) and then expire. Sign-in name, email, and profile photo are kept while your Kübi account exists. Copied Drive files are stored in your organization's Kübi workspace like any other uploaded document until you or your administrator deletes them, or until the company or account is removed under Kübi's retention practices.
Deletion: You can stop Drive import by not initiating new imports; OAuth tokens then expire. Deleting an imported document in Kübi removes Kübi's copy. It does not delete the original file in Google Drive. Your organization administrator controls user and company account removal within your tenant.
AI and Limited Use: Copied Drive file content is used only to provide features for that customer (for example OCR, embeddings, document summaries, and grounded Ask Kübi answers) via the OpenAI API. Optional Claude, Gemini, and DeepSeek models are available for general chat only and do not retrieve Drive or company knowledge files. We do not use Google user data to create, train, or improve foundational or generalized machine learning or artificial intelligence models. We do not sell, rent, or transfer Google user data to third parties for advertising, creditworthiness, or data brokerage. We do not allow humans to read Google user data except when you give affirmative consent for a specific support request, when necessary for security or legal compliance, or when aggregated for internal operations consistent with applicable law. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Revocation: You can stop using Google sign-in by using another sign-in method where available. You can stop Drive import by not initiating new imports. Your organization administrator controls account removal within your tenant.
12. Microsoft user data
Kübi integrates with Microsoft services in three ways. This section describes how we access, use, store, and share Microsoft user and Graph data.
Sign in with Microsoft: If you choose Microsoft to authenticate, Kübi requests openid, email, and profile scopes. We receive your name, email address, and profile photo URL to create your account, identify your session, and display your profile within your organization. We use this data only to provide authentication and account features visible in Kübi. We do not use Microsoft sign-in data for advertising.
OneDrive and SharePoint import (optional): If you import documents from Microsoft, Kübi uses the Microsoft file picker. The picker requests read access such as Files.Read.All and, where SharePoint libraries are used, related Sites read permissions. We access only files you explicitly select. Selected files are copied into your organization's isolated Kübi workspace for search and AI features governed by your organization's access rules. We do not read your OneDrive or SharePoint files for purposes unrelated to the import you requested.
Microsoft Teams workplace notifications (optional, Team plan): If a company administrator connects Teams, Kübi requests delegated Microsoft Graph permissions User.Read, Team.ReadBasic.All, Channel.ReadBasic.All, plus openid, profile, and offline_access so the administrator can pick a team and announcement channel. When a user chooses Connect my Teams, Kübi requests User.Read (and openid, profile, offline_access) to link that user's Microsoft identity for personal DMs.
We store: Microsoft tenant id, team id and name, announcement channel id and name, the user's Azure AD object id, a Bot Framework conversation reference for DMs, and encrypted tokens needed to post messages. We list teams and channels so the administrator can choose where Kübi may post.
Kübi's Teams app is notification-only. We post announcement-channel messages and personal DMs that the organization and user have enabled (for example join requests, document-ready notices, escalation updates, and admin test messages). Those posts may include company name, file names, and a short optional comment the uploader added. We do not read Teams channel history, meeting content, or user chat messages to build Kübi's knowledge base. Inbound bot events are used only to record that a user added Kübi so we can deliver DMs.
Limited use: We do not sell, rent, or transfer Microsoft user or Graph data to third parties for advertising, creditworthiness, or data brokerage. We do not use Microsoft Graph data to train public AI models. We do not allow humans to read this data except when you give affirmative consent for a specific support request, when necessary for security or legal compliance, or when aggregated for internal operations consistent with applicable law.
Revocation: You can stop using Microsoft sign-in by using another sign-in method where available. You can stop OneDrive import by not initiating new imports. A company administrator can disconnect Teams in Settings. A user can disconnect personal Teams DMs in Profile. Disconnecting removes Kübi's authorization to post; data already posted remains in your Microsoft tenant under your Microsoft retention settings. Your organization administrator controls account removal within your Kübi tenant.
13. Slack user data
Kübi's Slack app is optional and requires the Team plan (or another plan that includes Slack notifications). This section describes how we access, use, store, and share Slack data.
Company install: A company administrator installs Kübi and authorizes bot scopes chat:write, chat:write.public, channels:read, im:write, users:read, and users:read.email. We use these scopes to list public channels for the announcement-channel picker, post to the chosen channel, open a DM with a linked user, and resolve Slack user ids for delivery. users:read.email is requested so we can match a Slack member to a Kübi profile when needed. We do not use Slack as a marketing list.
User connect: A user who wants personal DMs authorizes Slack identity.basic. We store that user's Slack user id and the bot DM channel id.
We store: Slack workspace (team) id, announcement channel id and name, encrypted bot token, linked Slack user ids, DM channel ids, and encrypted user tokens when retained for that connect flow. Tokens are stored server-side, encrypted at rest, and are not sent to the browser.
Kübi posts outbound notifications only. Typical posts include org join-request alerts, document-published announcements (file name and optional comment), personal DMs for escalations and upload-finished events, and admin test messages. We do not read Slack channel history, private messages, or files in Slack to train Kübi or to index them as knowledge. We do not listen to user messages in the Slack app for two-way chat.
Limited use: We do not sell Slack data. We do not use Slack data for advertising. We do not use Slack messages or member directories to train public AI models. Slack data is used only to deliver the notifications the organization and user enabled, to keep the integration connected, and to provide support or security when necessary.
Revocation: A company administrator can disconnect Slack in Settings. A user can disconnect personal Slack DMs in Profile. Disconnecting revokes Kübi's authorization to post. Messages already posted remain in your Slack workspace under your Slack retention settings.
Privacy and data questions: hello@askkubi.com