Cubbie Privacy Policy

Effective:
May 7, 2026
Last updated:
September 22, 2026

The short version. The full text below is what governs.

  • We do not sell your data Cubbie does not sell personal information for money, and connecting your stack does not put it in front of vendors looking to pitch you. Some analytics and ad cookies still count as sharing under state law; opt out by emailing [email protected].
  • No AI training on your content Model providers are not permitted to train their foundation models on buyer content. We do store AI inputs and outputs, and we use your content to run and improve the Service, including aggregated, de-identified analytics.
  • Bank connections are read-only Connect a bank or card and Cubbie reads the transaction history through Plaid to find recurring software charges. Only those are saved. The rest is discarded when the scan ends, and for these connections we never store balances, account numbers, or raw transactions. Disconnect and the subscriptions detected from your bank go with it. Vendors who add a payout account are the exception: those account details are stored encrypted so payouts can be sent.
  • Who else touches your data Hosting, payments, email, analytics, error monitoring, and AI run through outside companies under written contracts that limit what they may do with personal information. Those that handle data we process for business customers are named in our Data Processing Addendum.
  • What a vendor sees Place an order and that vendor receives your company name, contact, and order details. Record a vendor’s product in your account and we may tell that vendor your company uses it. Sharing beyond that happens for legal process, a transfer to a company Rei Llazani forms or an acquisition of Cubbie, limited business contact details shared with other organizations Rei runs, or when you direct it.
  • Cookies are on by default Essential and analytics cookies, including Google Analytics, load for every visitor. There is no consent banner; you turn them off in your browser settings or with Google’s opt-out add-on.
  • Export or delete anytime Account settings has self-service data export and deletion. Transaction and tax records stay for seven years and audit logs for at least one year regardless.
This policy explains what personal information Cubbie collects, why, who we share it with, how long we keep it, and the rights you have. If you process personal data through Cubbie on behalf of others (for example, an enterprise managing employee subscription data), our Data Processing Addendum applies in addition to this policy.

1. Who we are

Cubbie is operated by Rei Llazani, an individual, and is not yet incorporated. In this policy, “Cubbie,” “we,” and “us” mean Rei Llazani as the operator of Cubbie. Rei plans to form a company in October 2026 to operate Cubbie. At that point Cubbie, this policy, your account, and the personal information we hold may be transferred to that company, with notice to you. You can reach us at [email protected]. For most personal information described in this policy, we act as the controller. For personal information processed on behalf of business customers (e.g., subscription data uploaded by an enterprise about its employees), we act as processor for that customer; the relevant DPA governs.

2. Information we collect

2.1 Information you give us

  • Account & profile. Name, email address, phone (optional), employer / organization, job title, profile photo, time zone, and authentication identifiers.
  • Identity verification and payout details. For Vendors who set up payouts: business verification details (legal entity, beneficial ownership) and tax forms (e.g., W-9 / W-8) where we request them, and the bank account details you enter or link through Plaid, which we store encrypted. Vendors who connect Stripe give their details to Stripe directly.
  • Commercial information. Orders, contracts, refunds, disputes, credits, payouts.
  • Buyer-supplied data. Subscription registry entries, owner / cancellation contact emails, contracts you upload, RFP content, vendor relationship notes.
  • Reviews & product feedback. Ratings, written reviews, structured pros / cons / use case fields.
  • Communications. Emails, support tickets, in-product chat, and survey responses.

2.2 Information we collect automatically

  • Device & log data. IP address, browser, operating system, device type, referrer, pages viewed, timestamps, and approximate location derived from IP.
  • Usage events. Clicks, searches, navigation, feature interactions, and outcome states (e.g., onboarding milestones).
  • Cookies & similar technologies. Identifiers stored in cookies, localStorage, or tags. See Section 9.
  • Performance & reliability. Real User Monitoring (Web Vitals: LCP, INP, CLS), error reports, slow-query logs, and rate-limit events.

2.3 Information from third parties

  • Identity providers. If you sign in with Google, Microsoft, Okta, JumpCloud, or another IdP we support, we receive the profile fields you authorize and group / role data when applicable.
  • Connected systems. If you connect billing, accounting, or spend platforms (e.g., Stripe, NetSuite, QuickBooks, Brex, Ramp), we receive the data scopes you authorize.
  • Bank and card connections. If you connect a business bank account or card through Plaid, we receive read-only transaction history for the accounts you authorize, and retain only the recurring software charges detected from it. See Section 5.
  • Payment processors. Stripe (and any successor) processes card and bank details; we receive transaction metadata, tokenized identifiers, and risk signals, not full card numbers.
  • Public sources & data partners. Vendor catalog data (including data gathered by automated crawling of publicly available vendor websites, and we respect robots.txt), company firmographics, security and compliance signals, and public review data.

3. How we use information

We use information for the following purposes and on the legal bases shown:

PurposeExamplesLegal basis (GDPR)
Provide and operate the ServiceAccount creation, checkout, subscription management, search, AI advisorContract; legitimate interests
Improve and personalizeRecommendations, ranking, A/B tests, analyticsLegitimate interests; consent (where required)
Security and fraud preventionAuth, abuse detection, dispute review, audit loggingLegitimate interests; legal obligation
Compliance and reportingKYB / AML, tax (1099, sales / VAT), audit retentionLegal obligation
Marketing and communicationsLifecycle emails, surveys, transactional noticesConsent (marketing); legitimate interests (transactional)
Customer supportTickets, escalations, account changesContract; legitimate interests

4. AI processing

Our AI advisor and other AI features process inputs and produce outputs using third-party foundation models (currently including Anthropic’s Claude family). We:

  • Send only the inputs needed for the requested feature.
  • Strip or redact obvious secrets where feasible (e.g., tokens, keys).
  • Do not permit model providers to use Buyer Content to train their foundation models. Our providers process API inputs without training on them by default, and we do not enroll Buyer Content in any training program.
  • Apply per-organization budget caps to limit cost, scope, and abuse.
  • Log inputs, outputs, and metadata for security, debugging, abuse review, and audit.

4.1 Google API data (Google Workspace and Gmail): Limited Use

When you connect Google Workspace to Cubbie, we access only the directory and usage data you authorize (for example, your organization’s users, license/seat counts, and aggregate usage reports) for the sole purpose of providing the features you requested: surfacing your software stack and generating seat-rightsizing recommendations. When you connect a billing mailbox through the Gmail API, we read only the vendor invoice, receipt, and renewal messages needed to surface those subscriptions and reminders to you; we never send mail on your behalf. To identify the vendor, amount, and renewal date, the sender, subject, and a short excerpt of each matching message, together with the connected mailbox address, are processed by our AI inference provider (Anthropic) solely to provide this feature, and are not used to train generalized AI models. Cubbie’s use and transfer to any other app of information received from Google APIs (including Google Workspace APIs and the Gmail API) will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We use Google Workspace and Gmail data only to provide and improve the user-facing features you authorized, and never for advertising.
  • We do not use Google Workspace or Gmail data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
  • We do not sell Google Workspace or Gmail data, and we do not transfer it to others except as necessary to provide or improve the user-facing feature, to comply with applicable law, or as part of a merger or acquisition with notice as required.
  • We do not allow humans to read Google Workspace or Gmail data unless we have your affirmative agreement for specific data, it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or the data has been aggregated and anonymized and is used for internal operations.

5. Bank and card connections

Buyers may connect a business bank account or company card so Cubbie can detect the software subscriptions being paid for. This section describes how that connection works and what Cubbie does with the data it returns.

5.1 What we access

Bank connections run through Plaid Inc. You enter your bank credentials with Plaid, not with Cubbie; we never receive or store them. Plaid returns a read-only access token, which Cubbie uses to request transaction history for the accounts you authorize, going back up to 730 days. For these connections we request only Plaid’s Transactions product: Cubbie cannot move money, initiate payments, or change anything at your bank. Vendors who link a payout account through Plaid use Plaid’s Auth product instead, which gives us that account’s account and routing numbers so payouts can be sent to it.

Recurring charges can only be identified against the full history, so a scan reads the transactions on those accounts rather than a pre-filtered subset. Charges unrelated to software are read in the course of a scan and are not retained; Section 5.2 sets out exactly what is kept.

5.2 What we keep, and what we discard

Only the recurring software subscriptions our detector identifies are written to your Account. For each one we store the vendor name, amount, billing cadence, first and last charge dates, month-by-month totals, an inferred renewal date, and a small number of Plaid transaction identifiers kept as provenance. Where you dismiss a detection as incorrect, we retain that merchant name so the same entry is not re-imported.

For these connections, we do not store your raw transaction history, account or routing numbers, or account balances. Transactions that are not identified as software subscriptions exist only in memory for the duration of a scan and are discarded when it finishes. They are never written to our database, never used to build a profile of your spending, and never shared with vendors. Payout accounts that Vendors add are different: their account and routing numbers are stored encrypted, as described in Section 2.1, and used only to send payouts.

5.3 Security, retention, and disconnecting

  • Plaid access tokens are encrypted at rest with AES-256-GCM under a key held outside the database.
  • Each scan re-requests data from Plaid rather than reading a stored copy, so there is no accumulating archive of your transactions on our side.
  • You can disconnect any connected account from your dashboard at any time. Disconnecting revokes the token at Plaid.
  • When you disconnect your last connected account, the subscriptions and pending detections that came from bank data are deleted from your Account.
  • Subscription records you keep, edit, or confirm are retained under Section 8 like any other registry entry.

5.4 Plaid’s own handling of your data

Plaid processes your bank data under its own agreement with you, and its practices are described in Plaid’s End User Privacy Policy. Requests to Plaid about the data it holds, including deletion, are made to Plaid directly through my.plaid.com. Disconnecting in Cubbie revokes our access; it does not by itself erase records Plaid keeps as a controller.

6. How we share information

We share information in the following situations:

  • Vendors and Buyers. Information necessary to complete transactions (e.g., a Vendor sees the company name, contact, and order details for a Buyer who places an Order).
  • Vendors whose products your company uses. When your organization records a vendor’s product in its Cubbie account, we may tell that vendor that your company uses it, including the name of the team member who recorded it.
  • Service providers (sub-processors). Hosting, payment processing, email delivery, analytics, AI inference, observability, e-signature, and similar service providers, all under written contracts that limit their use of personal information.
  • Other organizations run by Cubbie’s founder. Rei Llazani also runs other businesses and organizations. We may share limited business contact information with them, for example so the same person is not contacted too often, and only in ways consistent with this policy.
  • Legal and safety. Where required by law, valid legal process, or to protect rights, safety, and property of Cubbie or others.
  • Business transfers. To a company Rei Llazani forms to operate Cubbie, or in connection with a merger, acquisition, financing, or sale of assets, with notice to you.
  • With your consent. Any other sharing you direct or authorize.

We do not sell personal information for monetary consideration. Some routine analytics or advertising vendor cookies may qualify as “sharing” or “selling” under certain U.S. state laws (e.g., the California Consumer Privacy Act as amended by CPRA); you can opt out by emailing [email protected] or by using the browser-level cookie controls described in Section 9.

7. International data transfers

Cubbie is based in the United States. If you access the Service from outside the U.S., your personal information will be transferred to and processed in the U.S. and other countries where our service providers operate. For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (and the U.K. Addendum / Swiss equivalents where applicable), and apply additional technical and organizational measures where transfer impact assessments indicate they are warranted.

8. Retention

We retain personal information only as long as needed for the purposes described in this policy and to comply with our legal, accounting, and reporting obligations. Specific retention windows include:

  • Account records: for the life of the Account plus a reasonable wind-down window after closure.
  • Transaction and tax records: seven (7) years to satisfy financial and tax-reporting obligations.
  • Audit logs: at least one (1) year, longer where required for compliance.
  • Marketing preferences and opt-out lists: retained as long as you remain on or off lists.
  • Backups: rotated according to our backup policy and overwritten in due course.

9. Cookies and tracking

We use cookies and similar technologies in the following categories. Essential and analytics cookies (including Google Analytics) are set by default for all visitors; we do not currently display a cookie consent banner. You can manage or block cookies through your browser settings, use Google's Analytics opt-out browser add-on, and manage notification and communication preferences from your account settings when signed in. Disabling cookies may degrade some features.

CategoryPurposeExamples
Strictly necessaryAuthentication, session, security, load balancingSession cookies, CSRF tokens
FunctionalRemember preferences (locale, theme, dismissed banners)Locale cookies, dismissal flags
AnalyticsUsage measurement and improvementInternal RUM beacons; Google Analytics (when enabled)
AdvertisingAd attribution where you have opted inLinkedIn Insight Tag (when enabled)

10. Your rights

Depending on where you live, you may have the rights described below. To exercise a right, sign in to your Account and use the data export / deletion tools, or contact us at [email protected]. We may verify your identity before responding and will respond within the time required by law.

10.1 EEA, U.K., and Switzerland

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (subject to legal retention requirements).
  • Restrict or object to processing based on legitimate interests.
  • Data portability for data you provided.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with your supervisory authority.

10.2 California (CCPA / CPRA)

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share.
  • Delete personal information, subject to exceptions.
  • Correct inaccurate personal information.
  • Limit use of sensitive personal information.
  • Opt out of sale or sharing: exercise by emailing us or via browser-level cookie controls (Section 9).
  • Non-discrimination for exercising rights.

We have not knowingly sold personal information of California consumers under 16 in the preceding 12 months.

10.3 Other U.S. state laws

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comparable laws have similar rights. We provide the same controls used for CCPA requests to residents of those states.

11. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact [email protected].

12. Security

We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS) and at rest, access controls, audit logging, role-based permissions, secret-rotation tooling, and a tamper-evident audit chain for sensitive records. No system is perfectly secure; if you believe your Account has been compromised, contact [email protected].

13. Marketing communications

We send transactional emails (e.g., receipts, password resets, security alerts) without marketing-opt-in because they are necessary to operate the Service. For marketing emails, we rely on your consent or our legitimate interest as permitted by law and offer an unsubscribe link in every message. You can also manage preferences in your Account settings.

14. Third-party links

The Service may link to third-party websites and applications. We are not responsible for the privacy practices of those third parties. Review their privacy policies before providing personal information.

15. Changes to this policy

We may update this policy from time to time. If a change is material, we will provide reasonable advance notice (such as by email or in-product notice). The “Last updated” date at the top of this policy reflects the most recent changes.

16. Contact us

Questions, requests, and complaints can be sent to [email protected]. For data processing on behalf of business customers, see our Data Processing Addendum. EEA and U.K. residents can reach us at the same address.

© 2026 Cubbie. All rights reserved.