Privacy Policy for FileBird Cloud

Privacy Policy for FileBird Cloud

Effective Date: November 8, 2024
Last Updated: June 23, 2026

1. Introduction

NinjaTeam (“NinjaTeam”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how the FileBird Cloud plugin (“FileBird Cloud” or the “Plugin”) collects, uses, stores, and protects information when you connect your Google Drive account to your WordPress website.

FileBird Cloud is a WordPress plugin that enables website owners to connect their Google Drive account to their WordPress website and import media files from Google Drive into the WordPress Media Library using Google’s OAuth authentication and Google Drive API.

By using FileBird Cloud, you acknowledge that you have read and understood this Privacy Policy.


2. Information We Access

FileBird Cloud requires access to certain Google Drive information solely to provide the functionality requested by the user.

The Plugin may access:

  • Google account authentication information necessary to establish and maintain an authorized connection.
  • Information about files and folders within the user’s Google Drive account necessary to allow browsing and selection of content for import.
  • Authentication tokens issued by Google to maintain the authorized connection between the user’s WordPress website and Google Drive.

No Collection or Storage of Google Drive Content

NinjaTeam does not collect, store, retain, analyze, monitor, share, sell, or otherwise process the contents of users’ Google Drive accounts.

Specifically, NinjaTeam does not collect or store:

  • Files
  • Documents
  • Images
  • Videos
  • Audio files
  • Folders
  • File contents
  • File metadata beyond what is temporarily required for functionality
  • Any other content stored in Google Drive

Google Drive content is transferred directly between:

  1. The user’s Google Drive account; and
  2. The user’s own WordPress website.

NinjaTeam’s servers do not permanently store, host, archive, or retain Google Drive content.


3. User Authorization and Consent

Access to Google Drive is granted only after explicit user authorization through Google’s OAuth consent process.

Before FileBird Cloud can access any Google Drive data:

  1. The user must initiate the connection process.
  2. Google presents an OAuth consent screen describing the requested permissions.
  3. The user must explicitly approve the requested permissions.
  4. Google issues authorization credentials that enable the connection.

No access to Google Drive occurs without the user’s knowledge and affirmative consent.

Users may revoke authorization at any time through their Google Account settings or by disconnecting the Plugin.


4. How Google Drive Data Is Used

FileBird Cloud uses authorized Google Drive access solely to provide the functionality requested by the user.

Google Drive data is used only to:

  • Display Google Drive files and folders within WordPress.
  • Allow users to browse their Google Drive content.
  • Enable users to select files for import.
  • Import selected files into the WordPress Media Library.
  • Maintain the authenticated connection between WordPress and Google Drive.
  • Support technical functionality necessary for Plugin operation.

Google Drive data is not used for:

  • Advertising
  • Marketing
  • Behavioral profiling
  • Data mining
  • AI model training
  • Machine learning training datasets
  • Sale of user data
  • User tracking unrelated to Plugin functionality
  • Analytics unrelated to providing the requested service

FileBird Cloud accesses only the information necessary to perform the functions explicitly requested by the user.


5. Data Storage and Retention

Imported Files

When a user chooses to import a file from Google Drive:

  • The selected file is copied to the user’s WordPress website.
  • The imported file becomes part of the WordPress Media Library.
  • The file is stored on the user’s hosting environment or infrastructure.
  • NinjaTeam does not host or store imported files.

Authentication Tokens

To maintain the authorized connection between Google Drive and WordPress, authentication credentials such as access tokens and refresh tokens may be stored on the user’s WordPress website.

These credentials are used solely for:

  • Maintaining the authenticated connection.
  • Facilitating authorized requests to Google APIs.
  • Providing the functionality requested by the user.

Authentication credentials are not used for any unrelated purpose.

Retention

Authentication data is retained only for as long as necessary to maintain the authorized connection or until:

  • The user disconnects the Plugin;
  • The user revokes Google authorization;
  • The user deletes the Plugin; or
  • The credentials expire or become invalid.

6. Google API Services User Data Policy Compliance

FileBird Cloud’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • Google user data is accessed solely to provide and improve the user-requested functionality of the Plugin.
  • Google user data is not sold to any third party.
  • Google user data is not used for advertising purposes.
  • Google user data is not used to create advertising profiles.
  • Google user data is not used for data brokerage purposes.
  • Google user data is not used for AI model training or machine learning model development.
  • Google user data is not transferred to third parties except where necessary to provide the user-requested service or where required by law.
  • Access to Google user data is limited to what is necessary to provide the functionality explicitly requested by the user.

The use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


7. Third-Party Services

FileBird Cloud relies on third-party services provided by Google.

Google OAuth

Google OAuth is used to authenticate users and obtain authorization to access Google Drive resources.

Google Drive API

The Google Drive API is used to:

  • Display Google Drive files and folders.
  • Retrieve information necessary for browsing.
  • Facilitate the import of user-selected files into WordPress.

Use of Google services is subject to Google’s own policies and agreements, including:

  • Google Privacy Policy
  • Google Terms of Service
  • Google API Services User Data Policy

Users are encouraged to review Google’s policies to understand how Google processes information.


8. Security Measures

NinjaTeam implements reasonable technical and organizational safeguards designed to protect authentication credentials and authorized access.

These measures may include:

  • Secure communication using HTTPS/TLS encryption.
  • Access controls designed to prevent unauthorized access.
  • Secure handling of authentication tokens.
  • Data minimization practices.
  • Regular maintenance and security updates.
  • Limiting access to information necessary for Plugin functionality.

While no method of transmission or storage can be guaranteed to be completely secure, NinjaTeam takes commercially reasonable measures to protect authorized access and authentication data.


9. User Rights and Controls

Users maintain control over their Google Drive connection and imported content.

Revoking Google Access

Users may revoke FileBird Cloud’s access to Google Drive at any time through their Google Account permissions settings.

Disconnecting the Plugin

Users may disconnect Google Drive from WordPress through the Plugin settings.

Once disconnected, the Plugin can no longer access Google Drive unless authorization is granted again.

Removing Imported Files

Users may delete imported files from their WordPress Media Library at any time using WordPress administrative tools.

Access and Correction

Where applicable under relevant privacy laws, users may request access to information concerning the processing of their personal data and may request correction of inaccurate information.


10. GDPR and International Privacy Compliance

For users located in the European Economic Area (EEA), United Kingdom, Switzerland, and other jurisdictions with similar privacy laws, NinjaTeam processes personal data in accordance with applicable legal requirements.

Lawful Basis for Processing

Where applicable, processing is based on one or more of the following legal grounds:

  • User consent;
  • Performance of a contract or requested service;
  • Compliance with legal obligations;
  • Legitimate interests in providing and securing the Plugin.

Data Minimization

FileBird Cloud accesses only the minimum amount of information necessary to provide the requested functionality.

Purpose Limitation

Information obtained through Google APIs is used exclusively for the purposes described in this Privacy Policy and is not repurposed for unrelated activities.

User Rights

Subject to applicable law, users may have rights including:

  • Right of access;
  • Right to rectification;
  • Right to erasure;
  • Right to restrict processing;
  • Right to data portability;
  • Right to object to processing;
  • Right to withdraw consent.

Requests regarding privacy rights may be submitted using the contact information provided below.


11. Children’s Privacy

FileBird Cloud is not directed to children and is not intended for use by individuals under the age required by applicable law to consent to data processing.

NinjaTeam does not knowingly collect personal information from children.


12. Changes to This Privacy Policy

NinjaTeam may update this Privacy Policy from time to time to reflect changes in legal requirements, Plugin functionality, or business practices.

Updated versions will be published on our website with a revised “Last Updated” date.

Continued use of FileBird Cloud after changes become effective constitutes acceptance of the revised Privacy Policy.


13. Contact Information

If you have questions about this Privacy Policy, Google Drive access, data handling practices, or your privacy rights, please contact:

NinjaTeam
Website: https://ninjateam.org

For privacy-related inquiries, please use the contact methods available on our website.


14. Google OAuth Verification Statement

FileBird Cloud is designed according to Google’s principles of transparency, user control, data minimization, and purpose limitation.

The Plugin:

  • Requires explicit user consent through Google’s OAuth authorization process.
  • Requests only the permissions necessary to provide its stated functionality.
  • Does not collect or store Google Drive content on NinjaTeam servers.
  • Does not sell, share, or monetize Google user data.
  • Does not use Google user data for advertising, profiling, analytics unrelated to Plugin functionality, or AI model training.
  • Allows users to revoke access at any time.
  • Uses Google user data solely to provide the functionality requested by the user.

NinjaTeam is committed to maintaining compliance with Google’s API requirements and applicable privacy regulations.