Trust & Security

Last updated: August 6, 2026

Ush schedules meetings by reading the messages and calendar you connect. That is a significant thing to ask of a company, so this page sets out plainly what we do with that data, who else touches it, exactly which Google permissions we hold and why, and the agreement we will sign with you. It is written for the people who review suppliers — legal, security, and procurement — and everything on it is intended to be checkable.

If something you need is missing, email [email protected] and we will answer it directly.

How we protect your data

Encrypted in transit
TLS 1.2 and TLS 1.3 for all traffic between your browser and the Service, and for every call the Service makes to an upstream API. Weak cipher suites are refused.
Encrypted at rest
The entire database, every table and index, sits on AES-256 encrypted storage, as do backups. Nothing is stored on unencrypted disk.
Google credentials encrypted at the application layer
Your Google access and refresh tokens are encrypted with Fernet (AES-128-CBC with HMAC-SHA256) before they are stored, and are readable only by the components that call Google APIs on your behalf.
Strict separation between customers
Every database query is scoped to the account that owns the data. The separation is enforced in code rather than by convention, and is covered by tests that fail the build if data could cross between accounts.
Least-privilege Google permissions, verified at sign-in
We request the smallest set of Google permissions the product needs. At sign-in the granted permissions are checked against that set, and a grant that does not match is refused rather than stored.
Access control and audit
Role-based access on the principle of least privilege, with access logging. Support staff can act on an account only through a time-limited token whose every use is logged.
Independent annual assessment
The application is assessed each year against the Google Cloud Application Security Assessment (CASA) Tier 2 framework by an independent assessor.
Secure development and vulnerability management
Dependency monitoring, vulnerability management, and enforced security headers including a content security policy. Cross-site request forgery protection applies by default to every request that changes data in a signed-in session. It is not used in the two places where a session-bound token cannot exist and there is nothing for it to guard: the accountless sharing tools such as availability polls and leave boards, which are authorised by the unguessable link the recipient was sent and hold no mailbox or calendar data; and the inbound webhook from our Slack integration, where every request is authorised by a cryptographic signature check.
Your data is never used to train AI models
Neither we nor our AI provider use your mailbox or calendar content to train or improve any general-purpose AI model. This is a contractual restriction on the provider, not only our own policy.
Deletion on request
Delete your account or withdraw Google access and the associated data is deleted within thirty (30) days, and removed from backups as the thirty-day recovery window rotates.

Who else handles your data

These are the outside companies that process customer data on our behalf. Each is bound by a written agreement requiring confidentiality, security, and purpose limitation. We tell customers before we add or replace one.

Company What they do for us Where
Google Cloud (Alphabet Inc.) Hosting for the ush.team production environment on Compute Engine, together with networking and logging, and operation of the Gmail, Calendar and Maps Geocoding APIs and the OAuth sign-in that the Service calls on your behalf. Databases are PostgreSQL instances we run and administer ourselves on that infrastructure, not a Google-managed database service. As configured in our Google Cloud project; data may be processed in the United States and other regions where Google operates
Hetzner Online GmbH Hosting for the theush.uk environment, which runs the web application, the background worker and the PostgreSQL database holding the data described in Section 3, including encrypted Google credentials. Helsinki, Finland (European Union)
Cloudflare, Inc. Authoritative DNS, and TLS termination and reverse proxying for theush.uk. Because the encrypted connection from your browser ends at Cloudflare's network and a second one is opened to our server, Cloudflare processes the content of requests to that site in transit. It is not in the path for ush.team, which your browser connects to directly. Global edge network, including locations outside the United Kingdom and European Economic Area; Cloudflare, Inc. is established in the United States
OpenAI, L.L.C. (OpenAI API) Used to classify emails, extract scheduling intent, and draft replies. Inputs and outputs are processed under OpenAI's API data-usage policy, under which OpenAI does not use API inputs or outputs to train or improve its models. OpenAI retains API data for a limited period (currently up to thirty (30) days) for abuse and misuse monitoring and then deletes it, except where a longer retention is required by law. United States

Customer-support requests are handled over email using Google Workspace; we do not use a separate help-desk tool. This list is the same one published in Section 6 of our Privacy Policy, and both are rendered from one source so they cannot disagree.

The Google permissions we request, and why

Ush asks for 7 permissions on your Google account — no more. Each one below is used by the product; none is requested speculatively. The "smallest that works" column records the narrower permission we considered and why it was not enough, because asking for more than we need is the easiest way to lose your trust.

Permission Why we need it Smallest that works
Sign you in openid Required by Google's OpenID Connect flow to issue the identity token that proves you signed in. No narrower alternative exists; no data is read under this permission.
Your email address https://www.googleapis.com/auth/userinfo.email Identifies your account. It is also the key that keeps each customer's data separate from every other customer's. No narrower alternative exists.
Your name https://www.googleapis.com/auth/userinfo.profile Used as the sender display name on the reply drafts Ush prepares for you. No narrower alternative exists.
The list of your calendars https://www.googleapis.com/auth/calendar.readonly Read during setup only, so you can choose which calendar Ush should schedule against. The narrower events permission cannot list calendars, only read events on a calendar already known to us.
Read your email https://www.googleapis.com/auth/gmail.readonly To recognise which incoming messages are meeting requests and read the details needed to schedule them — who is asking, for when, where, and in which time zone. Headers-only access would not work: recognising a meeting request and reading its constraints requires the message body.
Read and write calendar events https://www.googleapis.com/auth/calendar.events To read your existing commitments so Ush proposes times you are actually free, and to place a tentative hold on a slot you pick so it is not double-booked while the other side confirms. Read-only access to events cannot place or remove the hold, which is the only reason write access is requested.
Prepare draft replies https://www.googleapis.com/auth/gmail.compose Ush writes a suggested reply into your Drafts folder for you to review. It never sends mail on your behalf. Deliberately narrower than the send permission: this one cannot send mail at all. There is no smaller permission that allows creating a draft.

You can withdraw these permissions at any time at https://myaccount.google.com/permissions. Once you do, we delete the associated Google data within thirty (30) days.

What we will never do with your data

  • We do not use your mailbox or calendar content to train or improve any general-purpose AI model, and our AI provider is contractually prohibited from doing so with data we send them.
  • We do not sell or rent your data, and we do not share it for advertising of any kind.
  • We do not send email on your behalf. Ush writes a draft; you review and send it.
  • Our people do not read your mailbox or calendar content, except with your explicit agreement on specific messages, where strictly necessary to investigate abuse or a security incident, or where the law requires it.
  • We do not use your data to build a product for anyone else. What Ush learns from your scheduling is applied to your account only.

Our handling of Google Workspace data complies with the Google API Services User Data Policy, including its Limited Use requirements.

Data processing agreement

For the mailbox and calendar content we handle, you are the controller of that data and Ush is your processor — we act on your instructions, not for our own purposes. Section 1 of our Privacy Policy sets out which role applies to which data.

That processing is governed by a written data processing agreement incorporating the terms required by Article 28(3) of the UK and EU GDPR. Under it:

  • We process customer data only on your documented instructions, and for no purpose of our own.
  • Everyone with access is bound by a duty of confidentiality.
  • We apply the security measures set out above, as required by Article 32.
  • We engage sub-processors only under written terms no less protective than those we owe you, we remain responsible for them, and we tell you before adding or replacing one.
  • We assist you in responding to requests from the people whose data it is.
  • We assist you with your own breach-notification and data-protection-impact-assessment obligations, and notify you of a breach without undue delay.
  • We delete or return customer data at the end of the contract.
  • We give you the information you need to demonstrate compliance, and submit to audit.
  • Transfers out of the UK and EEA rely on the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses.

To get the agreement in front of your legal team, email [email protected] with the subject line "DPA Request". We will send you our agreement to sign, or sign yours if your organisation prefers to use its own template — tell us which and we will work to whichever gets you cleared faster. If our agreement and our Privacy Policy ever conflict on customer data, the agreement prevails.

Company, contacts and reporting a vulnerability

  • Ush Technology Ltd, registered in England and Wales, company number 16376776.
  • Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
  • General and security-pack questions: [email protected].
  • Data processing agreements: [email protected], subject line "DPA Request".
  • Privacy and data-subject requests: [email protected], subject line "Privacy Request".
  • Reporting a security vulnerability: [email protected]. Our machine-readable contact is published at /.well-known/security.txt. We will acknowledge your report and keep you informed; please give us a reasonable opportunity to fix the issue before disclosing it publicly.

The full legal documents are our Privacy Policy and Terms of Service. This page summarises them for reviewers; where it and they differ, they govern.