1. Who we are
This site and the services described below are operated by Sroma Technologies ("we", "us", "our"). You can reach us at support@kukubots.com for any question about this policy or about data we hold.
2. What this policy covers
This policy covers two things:
- This website — kukubots.com, the public KukuBots marketing site.
- The KukuBots Reputation Engine — our review-management application, described at kukubots.com/reputation and used by invited business accounts at spa35.kukubots.com. This is the product that connects to Google Business Profile, and section 4 below is written for it.
It does not cover any third-party site we link to. Those sites have their own policies.
3. Information we collect
3.1 Website visitors
- Contact enquiries. If you submit the contact form, we receive your name, email address, phone number (optional), city or location, company name (optional), preferred contact method, and the message you type, so that we can reply. Each enquiry is delivered to us as a private notification message.
- Page-visit analytics. When the home page loads we record the page address and title, the referring URL, a timestamp, your browser's user-agent string and language, the size of the browser window, your time zone, and the IP address the request came from; when you leave it, we record the page address and time. This is sent to our own automation backend so we can see which pages are used; we do not use Google Analytics or any advertising network.
3.2 Reputation Engine users
Accounts are created by invitation only. For each user we store a name, an email address, a hashed password (we never store the password itself), a role, and sign-in timestamps. We also keep an audit record of actions taken in the application — who approved, edited, or published a reply, and when.
3.3 Google account data
Covered in full in the next section.
4. Google user data
The Reputation Engine connects to Google Business Profile so that a business can read and reply to its own Google reviews from one place. That connection is made by the business owner or an authorised manager, through Google's own consent screen, and can be withdrawn at any time.
4.1 The permission we request
We request a single scope,
https://www.googleapis.com/auth/business.manage. It is the only scope Google
offers for reading and replying to Business Profile reviews, and we request it solely for
that purpose. We do not request access to Gmail, Drive, Contacts, Calendar, Photos, or
any other Google service.
4.2 What we access
| Data | Why |
|---|---|
| Business account and location identifiers and names | To let you pick which of your locations to connect, and to address the right listing |
| Reviews on that location — reviewer display name, reviewer profile photo URL, star rating, review text, and timestamps | To show reviews in your inbox and to generate a suggested reply |
| Replies already published on those reviews | To show what has been answered and to avoid replying twice |
All of this is information that Google already displays publicly on the business listing.
4.3 What we write back
The only thing we ever write to Google is a reply to a review on the location you connected. A reply is published either because a user of your account approved it, or because it met auto-publish rules that an administrator of your account configured and can switch off at any time. We never post reviews, never edit your listing, and never act on any location you have not connected.
4.4 How it is stored
- Reviews, drafts, and published replies are stored in a PostgreSQL database on our hosting provider's server, reachable only over TLS.
- The OAuth access and refresh tokens Google issues are encrypted at rest before they are written to the database, using a key held outside the database. They are never logged and never displayed.
- Data is separated per account, and the application has no code path that lets one account read another account's rows.
4.5 Who we share it with
We do not sell Google user data, we do not use it for advertising, and we do not use it to train any general-purpose model. It is shared with exactly two categories of recipient:
- Our hosting provider, which stores the database and runs the application on our behalf.
- A third-party AI language-model provider, which receives the text of a review and your configured brand-voice settings for the single purpose of returning a suggested reply. It receives no tokens, no credentials, and no account data.
We will also disclose data if we are legally required to, and we will tell you unless we are prohibited from doing so.
4.6 Limited Use
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.7 Withdrawing access
You can disconnect the Google connection from inside the application at any time, which revokes our tokens. You can also revoke it directly from your Google Account at myaccount.google.com/permissions. Once revoked, we stop reading your reviews and stop publishing replies immediately. To have the review data we already hold deleted as well, email support@kukubots.com and we will delete it.
5. How we use information
- To operate the Reputation Engine: fetch reviews, draft replies, publish approved replies.
- To notify the right people when a review needs attention.
- To secure the service — authentication, rate limiting, and an audit trail.
- To answer enquiries you send us.
- To understand which pages of this website are used.
We do not sell personal information, and we do not run behavioural advertising.
6. Cookies
This marketing site sets no cookies. The Reputation Engine sets one essential cookie: an httpOnly session cookie used to keep you signed in. It is not used for tracking, and there are no advertising or cross-site cookies on either.
7. Security
- All traffic is served over HTTPS with HSTS.
- Passwords are hashed with Argon2 and are never recoverable in plain text.
- Google OAuth tokens are encrypted at rest.
- Access inside an account is role-based, and every change is recorded in an append-only audit log.
- Application containers run unprivileged with dropped capabilities, and the database is not exposed to the public internet.
No system is perfectly secure, but if a breach affects your data we will notify you promptly.
8. How long we keep it
Reviews, drafts, published replies, notifications, and audit records are retained for as long as the account is active, because they are the account's operating history. When an account is closed we delete its data within 30 days, except where we are required to keep records for longer by law. Contact-form enquiries are kept only as long as needed to handle them.
9. Your choices and rights
You can ask us to give you a copy of the personal information we hold about you, correct it, or delete it. Write to support@kukubots.com and we will respond within 30 days. If you are a user of a business account, note that the account's administrator also controls that account's data.
10. Children
Our services are for businesses. They are not directed at children, and we do not knowingly collect information from anyone under 18.
11. International transfers
Our servers and our service providers may be located in countries other than yours. Where data crosses a border, it does so under the protections our providers offer for such transfers.
12. Changes to this policy
If we change this policy we will update the effective date at the top of the page. If a change materially affects how we handle Google user data, we will notify account administrators by email before it takes effect.
13. Contact
Sroma Technologies — support@kukubots.com