Effective date: August 18, 2026
This policy applies specifically to Cloud Recording Exporter. It does not automatically apply to other Nimbus Whale Labs products.
Information we process
After a Zoom user authorizes the app, we may process Zoom OAuth access and refresh tokens, Zoom account and user identifiers, granted scopes, meeting and recording identifiers, recording metadata, file types and sizes, transcript readiness, webhook event metadata, and destination configuration required to perform the requested export. We do not retain the Zoom profile email returned by the user-profile API.
When an export is enabled, recording and transcript content is processed for delivery to the storage destination selected by the user. Support communications may include the sender’s email address, issue description, and related diagnostic information.
Google user data
Cloud Recording Exporter requests only the Google Drive
drive.file permission. This limited permission lets the
app create and manage its Nimbus Whale Exports folder
and the files it uploads there. It does not permit Cloud Recording
Exporter to list or browse all files in your Google Drive.
When you connect Google Drive, we access and store an OAuth access token, refresh token, granted scope, and the identifier and name of the app-created export folder. We process file identifiers, basic metadata, and upload responses only for files the app creates. We do not read unrelated files from your Drive.
Google user data is used only to authenticate your connection, create or reuse the export folder, upload the Zoom recordings and transcripts you select, verify upload results, and refresh authorization while the connection remains active. It is not sold, used for advertising or profiling, or used to train general-purpose AI models.
Google OAuth tokens and folder identifiers are encrypted at rest and retained only while your Drive connection remains active. Using the Disconnect Google Drive control revokes the Google grant and deletes the locally stored connection credentials and configuration. Files already uploaded remain in your Google Drive under your control.
Cloud Recording Exporter’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How information is used
We use this information only to authenticate with Zoom, detect completed recordings and transcripts, transfer selected files, verify export results, provide operational support, prevent abuse, and comply with valid legal obligations. We do not sell personal information or use Zoom data for advertising, profiling, or training general-purpose AI models.
Sharing and subprocessors
Data is transmitted to Zoom and to the destination provider selected by the user, such as Google Drive, Amazon Web Services, or Microsoft Azure. We may use infrastructure providers necessary to host and secure the service. We do not disclose recording content to unrelated third parties.
Retention
OAuth tokens and operational installation metadata are retained while the app remains authorized. Sanitized event and export metadata may be retained while needed to operate, troubleshoot, and reconcile the authorized workflow. Cloud Recording Exporter is designed to stream recording content to the chosen destination rather than keep a separate content archive.
When Zoom confirms deauthorization, the matching Zoom access and refresh tokens are deleted and future exports stop. Files already transferred remain in the user-controlled destination. To prevent repeated introductory trials, a one-way hash derived from the Zoom user ID may be retained together with the trial date and related Stripe subscription reference for up to 365 days after a trial begins, including after Nimbus account deletion. The raw Zoom user ID and Zoom email are not stored in this trial ledger. Support requests are normally deleted within 30 days after resolution unless longer retention is required for security or legal reasons.
Security
Zoom and Google OAuth token sets are encrypted at rest using AES-256-GCM, private runtime files are restricted to the service account, traffic uses HTTPS, webhook signatures and timestamps are verified, and raw OAuth tokens and recording download URLs are excluded from event logs. See the Security Overview.
Your data-subject rights
Depending on your location and applicable law, you may have the right to request access to personal information we hold about you, correction of inaccurate information, deletion, restriction or objection to certain processing, data portability, and withdrawal of consent where processing is based on consent. You may also have the right to lodge a complaint with your local privacy or data-protection authority. These rights are subject to legal exceptions and may not apply in every circumstance.
To exercise a right, revoke authorization, request deletion, or ask for clarification, email [email protected] with the subject “Cloud Recording Exporter privacy request.” Tell us which right you are exercising and the Nimbus Whale account email associated with the request. We may ask for reasonable information to verify your identity before disclosing or deleting data. We will acknowledge the request, respond within the timeframe required by applicable law, and explain any lawful reason we cannot complete it.
You can revoke Cloud Recording Exporter from Zoom Marketplace, disconnect Google Drive from the dashboard, and revoke Google access from your Google Account’s third-party connections page. Destination files must be managed through the destination provider. See the connection and removal instructions.
Contact
Privacy requests may be sent to [email protected]. Do not include OAuth tokens, client secrets, webhook secrets, recording passcodes, or cloud-provider credentials.