Effective date: September 24, 2026 · Applies to CB File Hub on Windows, macOS, Linux, Android and iOS
CB File Hub ("the app", "we") is a file manager. This policy explains what information the app handles, where it goes, and the choices you have. We wrote it to be read, not skimmed past — the short version is below.
No account, no servers of our own. CB File Hub does not operate a backend that receives your data.
No analytics, no ads, no tracking. The app contains no advertising or analytics SDKs and does not sell or share personal data.
Your files stay on your device. Data leaves your device only when you turn on a feature that connects to a service you choose (cloud backup, a cloud AI provider, a network server).
Google Drive access is limited to the files and folder the app itself creates (drive.file scope).
1. Data stored on your device
To work, the app keeps the following information locally, in its own database and settings on your device. It is not sent to us.
App data: settings, tags, smart albums, favourites, recent locations, open tabs, search history and thumbnail caches.
Connection profiles: addresses, usernames and passwords for SMB, FTP, WebDAV, SFTP and SSH servers you add, and SSH keys you import or generate.
AI settings: API keys you enter for AI providers, and your CB Agent conversations.
Sign-in tokens for cloud backup providers, stored in your operating system's secure storage (Windows Credential Manager, macOS/iOS Keychain, Android Keystore, or the Linux secret service).
2. Cloud Backup & Sync
Backup & Sync is optional and off until you connect a provider. When you connect Google Drive, Dropbox or OneDrive:
You sign in on the provider's own page in your browser or through the system account picker. CB File Hub never sees your password.
The app uploads a backup archive (a .zip containing your CB File Hub settings and tags) to a folder named CB File Hub Backups in your own cloud storage, and can list, download and restore those archives. Your personal files are not uploaded by this feature.
The app reads your account name and email address only to show which account is connected.
Data travels directly between your device and the provider over HTTPS. It does not pass through any server of ours.
Provider
Permissions requested
Why
Google Drive
drive.file, openid, email
Create and read only the backup files the app creates; show the connected account.
Upload, list and download backup archives; show the connected account.
OneDrive
Files.ReadWrite, User.Read, offline_access
Upload, list and download backup archives; show the connected account; stay signed in.
You can disconnect a provider at any time in Settings → Backup & Sync, which deletes the stored tokens from your device. You can also revoke access from your account settings at Google, Dropbox or Microsoft.
3. Google user data
When you connect Google Drive, CB File Hub accesses:
your email address, used only to display the connected account in the app;
files and folders in your Google Drive that CB File Hub created (the backup folder and archives), used only to store, list and restore your backups.
This data is processed on your device only. It is not sent to us or to anyone else, not used for advertising, not used to train AI or machine-learning models, and not read by humans.
CB File Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. CB Agent (AI assistant)
CB Agent can run in two ways, and you choose which:
Local models: the model runs entirely on your device. Your prompts and files are not sent anywhere. Downloading a model fetches it from the source you pick (for example Hugging Face), which sees a normal download request.
Cloud AI providers (for example OpenAI, Anthropic, Google, OpenRouter, Mistral, Groq, DeepSeek or a custom endpoint): when you add your own API key and send a message, your message and any context the agent includes to answer it — such as file names, folder paths, file metadata, or file contents you ask it to read — are sent directly from your device to that provider. That provider's own privacy policy and terms apply to that data. We do not receive it.
Actions the agent proposes (such as moving or deleting files) run on your device, and destructive actions ask for your confirmation.
5. Network connections & streaming
Network servers: when you browse SMB, FTP, WebDAV, SFTP or SSH servers, the app connects directly to the addresses you enter, using the credentials you provide.
Media streaming and casting: to play a file on another device, the app can start a temporary media server on your local network that serves only the files you choose to play.
6. Device permissions (Android)
Storage and media access (including All files access): to browse, open, copy, move, rename and delete files — the core purpose of a file manager.
Media location: to show photo location details stored in images you view. This stays on your device.
Network and Wi-Fi state, Internet: for network browsing, streaming, cloud backup and cloud AI providers.
Notifications, foreground service, wake lock: to keep media playing and show progress of long operations.
Install packages: to let you open an APK file you select with the system installer.
Phone state: CB File Hub does not use this to read or collect your phone number, call details or device identifiers.
Permissions are requested when a feature needs them, and you can withdraw them in your system settings.
7. Third-party services
Services you connect — cloud storage providers, AI providers, model hosts, and network servers — process data under their own policies. App stores (Microsoft Store, Google Play, Apple App Store) may collect installation and crash diagnostics under their own policies and your device settings; we only see aggregated statistics those stores provide.
8. Sharing & selling
We do not sell, rent or share your personal data, and we do not use it for advertising. Data reaches a third party only when you connect that party yourself, as described above.
9. Retention & deletion
Local data stays on your device until you delete it in the app, clear the app's data, or uninstall the app.
Backup archives stay in your cloud storage until you delete them there — they are your files.
Disconnecting a provider removes its tokens from your device immediately.
Because we hold no copy of your data, there is nothing for us to delete on a server; everything is under your control.
10. Security
Sign-in uses OAuth 2.0 with PKCE; tokens are kept in the operating system's secure storage; connections to cloud and AI providers use HTTPS. No method of storage or transmission is perfectly secure, so keep your device and accounts protected.
11. Children
CB File Hub is a general-purpose utility and is not directed at children under 13. We do not knowingly collect personal information from children.
12. Changes & contact
If this policy changes, we will update this page and its effective date. Significant changes will be noted in the app's release notes.
Ngày hiệu lực: 24/09/2026 · Áp dụng cho CB File Hub trên Windows, macOS, Linux, Android và iOS
CB File Hub ("ứng dụng", "chúng tôi") là một trình quản lý tệp. Chính sách này giải thích ứng dụng xử lý những thông tin nào, gửi chúng đi đâu và bạn có những lựa chọn gì. Bản tóm tắt ở ngay bên dưới.
Không tài khoản, không máy chủ riêng. CB File Hub không vận hành máy chủ nào để nhận dữ liệu của bạn.
Không phân tích, không quảng cáo, không theo dõi. Ứng dụng không chứa SDK quảng cáo hay phân tích, và không bán hay chia sẻ dữ liệu cá nhân.
Tệp của bạn ở trên thiết bị của bạn. Dữ liệu chỉ rời khỏi thiết bị khi bạn bật một tính năng kết nối tới dịch vụ do bạn chọn (sao lưu đám mây, nhà cung cấp AI, máy chủ mạng).
Quyền truy cập Google Drive bị giới hạn ở các tệp và thư mục do chính ứng dụng tạo ra (phạm vi drive.file).
1. Dữ liệu lưu trên thiết bị
Để hoạt động, ứng dụng lưu các thông tin sau ngay trên thiết bị của bạn, trong cơ sở dữ liệu và phần cài đặt của ứng dụng. Chúng không được gửi cho chúng tôi.
Dữ liệu ứng dụng: cài đặt, thẻ (tag), album thông minh, mục yêu thích, vị trí gần đây, các tab đang mở, lịch sử tìm kiếm và bộ nhớ đệm ảnh thu nhỏ.
Hồ sơ kết nối: địa chỉ, tên người dùng và mật khẩu của các máy chủ SMB, FTP, WebDAV, SFTP, SSH mà bạn thêm, cùng các khoá SSH bạn nhập hoặc tạo.
Cài đặt AI: khoá API bạn nhập cho các nhà cung cấp AI và các cuộc trò chuyện với CB Agent.
Token đăng nhập của nhà cung cấp sao lưu, được lưu trong kho bảo mật của hệ điều hành (Windows Credential Manager, macOS/iOS Keychain, Android Keystore hoặc Linux secret service).
2. Sao lưu & đồng bộ đám mây
Tính năng này là tuỳ chọn và chỉ hoạt động khi bạn kết nối một nhà cung cấp. Khi bạn kết nối Google Drive, Dropbox hoặc OneDrive:
Bạn đăng nhập trên trang của chính nhà cung cấp trong trình duyệt hoặc qua trình chọn tài khoản của hệ thống. CB File Hub không bao giờ thấy mật khẩu của bạn.
Ứng dụng tải một tệp sao lưu (.zip chứa cài đặt và thẻ của CB File Hub) lên thư mục CB File Hub Backups trong bộ nhớ đám mây của bạn, đồng thời có thể liệt kê, tải về và khôi phục các bản sao lưu đó. Tính năng này không tải tệp cá nhân của bạn lên.
Ứng dụng chỉ đọc tên và địa chỉ email tài khoản để hiển thị tài khoản nào đang được kết nối.
Dữ liệu truyền trực tiếp giữa thiết bị của bạn và nhà cung cấp qua HTTPS, không đi qua máy chủ nào của chúng tôi.
Nhà cung cấp
Quyền yêu cầu
Mục đích
Google Drive
drive.file, openid, email
Chỉ tạo và đọc các tệp sao lưu do ứng dụng tạo; hiển thị tài khoản đã kết nối.
Tải lên, liệt kê và tải về bản sao lưu; hiển thị tài khoản đã kết nối.
OneDrive
Files.ReadWrite, User.Read, offline_access
Tải lên, liệt kê và tải về bản sao lưu; hiển thị tài khoản; duy trì đăng nhập.
Bạn có thể ngắt kết nối bất cứ lúc nào tại Cài đặt → Sao lưu & Đồng bộ; thao tác này xoá token khỏi thiết bị. Bạn cũng có thể thu hồi quyền trong cài đặt tài khoản tại Google, Dropbox hoặc Microsoft.
3. Dữ liệu người dùng Google
Khi bạn kết nối Google Drive, CB File Hub truy cập:
địa chỉ email, chỉ dùng để hiển thị tài khoản đã kết nối trong ứng dụng;
các tệp và thư mục trong Google Drive do CB File Hub tạo ra (thư mục và tệp sao lưu), chỉ dùng để lưu, liệt kê và khôi phục bản sao lưu.
Dữ liệu này chỉ được xử lý trên thiết bị của bạn. Nó không được gửi cho chúng tôi hay bất kỳ ai khác, không dùng cho quảng cáo, không dùng để huấn luyện mô hình AI/học máy và không bị con người đọc.
Việc CB File Hub sử dụng và chuyển giao sang ứng dụng khác thông tin nhận được từ Google API sẽ tuân thủ Chính sách dữ liệu người dùng của Google API Services, bao gồm các yêu cầu về Sử dụng giới hạn (Limited Use).
4. CB Agent (trợ lý AI)
CB Agent có thể chạy theo hai cách, do bạn chọn:
Mô hình cục bộ: mô hình chạy hoàn toàn trên thiết bị. Câu lệnh và tệp của bạn không được gửi đi đâu. Khi tải mô hình, ứng dụng tải từ nguồn bạn chọn (ví dụ Hugging Face), nơi đó chỉ thấy một yêu cầu tải xuống thông thường.
Nhà cung cấp AI đám mây (ví dụ OpenAI, Anthropic, Google, OpenRouter, Mistral, Groq, DeepSeek hoặc endpoint tuỳ chỉnh): khi bạn thêm khoá API của riêng mình và gửi tin nhắn, tin nhắn cùng ngữ cảnh mà trợ lý đưa vào để trả lời — như tên tệp, đường dẫn thư mục, siêu dữ liệu, hoặc nội dung tệp bạn yêu cầu đọc — được gửi trực tiếp từ thiết bị tới nhà cung cấp đó. Chính sách quyền riêng tư và điều khoản của nhà cung cấp đó áp dụng cho dữ liệu này. Chúng tôi không nhận được dữ liệu đó.
Các hành động trợ lý đề xuất (như di chuyển hoặc xoá tệp) chạy trên thiết bị của bạn, và các hành động có tính phá huỷ đều yêu cầu bạn xác nhận.
5. Kết nối mạng & phát trực tuyến
Máy chủ mạng: khi duyệt máy chủ SMB, FTP, WebDAV, SFTP hoặc SSH, ứng dụng kết nối trực tiếp tới địa chỉ bạn nhập, bằng thông tin đăng nhập bạn cung cấp.
Phát và truyền media: để phát tệp trên thiết bị khác, ứng dụng có thể mở một máy chủ media tạm thời trong mạng nội bộ, chỉ phục vụ những tệp bạn chọn phát.
6. Quyền trên thiết bị (Android)
Truy cập bộ nhớ và media (bao gồm quyền truy cập mọi tệp): để duyệt, mở, sao chép, di chuyển, đổi tên và xoá tệp — chức năng cốt lõi của trình quản lý tệp.
Vị trí trong media: để hiển thị thông tin vị trí được lưu trong ảnh bạn xem. Thông tin này ở lại trên thiết bị.
Trạng thái mạng, Wi-Fi, Internet: cho duyệt mạng, phát trực tuyến, sao lưu đám mây và nhà cung cấp AI đám mây.
Thông báo, dịch vụ nền, giữ màn hình/CPU: để tiếp tục phát media và hiển thị tiến trình các thao tác dài.
Cài đặt gói: để bạn mở tệp APK đã chọn bằng trình cài đặt của hệ thống.
Trạng thái điện thoại: CB File Hub không dùng quyền này để đọc hay thu thập số điện thoại, thông tin cuộc gọi hoặc mã định danh thiết bị.
Quyền chỉ được yêu cầu khi tính năng cần đến, và bạn có thể thu hồi trong cài đặt hệ thống.
7. Dịch vụ bên thứ ba
Các dịch vụ bạn kết nối — nhà cung cấp lưu trữ đám mây, nhà cung cấp AI, nơi lưu trữ mô hình và máy chủ mạng — xử lý dữ liệu theo chính sách riêng của họ. Các cửa hàng ứng dụng (Microsoft Store, Google Play, Apple App Store) có thể thu thập dữ liệu cài đặt và báo cáo lỗi theo chính sách của họ và cài đặt thiết bị của bạn; chúng tôi chỉ thấy số liệu thống kê tổng hợp mà các cửa hàng cung cấp.
8. Chia sẻ & mua bán dữ liệu
Chúng tôi không bán, cho thuê hay chia sẻ dữ liệu cá nhân của bạn và không dùng nó cho quảng cáo. Dữ liệu chỉ đến bên thứ ba khi chính bạn kết nối với bên đó, như mô tả ở trên.
9. Lưu giữ & xoá dữ liệu
Dữ liệu cục bộ ở trên thiết bị cho tới khi bạn xoá trong ứng dụng, xoá dữ liệu ứng dụng hoặc gỡ cài đặt.
Tệp sao lưu nằm trong bộ nhớ đám mây của bạn cho tới khi bạn xoá chúng ở đó — đó là tệp của bạn.
Ngắt kết nối một nhà cung cấp sẽ xoá token của nhà cung cấp đó khỏi thiết bị ngay lập tức.
Vì chúng tôi không giữ bản sao dữ liệu nào của bạn, không có gì trên máy chủ để xoá; mọi thứ đều do bạn kiểm soát.
10. Bảo mật
Đăng nhập dùng OAuth 2.0 với PKCE; token được giữ trong kho bảo mật của hệ điều hành; kết nối tới nhà cung cấp đám mây và AI dùng HTTPS. Không phương thức lưu trữ hay truyền tải nào an toàn tuyệt đối, vì vậy hãy bảo vệ thiết bị và tài khoản của bạn.
11. Trẻ em
CB File Hub là tiện ích đa năng và không hướng tới trẻ em dưới 13 tuổi. Chúng tôi không cố ý thu thập thông tin cá nhân của trẻ em.
12. Thay đổi & liên hệ
Nếu chính sách thay đổi, chúng tôi sẽ cập nhật trang này và ngày hiệu lực. Thay đổi quan trọng sẽ được ghi trong ghi chú phát hành của ứng dụng.