Skip to content
HUHU API

HUHU API · Privacy

Privacy policy

Effective and last updated:

HUHU API provides a workspace for managing connected email accounts, proxy inventory and API workflows. This policy explains how the HUHU API administrator handles information through this service and its Huhu IAM sign-in service.

1. Information we process

When you sign in, we process your account identifier, display name, email address, authentication status and access permissions. Security and operational records may include your IP address, request time, requested path, task outcome and account activity.

If you use a connected service, we also process the data you import or ask us to retrieve: account details, connection credentials, proxy settings, mailbox addresses, aliases, messages, verification codes and task records. These features require separate account access or configuration.

2. Google sign-in

When Google sign-in is enabled and you choose it, Huhu IAM requests the openid, email and profile permissions. It receives your Google account identifier, name, email address and email verification status to verify your identity and associate it with an IAM account. HUHU API then receives the identity and permissions issued by IAM.

Google sign-in does not request Gmail message, contact, calendar or Drive access. It does not enable mailbox access in HUHU API. Google account passwords remain with Google.

We use Google identity information to provide sign-in, account identification, access control and security. We do not sell it, use it for advertising or credit decisions, or use it to train general-purpose AI models. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

3. How information is used and shared

We use information to authenticate users, display authorized account information, run requested workflows, return API results and diagnose failures. Authorized administrators can access data necessary to administer the service and handle support or security incidents.

Google processes Google sign-in; Huhu IAM processes authentication and account authorization. Our hosting and network-delivery providers, including Cloudflare, process traffic needed to deliver and protect the service. Connected email or proxy providers receive requests needed for the features you select. We do not send Google identity information to those providers to run unrelated mailbox or proxy operations.

Information may be disclosed when needed to comply with an applicable legal obligation or protect the service and its users. Data exports and any receive-code links you create can disclose the selected records to their recipients; keep these files and links private.

4. Storage and protection

Account, linked identity and operational records are stored on backend servers. Sensitive integration credentials use the backend's encrypted storage boundary, and access to protected records requires authorization. Public connections use HTTPS.

HUHU API uses an essential Secure, HttpOnly session cookie to restore console sign-in after a refresh or a later visit. OAuth tokens are encrypted on the server and are not exposed to page scripts or stored in browser local storage, session storage or IndexedDB. Product sessions last at most eight hours and expire after two hours without activity; IAM may require earlier verification. Signing out revokes this application session. IAM and Google maintain their own authentication cookies. This console does not include advertising trackers.

5. Retention and deletion

Account and linked identity records are retained while needed to provide access, administer the account and maintain security records. Imported account, mailbox and task data may remain until removed through the available management controls or by an administrator. Logging and backup retention is managed by the service operator; removal from the live service does not immediately erase every retained backup or security record.

To request access, correction or deletion, email yanghucheng134@gmail.com and identify the account and data concerned. We may ask you to verify that you control the account before acting. We will explain any records that must be retained and the applicable deletion process. Do not send passwords, tokens, cookies or verification codes by email.

6. Your choices

You can stop using the service, sign out, remove connected data where the relevant controls are available, or contact the administrator to close access. You can review or remove HUHU API's Google authorization in your Google Account connections. Removing Google authorization does not itself delete records already stored by IAM or HUHU API; contact us to request their removal.

7. Changes and contact

Updates to this policy will be published on this page with a revised date. Changes to the use of Google data will be disclosed before that new use begins and, where required, will require renewed consent.

Service operator: HUHU API administrator. Support and privacy contact: yanghucheng134@gmail.com.