emploidai Marketplace

Google Cloud Tools privacy policy

Policy content supplied in the product package by its publisher.

← Back to Google Cloud Tools

Privacy Policy

This document describes how the Google Cloud Tools plugin for Dify handles data. The plugin acts as a thin wrapper around Google Cloud Storage (GCS) APIs and processes only the information required to complete each tool invocation. No analytics or marketing telemetry is collected.

Data Collection

  • User inputs. Bucket names, object paths, prefixes, uploaded files, and text bodies that you explicitly provide through a tool are forwarded to GCS solely to execute that request.
  • Configuration metadata. The Service Account JSON plus the optional "Project ID (optional)" / "Bucket Name (任意)" / "Location (任意)" fields from the provider UI are held only in the plugin runtime to authenticate requests with google-cloud-storage. None of these values are persisted to disk.
  • Responses from GCS. Object metadata, payloads, or signed URLs returned by GCS are streamed back to Dify. The plugin does not keep copies for later use.

Data Usage

  • Inputs are transmitted to Google Cloud Storage for listing objects, downloading content, uploading files, deleting objects, or generating signed URLs—depending on the tool you call.
  • Outputs are passed straight to your workflow or agent after light formatting (JSON wrapping, Base64 encoding when requested). The plugin never reuses the data for training or secondary analysis.

Data Storage

  • The plugin does not store user inputs or outputs on disk. Temporary variables live only in memory during the request lifecycle.
  • When you upload content via gcs_upload_object, the binary/text is stored in your GCS bucket under the path you specify. The plugin itself retains nothing after the API call completes.

Third-party Services

  • The only external service contacted is Google Cloud Storage through official Google APIs. No other third parties receive your data.

Security

  • All calls are made over HTTPS via the google-cloud-storage client libraries. Service Account secrets are instantiated in memory and protected by a log filter that masks private_key, client_email, and related fields.
  • IAM policies, bucket ACLs, and signed URL lifetimes remain under your control. The plugin operates strictly within the permissions granted to the supplied Service Account.
  • No AWS or other cloud credentials are stored in this repository; only the active Google Cloud Tools plugin remains after repository cleanup.

If you have any privacy questions, please open an issue in this repository or reach out to the maintainer directly.