Privacy Policy
This Privacy Policy describes how Doc-Scribe.ai ("we", "us", "our") collects, uses, and protects information when you use our document intelligence platform (the "Service"). By using the Service you consent to the practices described here.
1. Information we collect
Account & usage data
- Account information — name, email, organization, role, and language preference you provide at sign-up.
- Documents you upload — files you or your organization add to the platform, along with derived text, embeddings, and metadata used to power search and AI features.
- Usage telemetry — page views, feature interactions, error reports, and audit-log entries needed to operate the Service, troubleshoot issues, and satisfy security-compliance obligations.
- Technical data — IP address, user-agent, session identifiers, retained for the duration required by the region's applicable data-protection regime.
Cloud storage integrations (Google Drive, Dropbox, OneDrive)
Doc-Scribe.ai offers optional integrations with Google Drive, Dropbox, and Microsoft OneDrive. They are off by default. You enable one by completing that provider's OAuth consent flow and then linking one specific folder to a category in Doc-Scribe.ai. For all three providers:
- Folder-scoped — we read only the folder you explicitly select in the provider's own picker, and never traverse or read files outside it.
- Read-only — we request read-only scopes only, and never write to, modify, rename, or delete anything in your cloud storage account.
- One-way — sync runs in a single direction (provider → Doc-Scribe.ai). Nothing you do inside Doc-Scribe.ai is pushed back to your cloud storage.
- Imported into your tenant — file contents are copied into your organization's private tenant storage in Amazon S3 (encrypted at rest with AES-256) and indexed for AI-powered search, summarization, and metadata extraction.
Data received from Google Drive
When you connect a Google Drive account to Doc-Scribe.ai, the Service uses Google's OAuth
2.0 flow to request read-only access to your Drive (drive.readonly scope).
You explicitly pick a single folder using Google's official folder picker. Doc-Scribe.ai
never reads files outside that folder.
The following is transferred from Google to Doc-Scribe.ai:
- File contents for the files inside the folder you selected — copied into your Doc-Scribe.ai tenant's storage in Amazon S3 (region-specific to your deployment) and processed for search, summarization, and metadata extraction. Files are stored encrypted at rest with AES-256 (S3 server-side encryption).
- File metadata (name, size, MIME type, modification time, folder path) — used to preserve folder structure and detect changes on subsequent syncs.
- Your email address — via the
userinfo.emailscope, so syncs performed on your behalf can be attributed to your account in Doc-Scribe.ai's audit log.
Data received from Dropbox
When you connect a Dropbox account to Doc-Scribe.ai, the Service uses Dropbox's OAuth 2.0
flow to request the read-only scopes files.metadata.read,
files.content.read, and account_info.read. You explicitly pick a
single folder using the official Dropbox Chooser. Doc-Scribe.ai never reads files outside
that folder.
The following is transferred from Dropbox to Doc-Scribe.ai:
- File contents for the files inside the folder you selected — copied into your Doc-Scribe.ai tenant's storage in Amazon S3 (region-specific to your deployment) and processed for search, summarization, and metadata extraction. Files are stored encrypted at rest with AES-256 (S3 server-side encryption).
- File metadata (name, size, folder path, content hash, revision, and server-modified time) — used to preserve folder structure and to detect changes on subsequent syncs.
- Your Dropbox account email and account ID — read once at connection time so the connected account can be shown in the Doc-Scribe.ai interface and syncs performed on your behalf can be attributed to your account in the audit log.
Doc-Scribe.ai calls only Dropbox's read endpoints — /2/files/list_folder,
/2/files/list_folder/continue,
/2/files/list_folder/get_latest_cursor, /2/files/download, and
/2/users/get_current_account. No Dropbox endpoint that writes, moves, shares,
or deletes content is ever called.
Data received from Microsoft OneDrive
When you connect a OneDrive account to Doc-Scribe.ai, the Service uses Microsoft's OAuth
2.0 flow to request the scopes Files.Read.All, User.Read, and
offline_access. offline_access is required only so that sync can
continue in the background without prompting you to sign in repeatedly; it grants no
additional access to content. You explicitly pick a single folder, and Doc-Scribe.ai never
reads files outside it.
The following is transferred from Microsoft to Doc-Scribe.ai:
- File contents for the files inside the folder you selected — copied into your Doc-Scribe.ai tenant's storage in Amazon S3 and processed for search, summarization, and metadata extraction, encrypted at rest with AES-256.
- File metadata (name, size, MIME type, item ID, parent folder path, and modification time) via the Microsoft Graph delta API — used to preserve folder structure and detect changes on subsequent syncs.
- Your basic profile (name, email address) via
User.Read— so the connected account can be shown in the interface and syncs can be attributed in the audit log.
For every cloud storage integration, Doc-Scribe.ai does not:
- Traverse or read files outside the folder you explicitly picked.
- Modify, write to, rename, or delete anything in your Google Drive, Dropbox, or OneDrive account.
- Share data derived from these services with third parties for advertising, profiling, or any purpose unrelated to the document management features you configured. The only sub-processors that receive this content are the AI providers named in section 3.
- Use data received from these services to train, retrain, or fine-tune any general-purpose machine-learning model. AI features (search, summarization) call third-party model APIs on demand and pass only the specific document content required to answer your request; no training occurs.
2. How we use information
- To provide the Service — indexing, search, summarization, extraction, sync, and other features you have configured.
- To secure the Service — abuse detection, audit logging, incident response.
- To communicate with you — service notifications, security alerts, and, only where you have opted in, product updates.
- To comply with legal obligations — retaining records where a jurisdiction's law requires it.
3. AI processing
AI features (chat, summarization, tag extraction, semantic search) call third-party foundation-model APIs — currently Amazon Bedrock (Anthropic Claude, Amazon Nova) — on demand. Only the specific document content required to answer a user request is sent, scoped to what that user is authorised to see. Model providers do not use Doc-Scribe.ai customer data for training under their Bedrock terms of service.
4. Data retention
Documents remain in your tenant's storage until you delete them within Doc-Scribe.ai or your organization's tenant is closed. Deleted files move to the platform's trash and are permanently removed after the retention window configured for your tenant (default 30 days).
For cloud storage integrations specifically: you can disconnect Google Drive, Dropbox, or OneDrive at any time from a category's settings, or revoke Doc-Scribe.ai's access directly in your Google, Dropbox, or Microsoft account settings. Disconnecting removes the stored OAuth refresh token immediately, and no further syncs will run until you reconnect and grant consent again. Files already imported before disconnect remain in your Doc-Scribe.ai tenant, subject to the retention rules above, until you delete them.
5. Security
- Encryption in transit — TLS 1.2+ for every network hop.
- Encryption at rest — AWS-managed AES-256 for object storage and DynamoDB.
- Token security — OAuth refresh tokens for Google Drive, Dropbox, and OneDrive are encrypted with a dedicated AWS KMS key (per-deployment, annual rotation, retain-on-delete) before being written to DynamoDB. Access tokens are minted on demand from the refresh token and are never persisted.
- Access control — role-based access, tenant isolation at the partition-key level, audit logging on every mutating action.
- Least privilege — each service component operates with the minimum IAM permissions required.
6. Data location
Your data is stored in the Amazon Web Services region of the specific Doc-Scribe.ai
deployment your organization uses (for example, ap-southeast-2 Sydney or
us-east-1 Virginia). Copies are not made outside that region.
7. Your rights
Depending on your jurisdiction (GDPR, CCPA, PDPA, etc.), you may have rights to access, correct, export, or delete your personal information. Contact support@doc-scribe.ai to exercise them. We respond within the timeframe required by the applicable law.
8. Children
Doc-Scribe.ai is not directed to individuals under 16 and we do not knowingly collect information from them.
9. Changes to this policy
We update this policy from time to time. Material changes will be notified via the Service or by email to your tenant's administrator. The "Last updated" date at the top reflects the latest revision.
10. Third-party API disclosures
Google. Doc-Scribe.ai's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Dropbox. Doc-Scribe.ai's use of the Dropbox API adheres to the Dropbox API Terms and Conditions and the Dropbox Developer Branding Guidelines. Information received from the Dropbox API is used solely to provide the document management features you have configured. It is not sold, is not used for advertising or profiling, and is not used to train or fine-tune general-purpose machine-learning models.
Microsoft. Doc-Scribe.ai's use of Microsoft Graph adheres to the Microsoft APIs Terms of Use, on the same basis: information received is used only to provide the features you configured, and is never sold, used for advertising, or used for model training.
11. Contact
Questions about this policy or our data practices go to support@doc-scribe.ai.