Legal

Privacy Policy

Last updated: 8 September 2026

This Privacy Policy describes how Doc-Scribe.ai ("we", "us", "our") collects, uses, and protects information when you use our document intelligence platform (the "Service"). By using the Service you consent to the practices described here.

1. Information we collect

Account & usage data

Cloud storage integrations (Google Drive, Dropbox, OneDrive)

Doc-Scribe.ai offers optional integrations with Google Drive, Dropbox, and Microsoft OneDrive. They are off by default. You enable one by completing that provider's OAuth consent flow and then linking one specific folder to a category in Doc-Scribe.ai. For all three providers:

Data received from Google Drive

When you connect a Google Drive account to Doc-Scribe.ai, the Service uses Google's OAuth 2.0 flow to request read-only access to your Drive (drive.readonly scope). You explicitly pick a single folder using Google's official folder picker. Doc-Scribe.ai never reads files outside that folder.

The following is transferred from Google to Doc-Scribe.ai:

Data received from Dropbox

When you connect a Dropbox account to Doc-Scribe.ai, the Service uses Dropbox's OAuth 2.0 flow to request the read-only scopes files.metadata.read, files.content.read, and account_info.read. You explicitly pick a single folder using the official Dropbox Chooser. Doc-Scribe.ai never reads files outside that folder.

The following is transferred from Dropbox to Doc-Scribe.ai:

Doc-Scribe.ai calls only Dropbox's read endpoints — /2/files/list_folder, /2/files/list_folder/continue, /2/files/list_folder/get_latest_cursor, /2/files/download, and /2/users/get_current_account. No Dropbox endpoint that writes, moves, shares, or deletes content is ever called.

Data received from Microsoft OneDrive

When you connect a OneDrive account to Doc-Scribe.ai, the Service uses Microsoft's OAuth 2.0 flow to request the scopes Files.Read.All, User.Read, and offline_access. offline_access is required only so that sync can continue in the background without prompting you to sign in repeatedly; it grants no additional access to content. You explicitly pick a single folder, and Doc-Scribe.ai never reads files outside it.

The following is transferred from Microsoft to Doc-Scribe.ai:

For every cloud storage integration, Doc-Scribe.ai does not:

2. How we use information

3. AI processing

AI features (chat, summarization, tag extraction, semantic search) call third-party foundation-model APIs — currently Amazon Bedrock (Anthropic Claude, Amazon Nova) — on demand. Only the specific document content required to answer a user request is sent, scoped to what that user is authorised to see. Model providers do not use Doc-Scribe.ai customer data for training under their Bedrock terms of service.

4. Data retention

Documents remain in your tenant's storage until you delete them within Doc-Scribe.ai or your organization's tenant is closed. Deleted files move to the platform's trash and are permanently removed after the retention window configured for your tenant (default 30 days).

For cloud storage integrations specifically: you can disconnect Google Drive, Dropbox, or OneDrive at any time from a category's settings, or revoke Doc-Scribe.ai's access directly in your Google, Dropbox, or Microsoft account settings. Disconnecting removes the stored OAuth refresh token immediately, and no further syncs will run until you reconnect and grant consent again. Files already imported before disconnect remain in your Doc-Scribe.ai tenant, subject to the retention rules above, until you delete them.

5. Security

6. Data location

Your data is stored in the Amazon Web Services region of the specific Doc-Scribe.ai deployment your organization uses (for example, ap-southeast-2 Sydney or us-east-1 Virginia). Copies are not made outside that region.

7. Your rights

Depending on your jurisdiction (GDPR, CCPA, PDPA, etc.), you may have rights to access, correct, export, or delete your personal information. Contact support@doc-scribe.ai to exercise them. We respond within the timeframe required by the applicable law.

8. Children

Doc-Scribe.ai is not directed to individuals under 16 and we do not knowingly collect information from them.

9. Changes to this policy

We update this policy from time to time. Material changes will be notified via the Service or by email to your tenant's administrator. The "Last updated" date at the top reflects the latest revision.

10. Third-party API disclosures

Google. Doc-Scribe.ai's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Dropbox. Doc-Scribe.ai's use of the Dropbox API adheres to the Dropbox API Terms and Conditions and the Dropbox Developer Branding Guidelines. Information received from the Dropbox API is used solely to provide the document management features you have configured. It is not sold, is not used for advertising or profiling, and is not used to train or fine-tune general-purpose machine-learning models.

Microsoft. Doc-Scribe.ai's use of Microsoft Graph adheres to the Microsoft APIs Terms of Use, on the same basis: information received is used only to provide the features you configured, and is never sold, used for advertising, or used for model training.

11. Contact

Questions about this policy or our data practices go to support@doc-scribe.ai.