Privacy Policy
Last updated: August 3, 2026
DocumindAI ("we", "us", "the application") is a grounded document question-answering product operated for users of the DocumindAI web application at https://documinai.in. This privacy policy describes how DocumindAI accesses, uses, stores, shares, and protects personal data — including Google user data — when you use the service. If we change how we use Google user data, we will update this policy and the "Last updated" date above.
Information we collect
- Account data — email address, display name, and authentication identifiers from Firebase Authentication, including Google Sign-In when you choose that sign-in method.
- Workspace data — documents you upload, chat queries, generated answers, and citations, stored under your tenant.
- Bring-your-own credentials — API keys and cloud configuration you supply (Cohere, Pinecone, Google Cloud Storage service-account JSON). These are encrypted at rest and used only to operate your workspace.
- Technical logs — request metadata such as timestamps, status codes, and tenant/user identifiers for reliability and abuse prevention. We do not log raw API secrets or full document bodies in application logs.
Google user data DocumindAI accesses
DocumindAI may access Google user data in two separate flows, only when you choose them:
- Google Sign-In (Firebase Authentication) — your Google account email, display name, and a stable user identifier used to create or sign in to your DocumindAI account.
-
Google Cloud OAuth (optional storage setup) — when
you use "Sign in with Google" on the credentials setup page to provision
Cloud Storage, DocumindAI requests these scopes and accesses the
corresponding data:
- OpenID / email — your Google account email to associate the consenting user with the setup session.
- Cloud Platform projects (read-only) — the list of GCP projects visible to your account so you can select one.
- Cloud Storage (full control) — ability to list/create buckets and set bucket IAM in the project you select.
- IAM — ability to create a service account and mint a JSON key scoped for that bucket.
How DocumindAI uses Google user data
We use Google user data solely to provide and improve DocumindAI's user-facing features:
- Authenticate you and maintain your DocumindAI account session.
- Let you choose a GCP project and Cloud Storage bucket for your documents.
- Provision a bucket-scoped service account so DocumindAI can store and retrieve documents you upload for question-answering.
- Prevent abuse and troubleshoot reliability issues using technical logs.
DocumindAI does not use Google user data for targeted advertising, selling to data brokers, credit or lending decisions, or to develop, improve, or train non-personalized AI and/or ML models. Google APIs accessed by DocumindAI are not used to train generalized AI/ML models.
Storage of Google user data
After a successful Cloud Storage setup we discard the short-lived Google OAuth access token used for provisioning. We do not retain your Google OAuth refresh token. We store only the encrypted service-account JSON key you authorized, under your tenant, so DocumindAI can continue to read and write objects in the bucket you selected. Account email and identifiers from Google Sign-In are stored in Firebase Authentication and related Firestore profile records needed to operate your account.
Sharing, transfer, and disclosure
We do not sell Google user data. We do not transfer or disclose Google user data to third parties for advertising, data brokerage, or training generalized AI/ML models. Limited disclosure may occur only as needed to operate the service you requested:
- Google Cloud Platform APIs — to perform the provisioning actions you authorized (list projects, manage the selected bucket, create the service account).
- Infrastructure processors that host DocumindAI (for example Firebase / Google Cloud for the application itself) under contractual confidentiality obligations.
- When required by law, legal process, or to protect the security of the service and its users.
Your own Cohere, Pinecone, and Google Cloud Storage usage under credentials you provide is billed to and governed by those providers; DocumindAI does not resell that data.
Data protection
Security procedures are in place to protect the confidentiality of your data. Tenant API keys and Google Cloud service-account credentials are encrypted at rest using application-level encryption before storage. Access to tenant data is gated by authenticated sessions and role-based permissions. Transport uses HTTPS. We limit logging of secrets and document contents.
Retention and deletion
We retain personal information for as long as needed to provide DocumindAI and fulfill the purposes in this policy, unless a longer period is required by law. You may delete uploaded documents and disconnect Cohere, Pinecone, or Google Cloud Storage credentials from the product UI at any time. Disconnecting Google Cloud credentials removes the stored encrypted service-account key from DocumindAI; it does not automatically delete the GCP project, bucket, or service account in your Google Cloud project — you remain responsible for those resources.
You may revoke DocumindAI's Google authorizations in Google Account → Third-party access. To request deletion of your DocumindAI account and associated personal data, contact the support email listed on the Google OAuth consent screen for DocumindAI. When a retention period expires for a given data type, we delete or destroy it, subject to legal and security backup requirements that may briefly persist.
Changes to this policy
We may update this privacy policy. When we do, we will revise the "Last updated" date. Material changes to how we use Google user data will be reflected here before those changes take effect.
Contact
Questions about this policy or DocumindAI's handling of Google user data: use the support email on the Google OAuth consent screen for DocumindAI, or contact the project maintainers.
See also our Terms of Service.